Allied-telesis AT-S63 User Manual

Browse online or download User Manual for Computer hardware Allied-telesis AT-S63. Allied Telesis AT-S63 User Manual [en] [es] [fr]

  • Download
  • Add to my manuals
  • Print
  • Page
    / 710
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 0
Management
Software
AT-S63
Menus Interface
User’s Guide
AT-9424T/SP AND AT-9424T/GB
LAYER 2+ GIGABIT ETHERNET SWITCHES
VERSION 1.0.0
®
PN 613-50570-00 Rev A
Page view 0
1 2 3 4 5 6 ... 709 710

Summary of Contents

Page 1 - User’s Guide

Management SoftwareAT-S63◆Menus InterfaceUser’s GuideAT-9424T/SP AND AT-9424T/GBLAYER 2+ GIGABIT ETHERNET SWITCHESVERSION 1.0.0®PN 613-50570-00 Rev A

Page 2

Contents10GARP VLAN Registration Protocol ...

Page 3

Chapter 5: Enhanced Stacking100 Section I: Basic FeaturesSelecting a Switch in an Enhanced StackBefore you perform a procedure on a switch in an enhan

Page 4

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 1013. From the Stacking Services menu, type 1 to select Get/Refresh L

Page 5 - Section II

Chapter 5: Enhanced Stacking102 Section I: Basic Features5. Type the number of the switch in the list you want to manage.A prompt is displayed if the

Page 6

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 103Returning to the Master Switch When you have finished managing a s

Page 7

Chapter 5: Enhanced Stacking104 Section I: Basic FeaturesDisplaying the Enhanced Stacking StatusTo view the stacking status of a switch in a stack, pe

Page 8

Section I: Basic Features 105Chapter 6Port ParametersThis chapter contains the procedures for viewing and changing the parameter settings for the indi

Page 9

Chapter 6: Port Parameters106 Section I: Basic FeaturesConfiguring Port ParametersTo configure the most basic parameter settings for a port, perform t

Page 10 - Section IV

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 107The Port Configuration menu is shown in Figure 27.Figure 27. Port

Page 11

Chapter 6: Port Parameters108 Section I: Basic Featuresto the port. After the problem has been fixed, you can enable the port again to resume normal o

Page 12 - Contents

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 109A switch port using autonegotiation defaults to half-duplex if it

Page 13

AT-S63 Management Software Menus Interface User’s Guide11Configuring the Web Server ...

Page 14

Chapter 6: Port Parameters110 Section I: Basic Featuresthrough or crossover twisted pair cable when connecting any network device to a port on the swi

Page 15

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 111Configuring Head of Line BlockingHead of line (HOL) blocking is a

Page 16

Chapter 6: Port Parameters112 Section I: Basic FeaturesFor example, referring to the figure above, when the utilization of the storage capacity of por

Page 17

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 113Configuring Flow Control and Back PressureA switch port uses flow

Page 18

Chapter 6: Port Parameters114 Section I: Basic Features3. Enter the number of the port you want to configure. To configure a range of ports, enter the

Page 19

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 1158. Type 4 to select Back Pressure Threshold. This selection specif

Page 20

Chapter 6: Port Parameters116 Section I: Basic FeaturesConfiguring FilteringIf the performance of your network is affected by heavy traffic, you can u

Page 21

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 1176. Type 2 to toggle Unknown Multicast Filtering between Disabled a

Page 22

Chapter 6: Port Parameters118 Section I: Basic FeaturesSetting Up Rate LimitingThe rate limiting feature allows you to set the maximum number of ingre

Page 23 - How This Guide is Organized

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 119A prompt is displayed:Enter the Rate Limit (packets/second):[0 to

Page 24

Contents12Deleting a Certificate ...

Page 25 - Document Conventions

Chapter 6: Port Parameters120 Section I: Basic FeaturesResetting a PortResetting a port is useful in situations where a port is having problems establ

Page 26

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 121Forcing Port RenegotiationPort renegotiation prompts the port to a

Page 27 - Contacting Allied Telesyn

Chapter 6: Port Parameters122 Section I: Basic FeaturesResetting the Port Configuration to the DefaultsYou can return port settings to the default val

Page 28 - Management Software Updates

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 123Displaying Port StatisticsTo display Ethernet port statistics, per

Page 29 - Overview

Chapter 6: Port Parameters124 Section I: Basic FeaturesThe Display Port Statistics menu is shown in Figure 33. Figure 33. Display Port Statistics Men

Page 30 - Management Overview

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 125Multicast Frames SentNumber of multicast frames transmitted from t

Page 31

Chapter 6: Port Parameters126 Section I: Basic FeaturesClearing Port StatisticsTo clear the Ethernet port statistics and reset them to “0”, perform th

Page 32 - Local Management Session

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 127Displaying Port StatusTo display the current status of the ports o

Page 33 - Telnet Management Session

Chapter 6: Port Parameters128 Section I: Basic FeaturesUp - Indicates that a valid link exists between the port and the end node. Down - Indicates tha

Page 34 - Chapter 1: Overview

Section I: Basic Features 129Chapter 7MAC Address TableThe chapter contains the procedures for viewing the static and dynamic MAC address table.This c

Page 35 - SNMP Management Session

AT-S63 Management Software Menus Interface User’s Guide13IP Options Attack ...

Page 36 - Management Access Levels

Chapter 7: MAC Address Table130 Section I: Basic FeaturesMAC Address OverviewEach hardware device that you connect to your Ethernet network has a uniq

Page 37 - Basic Features

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 131learns by examining the source MAC addresses of the frames receive

Page 38 - 38 Section I: Basic Features

Chapter 7: MAC Address Table132 Section I: Basic FeaturesDisplaying the MAC Address TablesThe AT-S63 management software has two menu selections for d

Page 39 - Management Session

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 133Choose one of the following display types.1 - Display AllThis sele

Page 40

Chapter 7: MAC Address Table134 Section I: Basic FeaturesTypeThe type of the address: static or dynamic.An example of a multicast MAC address table is

Page 41 - Section I: Basic Features 41

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 1353 - Display DynamicThis selection displays only the dynamic addres

Page 42 - Stacking

Chapter 7: MAC Address Table136 Section I: Basic FeaturesAdding Static Unicast and Multicast MAC AddressesThis section contains the procedure for addi

Page 43 - Quitting a Local

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 137If you are entering a static multicast address, you must specify t

Page 44

Chapter 7: MAC Address Table138 Section I: Basic FeaturesDeleting Unicast and Multicast MAC AddressesTo delete a dynamic or static unicast or multicas

Page 45 - Quitting a

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 139Deleting All Dynamic MAC AddressesTo delete all dynamic unicast an

Page 47 - Basic Switch Parameters

Chapter 7: MAC Address Table140 Section I: Basic FeaturesChanging the Aging TimeThe switch uses the aging time to delete inactive dynamic MAC addresse

Page 48 - 48 Section I: Basic Features

Section I: Basic Features 141Chapter 8Port TrunkingThis chapter contains the procedures for creating, modifying, and deleting port trunks. Sections in

Page 49 - Section I: Basic Features 49

Chapter 8: Port Trunking142 Section I: Basic FeaturesPort Trunking OverviewA port trunk is an economical way for you to increase the bandwidth between

Page 50 - Address?

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 143❑ When you cable a trunk, the order of the connections should be m

Page 51

Chapter 8: Port Trunking144 Section I: Basic FeaturesThe AT-S63 management software offers six load distribution methods. They are: ❑ Source MAC Addre

Page 52 - 52 Section I: Basic Features

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 145data link provided by an SFP transceiver in switch #2.Figure 41.

Page 53 - Section I: Basic Features 53

Chapter 8: Port Trunking146 Section I: Basic FeaturesNote that packets sent back from the destination node to the original source node may travel the

Page 54 - 54 Section I: Basic Features

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 147Table 2 shows how switch #2 might distribute the server traffic ac

Page 55 - Section I: Basic Features 55

Chapter 8: Port Trunking148 Section I: Basic FeaturesThis method is useful when a port trunk needs to send packets from one source node to many destin

Page 56 - Information

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 149Creating a Port TrunkThis section contains the procedure for creat

Page 57 - Section I: Basic Features 57

15FiguresFigure 1: Connecting the Management Cable to the RJ-45 Serial Terminal Port ...

Page 58 - Rebooting a Switch

Chapter 8: Port Trunking150 Section I: Basic FeaturesThe Port Trunking menu is shown in Figure 42.Figure 42. Port Trunking Menu3. From the Port Trunk

Page 59 - Section I: Basic Features 59

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 151The following prompt is displayed:Enter Trunk Name:7. Type a name

Page 60 - 60 Section I: Basic Features

Chapter 8: Port Trunking152 Section I: Basic FeaturesModifying a Port TrunkThis section contains the procedure for modifying a port trunk on the switc

Page 61 - Section I: Basic Features 61

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 153The Modify Trunk menu is displayed. The menu displays the operatin

Page 62 - Setting the System Time

Chapter 8: Port Trunking154 Section I: Basic Features7. To change the ports of a trunk, type 4 to select Trunk Ports and, when prompted, enter the new

Page 63 - System Time

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 155Deleting a Port TrunkCautionDisconnect the cables from the port tr

Page 64 - D - Disabled) ->

Chapter 8: Port Trunking156 Section I: Basic FeaturesDisplaying the Port TrunksTo display a port trunk, perform the following procedure:1. From the Ma

Page 65 - -> 600

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 157SRC IP - Source IP address trunkingDST IP - Destination IP address

Page 66 - 66 Section I: Basic Features

Chapter 8: Port Trunking158 Section I: Basic Features

Page 67 - Configuring the Console Timer

Section I: Basic Features 159Chapter 9Port MirroringThis chapter contains the procedures for creating and deleting a port mirror. Sections in the chap

Page 68 - 68 Section I: Basic Features

Figures16Figure 38: Display All Menu - Multicast MAC Addresses ...

Page 69 - Supported baud rates are:

Chapter 9: Port Mirroring160 Section I: Basic FeaturesPort Mirroring OverviewThe port mirroring feature allows you to unobtrusively monitor the traffi

Page 70 - Pinging a Remote System

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 161Creating a Port MirrorTo create a port mirror, perform the followi

Page 71 - Default Values

Chapter 9: Port Mirroring162 Section I: Basic Features5. Type 2 to select Mirror-To (Destination) Port.The following prompt is displayed:Mirror-To Por

Page 72

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 163Disabling a Port MirrorTo delete a port mirror, perform the follow

Page 73 - Hardware

Chapter 9: Port Mirroring164 Section I: Basic FeaturesModifying a Port MirrorTo modify the port mirror, perform the following procedure:1. From the Ma

Page 74 - ° Celsius

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 165Displaying the Port MirrorTo display the port mirror, perform the

Page 75 - Section I: Basic Features 75

Chapter 9: Port Mirroring166 Section I: Basic Features

Page 76 - 76 Section I: Basic Features

167Section IIAdvanced FeaturesThe chapters in this section explain additional switch management features of the AT-S63 management software. The chapte

Page 77 - Section I: Basic Features 77

168 Section II: Advanced Features

Page 78 - 78 Section I: Basic Features

Section II: Advanced Features 169Chapter 10File SystemThe chapter describes the AT-S63 file system, and how you can use the file system to copy, renam

Page 79 - SNMPv1 and SNMPv2c

AT-S63 Management Software Menus Interface User’s Guide17Figure 93: CIST and VLAN Guideline - Example 2 ...

Page 80 - SNMPv1 and SNMPv2c Overview

Chapter 10: File System170 Section II: Advanced FeaturesFile System OverviewThe AT-S63 management software has a file system for storing system files.

Page 81

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 171where:❑ filename is a descriptive name for the file, and may b

Page 82 - Default SNMP

Chapter 10: File System172 Section II: Advanced FeaturesWorking with Boot Configuration FilesA boot configuration file contains a series of commands t

Page 83

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 173page 175Creating a Boot Configuration FileBefore you begin to

Page 84

Chapter 10: File System174 Section II: Advanced Features5. Enter a file name for the new boot configuration file. The file name can be up to 16 alphan

Page 85

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 175Selecting the Active Boot Configuration File for the SwitchYou

Page 86 - Enter Trap Receiver IP Addr:

Chapter 10: File System176 Section II: Advanced FeaturesThe file name is displayed following selection 1 in the File Operations menu. The file name sh

Page 87

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 177The contents of the boot configuration file are displayed in t

Page 88 - Modifying a Community String

Chapter 10: File System178 Section II: Advanced FeaturesThe following are several guidelines for editing a boot configuration file:❑ The text editor m

Page 89 - Enter SNMP Community Name:

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 179Copying a System FileTo copy a file in the file system, perfor

Page 90

Figures18Figure 148: GID Architecture ...

