Manuale d’uso / di manutenzione del prodotto MNS-6K-SECURE 14.1.4 del fabbricante GarrettCom
Vai alla pagina of 364
MAGNUM 6K F AMIL Y OF SWIT CHES Mana ged Netw or k Softw are (MNS) MNS-6K-SECURE 14.1.4 and MNS-6K 4.1.4 CLI User Guide.
Pr eface This guide describes how to use the Command Line Interface (CLI) for the Magnum 6K family of switches. For the Web Management Interface please refer to the Web Management Guide.
ii T r ademar ks GarrettCom Inc. reserves the right to change spe cifications, perform ance characteristics and/or model offerings with out notice. GarrettCom, Magnum, S-Ring, Link-Loss-Learn, Converter Switch, Conve nient Switch and Personal Swit ch are trademarks and Person al Hub is a registered trademark of Garrett Com, Inc.
T able of Contents 1 – Conventions Followed ............................................................... 19 Flow of the User Guide .......................................................... 21 2 – Getting Started ...............................
Upgrading to MNS-6K-SECURE ......................................... 36 List of commands in this chapter .......................................... 37 3 – IP Address and System Information ..................................... 39 IP Addressing .....
Configuring IPv6 ...................................................................... 74 List of commands in this chapter .......................................... 75 5 – DHCP Server ...............................................................
8 – Access Using RADIUS ................................................. 106 RADIUS ..................................................................................... 106 802.1x ...................................................................
Using STP ................................................................................ 148 List of commands in this chapter ........................................ 158 13 – Rapid Spanning Tree Pr otocol (RSTP) ...................... 159 RSTP concepts .
Configuring QoS .................................................................... 208 List of commands in this chapter ........................................ 213 18 – IGMP ........................................................................
System Events ......................................................................... 272 MAC Address Table .............................................................. 277 List of commands in this chapter ........................................ 278 APPENDIX 1 - Command listing by Chapter .
x Using Mozilla Firefox (ver. 3.x) ........................................... 329 Using Internet Explorer (ver 7.x) ........................................ 333 Using Other Browsers ........................................................... 334 APPENDIX 5 – Updating MNS-6K Software .
List of Figures F IGURE 1 - HyperTerminal screen showing the serial settings ................................................................. 25 F IGURE 2 - Prompt indicating the switch model number as well as mode of operation – note the commands to switch between the levels is not shown here.
F IGURE 24 - Changing telnet access – note in this case , the enable command was repeated without any effect to the switch ................................................................................................................ 42 F IGURE 25 - Reviewing the console parameters – note telnet is enabled .
F IGURE 46 – displaying configuration for different mo dules. Note – multiple modules can be specified on the command line ..................................................................................................... 64 F IGURE 47 – Hide or display system passwords .
F IGURE 70 – securing the network using port access ............................................................................ 113 F IGURE 71 – Flow chart describing the interact ion between local users and TACACS authorization .................
F IGURE 94 – More than one S-Ring pair can be selec ted and more than one S-Ring can be defined per switch. Note – the mP62 as we ll as the ES42 switches support LLL and can participate in S-Ring as an acc ess switch ..............................
F IGURE 112 – The network for the ‘show lacp’ command listed below .................................................. 203 F IGURE 113 – LACP information over a network ...........................................................................
F IGURE 136 – Predefined conditions for the relay ................................................................................ 257 F IGURE 137 – Setting up the external electrical relay and alerts ..............................................
xviii F IGURE 163 – Make sure to select the Xmodem protoc ol and the proper directory where t he configuration is saved. Click on Receive. This starts the file transfer. ......................................... 345 F IGURE 164 – Status window for Xmodem (using HyperTerminal under Windows X P) .
Chapter 1 1 – Con v entions F ollo w ed Conventions followed in the manual… o best use this document, please review some of the conventions followed in the manual, including screen captures, inte ractions and commands with the switch, etc.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Re Re ab lated Topics lated topics show that GarrettCom strongly recommends reading out those topics. You may choose to skip those if you already have prior detailed knowledge on those subjects. j Tool box – Necessary software and hard ware components needed (or recommended to have) as a prerequisi te.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Flow of the User Guide The manual is designed to guide th e user through a sequence of events. Chapter 1 – this chapter Chapter 2 is the basic setup as required by the Magnum 6K family of switc hes. After completing Chapter 2, the configuration can be done using the web interface.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 22 Chapter 12 shows how STP can be setup and used. To day, RSTP is pref erred over STP. Chapter 13 shows how RSTP is setup and used as well as how RSTP can be used with legacy devices which support STP only. Chapter 14 focuses on S-Ring™ and setup of S-Ring.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Chapter 2 2 – Getting Star ted First few sim ple steps … his section explains how the GarrettCom Magnum 6K family of switches can be setup using the console port on the switch.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE and a PC is networked to the switch, the switch’s command line interface (CLI) can be accessed via telnet. To manage the switch th rough in-band (networked) access (e.g. telnet, or Web Browser Interface), you should config ure the switch with an IP address an d subnet mask compatible with your network.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Once the switch is configured with an IP address, the Command Line Interface (or CLI) is also accessible using telnet as well as the serial port. Access to th e switch can be either through the console interface or remotely over the network.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE The switch has three modes of operation – Operator (least privilege), Manager and Configuration. The prompts for the switches change as the switch changes modes from Operator to Manager to Configuration. The pr ompts are shown in Figure 2 below, with a brief explanation of what the different prompts indicate.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Should a situation arise when there are mult iple new switches powered up at the same time, there could be a situati on of duplicate IP addresses. In this situation, only one Magnum switch will be assigned the IP address of 192.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE • Power on the switch • Once the login prompt appears, login as manager using default password (manager) • Configure the IP address, network mask and defaul.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Version : Magnum 6K25 build 14.1 Jul 28 2008 07:51: 45 MAC Address : 00:20:06:25:b7:e0 IP Address : 192.168.1.150 Subnet Mask : 255.255.255.0 Gateway Address : 192.168.1.10 CLI Mode : Manager System Name : Magnum6K25 System Description : 25 Port Modular Ethernet Switch System Contact : support@garrettcom.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE command is shown below in Figure 6 Magnum6K25> enable manager Password: ******* Magnum6K25# F IGURE 7 - Switching users and privilege levels.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25# user Magnum6K25(user)## add user=peter level=2 Enter User Password :****** Confirm New Password :***** * Magnum6K25(user)## F IGURE 8 - Adding a user with Manager level privilege In this example, user ‘peter’ was added with Manager privilege.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25(user)## F IGURE 11 - Changing the privileg e levels for a user In this example, user ‘peter’ was modified to Operator privileges. Modifying Access Privile ges User access allows the network adm inistrators to control as to who has read and write access and for which set of command groups.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25( u s e r )# # useraccess user=peter group=vlan,user,system type=read enable Access rules set for Read Operation.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Help Typing the ‘ help ’ command lists the commands you can execute at the current privilege level. For example, typing ‘ help ’ at the Operator level sho.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE show active-vlan show address-table show ag e show alarm show ar p show auth <config|ports> show backpressure show bootmode --more-- F IGURE 16 - Options for the ‘show’ command Conte xt help Other ways to display help, specifically, wi th reference to a command or a set of commands, use the TAB key.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25> se<TAB> passwor d timeout vlan Magnum6K25> set F IGURE 19 - Listing commands options – note the comma nd was not completed and the TAB key completed the command. Exiting To exit from the CLI interface and terminate the console session use the ‘ logout ’ command.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Saving current configuration Configuration saved Saving current event logs Event logs saved Magnum6K25# F IGURE 21 – Upgrading to MNS-6K-SECURE After the license key is entered – please use the save command to save the key in flash memory.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 38 Syntax <TAB> - listing all commands available at the privilege level Syntax <command string> <TAB> - options for a command Syntax <first c.
Chapter 3 3 – IP Addr ess and System Inf or ma tion First simple steps to follow … his section explains how the Magnum 6K fam ily of switches can be setup using other automatic methods such as bootp and DHCP . Besides this, other parameters required for proper operation of the switch in a network are discussed.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 40 To verify the IP address settings, the ‘show ipconfig’ command can be used. Magnum6K25> show ipconfig IP Address : 192.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE ht: is the “hardware type”. For the Magnum 6K family of switches, set this to ether (for Ethernet). This tag must precede the “ ha” ta g.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE switch is put on a network and the speci fic configurations are loaded from a centralized BootP server Magnum6K25# set bootmode type=dhcp Save Configuration and R.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25# show console Console/Serial Link Inbound Telnet Enabled : Yes Outbound Telnet Enabled : Yes Web Console Enabled : Yes SNMP Enabled : Yes Terminal Type.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25# user Magnum6K25(us er)## useraccess user=peter service=telnet enable Telnet Access Enabled. Magnum6K25(us er)## exit Magnum6K25# show session Current Sessions: SL # Session Id Connection User Name User Mode 1 1 163.