Page 91

Chapter 10: File System180 Section II: Advanced FeaturesRenaming a System FileTo rename a system file, perform the following procedure:1. From the Mai

Page 92

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 181Deleting a System FileTo delete a system file, perform the fol

Page 93 - Enhanced Stacking

Chapter 10: File System182 Section II: Advanced FeaturesDisplaying System FilesUse this procedure to display a list of the system files currently stor

Page 94 - Enhanced Stacking Overview

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 183The List Files menu is displayed. An example of the menu is sh

Page 95 - Section I: Basic Features 95

Chapter 10: File System184 Section II: Advanced Features

Page 96 - IP Address

Section I: Basic Features 185Chapter 11File Downloads and UploadsThis chapter contains the procedures for downloading a new AT-S63 image file onto the

Page 97 - Section I: Basic Features 97

Chapter 11: File Downloads and Uploads186 Section I: Basic FeaturesDownloading the AT-S63 Image File onto a SwitchThis section contains two procedures

Page 98 - 98 Section I: Basic Features

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 187Downloadingthe AT-S63Image from aLocalManagementSessionTo download

Page 99 - Section I: Basic Features 99

Chapter 11: File Downloads and Uploads188 Section I: Basic FeaturesThe following prompt is displayed:TFTP Server IP address:b. Enter the IP address of

Page 100 - 100 Section I: Basic Features

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 18910. From the HyperTerminal main window, select Send File from the

Page 101 - Section I: Basic Features 101

AT-S63 Management Software Menus Interface User’s Guide19Figure 203: Display Port Access Status Menu ...

Page 102 - 102 Section I: Basic Features

Chapter 11: File Downloads and Uploads190 Section I: Basic Featuresstatus of the software download. The download process takes several minutes to comp

Page 103 - Section I: Basic Features 103

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 1915. From the Downloads and Uploads menu, type 1 to select Download

Page 104 - 104 Section I: Basic Features

Chapter 11: File Downloads and Uploads192 Section I: Basic FeaturesDownloading an AT-S63 Image File Switch to SwitchThe previous section contained pro

Page 105 - Port Parameters

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 193NoteYou cannot download AT-S63 software onto any type of enhanced

Page 106 - Configuring Port Parameters

Chapter 11: File Downloads and Uploads194 Section I: Basic FeaturesDownloading an AT-S63 Configuration File Switch to SwitchThis procedure explains ho

Page 107 - Section I: Basic Features 107

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 195NoteYou can download an AT-9400 Series configuration file only ont

Page 108 - 108 Section I: Basic Features

Chapter 11: File Downloads and Uploads196 Section I: Basic FeaturesDownloading a System FileThis section contains the procedures for downloading a sys

Page 109 - Section I: Basic Features 109

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 197❑ If you are using TFTP, you should start the TFTP server before y

Page 110 - 110 Section I: Basic Features

Chapter 11: File Downloads and Uploads198 Section I: Basic FeaturesGetting the file from Remote TFTP Server - Please wait ...e. If you have not alread

Page 111 - Section I: Basic Features 111

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 199The Send File window is shown in Figure 54. Figure 57. Send File

Page 112 - Enter port-list ->

Copyright © 2004 Allied Telesyn, Inc. All rights reserved. No part of this publication may be reproduced without prior written permission from Allied

Page 113

Figures20

Page 114 - 114 Section I: Basic Features

Chapter 11: File Downloads and Uploads200 Section I: Basic FeaturesDownloading aSystem Filefrom a TelnetManagementSessionTo download a system file ont

Page 115 - Section I: Basic Features 115

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 201Uploading a System FileYou use the procedures in this section to u

Page 116 - Configuring Filtering

Chapter 11: File Downloads and Uploads202 Section I: Basic FeaturesUploading aSystem Filefrom a LocalManagementSessionTo upload a system file to a wor

Page 117 - Enabled

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 203After the switch has uploaded the system file, the following messa

Page 118 - Setting Up Rate Limiting

Chapter 11: File Downloads and Uploads204 Section I: Basic Features11. From the HyperTerminal main window, select select Receive File from the Transfe

Page 119 - Section I: Basic Features 119

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 205The System Utilities menu is shown in Figure 7 on page 58.3. From

Page 120 - Resetting a Port

Chapter 11: File Downloads and Uploads206 Section I: Basic Features

Page 121 - Forcing Port Renegotiation

Section II: Advanced Features 207Chapter 12Event LogThis chapter describes the event log that allows you to view information about network activity. S

Page 122

Chapter 12: Event Log208 Section II: Advanced FeaturesEvent Log OverviewA managed switch is a complex piece of computer equipment that includes both h

Page 123 - Displaying Port Statistics

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 209Enabling or Disabling the Event LogsTo enable or disable the e

Page 124 - 124 Section I: Basic Features

21TablesTable 1: Switch #1 - Source MAC Address Load Distribution ...

Page 125 - Section I: Basic Features 125

Chapter 12: Event Log210 Section II: Advanced Features4. To determine what action the switch takes when the event log reaches its maximum capacity, ty

Page 126 - Clearing Port Statistics

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 211Displaying EventsEach time that you want to view the event log

Page 127 - Displaying Port Status

Chapter 12: Event Log212 Section II: Advanced FeaturesFullDisplays the same information as Normal, plus the file name, line number, and event ID. An e

Page 128 - 128 Section I: Basic Features

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 213Table 6 shows the list of modules.Table 6. AT-S63 Software Mo

Page 129 - MAC Address Table

Chapter 12: Event Log214 Section II: Advanced FeaturesTo select specific modules, type the names separated by commas. The module names are not case se

Page 130 - MAC Address Overview

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 215Figure 62 shows an example of an event log in Normal mode. Fig

Page 131 - Section I: Basic Features 131

Chapter 12: Event Log216 Section II: Advanced FeaturesWhen you display the events in full mode, more information is included. Figure 63 shows the same

Page 132 - 132 Section I: Basic Features

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 217Clearing the Event LogYou can clear the event log to remove ol

Page 133 - Section I: Basic Features 133

Chapter 12: Event Log218 Section II: Advanced FeaturesSaving an Event Log to a FileYou can save anevent log to a file to review later. The file is sav

Page 134 - 134 Section I: Basic Features

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 219The File Operations menu is displayed, as shown in Figure 49 o

Page 136 - 136 Section I: Basic Features

Chapter 12: Event Log220 Section II: Advanced Features

Page 137 - Section I: Basic Features 137

Section II: Advanced Features 221Chapter 13Quality of ServiceThis chapter contains the procedures for configuring Quality of Service (QoS). Sections i

Page 138 - XXXXXX XXXXXX

Chapter 13: Quality of Service222 Section II: Advanced FeaturesQuality of Service OverviewWhen a port on an Ethernet switch becomes oversubscribed—its

Page 139 - Section I: Basic Features 139

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 223Each switch port has eight egress queues. The queues are Q0 th

Page 140 - Changing the Aging Time

Chapter 13: Quality of Service224 Section II: Advanced Featurespackets with a priority of 2 should be handled in Q0. The result is shown in Table 9.Th

Page 141 - Port Trunking

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 225Q3, the highest priority queue, before moving on to the other

Page 142 - Port Trunking Overview

Chapter 13: Quality of Service226 Section II: Advanced FeaturesTable 10 shows an example of weighted round robin priority scheduling.In this example,

Page 143 - Distribution

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 227Configuring CoSAs explained in ”Quality of Service Overview” o

Page 144 - 144 Section I: Basic Features

Chapter 13: Quality of Service228 Section II: Advanced FeaturesThe Class of Service (CoS) menu is shown in Figure 65.Figure 65. Class of Service (CoS

Page 145 - Workstation D

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 2295. Enter a value from 0to 7 that corresponds to the egress que

Page 146 - 146 Section I: Basic Features

23PrefaceThis guide contains instructions on how to configure an AT-9400 Series Layer 2+ Gigabit Ethernet Switch using the AT-S63 management software

Page 147 - Section I: Basic Features 147

Chapter 13: Quality of Service230 Section II: Advanced FeaturesMapping CoS Priorities to Egress QueuesThis procedure explains how to change the defaul

Page 148 - 148 Section I: Basic Features

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 231Configuring Egress SchedulingThis procedure explains how to se

Page 149 - Creating a Port Trunk

Chapter 13: Quality of Service232 Section II: Advanced FeaturesLeaving the default value of 1 for each queue gives all egress queues the same weight.5

Page 150 - 150 Section I: Basic Features

Section II: Advanced Features 233Chapter 14IGMP SnoopingThis chapter explains how to activate and configure the Internet Group Management Protocol (IG

Page 151 - Enter Trunk Name:

Chapter 14: IGMP Snooping234 Section II: Advanced FeaturesIGMP Snooping OverviewThe IGMP snooping protocol enables routers to create lists of nodes th

Page 152 - Modifying a Port Trunk

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 235Without IGMP snooping a switch would be obligated to flood mul

Page 153 - Section I: Basic Features 153

Chapter 14: IGMP Snooping236 Section II: Advanced FeaturesConfiguring IGMP SnoopingTo configure IGMP snooping on the switch, perform the following pro

Page 154 - 154 Section I: Basic Features

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 2373. Adjust the following parameters as necessary:1 - IGMP Snoop

Page 155 - Deleting a Port Trunk

Chapter 14: IGMP Snooping238 Section II: Advanced FeaturesWhen you select a value for this parameter, it is important to note that the value you enter

Page 156 - Displaying the Port Trunks

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 239Enabling or Disabling IGMP SnoopingTo configure IGMP snooping

Page 157 - Section I: Basic Features 157

Preface24lists, encryption, web server, port-based access control, Denial of Service, TACACS+ and RADIUS.For information on managing a AT-9400 Series

Page 158 - 158 Section I: Basic Features

Chapter 14: IGMP Snooping240 Section II: Advanced FeaturesDisplaying a List of Host NodesYou can use the AT-S63 management software to display a list

Page 159 - Port Mirroring

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 241Port/TrunkThe port on the switch to which a host node of the m

Page 160 - Port Mirroring Overview

Chapter 14: IGMP Snooping242 Section II: Advanced FeaturesDisplaying a List of Multicast RoutersA multicast router is a router that is receiving multi

Page 161 - Creating a Port Mirror

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 243Router IPThe IP address of the multicast router.

Page 162 - Mirror-To Port (0-24):

Chapter 14: IGMP Snooping244 Section II: Advanced Features

Page 163 - Disabling a Port Mirror

Section II: Advanced Features 245 Chapter 15RRP SnoopingThis chapter explains RRP snooping and contains the following sections: ❑ ”RRP Snooping Overvi

Page 164 - Modifying a Port Mirror

Chapter 15: RRP Snooping246 Section II: Advanced FeaturesRRP Snooping OverviewThe Router Redundancy Protocol (RRP) allows multiple routers to share th

Page 165 - Displaying the Port Mirror

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 247The following guidelines apply to the RRP snooping feature:❑ T

Page 166 - 166 Section I: Basic Features

Chapter 15: RRP Snooping248 Section II: Advanced FeaturesEnabling or Disabling RRP SnoopingTo enable or disable RRP snooping on a switch, perform the

Page 167 - Advanced Features

Section II: Advanced Features 249Chapter 16STP and RSTPThis chapter provides background information on the Spanning Tree Protocol (STP) and Rapid Span

Page 168

AT-S63 Management Software Menus Interface User’s Guide25Document ConventionsThis document uses the following conventions:NoteNotes provide additional

Page 169 - File System

Chapter 16: STP and RSTP250 Section II: Advanced FeaturesSTP and RSTP OverviewThe performance of a Ethernet network can be negatively impacted by the

Page 170 - File System Overview

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 251Bridge Priorityand the RootBridgeThe first task that bridges p

Page 171 - Groups of Files

Chapter 16: STP and RSTP252 Section II: Advanced FeaturesPath Costs and Port CostsAfter the root bridge has been selected, the bridges must determine

Page 172 - Configuration

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 253Table 14 lists the STP port costs with Auto-Detect when a port

Page 173

Chapter 16: STP and RSTP254 Section II: Advanced Featurespriority for a port, you enter the increment of the desired value. Table 17 lists the values

Page 174 - Enter the file name:

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 255root bridge sufficient time to propagate a topology change thr

Page 175 - Active Boot

Chapter 16: STP and RSTP256 Section II: Advanced FeaturesSeries switches that have been connected with one data link. With the link operating in full-

Page 176 - Viewing a Boot

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 257A port can be both a point-to-point and an edge port at the sa

Page 177 - Editing a Boot

Chapter 16: STP and RSTP258 Section II: Advanced Featureson the switches, one of the links is disabled. In the example, the port on the top switch tha

Page 178 - Chapter 10: File System

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 259Enabling or Disabling a Spanning Tree ProtocolThe AT-S63 manag

Page 179 - Copying a System File

Preface26Where to Find Web-based GuidesThe installation and user guides for all Allied Telesyn products are available in portable document format (PDF

Page 180 - Renaming a System File

Chapter 16: STP and RSTP260 Section II: Advanced Features4. If you selected STP as the active spanning tree protocol, go to ”Configuring STP” on page

Page 181 - Deleting a System File

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 261Configuring STPThis section contains the following procedures:

Page 182 - Displaying System Files

Chapter 16: STP and RSTP262 Section II: Advanced Features3. Adjust the following parameters as needed.1 - Bridge PriorityThe priority number for the b

Page 183

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 2634. After making changes, type R until you return to the Main M

Page 184

Chapter 16: STP and RSTP264 Section II: Advanced FeaturesThe Configure STP Port Settings menu is shown in Figure 81.Figure 81. Configure STP Port Set

Page 185 - File Downloads and Uploads

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 265Displaying STPPort SettingsTo display STP port settings, perfo

Page 186 - 186 Section I: Basic Features

Chapter 16: STP and RSTP266 Section II: Advanced FeaturesCostPort cost of the port. The default is Auto-Update.Priority The number used as a tie break

Page 187 - Section I: Basic Features 187

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 267Configuring RSTPThis section contains the following procedures

Page 188 - 188 Section I: Basic Features

Chapter 16: STP and RSTP268 Section II: Advanced Features3. Adjust the following parameters as necessary.1 - Force VersionThis selection determines wh

Page 189 - Section I: Basic Features 189

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 2696 - Bridge IdentifierThe MAC address of the bridge. The bridge

Page 190 - 190 Section I: Basic Features

AT-S63 Management Software Menus Interface User’s Guide27Contacting Allied TelesynThis section provides Allied Telesyn contact information for technic

Page 191 - Section I: Basic Features 191

Chapter 16: STP and RSTP270 Section II: Advanced Features4. Enter the number of the port you want to configure. To configure a range of ports, enter t

Page 192 - 192 Section I: Basic Features

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 2713 - Point-to-PointThis parameter defines whether the port is f

Page 193 - -> [Yes/No]

Chapter 16: STP and RSTP272 Section II: Advanced FeaturesThe Display RSTP Port Configuration menu is shown in Figure 86.Figure 86. Display RSTP Port

Page 194 - 194 Section I: Basic Features

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 273The Spanning Tree Configuration menu is shown in Figure 78 on

Page 195

Chapter 16: STP and RSTP274 Section II: Advanced Features❑ Learning - The port is enabled for receiving, but not forwarding packets.❑ Forwarding - Nor

Page 196 - Downloading a System File

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 2754. Type Y for Yes or N for No and press Return.The RSTP config

Page 197 - Management

Chapter 16: STP and RSTP276 Section II: Advanced Features

Page 198 - 198 Section I: Basic Features

Section II: Advanced Features 277Chapter 17MSTPThis chapter provides background information on the Multiple Spanning Tree Protocol (MSTP) and contains

Page 199 - Section I: Basic Features 199

Chapter 17: MSTP278 Section II: Advanced FeaturesMSTP OverviewAs mentioned in Chapter 16, ”STP and RSTP” on page 249, STP and RSTP are referred to as

Page 200

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 279Multiple Spanning Tree Instance (MSTI)The individual spanning

Page 201 - Uploading a System File

Preface28Management Software UpdatesNew releases of management software for our managed products are available for download from either of the followi

Page 202 - Uploading a

Chapter 17: MSTP280 Section II: Advanced FeaturesIn Figure 88, the link between the two parts of the Production VLAN is blocked, resulting in a loss o

Page 203 - Section I: Basic Features 203

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 281Figure 89 illustrates the same two AT-9400 Series switches and

Page 204

Chapter 17: MSTP282 Section II: Advanced FeaturesA MSTI can contain more than one VLAN. This is illustrated in Figure 90 where there are two AT-9400 S

Page 205 - Section I: Basic Features 205

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 283❑ An AT-9400 Series switch can support up to 16 spanning tree

Page 206 - 206 Section I: Basic Features

Chapter 17: MSTP284 Section II: Advanced Featuresthat you maintain this number, only that each bridge in a region have the same number.The bridges of

Page 207 - Event Log

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 285Figure 91 illustrates the concept of regions. It shows one MST

Page 208 - Event Log Overview

Chapter 17: MSTP286 Section II: Advanced FeaturesThe same is true for any ports connected to bridges running the single-instance spanning tree STP or

Page 209

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 287❑ Each MSTI must have a regional root for locating loops in th

Page 210 - Chapter 12: Event Log

Chapter 17: MSTP288 Section II: Advanced FeaturesMSTP with STP and RSTPMSTP is fully compatible with STP and RSTP. If a port on an AT-9400 Series swit

Page 211 - Displaying Events

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 289❑ All of the bridges in a region must have the same configurat

Page 212

29Chapter 1OverviewThis chapter describes the AT-S63 software functions, the types of sessions you can use to access the software, and the management

Page 213

Chapter 17: MSTP290 Section II: Advanced Featuresthat the port is a member of both CIST and MSTI 7, while the BPDUs from port 1 would indicate the por

Page 214

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 291To avoid this issue, always assign all VLANs on a switch, incl

Page 215

Chapter 17: MSTP292 Section II: Advanced FeaturesThere are several ways to address this issue. One is to have only one MSTP region for each subnet in

Page 216

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 293Selecting MSTP as the Spanning Tree ProtocolTo select and acti

Page 217 - Clearing the Event Log

Chapter 17: MSTP294 Section II: Advanced FeaturesConfiguring MSTP Bridge SettingsTo configure a bridge’s MSTP settings, perform the following procedur

Page 218 - Saving an Event Log to a File

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 2952 - Hello TimeThe time interval between generating and sending

Page 219

Chapter 17: MSTP296 Section II: Advanced Featuresrevision level must be the same on all bridges in a region. Different regions can have the same revis

Page 220

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 297Configuring the CIST PriorityThis procedure explains how to ad

Page 221 - Quality of Service

Chapter 17: MSTP298 Section II: Advanced FeaturesThe following prompt is displayed:Enter new priority [the value will be multiplied by 4096]: [0 to 15

Page 222 - Quality of Service Overview

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 299Displaying the CIST PriorityTo change the CIST priority, perfo

Page 223

3ContentsFigures ...

Page 224

Chapter 1: Overview30Management OverviewThe AT-S63 management software is intended for the AT-9400 Series switches. You use the software to monitor an

Page 225

Chapter 17: MSTP300 Section II: Advanced FeaturesPath CostSpecifies the path cost from the bridge to the regional root. If the bridge is the regional

Page 226

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 301Creating, Deleting, and Modifying MSTI IDsThe following sectio

Page 227 - Configuring CoS

Chapter 17: MSTP302 Section II: Advanced Features8. After making changes, type R until you return to the Main Menu. Then type S to select Save Configu

Page 228

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 303Enter the MSTI ID to be modified: [1 to 15] ->5. Enter the

Page 229

Chapter 17: MSTP304 Section II: Advanced FeaturesAdding, Removing, or Modifying VLAN Associations to MSTI IDsWhen you create a new MSTI ID, you are gi

Page 230

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 305The VLAN-MSTI Association menu is shown in Figure 98.Figure 98

Page 231 - Configuring Egress Scheduling

Chapter 17: MSTP306 Section II: Advanced Features4. From the MSTP menu, type V to select VLAN-MSTI Association menu.The VLAN-MSTI Association menu is

Page 232 - Changes

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 3076. Enter the MSTI ID to which you want to associate a VLAN. A

Page 233 - IGMP Snooping

Chapter 17: MSTP308 Section II: Advanced FeaturesThe VLANs already associated with the MSTI ID are removed when the new VLANs are added. The removed V

Page 234 - IGMP Snooping Overview

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 309Configuring MSTP Port SettingsTo configure a port’s MSTP param

Page 235

AT-S63 Management Software Menus Interface User’s Guide31There are four ways to access the management software on an AT-9400 Series switch. These meth

Page 236 - Configuring IGMP Snooping

Chapter 17: MSTP310 Section II: Advanced FeaturesThe Configure MSTP Port Settings menu is shown in Figure 100.Figure 100. Configure MSTP Port Setting

Page 237

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 311Table 19 lists the RSTP port costs with Auto-Detect when the p

Page 238 - Chapter 14: IGMP Snooping

Chapter 17: MSTP312 Section II: Advanced FeaturesDisplaying the MSTP Port Configuration To display the MSTP port configuration, perform the following

Page 239

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 313PortThe port number.Edge-PortWhether or not the port is functi

Page 240

Chapter 17: MSTP314 Section II: Advanced FeaturesDisplaying the MSTP Port StateTo display the MSTP port state, perform the following procedure:1. From

Page 241

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 315The MSTP Port State menu displays a table that contains the fo

Page 242

Chapter 17: MSTP316 Section II: Advanced FeaturesResetting MSTP to the DefaultsTo reset MSTP to the defaults, perform the following procedure:1. From

Page 243 - Router IP

Section II: Advanced Features 317Chapter 18SNMPv3This chapter provides a description of the AT-S63 implementation of the SNMPv3 protocol. In addition,

Page 244

Chapter 18: SNMPv3318 Section II: Advanced FeaturesSNMPv3 OverviewThe SNMPv3 protocol builds on the existing SNMPv1 and SNMPv2c protocol implementatio

Page 245 - RRP Snooping

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 319❑ ”SNMPv3 Tables” on page 322❑ ”SNMPv3 Configuration Example”

Page 246 - RRP Snooping Overview

Chapter 1: Overview32Local Management SessionYou establish a local management session with an AT-9400 Series switch when you use the RJ-45 to RS-232 m

Page 247

Chapter 18: SNMPv3320 Section II: Advanced FeaturesSNMPv3 MIBViewsThe SNMPv3 protocol allows you to configure MIB views for users and groups. The MIB

Page 248 - Chapter 15: RRP Snooping

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 321a MIB subtree view and a subtree mask is analogous to the rela

Page 249 - STP and RSTP

Chapter 18: SNMPv3322 Section II: Advanced Features❑ Privacy Protocol❑ GroupTo configure the SNMP security information, you associate a user and its r

Page 250 - STP and RSTP Overview

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 323operator privileges. See Appendix B, ”SNMPv3” on page 317 for

Page 251 - Bridge Priority

Chapter 18: SNMPv3324 Section II: Advanced Features❑ ”SNMPv3 User Table” on page 324❑ ”SNMPv3 View Table” on page 324❑ ”SNMPv3 SecurityToGroup Table”

Page 252 - Chapter 16: STP and RSTP

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 325For each group, you can assign read, write, and notify views o

Page 253

Chapter 18: SNMPv3326 Section II: Advanced FeaturesSNMPv3 Target Parameters TableThe Configure SNMPv3 Target Parameters Table menu allows you to defin

Page 254

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 327Configuring SNMPv3 EntitiesThis section describes how to confi

Page 255

Chapter 18: SNMPv3328 Section II: Advanced FeaturesConfiguring the SNMPv3 User TableThis section contains a description of the SNMPv3 User Table and h

Page 256 - Edge Port

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 329The Configure SNMPv3 Table menu is shown in Figure 106.Figure

Page 257 - Spanning Tree

AT-S63 Management Software Menus Interface User’s Guide33Telnet Management SessionYou can use any management station on your network that has the Teln

Page 258

Chapter 18: SNMPv3330 Section II: Advanced Features5. To create a new user table, type 1 to select Create SNMPv3 Table Entry.The following prompt is d

Page 259

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 3318. Enter an authentication password of up to 32 alphanumeric c

Page 260

Chapter 18: SNMPv3332 Section II: Advanced FeaturesN-NonVolatileSelect this storage type if you want the ability to save an entry in the SNMPv3 User T

Page 261 - Configuring STP

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 333Modifying anSNMPv3 UserTable EntryThis section describes how t

Page 262

Chapter 18: SNMPv3334 Section II: Advanced Features4. To change the authentication protocol and password, type 1 to select Set Authentication Protocol

Page 263 - Port Settings

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 335Authentication protocol algorithm has been changed.The followi

Page 264

Chapter 18: SNMPv3336 Section II: Advanced FeaturesThe following prompt is displayed:Enter Privacy Protocol [D-DES, N-None]:6. Choose one of the follo

Page 265 - Displaying STP

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 337The Modify SNMPv3 Table menu is shown in Figure 108 on page 33

Page 266 - Settings

Chapter 18: SNMPv3338 Section II: Advanced FeaturesConfiguring the SNMPv3 View TableThis section contains a description of the SNMPv3 View Table and h

Page 267 - Configuring RSTP

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 339The Configure SNMPv3 View Table menu is shown in Figure 109.Fi

Page 268

Chapter 1: Overview34Web Browser Management SessionYou can also use a web browser to manage a switch. This too is referred to as remote management, ju

Page 269 - RSTP Port

Chapter 18: SNMPv3340 Section II: Advanced FeaturestcpThe following prompt is displayed:Enter Subtree Mask (Hex format):6. Enter a subtree mask in hex

Page 270

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 341making changes to an SNMPv3 View Table entry with a Volatile s

Page 271 - Displaying the

Chapter 18: SNMPv3342 Section II: Advanced Features5. Enter the subtree for this view.Do you want to delete this table entry?(Y/N):[Yes/No]->6. Ent

Page 272 - RSTP Port State

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 343The Modify SNMPv3 View Table menu is shown in Figure 110.Figur

Page 273

Chapter 18: SNMPv3344 Section II: Advanced FeaturesThis is an optional parameter that is used to further refine the value in the View Subtree paramete

Page 274 - Resetting RSTP

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 345Enter View Name:5. Enter a View Name that was previously confi

Page 275

Chapter 18: SNMPv3346 Section II: Advanced Features3. From the Configure SNMPv3 View Table menu, type 3 to select Modify SNMPv3 Table Entry.The Modify

Page 276

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 347Configuring the SNMPv3 Access TableThis section contains a des

Page 277 - Chapter 17

Chapter 18: SNMPv3348 Section II: Advanced FeaturesThe Configure SNMPv3 Access Table menu is shown in Figure 111.Figure 111. Configure SNMPv3 Access

Page 278 - MSTP Overview

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 349NoteThe Context Prefix and the Context Match fields are a read

Page 279

AT-S63 Management Software Menus Interface User’s Guide35SNMP Management SessionAnother way to remotely manage the switch is with an SNMP management p

Page 280 - Chapter 17: MSTP

Chapter 18: SNMPv3350 Section II: Advanced FeaturesP-AuthPrivThis option represents authentication and the privacy protocol. Select this security leve

Page 281 - AT-9424T/GB

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 351storage type, the S - Save Configuration Changes option does n

Page 282

Chapter 18: SNMPv3352 Section II: Advanced FeaturesEnter Group Name:4. Enter the Group Name that you want to delete.The following prompt is displayed:

Page 283 - Multiple

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 353protocol and authenticate SNMP entities. This level provides t

Page 284

Chapter 18: SNMPv3354 Section II: Advanced Features1. Follow steps 1 through 5 in the procedure described in ”Creating an SNMPv3 User Table Entry” on

Page 285

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 3556. Enter the Security Model configured for this Group Name. Yo

Page 286

Chapter 18: SNMPv3356 Section II: Advanced FeaturesEnter Read View Name:8. Enter a value that you configured with the View Name parameter in the SNMPv

Page 287

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 357Select one of the following SNMP protocols:1-v1Select this val

Page 288 - Guidelines

Chapter 18: SNMPv3358 Section II: Advanced FeaturesEnter Write View Name:8. Enter a value that you configured with the View Name parameter in the SNMP

Page 289

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 3591-v1Select this value to associate the Group Name with the SNM

Page 290

Chapter 1: Overview36Management Access LevelsThere are two levels of management access in the AT-S63 management software: manager and operator. When y

Page 291 - Switch B

Chapter 18: SNMPv3360 Section II: Advanced Features8. Enter a value that you configured with the View Name parameter in the SNMPv3 View Table. A Notif

Page 292

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 3611-v1Select this value to associate the Group Name with the SNM

Page 293

Chapter 18: SNMPv3362 Section II: Advanced Features8. Select one of the following storage types for this table entry:V - VolatileSelect this storage t

Page 294

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 363Configuring the SNMPv3 SecurityToGroup TableThis section conta

Page 295

Chapter 18: SNMPv3364 Section II: Advanced FeaturesThe Configure SNMPv3 SecurityToGroup Table menu is shown in Figure 113.Figure 113. Configure SNMPv

Page 296

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 3653-v3Select this value to associate the Group Name with the SNM

Page 297 - Configuring the CIST Priority

Chapter 18: SNMPv3366 Section II: Advanced Features8. After making changes, type R until you return to the Main Menu. Then type S to select Save Confi

Page 298 - 4096]: [0 to 15] ->

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 3673-v3Select this value to associate the Group Name with the SNM

Page 299 - Displaying the CIST Priority

Chapter 18: SNMPv3368 Section II: Advanced FeaturesThe Modify SecurityToGroup Table is displayed as shown Figure 113.Figure 114. Modify SNMPv3 Securi

Page 300

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 3693-v3Select this value to associate the User Name with the SNMP

Page 301 - Creating an

37Section IBasic FeaturesThe chapters in this section provide information and procedures for basic switch setup using the AT-S63 management software.

Page 302 - Modifying an

Chapter 18: SNMPv3370 Section II: Advanced Features6. Enter the Security Model configured for this User Name. You cannot change the value of the Secur

Page 303 - 4096] [0 to 15] -> 8

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 371Configuring the SNMPv3 Notify TableThis section contains a des

Page 304 - VLAN from an

Chapter 18: SNMPv3372 Section II: Advanced FeaturesThe Configure SNMPv3 Notify Table menu is shown in Figure 115.Figure 115. Configure SNMPv3 Notify

Page 305 - VLAN to an

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 373I-InformIndicates this notify table is used to send inform mes

Page 306

Chapter 18: SNMPv3374 Section II: Advanced FeaturesThe Configure SNMPv3 Notify Table menu is shown in Figure 115 on page 372.NoteTo display a Group Na

Page 307 - Enter the list of VLANs:

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 375The Configure SNMPv3 Notify Table menu is shown in Figure 115

Page 308 - Clearing VLAN

Chapter 18: SNMPv3376 Section II: Advanced Features7. After making changes, type R until you return to the Main Menu. Then type S to select Save Confi

Page 309

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 377Modifying a Storage TypeTo modify the Storage Type parameter i

Page 310

Chapter 18: SNMPv3378 Section II: Advanced Features7. After making changes, type R until you return to the Main Menu. Then type S to select Save Confi

Page 311

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 379Configuring the SNMPv3 Target Address TableThis section contai

Page 312

38 Section I: Basic Features

Page 313

Chapter 18: SNMPv3380 Section II: Advanced FeaturesThe Configure SNMPv3 Table menu is shown in Figure 106 on page 329.2. From the Configure SNMPv3 Tab

Page 314

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 3816. Enter a UDP port.You can enter a UDP port in the range of 0

Page 315

Chapter 18: SNMPv3382 Section II: Advanced FeaturesTarget Parameters Name parameter in the Configure SNMPv3 Target Parameters Table.The following prom

Page 316 - [Yes/No] ->

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 383The Configure SNMPv3 Target Address Table menu is shown in Fig

Page 317 - Chapter 18

Chapter 18: SNMPv3384 Section II: Advanced Features1. Follow steps 1 through 5 in the procedure described in ”Creating an SNMPv3 User Table Entry” on

Page 318 - SNMPv3 Overview

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 385This is the name of the SNMP manager, or host, that manages th

Page 319 - Protocol

Chapter 18: SNMPv3386 Section II: Advanced FeaturesThe following prompt is displayed:Enter UDP Port#: [0 to 65535]-> 1626. Enter a UDP port.You can

Page 320 - SNMPv3 MIB

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 387Enter Timeout (10mS): [0 to 2147483647]-> 15006. Enter a ti

Page 321 - Notification

Chapter 18: SNMPv3388 Section II: Advanced FeaturesThe following prompt is displayed:Enter Retries:[0 to 255]-> 36. Enter the number of times the s

Page 322 - SNMPv3 Access Table

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 389Enter a Tag List of up to 256 alphanumeric characters. Use a s

Page 323

Section I: Basic Features 39Chapter 2Starting a Local or Telnet Management SessionThis chapter contains the procedure for starting a local or Telnet m

Page 324 - Chapter 18: SNMPv3

Chapter 18: SNMPv3390 Section II: Advanced FeaturesThe value configured here must match the value configured with the Target Parameters Name parameter

Page 325

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 391file. After making changes to an SNMPv3 Target Address Table e

Page 326

Chapter 18: SNMPv3392 Section II: Advanced FeaturesConfiguring the SNMPv3 Target Parameters TableThis section contains a description of the SNMPv3 Tar

Page 327 - Configuring SNMPv3 Entities

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 393❑ Storage TypeThere are three functions you can perform with t

Page 328 - Table Entry

Chapter 18: SNMPv3394 Section II: Advanced Features3. To create an SNMPv3 Target Parameters Table, type 1 to select Create SNMPv3 Table Entry.The foll

Page 329

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 395Enter Security Level [N-NoAuthNoPriv, A-AuthNoPriv, P-AuthPriv

Page 330 - Enter User (Security) Name:

Chapter 18: SNMPv3396 Section II: Advanced FeaturesN-NonVolatileSelect this storage type if you want the ability to save an entry in the SNMPv3 Target

Page 331 - Enter Privacy Password:

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 397The following prompt is displayed:Do you want to delete this t

Page 332

Chapter 18: SNMPv3398 Section II: Advanced FeaturesNoteYou cannot modify the Target Params Name parameter.NoteYou cannot modify an entry in the SNMPv3

Page 333

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 399The Modify SNMPv3 Target Parameters Table menu is shown in Fig

Page 334 - Enter User Name:

Contents4How Do You Assign an IP Address? ...

Page 335 - Re-enter Privacy password:

Chapter 2: Starting a Local or Telnet Management Session40 Section I: Basic FeaturesLocal Management SessionTo establish a local management session, y

Page 336

Chapter 18: SNMPv3400 Section II: Advanced FeaturesModifying the Security ModelFor the Security or User Name you have selected, the value of the Secur

Page 337

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 4011-v1Select this value if this User Name is associated with the

Page 338 - SNMPv3 View

Chapter 18: SNMPv3402 Section II: Advanced FeaturesEnter a value of up to 32 alphanumeric characters.The following prompt is displayed:Enter Security

Page 339

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 403Modifying the Message Process ModelYou can modify the Message

Page 340

Chapter 18: SNMPv3404 Section II: Advanced Features3-v3Select this value to process messages with the SNMPv3 protocol. 7. After making changes, type R

Page 341

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 405N-NonVolatileSelect this storage type if you want the ability

Page 342

Chapter 18: SNMPv3406 Section II: Advanced FeaturesConfiguring the SNMPv3 Community TableThis section contains a description of the SNMPv3 Community T

Page 343

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 407For each SNMPv3 Community Table entry, you can configure the f

Page 344 - 1.3.6.1.2.1.2.2.1.0.3

Chapter 18: SNMPv3408 Section II: Advanced FeaturesThe Configure SNMPv3 Community Table menu is shown in Figure 121.Figure 121. Configure SNMPv3 Comm

Page 345 - 1.3.6.1.2.1.6

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 409The following prompt is displayed:Enter Security Name:6. Enter

Page 346

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 412. Connect the other end of the cable to an RS-232 port on a termin

Page 347 - SNMPv3 Access

Chapter 18: SNMPv3410 Section II: Advanced FeaturesNoteThe Row Status parameter is a read-only field. The Active value indicates the SNMPv3 Community

Page 348

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 411Modifying anSNMPv3CommunityTable EntryFor each entry in the SN

Page 349 - P-AuthPriv]:

Chapter 18: SNMPv3412 Section II: Advanced FeaturesThe Modify SNMPv3 Community Table menu is shown in Figure 122.Figure 122. Modify SNMPv3 Community

Page 350 - Enter Notify View Name:

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 413Modifying the Security NameTo modify the Security Name paramet

Page 351

Chapter 18: SNMPv3414 Section II: Advanced FeaturesThe Configure SNMPv3 Table menu is displayed as shown in Figure 106 on page 329.2. From the Configu

Page 352 - A-AuthNoPriv, P-AuthPriv]:

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 4153. From the Configure SNMPv3 Community Table, type 3 to select

Page 353

Chapter 18: SNMPv3416 Section II: Advanced FeaturesDisplaying SNMPv3 Table MenusThe procedures in this section describe how to display the SNMPv3 Tabl

Page 354

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 417The Display SNMPv3 Table menu is shown in Figure 123.Figure 12

Page 355

Chapter 18: SNMPv3418 Section II: Advanced Features1. Follow steps 1 through 5 in the procedure described in ”Displaying the Display SNMPv3 User Table

Page 356

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 419The Display SNMPv3 Access Table menu is shown in Figure 126.Fi

Page 357

Chapter 2: Starting a Local or Telnet Management Session42 Section I: Basic FeaturesIf the switch has been configured with a name, the name is display

Page 358

Chapter 18: SNMPv3420 Section II: Advanced FeaturesThe Display SNMPv3 SecurityToGroup Table menu is shown in Figure 127.Figure 127. Display SNMPv3 Se

Page 359

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 421Displaying theDisplay SNMPv3Target AddressTable MenuThis secti

Page 360

Chapter 18: SNMPv3422 Section II: Advanced FeaturesThe Display SNMPv3 Target Parameters Table menu is shown in Figure 127.Figure 130. Display SNMPv3

Page 361

AT-S63 Management Software Menus Interface User’s GuideSection II: Advanced Features 423The Display SNMPv3 Community Table menu is shown in Figure 127

Page 362

Chapter 18: SNMPv3424 Section II: Advanced Features

Page 363 - SecurityToGroup

425Section IIIVLANsThe chapters in this section explain how to set up VLANs using the AT-S63 management software. The chapters include:❑ Chapter 19, ”

Page 364

426 Section III: VLANs

Page 365

Section III: VLANs 427 Chapter 19Port-based and Tagged VLANsThis chapter contains basic information about virtual LANs (VLANs) and procedures for crea