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE strong algorithms such as blowfish, 3DES, IDEA etc.). Encryption provides confidentiality and integrity of data. . The goal of SSH was to repl ace the earlier rlogin, Telnet and rsh protocols, which did not provide strong authentication or guarantee confidentiality.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE • The user authentication layer (RFC 4252). This layer handles client authentication and provides a number of authentication methods. Authentica tion is client-driven , a fact commonly misunderstood by users; when one is prompted for a password, it may be the SSH client prompting, not the server.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25 (access)# # ssh ? ssh <enable|disable > : Enable s or Di sa bles the SSH ssh keygen : Generate Security Keys.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Boot Mode : manual Inactivity Timeout(min) : 500 Address Age Interval(min) : 300 Inbound Telnet Enabled : Yes Web Agent Enabled : Yes SSH Server enabled : Yes Mod.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25# show dns DNS Server Address : 0.0.0.0 Domain Name : Not Set DNS Status : Disabled. Magnum6K25# set dns server=192.168.5.254 domain=customer-doma in.com Domain Name Server Set. Magnum6K25# show dns DNS Server Address : 192.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Setting serial por t par ameter s To be compliant with IT or other policies the console parameters can be changed from the CLI interface. This is best done by setting the IP address and then telnet over to the switch.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE System Contact : support@garrettcom.com System Location : Fremont, CA System ObjectId : 1.3.6.1.4.1.553.12.6 Magnum6K25# F IGURE 31 - System parameters using the show setup co mmand. Most parameters here cannot be changed Magnum6K25# show sysconfig System Name : Magnum6K25 System Contact : support@garrettcom.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25# snmp Magnum6K25(snmp)## setvar ? setvar : Configures system name, co ntact or location Usage: setvar [sysname|syscontac t|syslocation] =<string>.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax set timeformat format=<12|24> Syntax set daylight country=< country name> Magnum6K25# set daylight ? set daylight : Sets the day light loc atio.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 54 Syntax sntp [enable|disable] For example, to set the SNTP server to be 204.65.129.201 2 (with a time out of 3 seconds and a number of retries set to 3 times); allowi ng the synchronization to be ever 5 hours, the following commands are used Magnum6K25# sntp Magnum6K25(sntp)## se tsntp server=204.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 55 To upgrade to MNS-6K 4.x or MNS-6K-SEC URE 14.x, make sure the switch is first upgraded to version 3.7 or higher Once the configuration is saved – the saved conf iguration can be loaded to restore back the settings.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax show ftp - display the current ftp operation mode With MNS-6K additional capabilities have been added to save and load configurations.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE This can also perform the task of exporti ng a configuration file or uploading a new image to the switch [host=<hostname>] [ip=<ipa ddress>] [file=<.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE object or in a newer format as an ASCII (readable) file. The new format is preferred by GarrettCom and GarrettCom recommends all configuration f iles be saved in the new format.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE # of Magnum 6K switch configurations. As such, this script # provides insights into the configuratio n of Magnum 6K switch's # settings.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE System portion of the file only. GarrettCom r ecommends editing the “scr ipt” file (see below) Note 2 – File names cannot have special characters such as *#!@$^&* space and control characters. Script files Script file is a file containing a set of CLI commands which are used to configure the switch.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE # System Manager - This area configures System rel ated # # i nformation. # ################### ######################### ############## set bootmode type=manual ipconfig ip=192.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE ============== ================= ================ ==================== = 1 server 192.168.5.2 -- ****** 2 -- -- -- -- 3 -- -- -- -- 4 -- -- -- -- 5 -- -- -- -- 6 .
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE gvrp GVRP settings snmp SNMP settings web Web and SSL/TLS settings tacacs TACACS+ settings auth 802.1x Settings igmp IGMP Settings smtp SMTP settings If the module name is not specified the whole configuration is displayed.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE deftrapcomm=public authtrap=disa ble com2sec _cou nt=0 group_count =0 view_count=1 view1_name=all view1_type=inc luded view1_subtree=.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25# set secrets hide Secrets will be hidden. Magnum6K25# set secrets show Secrets will be visible. Magnum6K25# F IGURE 47 – Hide or display system passwords Er asing configur ation To erase the configuration and reset the configurations to factory default, you can use the command ‘kill config’.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE smtp SMTP settings If the module name is not specified the whole configuration is erased. For example, ‘kill config save=system’ preserves the system IP address, netmask and default gateway.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE List of commands in this c ha pter Syntax set bootmode type=<dhcp|bootp|manual |auto> [bootimg=<enable|disable>] [bootcfg=[<enable|disable>] –.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax set serial [baud=<rate>] [data=<5|6 |7|8>] [parity=<none|odd|even>] [stop=<1|1.5|2>] [flowctrl=<none|xonxoff> ] – sets seri.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Where <get|put|list|del> - different ftp operations [type=<app|config|oldco nf|script|hosts|log>] – optional type field. This is useful to specify whether a log file or host file is uploaded or downloaded.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Where <get|put> - different xmodem file transfer operations – get a file from the server or put the information on the server [type=<app|config|oldco nf|script|hosts|log>] – optional type field. This is useful to specify whether a log file or host file is uploaded or downloaded.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 71 Syntax show timezone – shows the system timezone Syntax show date – shows the system date Syntax show uptime – shows the amount of time the switch has be.