Page 366

Chapter 19: Port-based and Tagged VLANs428 Section III: VLANsVLAN OverviewA VLAN is a group of ports on an Ethernet switch that form a logical Etherne

Page 367 - Table Entr

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 429But with VLANS, you can change the LAN segment assignment of an end node

Page 368

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 43Quitting a LocalManagementSessionTo quit a local management session

Page 369

Chapter 19: Port-based and Tagged VLANs430 Section III: VLANsPort-based VLAN OverviewAs explained in ”VLAN Overview” on page 428, a VLAN consists of a

Page 370

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 431recognize and forward frames belonging to the same VLAN even though the V

Page 371 - SNMPv3 Notify

Chapter 19: Port-based and Tagged VLANs432 Section III: VLANsGeneral Rulesfor Creating aPort-basedVLANBelow is a summary of the general rules to obser

Page 372

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 433Port-basedExample 1Figure 132 illustrates an example of one AT-9424T/SP G

Page 373

Chapter 19: Port-based and Tagged VLANs434 Section III: VLANsPort-basedExample 2Figure 133 illustrates more port-based VLANs. In this example, two VLA

Page 374

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 435The table below lists the port assignments for the Sales, Engineering, an

Page 375

Chapter 19: Port-based and Tagged VLANs436 Section III: VLANsTagged VLAN OverviewThe second type of VLAN supported by the AT-S63 management software i

Page 376 - Enter Notify Name:

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 437❑ VLAN Identifier❑ Tagged and Untagged Ports❑ Port VLAN IdentifierNoteFor

Page 377

Chapter 19: Port-based and Tagged VLANs438 Section III: VLANsGeneral Rulesfor Creating aTagged VLANBelow is a summary of the rules to observe when you

Page 378

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 439Tagged VLANExampleFigure 134 illustrates how tagged ports can be used to

Page 379 - Address Table

Chapter 2: Starting a Local or Telnet Management Session44 Section I: Basic FeaturesTelnet Management SessionYou can use the Telnet application from a

Page 380

Chapter 19: Port-based and Tagged VLANs440 Section III: VLANsThis example is nearly identical to the ”Port-based Example 2” on page 434. Tagged ports

Page 381 - Enter Target Parameters:

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 441Creating a New Port-based or Tagged VLANTo create a new port-based or tag

Page 382

Chapter 19: Port-based and Tagged VLANs442 Section III: VLANsThe Configure VLANs menu is shown in Figure 136.Figure 136. Configure VLANs Menu3. From

Page 383

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 443The name can be from one to fifteen alphanumeric characters in length. Th

Page 384

Chapter 19: Port-based and Tagged VLANs444 Section III: VLANs8. If the VLAN will contain tagged ports, type 3 to select Tagged Ports and specify the p

Page 385 - Enter Target Address Name:

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 445Example of Creating a Port-based VLANThe following procedure creates the

Page 386

Chapter 19: Port-based and Tagged VLANs446 Section III: VLANsExample of Creating a Tagged VLANThe following procedure creates the Engineering VLAN in

Page 387

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 447Modifying a VLANNoteTo modify a VLAN, you need to know its VID. To view V

Page 388

Chapter 19: Port-based and Tagged VLANs448 Section III: VLANsEnter new value -> [1 to 4096] ->5. Enter the VID of the VLAN you want to modify.Th

Page 389

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 4493 - Tagged PortsUse this selection to add or remove tagged ports from the

Page 390

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 45Quitting aTelnetManagementSessionTo end a Telnet management session

Page 391

Chapter 19: Port-based and Tagged VLANs450 Section III: VLANsand reentering them again using the VID of the VLAN to which the port has been moved to.

Page 392

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 451Displaying VLANsTo view the name, VID number, and member ports of all the

Page 393 - Parameters

Chapter 19: Port-based and Tagged VLANs452 Section III: VLANsProtocolThe protocol associated with this VLAN. The possible settings are:Blank - The VLA

Page 394 - Enter Target Parameters Name:

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 453Deleting a VLANNoteTo delete a VLAN, you need to know its VID. To view VL

Page 395

Chapter 19: Port-based and Tagged VLANs454 Section III: VLANsNoteYou cannot delete the Default_VLAN, which has a VID of 1.The Delete VLAN menu expands

Page 396

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 4559. Repeat this procedure starting with Step 4 to delete other VLANs.10. A

Page 397

Chapter 19: Port-based and Tagged VLANs456 Section III: VLANsResetting to the Default VLANThe following procedure for deletes all VLANs, except the De

Page 398

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 4576. After making changes, type R until you return to the Main Menu. Then t

Page 399

Chapter 19: Port-based and Tagged VLANs458 Section III: VLANsDisplaying PVIDsThe following procedure displays a menu that lists the PVIDs for all the

Page 400

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 459Enabling or Disabling Ingress FilteringThere are rules a switch follows w

Page 401

Chapter 2: Starting a Local or Telnet Management Session46 Section I: Basic Features

Page 402

Chapter 19: Port-based and Tagged VLANs460 Section III: VLANsActivating or deactivating ingress filtering has no effect on the switch’s handling of pr

Page 403

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 461Specifying a Management VLANThe management VLAN is the VLAN on which an A

Page 404

Chapter 19: Port-based and Tagged VLANs462 Section III: VLANsneed to create the NMS VLAN on each AT-9400 Series switch that you want to manage remotel

Page 405

Section III: VLANs 463 Chapter 20Multiple VLANsThis chapter describes the multiple VLAN modes and how to select a mode.This chapter contains the follo

Page 406

Chapter 20: Multiple VLANs464 Section III: VLANsMultiple VLAN Mode OverviewThe multiple VLAN modes are designed to simplify the task of configuring th

Page 407 - Community

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 465VLANs. It also assigns the PVID values as well. For example, the PVID for

Page 408

Chapter 20: Multiple VLANs466 Section III: VLANsThis highly segmented configuration is useful in situations where traffic generated by each end node o

Page 409 - Enter Transport Tag:

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 467Another difference with this mode is that the uplink port is untagged. Co

Page 410

Chapter 20: Multiple VLANs468 Section III: VLANsSelecting a VLAN ModeThe following procedure explains how to select a VLAN mode. Available modes are:❑

Page 411

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 469Displaying VLAN InformationTo view the VLANs on the switch while the unit

Page 412

Section I: Basic Features 47Chapter 3Basic Switch ParametersThis chapter contains a variety of information and procedures for basic switch setup. Sect

Page 413 - Enter Community Index:

Chapter 20: Multiple VLANs470 Section III: VLANsThe Show Multiple VLANs menu is shown in Figure 145.Figure 145. Show VLANs Menu, Multiple VLANSThe Sh

Page 414

Section III: VLANs 471Chapter 21GARP VLAN Registration ProtocolThis chapter describes the GARP VLAN Registration Protocol (GVRP) and contains the foll

Page 415

Chapter 21: GARP VLAN Registration Protocol472 Section III: VLANsGARP VLAN Registration Protocol (GVRP) OverviewThe GARP VLAN Registration Protocol (G

Page 416 - Displaying SNMPv3 Table Menus

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 473Figure 146 provides an example of how GVRP works.Figure 146. GVRP Exampl

Page 417 - View Table

Chapter 21: GARP VLAN Registration Protocol474 Section III: VLANsVLAN. If it is not a member, it automatically adds the port to the VLAN as an tagged

Page 418 - Access Table

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 475❑ You can convert dynamic GVRP VLANs and dynamic GVRP port assignments to

Page 419

Chapter 21: GARP VLAN Registration Protocol476 Section III: VLANsGenericAttributeRegistrationProtocol (GARP)OverviewThe following is a technical overv

Page 420 - Notify Table

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 477GARP architecture is shown in Figure 147. Figure 147. GARP Architecture

Page 421

Chapter 21: GARP VLAN Registration Protocol478 Section III: VLANsthe applicant and registrar. This is shown in Figure 148.Figure 148. GID Architectur

Page 422 - Table Menu

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 479The job of the registrar is to record whether an attribute is registered,

Page 423

Chapter 3: Basic Switch Parameters48 Section I: Basic Features❑ ”Displaying Uplink Port Information” on page 76

Page 424

Chapter 21: GARP VLAN Registration Protocol480 Section III: VLANsConfiguring GVRPTo configure GVRP, perform the following procedure: The timers in the

Page 425 - Section III

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 4815. Type 2 to select GVRP GIP Status.The following prompt is displayed:Ent

Page 426 - 426 Section III: VLANs

Chapter 21: GARP VLAN Registration Protocol482 Section III: VLANsEnabling or Disabling GVRP on a PortThis procedure enables and disables GVRP on a swi

Page 427 - Port-based and Tagged VLANs

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 4835. Enter a port or a list of ports.The Configure GVRP Port Settings menu

Page 428 - VLAN Overview

Chapter 21: GARP VLAN Registration Protocol484 Section III: VLANsDisplaying the GVRP Port ConfigurationTo display the GVRP port configuration, perform

Page 429 - Section III: VLANs 429

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 485Displaying GVRP CountersTo display GVRP counters, perform the following p

Page 430 - Port-based VLAN Overview

Chapter 21: GARP VLAN Registration Protocol486 Section III: VLANsThe GVRP Counters menu (page 1) is shown in Figure 154.Figure 154. GVRP Counters Men

Page 431 - Identifier

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 487Figure 155. GVRP Counters Menu (page 2)The GVRP counters in the menus ar

Page 432 - 432 Section III: VLANs

Chapter 21: GARP VLAN Registration Protocol488 Section III: VLANsReceive Discarded: Port Not ListeningNumber of GARP PDUs discarded because the port t

Page 433 - Example 1

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 489Receive GARP Messages: LeaveEmptyTotal number of GARP LeaveEmpty messages

Page 434 - Example 2

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 49When Does a Switch Need an IP Address?One of the tasks of building

Page 435 - Section III: VLANs 435

Chapter 21: GARP VLAN Registration Protocol490 Section III: VLANsDisplaying the GVRP DatabaseTo display GVRP database, perform the following procedure

Page 436 - Tagged VLAN Overview

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 491GID indexValue of the GID index corresponding to the attribute. GID index

Page 437 - Untagged Ports

Chapter 21: GARP VLAN Registration Protocol492 Section III: VLANsDisplaying the GIP Connected Ports RingTo display the GIP connected ports ring, perfo

Page 438 - Tagged VLAN

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 493STP IDPresent if the GARP application is GVRP; identifies the spanning tr

Page 439

Chapter 21: GARP VLAN Registration Protocol494 Section III: VLANsDisplaying the GVRP State MachineTo display the GVRP state machine, perform the follo

Page 440 - 440 Section III: VLANs

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 495The GVRP State Machine menu (page 2) is displayed, as shown in Figure 159

Page 441 - Section III: VLANs 441

Chapter 21: GARP VLAN Registration Protocol496 Section III: VLANsApp Applicant state machine for the GID index on that particular port. One of:Normal

Page 442 - 442 Section III: VLANs

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 497App (Continued) Non-Participant Management state:“Von” Very Anxious Obser

Page 443 - Section III: VLANs 443

Chapter 21: GARP VLAN Registration Protocol498 Section III: VLANs

Page 444 - 444 Section III: VLANs

Section III: VLANs 499 Chapter 22Protected Ports VLANsThis chapter explains protected ports VLANs. It contains the following sections: ❑ ”Protected Po

Page 445 - Section III: VLANs 445

AT-S63 Management Software Menus Interface User’s Guide5Adding Static Unicast and Multicast MAC Addresses ...

Page 446 - 446 Section III: VLANs

Chapter 3: Basic Switch Parameters50 Section I: Basic FeaturesHow Do YouAssign an IPAddress?There are two ways that a switch can obtain an IP address.

Page 447 - Modifying a VLAN

Chapter 22: Protected Ports VLANs500 Section III: VLANsProtected Ports VLAN OverviewThe purpose of a protected ports VLAN is to allow multiple ports o

Page 448 - 448 Section III: VLANs

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 501In contrast, the uplink port in a protected ports VLAN, which is shared b

Page 449 - Press any key to continue

Chapter 22: Protected Ports VLANs502 Section III: VLANsinformation when you create the VLAN, and having the tables handy will make the job easier.Prot

Page 450 - 450 Section III: VLANs

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 503Creating a Protected Ports VLANTo create a new protected ports VLAN, perf

Page 451 - Displaying VLANs

Chapter 22: Protected Ports VLANs504 Section III: VLANsNoteA VLAN must be assigned a name.6. Type 2 to select VLAN ID (VID.The following prompt is dis

Page 452 - 452 Section III: VLANs

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 50511. To make this a protected ports VLAN, type Y. If you do not want this

Page 453 - Deleting a VLAN

Chapter 22: Protected Ports VLANs506 Section III: VLANsModifying a Protected Ports VLANPlease note the following before you perform this procedure:❑ T

Page 454 - 454 Section III: VLANs

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 5073. From the Configure VLANs menu, type 2 to select Modify VLAN.The Modify

Page 455 - Section III: VLANs 455

Chapter 22: Protected Ports VLANs508 Section III: VLANs2 - VLAN ID (VID)This is the VLAN’s VID value. You cannot change this value. 3 - Tagged PortsUs

Page 456 - Resetting to the Default VLAN

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 50911. If there are ports within the VLAN that still need to be assigned to

Page 457 - Section III: VLANs 457

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 51Configuring the IP Address, Switch Name, and Other Basic Parameters

Page 458 - Displaying PVIDs

Chapter 22: Protected Ports VLANs510 Section III: VLANsDisplaying a Protected Ports VLANTo view the name, VID number, and member ports of all the VLAN

Page 459 - Section III: VLANs 459

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 511An example of the Show VLANs window is shown in Figure 163.Figure 163. S

Page 460 - 460 Section III: VLANs

Chapter 22: Protected Ports VLANs512 Section III: VLANsDeleting a Protected Ports VLANAll untagged ports in a deleted protected ports VLAN are automat

Page 461 - Specifying a Management VLAN

AT-S63 Management Software Menus Interface User’s GuideSection III: VLANs 513The Delete VLAN menu expands to contain all relevant information about th

Page 462 - Press any key to continue

Chapter 22: Protected Ports VLANs514 Section III: VLANs9. Repeat this procedure starting with Step 4 to delete other VLANs.10. After making changes, t

Page 463 - Multiple VLANs

515Section IVSecurityThe chapters in this section describe the security features you can implement for an AT-9400 Series switch using the AT-S63 manag

Page 465 - Section III: VLANs 465

Section IV: Security 517Chapter 23Port Security This chapter explains how you can use the dynamic and static MAC addresses learned on the ports of the

Page 466 - Multiple VLAN

Chapter 23: Port Security518 Section IV: SecurityMAC Address Security OverviewThis feature can enhance the security of your network. You can use it to

Page 467 - Section III: VLANs 467

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 519A dynamic MAC address learned on a port operating in the Limited securi

Page 468 - Selecting a VLAN Mode

Chapter 3: Basic Switch Parameters52 Section I: Basic FeaturesThe System Configuration menu is shown in Figure 5.Figure 5. System Configuration Menu3

Page 469 - Displaying VLAN Information

Chapter 23: Port Security520 Section IV: Securityport after the port had reached its maximum number of dynamic MAC addresses, or that was not assigned

Page 470 - 470 Section III: VLANs

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 521Configuring MAC Address Port SecurityTo set the port security level, pe

Page 471 - Chapter 21

Chapter 23: Port Security522 Section IV: Security5. From the Configure Port Security menu, type 1 to select Security Mode. The following prompt is dis

Page 472 - 472 Section III: VLANs

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 523T - Trap: The port discards invalid frames and sends an SNMP trap.D - D

Page 473 - Switch #2

Chapter 23: Port Security524 Section IV: SecurityDisplaying Port Security LevelsTo view the current security levels for the ports on the switch, perfo

Page 474 - 474 Section III: VLANs

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 525The Display Port Security menu is shown in Figure 170.Figure 170. Disp

Page 475 - Section III: VLANs 475

Chapter 23: Port Security526 Section IV: SecurityParticipatingThis column applies only when the intrusion action for a port is set to trap or disable.

Page 476 - Protocol (GARP)

Section IV: Security 527Chapter 24Access Control ListsThis chapter explains how to create an access control list (ACL) to restrict Telnet and web brow

Page 477 - Section III: VLANs 477

Chapter 24: Access Control Lists528 Section IV: SecurityManagement ACL Security OverviewThis chapter explains how to restrict remote management access

Page 478 - 478 Section III: VLANs

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 529MaskYou need to enter a mask that indicates the parts of the IP address

Page 479 - Section III: VLANs 479

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 53from a management station that is separated from the switch by a ro

Page 480 - Configuring GVRP

Chapter 24: Access Control Lists530 Section IV: Securitythem.❑ The protocol is always TCP.❑ The management ACL does not control local management or re

Page 481 - Section III: VLANs 481

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 531Mask 255.255.255.0Protocol TCPInterface WebA management ACL can contain

Page 482 - 482 Section III: VLANs

Chapter 24: Access Control Lists532 Section IV: SecurityCreating the Management ACLTo create a management ACL, perform the following procedure:1. From

Page 483 - Section III: VLANs 483

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 5335. Enter a mask that indicates the parts of the IP address the switch s

Page 484 - 484 Section III: VLANs

Chapter 24: Access Control Lists534 Section IV: Security11. After making changes, type R until you return to the Main Menu. Then type S to select Save

Page 485 - Displaying GVRP Counters

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 535Adding an ACETo add an ACE, repeat the procedure in ”Creating the Manag

Page 486 - 486 Section III: VLANs

Chapter 24: Access Control Lists536 Section IV: SecurityDeleting an ACETo delete an ACE, perform the following procedure:1. From the Main Menu, type 5

Page 487 - Section III: VLANs 487

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 537Displaying the ACEsTo display the ACEs, perform the following procedure

Page 488 - 488 Section III: VLANs

Chapter 24: Access Control Lists538 Section IV: SecurityInterfaceThe interface that the management station uses to manage the switch. The options are

Page 489 - Section III: VLANs 489

Section IV: Security 539Chapter 25Web ServerThe chapter provides an overview of the web server feature and procedures to configure the server. It cont

Page 490 - Displaying the GVRP Database

Chapter 3: Basic Switch Parameters54 Section I: Basic FeaturesActivating the BOOTP and DHCP Client SoftwareThe BOOTP and DHCP application protocols we

Page 491 - Section III: VLANs 491

Chapter 25: Web Server540 Section IV: SecurityWeb Server OverviewThe AT-S63 management software is shipped with web server software. The software is a

Page 492 - 492 Section III: VLANs

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 541❑ TLS (Transmission Layer Security) version 1.0

Page 493 - Section III: VLANs 493

Chapter 25: Web Server542 Section IV: SecurityConfiguring the Web ServerThis procedure explains how to enable and disable the web server and how to co

Page 494 - GVRP State Machine

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 543The Web Server Configuration menu is shown in Figure 173.Figure 173. W

Page 495 - Section III: VLANs 495

Chapter 25: Web Server544 Section IV: Security7. To enable the web server, type 1 to toggle Status to Enabled.The Web Server Configuration menu is red

Page 496 - 496 Section III: VLANs

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 545General Steps for Configuring the Web Server for EncryptionThere are se

Page 497 - Section III: VLANs 497

Chapter 25: Web Server546 Section IV: Security6. After you have received the appropriate certificates back from the CA, download them into the AT-S63

Page 498 - 498 Section III: VLANs

Section IV: Security 547Chapter 26Encryption KeysThis chapter describes encryption keys and how you can use keys to improve the security of your switc

Page 499 - Protected Ports VLANs

Chapter 26: Encryption Keys548 Section IV: SecurityBasic OverviewProtecting your managed switches from unauthorized management access is an important

Page 500 - Protected Ports VLAN Overview

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 549Encryption KeyLengthTo create a key pair, you must specify its length.

Page 501 - Section III: VLANs 501

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 55The following prompt is displayed:BOOTP/DHCP (E-Enabled, D-Disabled

Page 502 - Protected Ports

Chapter 26: Encryption Keys550 Section IV: Securitypackets are sent encrypted. The web server on an AT-9400 Series switch, can operate in either mode.

Page 503 - Section III: VLANs 503

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 551Technical Overview of Secure Sockets LayerThis section describes the Se

Page 504 - 504 Section III: VLANs

Chapter 26: Encryption Keys552 Section IV: Securitywith by a third party because any change to the message changes the MAC.SSL uses asymmetrical (Publ

Page 505 - Enter Group Number ->

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 553Authentication Authentication is the process of ensuring that both the

Page 506 - 506 Section III: VLANs

Chapter 26: Encryption Keys554 Section IV: SecurityTechnical Overview of EncryptionThe encryption feature provides the following data security service

Page 507 - Section III: VLANs 507

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 555Plaintext is divided into 64-bit blocks which are encrypted with the DE

Page 508

Chapter 26: Encryption Keys556 Section IV: SecurityAsymmetrical (Public Key) EncryptionAsymmetrical encryption algorithms use two keys—one for encrypt

Page 509

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 557Typically a MAC is calculated using a keyed one-way hash algorithm. A k

Page 510 - 510 Section III: VLANs

Chapter 26: Encryption Keys558 Section IV: SecurityThe Diffie-Hellman algorithm, which is used by the AT-S63 management software, is one of the more c

Page 511 - Section III: VLANs 511

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 559Creating an Encryption KeyThis section contains the procedure for creat

Page 512 - 512 Section III: VLANs

Chapter 3: Basic Switch Parameters56 Section I: Basic FeaturesDisplaying the AT-9400 Series Switch Hardware and Software InformationTo display informa

Page 513 - Section III: VLANs 513

Chapter 26: Encryption Keys560 Section IV: SecurityThe Keys/Certificate Configuration menu is shown in Figure 176.Figure 176. Keys/Certificate Config

Page 514 - 514 Section III: VLANs

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 561The Create Key menu is shown in Figure 178.Figure 178. Create Key Menu

Page 515 - Security

Chapter 26: Encryption Keys562 Section IV: Security9. Type 4 to select Key Description.The following prompt is displayed:Enter new Description ->10

Page 516 - 516 Section IV: Security

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 563Deleting an Encryption KeyThis section contains the procedure for delet

Page 517 - Port Security

Chapter 26: Encryption Keys564 Section IV: SecurityModifying an Encryption KeyThe Key Management menu has a selection for modifying the description of

Page 518 - MAC Address Security Overview

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 565Exporting an Encryption KeyThe following procedure exports the public k

Page 519 - Section IV: Security 519

Chapter 26: Encryption Keys566 Section IV: SecurityThe Export Key to File menu is shown in Figure 179.Figure 179. Export Key to File Menu5. Type 1 to

Page 520 - MAC Address

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 567Key Export in Progress. Please wait...Done11. Press any key to return t

Page 521 - Section IV: Security 521

Chapter 26: Encryption Keys568 Section IV: SecurityImporting an Encryption KeyUse the following procedure to import a public key from the AT-S62 file

Page 522 - 522 Section IV: Security

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 569The Import Key from File menu is shown in Figure 180.Figure 180. Impor

Page 523 - Section IV: Security 523

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 57Model NameModel name of the AT-9400 Series switch. You cannot chang

Page 524 - 524 Section IV: Security

Chapter 26: Encryption Keys570 Section IV: Security10. Type 5 to select Import Key From File to import a key to the switch from an external file.The f

Page 525 - Section IV: Security 525

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 571Displaying the Encryption KeysTo display the encryption keys, perform t

Page 526 - 526 Section IV: Security

Chapter 26: Encryption Keys572 Section IV: SecurityLengthThe length of the key in bits.DigestThe CRC32 value of the MD5 digest of the public key.Descr

Page 527 - Access Control Lists

Section IV: Security 573Chapter 27PKI Certificates and SSLThis chapter contains the procedures for creating public key infrastructure (PKI) certificat

Page 528 - Parts of a

Chapter 27: PKI Certificates and SSL574 Section IV: SecurityNoteThis feature is only supported on the version of AT-S63 management software that featu

Page 529 - ACL Guidelines

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 575Basic OverviewThis chapter describes the second part of the encryption

Page 530 - 530 Section IV: Security

Chapter 27: PKI Certificates and SSL576 Section IV: Securitycompany’s network equipment. The value of a private CA is that the company can keep track

Page 531 - Section IV: Security 531

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 577Following are a few examples. This distinguished name contains only one

Page 532 - Creating the Management ACL

Chapter 27: PKI Certificates and SSL578 Section IV: SecurityGuidelines The guidelines for creating certificates are:❑ A certificate can have only one

Page 533 - Section IV: Security 533

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 579Technical OverviewThe public key infrastructure (PKI) feature is part o

Page 534 - 534 Section IV: Security

Chapter 3: Basic Switch Parameters58 Section I: Basic FeaturesRebooting a SwitchThis procedure reboots the switch.NoteAny configuration changes not sa

Page 535 - Adding an ACE

Chapter 27: PKI Certificates and SSL580 Section IV: SecurityCautionAlthough a certificate binds a public key to a subject to ensure the public key’s s

Page 536 - Deleting an ACE

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 581Elements of aPublic KeyInfrastructureA public key infrastructure is a s

Page 537 - Displaying the ACEs

Chapter 27: PKI Certificates and SSL582 Section IV: SecurityCertificateValidationTo validate a certificate, the end entity verifies the signature in t

Page 538 - Interface

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 583PKIImplementationThe following sections discuss Allied Telesyn’s implem

Page 539 - Web Server

Chapter 27: PKI Certificates and SSL584 Section IV: SecurityCreating a Self-signed CertificateThis section contains the procedure for creating a self-

Page 540 - Web Server Overview

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 585The Public Key Infrastructure (PKI) Configuration menu is shown in Figu

Page 541 - Section IV: Security 541

Chapter 27: PKI Certificates and SSL586 Section IV: SecurityNoteIn the X509 Certificate Management menu, MTrust means manually trusted. This field ind