Chapter 4 4 – IPv6 Next generation IP addr essing his section explains how the access to the GarrettCom Magnum MNS-6K can setup using IPv6 instead of IPv4 addressing described earlie r. IPv6 provides a much larger address space and is required today by many.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE incremental, with few or no critical interdepe ndencies. Most of today's internet uses IPv4, which is now nearly twenty years old. IPv4 has b een remarkably resilient in spite of its age, but it is beginning to have problems.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 74 used as an identifier for the node. A single interface may be assigned multiple IPv6 addresses of any type. There are three types of IPv6 addresses. These are unicast, anycast, and multicast. Unicast addresses identify a single interface.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 75 Magnum6K25# ipconfig ip=fe80::220 :6ff:fe 25:ed80 mask=ffff:ffff:ffff:ffff:: Action Parameter Missing. "add" assumed. IPv6 Parameters Set. Magnum6K25# show ipv6 IPv6 Address : fe80::220:6 ff:fe25:ed80 mask : ffff:ffff:ffff :ffff:: Magnum6K25# show ipconfig IP Address : 192.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 76.
77 5 – DHCP Ser v er Access to other devices on the netw ork…. his feature is available in MNS-6K-SECUR E only. This section explains how DHCP services can be provided for devices on the network.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 78 As described earlier, the Dynamic Host Configuration Protocol (DHCP) automates the assignment of IP addresses, subnet masks, defa ult gateway, DNS servers and other IP parameters.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE intervention. Most administrators prefer to use static IP addresses (which are allocated out for such purposes) instead of using the manual mode. Allocating specific IP address for specific network s or VLANs also aids in securing the network.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE The client broadcasts on the physical subnet to find available servers. Network administrators can configure a local router to forward DHCP packets to a DHCP server on a different subnet. This client-implementation creates a UDP packet with th e broadcast destination of 255.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE acknowledgement to the client. The system as a whole expects the client to configure its network interface with the supplied options.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax - reserve-ip ip=<ip> [mac=<mac>] - reserve a specific IP address for a device Syntax - clear-reserveip ip=<ip> - clear the reverse IP ass.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 83 Gateway : 192.168.10.1 Lease time : 8 Hours Magnum6K25(dhcpserv er)## dhcpsrv stop The Server takes few seconds to Stop.
Chapter 6 6 – SNTP Ser v er Synchr oniz ing the time…. fter discussing how to setup an SNTP client in an earlier chapter, it is important to figure out where the synchronizing server or the clock synchronization information comes from. This chapter discusses the details on how a Magnum switch can be setup as a SNTP server.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Time or Temps Atomique International (TAI) by inserting leap seconds at intervals of about 18 months. UTC time is disseminated by various m eans, including radio and satellite navigation systems, telephone modems and portable clocks.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Stratum 2 devices will peer with other Stratum 2 devices to provide more stable and robust time for all devices in the peer group.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE MNS-6K-SECURE Implementa tion Syntax sntpserver – enter the SNTP Server configuration mode Syntax sntpsrv <start|stop> - Start or stop the SNTP Services Syntax show sntpsrv – display the status of SNTP server The usage of the commands are shown below.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 88 List of commands in this c ha pter Syntax sntpserver – enter the SNTP Server configuration mode Syntax sntpsrv <start|stop> - Start or stop the SNTP Se.
Chapter 7 7 – Access Consider a tions Securing the switch access…. his section explains how the access to the GarrettCom Magnum MNS-6K can be secured. Further security considerations are also covered such as securing access by IP address or MAC address.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE P or t Security The port security feature can be used to bloc k computers from accessing the network by requiring the port to validate the MAC addre ss against a known list of MAC addresses. This port security feature is provided on an Et hernet, Fast Ethernet, or Gigabit Ethernet port.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25(port-security )## F IGURE 56 – Port security configuration mode From the port-security configuration mode , the switch can be configured to: 1) Auto-.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Note 1: There is a limitation of 200 MA C addresses per port and 500 MAC addresses per Switch for Port Security. Note 2: All the commands listed above have to be executed under the port-security configuration mode.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 11 ENABLE NONE NONE DISABLE 0 Not Configured 12 ENABLE NONE NONE DISABLE 0 Not Configured 13 ENABLE NONE NONE DISABLE 0 Not Configured 14 ENABLE NONE NONE DISABLE.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 00:07:50:ef:31:40 00:e0:29:22:15:85 00:03:47:ca:ac:45 00:30:48:70:71:23 00:c1:00:7f:ec:00 11 ENABLE NONE NONE ENABLE 0 00:c1:00:7f:ec:00 13 ENABLE NONE NONE DISABLE 0 00:c1:00:7f:ec:00 F IGURE 62 – Allowing specific MAC address on specific ports.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 9) (Optional step) Set the notification to notif y the management station on security breach attempts (Use command ‘signal port’ to make a log entry or send a.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Once port security is setup, it is important to manage the log and review the log often. If the signals are sent to the trap receiver, the traps should also be reviewed for intrusion and other infractions. Syslog and Logs Logs are available on MNS-6K as well as MNS-6K-SECURE.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Code Description 0 Emergency (or Fatal) system is unusable – called “fatal” in show log command 1 Alert : action must be taken immediately 2 Critical : crit.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE The ‘show log’ command displays the log information and the ‘clear log’ command clears the log entries. Syntax show log [fatal|alert|crit| error|warn|note.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Note 06-23-2007 05:59:02 P.M SNTP:SNTP Clie nt Started Note 06-23-2007 05:59:09 P.M SNTP:SNTP Time Synch roni zed Note 06-23-2007 05:59:10 P.M SNTP:SNTP Time Synch roni zed Note 06-23-2007 05:59:36 P.M CLI:Sessi on Started from Telnet: 192.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Server Added Magnum6K25 (syslog)## show syslog SysLog Status: Disabled Server ID: 1 SysLog Server Host : 192.168.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Server Enabled Magnum6K25 (syslog)## show syslog SysLog Status: Disabled Server ID: 2 SysLog Server Host : 192.168.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE attempts. This provides a chronological en try of all intrusions attempted on a specific port. The event log records events as single-line entries listed in chronological order, and serves as a tool for isolating problems.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE deny – deny specified services for specified IP addresses – IP addresses can be individua l stations, a group of stations or subnets.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax configure port-security – sets the port authorization based on MAC addresses Syntax port-security – configure port security settings Syntax allow mac=&.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 105 Syntax deny ip=<ipaddress> mask=< netmask> service=<name|li st> - deny specific IP address or range of IP addresses Syntax remove ip=<ipa.