Page 542 - Configuring the Web Server

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 5879. Enter the ID number of the encryption key that you want to use to cr

Page 543 - Section IV: Security 543

Chapter 27: PKI Certificates and SSL588 Section IV: SecurityAdding a Certificate to the DatabaseAfter you have created a certificate or received a cer

Page 544 - 544 Section IV: Security

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 589The Add Certificate menu is shown in Figure 185.Figure 185. Add Certif

Page 545 - Section IV: Security 545

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 59CautionThe switch does not forward traffic while it reloads its ope

Page 546 - 546 Section IV: Security

Chapter 27: PKI Certificates and SSL590 Section IV: SecurityNoteThis parameter has no affect on the operation of a certificate. The parameter is inclu

Page 547 - Encryption Keys

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 591Modifying a CertificateThe procedure in this section modifies a certifi

Page 548 - Basic Overview

Chapter 27: PKI Certificates and SSL592 Section IV: Security6. Enter the name of the certificate you want to modify. (This field is case sensitive.)Th

Page 549 - Section IV: Security 549

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 59310. After making changes, type R until you return to the Main Menu. The

Page 550 - 550 Section IV: Security

Chapter 27: PKI Certificates and SSL594 Section IV: SecurityDeleting a CertificateThe procedure in this section deletes a certificate from the certifi

Page 551 - Section IV: Security 551

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 5955. From the X509 Certificate Management menu, type 3 to select Delete C

Page 552 - Verification

Chapter 27: PKI Certificates and SSL596 Section IV: SecurityViewing a CertificateThis procedure displays information about a certificate, such as its

Page 553 - Section IV: Security 553

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 597The View Certificate Details menu (page 1) is shown in Figure 187.Figur

Page 554 - Encryption

Chapter 27: PKI Certificates and SSL598 Section IV: SecurityPublic Key AlgThe public key algorithm.Not Valid BeforeThe date the certificate became act

Page 555 - Section IV: Security 555

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 599Generating an Enrollment RequestTo request a certificate from a CA, you

Page 556

Contents6Downloading a System File from a Telnet Management Session ...

Page 557 - Algorithms

Chapter 3: Basic Switch Parameters60 Section I: Basic FeaturesConfiguring the Manager and Operator PasswordsThere are two levels of management access

Page 558 - 558 Section IV: Security

Chapter 27: PKI Certificates and SSL600 Section IV: SecurityThe Generate Enrollment Request menu is shown in Figure 189.Figure 189. Generate Enrollme

Page 559 - Creating an Encryption Key

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 601NoteYou cannot change option 4, Type. The PKCS10 value indicates the in

Page 560 - 560 Section IV: Security

Chapter 27: PKI Certificates and SSL602 Section IV: SecurityInstalling CA Certificates onto a SwitchThis section lists the procedures that you will ne

Page 561 - Section IV: Security 561

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 603Viewing or Configuring the Number of Certificates in the DatabaseThe ma

Page 562 - Enter new Description ->

Chapter 27: PKI Certificates and SSL604 Section IV: SecurityConfiguring SSLTo configure the SSL protocol, perform the following procedure:1. From the

Page 563 - Deleting an Encryption Key

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 6055. After making changes, type R until you return to the Main Menu. Then

Page 564 - Modifying an Encryption Key

Chapter 27: PKI Certificates and SSL606 Section IV: Security

Page 565 - Exporting an Encryption Key

Section IV: Security 607Chapter 28Secure Shell (SSH)The chapter contains overview information about the Secure Shell (SSH) protocol as well a procedur

Page 566 - 566 Section IV: Security

Chapter 28: Secure Shell (SSH)608 Section IV: SecuritySSH OverviewSecure management is increasingly important in modern networks, as the ability to ea

Page 567 - Section IV: Security 567

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 609❑ RSA public keys with lengths of 512 to 2048 bits are supported. Keys

Page 568 - Importing an Encryption Key

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 61The Passwords Configuration menu is shown in Figure 9.Figure 9. Pa

Page 569 - Section IV: Security 569

Chapter 28: Secure Shell (SSH)610 Section IV: SecurityYou can download client software from the Internet. Two popular SSH clients are PuTTY and CYGWIN

Page 570 - 570 Section IV: Security

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 611Figure 191 SSH Remote Management of a Slave SwitchBecause enhanced sta

Page 571 - Section IV: Security 571

Chapter 28: Secure Shell (SSH)612 Section IV: Security1. Create two encryption key pairs on the master switch of the enhanced switch. One pair will fu

Page 572 - 572 Section IV: Security

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 613Configuring SSHThis section describes how to configure the switch as an

Page 573 - PKI Certificates and SSL

Chapter 28: Secure Shell (SSH)614 Section IV: Security3. Type 2 to select Host Key ID.The following prompt is displayed:Enter Host Key ID [0 to 65535]

Page 574 - 574 Section IV: Security

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 615Type E to enable the SSH server. Select this value after you have finis

Page 575

Chapter 28: Secure Shell (SSH)616 Section IV: SecurityDisplaying SSH InformationTo display SSH server information, perform the following procedure:1.

Page 576 - Distinguished

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 617Server PortThe well-known port for SSH. The default is port 22.Host Key

Page 577 - Section IV: Security 577

Chapter 28: Secure Shell (SSH)618 Section IV: Security

Page 578 - 578 Section IV: Security

Section IV: Security 619Chapter 29802.1x Port-based Network Access ControlThis chapter explains 802.1x Port-based Network Access Control and how you c

Page 579 - Technical Overview

Chapter 3: Basic Switch Parameters62 Section I: Basic FeaturesSetting the System TimeThis procedure explains how to set the switch’s date and time. Se

Page 580 - 580 Section IV: Security

Chapter 29: 802.1x Port-based Network Access Control620 Section IV: SecurityIEEE 802.1x Port-based Network Access Control OverviewThe AT-S63 managemen

Page 581 - Infrastructure

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 621prohibits network access by a supplicant until the network user has ent

Page 582 - Revocation Lists

Chapter 29: 802.1x Port-based Network Access Control622 Section IV: SecurityPort Roles Part of the task of implementing this feature is specifying the

Page 583 - Implementation

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 623Figure 194. Example of the Authenticator RoleAs mentioned earlier, the

Page 584 - 584 Section IV: Security

Chapter 29: 802.1x Port-based Network Access Control624 Section IV: SecurityFigure 195. Example of the Supplicant RoleNoteStrictly limit the use of t

Page 585 - Section IV: Security 585

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 625❑ The date and time when the event occurred❑ The number of packets tran

Page 586 - 586 Section IV: Security

Chapter 29: 802.1x Port-based Network Access Control626 Section IV: Security❑ The IP addresses of up to three RADIUS servers. ❑ The encryption key use

Page 587 - Section IV: Security 587

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 627log on.❑ A username and password combination is not tied to the MAC add

Page 588 - 588 Section IV: Security

Chapter 29: 802.1x Port-based Network Access Control628 Section IV: Security❑ Set ports used to interconnect switches to the none role. This is illust

Page 589 - Section IV: Security 589

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 629Setting Port RolesThis procedure sets port roles. For an explanation of

Page 590 - Enter file name (*.key) ->

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 63The Configure System Time menu is shown in Figure 10.Figure 10. Co

Page 591 - Modifying a Certificate

Chapter 29: 802.1x Port-based Network Access Control630 Section IV: SecurityThe Configure Port Access Role menu is shown in Figure 198.Figure 198. Co

Page 592 - 592 Section IV: Security

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 631Enabling or Disabling 802.1x Port-based Network Access ControlThis proc

Page 593 - Section IV: Security 593

Chapter 29: 802.1x Port-based Network Access Control632 Section IV: SecurityConfiguring Authenticator Port ParametersTo configure authenticator port p

Page 594 - Deleting a Certificate

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 633The Configure Authenticator Port Access Parameters menu is shown in Fig

Page 595 - Section IV: Security 595

Chapter 29: 802.1x Port-based Network Access Control634 Section IV: Security2 - Quiet PeriodThe quiet period is the number of seconds that the port re

Page 596 - Viewing a Certificate

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 635Ingress - A port, when in the unauthorized state, discards all ingress

Page 597 - Section IV: Security 597

Chapter 29: 802.1x Port-based Network Access Control636 Section IV: SecurityConfiguring Supplicant Port ParametersTo configure supplicant port paramet

Page 598 - 598 Section IV: Security

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 637The Configure Supplicant Port Access Parameters menu is shown in Figure

Page 599 - Section IV: Security 599

Chapter 29: 802.1x Port-based Network Access Control638 Section IV: Security5 - User NameThe user name is the username for the switch port. The port s

Page 600 - 600 Section IV: Security

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 639Displaying the Port Access ParametersTo display the port access paramet

Page 601 - ...Done

Chapter 3: Basic Switch Parameters64 Section I: Basic Features3. From the System Configuration menu, type 8 to select Configure System Time.The Config

Page 602 - 602 Section IV: Security

Chapter 29: 802.1x Port-based Network Access Control640 Section IV: SecurityPort RolePort access role configured for the port. The possible settings a

Page 603 - Database

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 641Configuring RADIUS AccountingThe AT-S63 management software supports RA

Page 604 - Configuring SSL

Chapter 29: 802.1x Port-based Network Access Control642 Section IV: Security2 - PortThis parameter specifies the UDP port for RADIUS accounting. The d

Page 605 - Section IV: Security 605

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 643

Page 606 - 606 Section IV: Security

Section IV: Security 644Chapter 30TACACS+ and RADIUS ProtocolsThis chapter describes how you can use two authentication protocols, TACACS+ and RADIUS,

Page 607 - Secure Shell (SSH)

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 645TACACS+ and RADIUS OverviewThe AT-S63 management software has two stand

Page 608 - SSH Overview

Chapter 30: TACACS+ and RADIUS ProtocolsSection IV: Security 646password combination that you create on the server software. The access level can eith

Page 609 - Section IV: Security 609

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 647Administrative for this attribute gives the username and password combi

Page 610

Chapter 30: TACACS+ and RADIUS ProtocolsSection IV: Security 648Enabling or Disabling TACACS+ or RADIUSTo enable or disable the server-based authentic

Page 611 - Master Switch

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 649NoteBefore enabling server-based authentication on the switch, you shou

Page 612 - 612 Section IV: Security

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 65NoteThe switch does not set DST automatically. If the switch is in

Page 613 - Configuring SSH

Chapter 30: TACACS+ and RADIUS ProtocolsSection IV: Security 650Configuring TACACS+To configure the TACACS+ client software, perform the following pro

Page 614 - 614 Section IV: Security

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 651If you will be specifying more than one TACACS+ server and if all of th

Page 615 - Section IV: Security 615

Chapter 30: TACACS+ and RADIUS ProtocolsSection IV: Security 652Displaying the TACACS+ SettingsTo display the TACACS+ settings, perform the following

Page 616 - Displaying SSH Information

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 653TAC TimeoutThe maximum amount of time the switch waits for a response f

Page 617 - Section IV: Security 617

Chapter 30: TACACS+ and RADIUS ProtocolsSection IV: Security 654Configuring RADIUSTo configure the RADIUS protocol, perform the following procedure:1.