Chapter 8 8 – Access Using RADIUS Using a RADIUS ser ver to authenticate access…. his feature is available in MNS-6K-S ECURE only. The IEEE 802.1x standard, Port Based Network Access Control , defines a mechanism for port-based network access control that makes use of the physical access characteris tics of IEEE 802 LAN infrastructure.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE received from the supplicant to a suitable authentication server. This allows the verification of user credentials to determine the consequent port authorization state. It is important to note that the authenticator’s functionality is independent of the actual authentication method.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 108 F IGURE 69 – 802.1x authentication details 1. The supplicant (laptop/host) is initially blocked from accessing the network. The supplicant wanting to access these services starts with an EAPOL-Start frame 2.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE The Magnum MNS-6K software implements the 802. 1x authenticator. It fully conforms to the standards as described in IEEE 802.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE maxreq – [optional] The maximum number of time s the authenticator will retransmit an EAP Request packet to the Supplicant before it times out the authentication session. Its default value is 2. It can be set to any integer value from 1 to 10.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25(auth)## auth disable 802.1X Authenticator is disabled. Magnum6K25(auth)## au thserver ip=192.168.1.239 secret=secret This command is not necess ary, ho.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25(auth)## show-port bac kend Port Supp Timeout Server Timeout Max Request (sec) (sec) ========== ================ ================= ====== 1 30 30 2 2 45.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25(auth)## show-port reauth Port Reauth Status Reauth Period (sec) ========== ================ ================= ====== 1 Enabled 300 2 Enabled 3600 3 Ena.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE List of commands in this c ha pter Syntax auth - configuration mode to conf igure the 802.1x parameters Syntax show auth <config|ports> - show the 802.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 115 Syntax reauth port=<num|list|range> [status=<e nable|disable>] [period=<10-86400>] - set values on how the authenticator (Magnum 6K switch) .
Chapter 9 9 – Access Using T A CA CS+ Using a TACACS+ ser ver to authenticate access…. his feature is available in MNS-6K-SECURE. TACACS+, short for Terminal Access Controller Access Control System, protocol prov ides access control for routers, network access servers and other networked computing de vices via one or more centralized servers.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE T ACA CS+ F lo w TACACS works in conjunction with the local use r list on the MNS-6K software (operating system.) Please refer to User Management for adding users on the MNS-6K software. The process of authentication as well as authoriz ation is shown in the flow chart below.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE is authentication where the user is verified against the network user database. The second stage is authorization, where it is determined whether th e user has operator access or manager privileges. T ACA CS+ Pac k et Packet encryption is a supported and is a configurable option for the Magnum MNS-6K software.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax tacplus <enable|disable> [ or der=<tac,local | local,tac>] - enable or disable TACACS authentication, specifying the order in which the serv er or local database is l ooked up where “tac,local” implies, first the TACAS+ server, then local logi ns on the device.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE ========== ================ ================= ===== 1 10.21.1.170 49 Enabled secret 2 10.21.1.123 49 Enabled some 3 -- -- -- -- 4 -- -- -- -- 5 -- -- -- -- Magnum6K25(user)## tacserver delete id=2 TACACS+ server is d elete d.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 121 [key=<string>] – [optional for add, mandatory with encrypt] when encryption is enabled, the secret shared key string must be supplied [mgrlevel=<le.
Chapter 10 10 – P or t Mir r oring and Setup Setup the ports for netw ork speeds , perfor mance as w ell as for monitoring…. his section explains how individual characteris tics of a port on the GarrettCom Magnum 6K family of switches are setup.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE The set of commands show how port 11 is mirrored on port 13. Any traffic on port 11 is also sent on port 13. Magnum6K25# show port-mirror Sniffer Port : 0 Monitor.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE speed – specifically sets the speed to be 10 or 100Mbps. Note – this works only with 10/100 ports – with 10Mbps ports, the option is ignored. No error is shown. See speed settings section below. flow – sets up flow control on the port.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE with the 802.3u standard, then the port conf iguration on the switch must be manually set to match the port configuration on the other device.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE where xonlimit can be from 3 to 30, default value is 4 xofflimit from 3 to 127, default value is 6 Syntax show flowcontrol Bac k Pr essur e Back Pressure is for half duplex operations and the controls provided indicates the number of buffers allowed for incoming traffic before a xon/xoff message is sent.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25# device Magnum6K25(device)## show flowcontrol XOnLimit : 4 XOffLimit : 6 Magnum6K25(device)## flowcontrol xonlimit=10 xofflimit=15 XOn Limit set succes.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Port Back Pressure : Disable Port Events Notify : log,trap,alarm Magnum6K25(device)## setport port=11 flow=enable bp=enable Magnum6K25(device)## show port Keys: E.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 129 programs (including some network games) ar e used. Storms can reduce network performance and cause bridges, routers, workstations, serv ers and PC's to slow down or even crash. Pr e v enting br oadcast stor ms The Magnum 6K family of switches is capa ble of detecting and limiting storms on each port.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 130 13 Enabled 19531 0 NO 14 Enabled 19531 0 NO 15 Enabled 19531 0 NO 16 Enabled 19531 0 NO Magnum 25(device ) # rate-threshold p rate 6K # ort=11 =3500 Broadcast.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 131 Syntax flowcontrol xonlimit=<value> xofflimit =<value> - configure flow control buffers yntax show flowcontrol – display flow control buffers yn.
132 11 – VLAN Cr eate separate netw ork segments (collision domains) across Magnum 6K family of switches….. hort for virtual LAN (VLAN) , a VLAN creates separate collision do mains or network segments that can span multiple Magnum 6K fami ly of switches.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 133 A group of network users (ports) assigned to a VLAN form a broadcast domain. Packets are forwarded only between ports that are de signated for the same VLAN. Cross-domain broadcast traffic in the switch is elimina ted and bandwidth is saved by not allowing packets to flood out on all ports.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 134 MNS-6K-SECURE supports up to 256 VLANs. F IGURE 80 – routing between different VLANs is perfor med usi ng a router such as a Magnum DX device or a Layer 3 switch (L3-switch) MNS-6K supports up to 32 VLANs per switch.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax add id=<vlan Id> [name=<v lan na me>] port=<number|list|range> [forbid=<number|list|range>] [<mgt|nomgt>] Disabling Management on VLAN Use the <nomgt> option when creating a VLAN as shown in the add id command abov e.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE have access to that information. No one else can access that VLAN. Similarly, if another switch had video surveillance equipment on VL AN 20 then only ports with access to VLAN 20 can have access to the video surveillance information.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 1. A word of caution – when TAG VLAN filtering is enabled, there can be serious connectivity repercussions – the only way to recove r from that it is to reload the switch without saving the configuration or by modifying the configuration from the console (serial) port 2.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE VLAN ID: 30 Name : marketing Status : Active ========== ============== PORT | STATUS ========== ============== 14 | DOWN Magnum6K25(port-v lan)## stop vlan=all All active VLAN's stopped. Magnum6K25(port-v lan)## exit Magnum6K25# show active-vlan Tag VLAN is currently active.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Tag based vlan Added Successfully. Vlan id :20 Vlan name : sales Ports :14-16 Magnum6K25(tag-vlan)## add id=20 name=marketing port=14-16 ERROR: Duplicate Vlan Id Magnum6K25(tag-vlan)## add id=30 name=marketing port=14-16 Tag based vlan Added Successfully.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 14 | UNTAGGE D | DOWN 15 | UNTAGGE D | DOWN 16 | UNTAGGED | DOWN VLAN ID: 30 Name : marketing Status : Pending ---------- -------------- ---------------- --------.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE ---------- -------------- ---------------- ------- PORT | MODE | STATUS ---------- -------------- ---------------- ------- 14 | UNTAGGED | DOWN 15 | UNTAGGED | DO.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 2 | UNTAGGED | DOWN 3 | UNTAGGED | DOWN 4 | UNTAGGED | DOWN 5 | UNTAGGED | DOWN 6 | UNTAGGED | DOWN 7 | UNTAGGED | DOWN 8 | UNTAGGED | DOWN 9 | UNTAGGED | DOWN 10.