Page 618 - 618 Section IV: Security

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 655the list. If there are no more servers, then the switch defaults to the

Page 619 - Access Control

Chapter 30: TACACS+ and RADIUS ProtocolsSection IV: Security 656Displaying RADIUS Status and SettingsTo display the RADIUS status and settings, perfor

Page 620 - 620 Section IV: Security

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 657Auth PortUDP port of the RADIUS protocol.Encryption KeyEncryption key f

Page 621

Chapter 30: TACACS+ and RADIUS ProtocolsSection IV: Security 658

Page 622 - 622 Section IV: Security

Section IV: Security 659Chapter 31Denial of Service DefenseThis chapter contains procedures for configuring the switch to protect against denial of se

Page 623 - Section IV: Security 623

Chapter 3: Basic Switch Parameters66 Section I: Basic FeaturesConfiguring the Console Startup ModeYou can configure the AT-S63 management software to

Page 624

Chapter 31: Denial of Service Defense660 Section IV: SecurityDenial of Service OverviewThe AT-S63 management software can help protect your switch aga

Page 625 - Section IV: Security 625

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 661SMURF Attack This DoS attack is instigated by an attacker sending a ICM

Page 626 - Network Access

Chapter 31: Denial of Service Defense662 Section IV: SecurityFollowing is a simplified overview of how the process takes place. This example assumes t

Page 627 - Section IV: Security 627

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 663If one is found, the following occurs:❑ The switch sends an SNMP trap t

Page 628

Chapter 31: Denial of Service Defense664 Section IV: SecurityIP OptionsAttackIn the basic scenario of an IP attack, an attacker sends packets containi

Page 629 - Setting Port Roles

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 665Configuring Denial of Service DefenseTo configure DoS defense, perform

Page 630 - 630 Section IV: Security

Chapter 31: Denial of Service Defense666 Section IV: Securityb. Type 1 to select IP Address.The following prompt is displayed:Enter the IP Address for

Page 631 - Section IV: Security 631

AT-S63 Management Software Menus Interface User’s GuideSection IV: Security 667A menu is displayed containing either one or two options, depending on

Page 632 - 632 Section IV: Security

Chapter 31: Denial of Service Defense668 Section IV: Security

Page 633 - Section IV: Security 633

669Appendix AAT-S63 Default SettingsThis appendix lists the AT-S63 factory default settings. It contains the following sections in alphabetical order:

Page 634 - 634 Section IV: Security

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 67Configuring the Console TimerThe AT-S63 management software uses th

Page 635 - Section IV: Security 635

Appendix A: AT-S63 Default Settings670❑ ”Management Access Control List Default Setting” on page 692

Page 636 - 636 Section IV: Security

AT-S63 Management Software Menus Interface User’s Guide671Basic Switch Default SettingsThis section lists the default settings for basic switch parame

Page 637 - Section IV: Security 637

Appendix A: AT-S63 Default Settings672NoteLogin names and passwords are case sensitive.RJ-45 SerialTerminal PortDefault SettingsThe following table li

Page 638 - 638 Section IV: Security

AT-S63 Management Software Menus Interface User’s Guide673SwitchAdministrationDefault SettingsThe following table describes the switch administration

Page 639 - Section IV: Security 639

Appendix A: AT-S63 Default Settings674Enhanced Stacking Default SettingThe following table lists the enhanced stacking default setting.Enhanced Stacki

Page 640 - 640 Section IV: Security

AT-S63 Management Software Menus Interface User’s Guide675SNMP Default SettingsThe following table describes the SNMP default settings.SNMP Communitie

Page 641 - Configuring RADIUS Accounting

Appendix A: AT-S63 Default Settings676Port Configuration Default SettingsThe following table lists the port configuration default settings.Port Config

Page 642 - 642 Section IV: Security

AT-S63 Management Software Menus Interface User’s Guide677Event Log Default SettingsThe following table lists the event log default settings.Event Log

Page 643 - Section IV: Security 643

Appendix A: AT-S63 Default Settings678Quality of ServiceThe following table lists the default mappings of IEEE 802.1p priority levels to egress port p

Page 644 - TACACS+ and RADIUS Protocols

AT-S63 Management Software Menus Interface User’s Guide679IGMP Snooping Default SettingsThe following table lists the IGMP Snooping default settings.I

Page 645 - TACACS+ and RADIUS Overview

Chapter 3: Basic Switch Parameters68 Section I: Basic FeaturesEnabling or Disabling the Telnet ServerThis procedure describes how to enable or disable

Page 646 - TACACS+ and

Appendix A: AT-S63 Default Settings680Denial of Service Prevention Default SettingsThe following table lists the default settings for the Denial of Se

Page 647 - Section IV: Security 647

AT-S63 Management Software Menus Interface User’s Guide681STP, RSTP, and MSTP Default SettingsThis section provides the spanning tree, STP RSTP, and M

Page 648 - TACACS+ or

Appendix A: AT-S63 Default Settings682MSTP DefaultSettingsThe following table lists the MSTP default settings.Port Priority 128RSTP Setting DefaultMST

Page 649 - Disabling

AT-S63 Management Software Menus Interface User’s Guide683VLAN Default SettingsThis section provides VLAN default settings.VLAN Setting DefaultDefault

Page 650 - Configuring TACACS+

Appendix A: AT-S63 Default Settings684GVRP Default SettingsThis section provides the default settings for GVRP.GVRP Setting DefaultStatus DisabledGIP

Page 651 - D-Disabled) ->

AT-S63 Management Software Menus Interface User’s Guide685Port Security Default SettingsThe following table lists the port security default settings.P

Page 652 - Section IV: Security 652

Appendix A: AT-S63 Default Settings686802.1x Port-Based Network Access Control Default SettingsThe following table describes the 802.1x Port-based Net

Page 653 - TAC Timeout

AT-S63 Management Software Menus Interface User’s Guide687Web Server Default SettingsThe following table lists the web server default settings.Web Ser

Page 654 - Configuring RADIUS

Appendix A: AT-S63 Default Settings688SSL Default SettingsThe following table lists the SSL default settings.SSL Setting DefaultMaximum Number of Sess

Page 655 - Section IV: Security 655

AT-S63 Management Software Menus Interface User’s Guide689PKI Default SettingsThe following table lists the PKI default settings, including the genera

Page 656 - Section IV: Security 656

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 69Setting the Baud Rate of the RJ-45 Type Serial Terminal PortThe def

Page 657 - Section IV: Security 657

Appendix A: AT-S63 Default Settings690SSH Default SettingsThe following table lists the SSH default settings.SSH Setting DefaultStatus DisabledHost Ke

Page 658 - Section IV: Security 658

AT-S63 Management Software Menus Interface User’s Guide691Server-Based Authentication Default SettingsThis section describes the server-based authenti

Page 659 - Denial of Service Defense

Appendix A: AT-S63 Default Settings692Management Access Control List Default SettingThe following table lists the default setting for the Management A

Page 660 - Denial of Service Overview

693Appendix BSNMPv3 Configuration ExamplesThis appendix provides two examples of SNMPv3 configuration using the SNMPv3 Table menus and a worksheet to

Page 661 - Section IV: Security 661

Appendix B: SNMPv3 Configuration Examples694SNMPv3 Configuration ExamplesThis appendix provides SNMPv3 configuration examples for the following types

Page 662 - 662 Section IV: Security

AT-S63 Management Software Menus Interface User’s Guide695Configure SNMPv3 SecurityToGroup TableUser Name:systemadmin24Security Model:v3Group Name: Ma

Page 663 - Ping of Death

Appendix B: SNMPv3 Configuration Examples696Configure SNMPv3 View Table Menu View Name: internetView Subtree OID: 1.3.6.1 (or internet)Subtree Mask: V

Page 664 - Service Defense

AT-S63 Management Software Menus Interface User’s Guide697Group NameSecurity ModelSecurity LevelRead View NameWrite View NameNotify View NameStorage T

Page 665 - Section IV: Security 665

Appendix B: SNMPv3 Configuration Examples698SNMPv3 Target Parameters TableTarget Parameters NameUser (Security) NameSecurity ModelSecurity LevelStorag

Page 666 - Enter port-list:

699IndexNumerics802.1x Port-based Network Access Controlaccess role, configuring 629authentication process 621authenticator portconfiguring 632describ

Page 667 - Section IV: Security 667

AT-S63 Management Software Menus Interface User’s Guide7Displaying the RSTP Port State ...

Page 668 - 668 Section IV: Security

Chapter 3: Basic Switch Parameters70 Section I: Basic FeaturesPinging a Remote SystemYou can instruct the switch to ping a remote device on your netwo

Page 669 - AT-S63 Default Settings

Index700forced 121status 128Bback pressuredefault setting 676described 113baud rate, terminal port 69boot configuration fileconfiguring parameters 174

Page 670

AT-S63 Management Software Menus Interface User’s Guide701downloading switch to switch 194configuration name 283, 295console disconnect intervalconfig

Page 671 - Basic Switch Default Settings

Index702software module list 213Ffactory defaultslist 669resetting 71file naming conventions 170file system, description 170files, upoading 201filteri

Page 672 - SNTP Default

AT-S63 Management Software Menus Interface User’s Guide703IEEE 802.1p standard 222IEEE 802.1w standard 267image file, downloading 190ingress filtering

Page 673

Index704MIB treediagram 320RFC 320MIB view 320MIBssupported 35viewing 318MSTI association to a VLANcreating 305removing 306MSTI IDassociating to VLANs

Page 674 - Switch State Slave

AT-S63 Management Software Menus Interface User’s Guide705path cost 300path cost, desciption 252PEM certificate format 587, 600Ping of Death attack 66

Page 675 - SNMP Default Settings

Index706diagram 433displaying 451, 469drawbacks 432modifying 447rules 432ports, untagged 431priority level and egress queue mappings 223privacy 319pri

Page 676

AT-S63 Management Software Menus Interface User’s Guide707configuring 230, 231described 224strict priorityconfiguring 231described 225weighted round r

Page 677 - Event Log Default Settings

Index708SNMPv3 Access Table, described 324SNMPv3 community 406SNMPv3 Community Table entrycreating 407deleting 410displaying 422modifyingcommunity nam

Page 678

AT-S63 Management Software Menus Interface User’s Guide709Spanning Tree Protocol (STP)and VLANs 257bridge forwarding delay 262bridge hello time 262bri

Page 679

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 71Returning the AT-S63 Management Software to the Factory Default Val

Page 680

Index710temperature threshold, setting 74terminal port baud rate, setting 69TFTPdefault setting for remote management 671downloading and uploading fil

Page 681

Chapter 3: Basic Switch Parameters72 Section I: Basic FeaturesIf you respond with yes, the following prompt is displayed:Do you want to reset static I

Page 682 - MSTP Default

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 73Displaying and Setting System Hardware InformationYou can view info

Page 683 - VLAN Default Settings

Chapter 3: Basic Switch Parameters74 Section I: Basic FeaturesThe System Hardware Information menu provides the following information:System 1.25 V Po

Page 684 - GVRP Default Settings

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 75The Configure System Hardware menu is shown in Figure 13. Figure 13

Page 685

Chapter 3: Basic Switch Parameters76 Section I: Basic FeaturesDisplaying Uplink Port InformationTo display the information about the GBIC or SFP trans

Page 686

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 77The GBIC/SFP Information menu (page 1) is displayed. Figure 15 show

Page 687 - Web Server Default Settings

Chapter 3: Basic Switch Parameters78 Section I: Basic FeaturesThe information displayed depends upon whether a GBIC or an SFP transceiver is installed

Page 688 - SSL Default Settings

Section I: Basic Operations 79Chapter 4SNMPv1 and SNMPv2cThis chapter explains how to activate SNMP management on the switch and how to create, modify

Page 689 - PKI Default Settings

Contents8Deleting an SNMPv3 User Table Entry ...

Page 690 - SSH Default Settings

Chapter 4: SNMPv1 and SNMPv2 Community Strings80 Section I: Basic OperationsSNMPv1 and SNMPv2c OverviewThe Simple Network Management Program (SNMP) is

Page 691

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Operations 81Access ModeThis defines what the community string will allow a ne

Page 692 - Status Disabled

Chapter 4: SNMPv1 and SNMPv2 Community Strings82 Section I: Basic OperationsIt does not matter which community strings you assign your trap receivers.

Page 693 - SNMPv3 Configuration Examples

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Operations 83Enabling or Disabling SNMP ManagementTo enable or disable SNMP ma

Page 694

Chapter 4: SNMPv1 and SNMPv2 Community Strings84 Section I: Basic OperationsSetting the Authentication Failure TrapAs mentioned in the SNMP Overview s

Page 695 - Operator

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Operations 85Creating an SNMP Community StringTo create a new SNMP community s

Page 696 - Worksheet

Chapter 4: SNMPv1 and SNMPv2 Community Strings86 Section I: Basic OperationsThe following prompt is displayed:Enter Access Mode [R-Read Only, W-Read/W

Page 697

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Operations 8711. After making changes, type R until you return to the Main Men

Page 698

Chapter 4: SNMPv1 and SNMPv2 Community Strings88 Section I: Basic OperationsModifying a Community StringTo modify a community string, perform the foll

Page 699

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Operations 89The menu options are described below:1 - Add Attributes to Commun

Page 700

AT-S63 Management Software Menus Interface User’s Guide9Deleting an SNMPv3 Community Table Entry ...

Page 701

Chapter 4: SNMPv1 and SNMPv2 Community Strings90 Section I: Basic Operations3. If you want to remove the IP address of a management workstation from t

Page 702

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Operations 913. Type E to enable the community string or D to disable it. This

Page 703

Chapter 4: SNMPv1 and SNMPv2 Community Strings92 Section I: Basic OperationsDisplaying the SNMP Community StringsTo display the attributes of all the

Page 704

Section I: Basic Features 93Chapter 5Enhanced StackingThis chapter explains the enhanced stacking feature. The sections in this chapter include:❑ ”Enh

Page 705

Chapter 5: Enhanced Stacking94 Section I: Basic FeaturesEnhanced Stacking OverviewThe enhanced stacking feature can make it easier for you to manage t

Page 706

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 95❑ The enhanced stacking feature uses the IP address 172.16.16.16. D

Page 707

Chapter 5: Enhanced Stacking96 Section I: Basic FeaturesNoteNo IP address is required if you intend to manage the enhanced stack solely through the RJ

Page 708

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 97To manage the switches of a subnet, you can start a local managemen

Page 709

Chapter 5: Enhanced Stacking98 Section I: Basic FeaturesSetting a Switch’s Enhanced Stacking StatusThe enhanced stacking status of the switch can be m

Page 710

AT-S63 Management Software Menus Interface User’s GuideSection I: Basic Features 99The Enhanced Stacking menu is shown in Figure 22.Figure 22. Enhanc

Comments to this Manuals

No comments