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Port 1 Default ID : 1 Filter Status : DISABLED. VLAN Memberships: Vlan: 1 Status : Active UNTAGGED Port 2 Default ID : 1 Filter Status : DISABLED. VLAN Memberships: Vlan: 1 Status : Active UNTAGGED <Deleting repeated information for port s 3 through 12> Port 13 Default ID : 1 Filter Status : DISABLED.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25(tag-vlan)## show-port VLAN Port Status. Port 1 Default ID : 1 Filter Status : DISABLED. VLAN Memberships: Vlan: 1 Status : Active UNTAGGED Port 2 Default ID : 1 Filter Status : DISABLED.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE VLAN Port Status. Port 14 Default ID : 1 Filter Status : ENABLED. VLAN Memberships: Vlan: 1 Status : Active UNTAGGED Vlan: 10 Status : Active TAGGED Vlan: 20 Stat.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax set-port port=<number|list|range> ta gging id=<number> status=<tagged| untagged> defines whether the outgoing packets from a port will be tagged or untagged.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Chapter 12 12 – Spanning T r ee Pr otocol (STP) Cr eate and manage alter nate paths to the netw ork panning Tree Protocol was designed to avoi d loops in an Ethernet network.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 148 V ariable or Attribute Default Value STP capabilities Disabled reconfiguring general operation priorit y 32768 Bridge maximum age 20 seconds Hello t ime 2 sec.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 149 Bridge ID : 80:00:00:20:06:25:ed:80 Bridge Priority : 32768 Bridge Forward Delay : 15 Bridge Hello Time : 2 Bridge Max Age : 20 Root Port : 0 Root Path Cost :.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 150 Designated Root : shows the MAC address of the bridge in the network elected or esignated as the root bridge. Normally when STP is not enabled the switch designates rity : shows the designated root brid ge’s priority.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 151 Priority: STP uses this to determine which por ts are used for forwarding. Lower the umber means higher priority. Value ranges from 0 to 255. Default is 128 mine the rwarding points. Values range from 1 to 65535 alues can be Listening, Learning, orwarding, Blocking and Disabled.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 152 STP CONFIGURATION ------------ -- --- Spanning Tree Enabled(Global) : YES Spanning Tree Enabled(Ports) : YES, 9,10,11,12,13,14,15,16 Protocol : Normal STP Bri.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 153 : specifies the switch (bridge) priority va lue. Priority This value is used along with the witch MAC address to determine which switch in the network is the root device. Lower h ports re the forwarding points.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 154 STP Port Configuration ---------- -------------- ---------------- -------------- ---------------- ---------------- -------------- ---------------- ---- Port# Type Priority Path Cost State Des.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 155 14 TP(10/100) 128 100 Disabled 80:00:00:20:06:25:ed:80 80:0e 15 TP(10/100) 128 100 Disabled 80:00:00:20:06:25:ed:80 80:0f 16 TP(10/100) 128 100 Disabled 8 0:0.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 156 Setting cost for STP...Successfully set the path cost for port 13 Magnum6K25(stp)## show stp ports STP Port Configuration ---------- -------------- ---------------- -------------- ---------------- ---------------- -------------- ---------------- ---- Port# Type Priority Path Cost State Des.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 157 Magnum6K25(stp)## show stp config STP CONFIGURATION ------------ -- --- Spanning Tree Enabled(Global) : YES Spanning Tree Enabled(Ports) : YES, 9,10,11,12,13,.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 158 RSTP CONFIGURATION ------------ -- --- Rapid STP/STP Enabled(Global) : NO Magnum6K25(stp)## F IGURE 86 – Configuring STP parameters List of commands in this.
Chapter 13 13 – Rapid Spanning T r ee Pr otocol (RSTP) Cr eate and manage alter nate paths to the netw ork apid Spanning Tree Protocol (RTSP), like STP, was designed to avoid loops in an Ethernet network. Rapid Spanning Tree Protocol (RSTP) (IEEE 802.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE • STP relays configuration messages receive d on the root port going out of its designated ports. If an STP switch (bridge) fails to receive a message from its neighbor it cannot be sure where along the path to the root a failure occurred.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Even though RSTP interoperates with STP, RSTP is so much more efficient at establ ishing the network path and the network convergence in case of a failure is very fast. For this reason, GarrettCom recommends that all your network devices be updated to support RSTP.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax rstp <enable|disable> - enable RSTP – by default, this is disabled and has to be manually activated Syntax port port=<number|list|range> [sta.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE RSTP CONFIGURATION ------------ -- --- Rapid STP/STP Enabled(Global) : YES RSTP/STP Enabled Ports : 9,10,11,12,13,14,15,16 Protocol : Normal RSTP Bridge ID : 00:0.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Root Path Cost : a path cost is assigned to indivi dual ports for the switch to determine which ports are the forwarding points.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Port#: indicates the port number. Value ranges from 01 to max number of ports in the switch Type: indicates the type of port – TP indicates Twisted Pair Priority: STP uses this to determine which ports are used for forwarding.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 06 TP(10/100) 128 200000 Forwar ding 80:00:00:2 0:06:30:00:01 00:06 07 TP(10/100) 128 200000 Discardi ng 80:00:00:20:06:2b:0f:e1 00:07 08 TP(10/100) 128 2000000 D.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Status: Enables or disables a port from participat ing in STP discovery. It’s best to only allow trunk ports to participate in STP.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Root Port : 0 Root Path Cost : 0 Designated Root : 00:00:00:20:06:25:ed:89 Designated Root Priority : 0 Root Bridge Forward Delay : 15 Root Bridge Hello Time : 02.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Root Bridge Max Age : 20 Topology Change count : 0 Time Since topology Chg : 100 Magnum6K25(rstp)## forceversion rstp Magnum6K25(rstp)## show-forceversion Force V.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25(rstp)## priority port=13 value=100 Magnum6K25(rstp)## show rstp ports RSTP Port Configuration ---------- -------------- ---------------- -------------- ---------------- ---------------- -------------- ------------- Port# Type Priority Path Cost State Des.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 16 TP(10/100) 128 2000000 Disabled 00:10 Magnum6K25(rstp)## port port=9 status=enable Magnum6K25(rstp)## show rstp ports RSTP Port Configuration ---------- -------------- ---------------- -------------- ---------------- ---------------- -------------- -------------- Port# Type Priority Path Cost State Des.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE List of commands in this c ha pter Syntax set stp type=<stp|rstp> - Set the switch to support RSTP or chan ge it back to STP.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 173 Syntax timers forward-delay=<4-30> hello=<1-10> age=<6-160> - change the STP Forward delay, Hello timer and Aging timer values.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Chapter 14 14 – S-Ring™ and Link-Loss-Lear n™ (LLL) Speed up r ecover y fr om faults in Ether net networks S -Ring uses ring topology to provide fast recovery from faults. These are based on industry standard STP technologies.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE S-Ring and LLL concepts S-Ring is built upon networking software standards such as IEEE 02.1d Spanning Tree Protocol (STP) or Rapid Spanning Tree Protocol STP) based on IEEE 802.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 3. There can be multiple S-Rings on a given Magnum 6K switch. There can be multiple ring topologies in a network. Each ring has to be a separate ring. Ring of rings or overlapping rings are not supported at this time 4.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE S-Ring with LLL RSTP STP Resiliency Fast recovery from a single point of failure. Ring Master is responsible for decision making Multiple points of failure – ea.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE F IGURE 92 – Normal RSTP/STP operations in a series of sw itches. Note – this normal status is designated RING_CLOSED BP D U T r a ff i c Forward ing Port Bl ockin g Port BP D U T r a ff i c Forward ing Port Bl ockin g Port This normal status is designated as RING_CLOSED.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 179 F IGURE 93 – A fault in the ring interrupts traffic. The bl ocking port now becomes forwarding s o that traffic can reach all switches in the network Note .
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE F IGURE 94 – More than one S-Ring pair can be selected an d more than one S-Ring can be defined per switch. Note – the mP62 as well as the ES42 swit ches supp.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE When the fault is cured, the re-emergence of th e ring structure enables the BPDU packets to flow again between the ring’s por t-pair. This is recognized by S-Ring (and RSTP/STP), and one of the ports in the ring’s port pair is changed to the bloc king state.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE please contact GarrettCom Inc. Sales (for purchasing the S-Ring feature) or Technical Support (to obtain the 12 character key.) If th e S-Ring capability was purchased along with the switch, the software license code will be included with the switch.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE • Same Duplex and • LLL - enable The necessary commands are Syntax stp – STP Configuration mode Syntax stp <enable|disable> - Start (Enable) or stop (Disable) ST P Syntax set stp type=<stp|rstp> - set the spanning tree protocol to be IEEE 802.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Ports 1 and 7 Configured f or sRing O peration Magnum6K25# show s-ring Magnum Ring Status: sRing Status: ENABLED Port 1 Port 2 Status 1 7 CLOSED F IGURE 96 – S-.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Link-Loss-Learn Enabled. Magnum6K25(stp)## lll a dd port=1,2,3 Added Ports: 1,2,3 Magnum6K25(stp)## show lll Link-Loss-Learn Status: LLL Status: ENABLED LLL Enabled on Ports: 1,2,3 Magnum6K25(stp)## lll d el port=2,3 Deleted Ports: 2,3 Magnum6K25(stp)## lll d isable Link-Loss-Learn Disa bled.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 186 Syntax lll add port=<port|list|range> - enable LLL on the list of specified ports Syntax lll del port=<port|list|range> - disable LLL on the list .
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Chapter 15 15 – Dual-Homing F a ult tolerance options for edge devices esigning and implementing high-availa bility Ethernet LAN topologies in networks can be challenging.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE F IGURE 98 – Dual-homing using ESD42 switch and Magnum 6K family of switches. In case of a connectivity break – the connection switch es to the standby path o.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 189 switches upstream. With MNS-6K, the user has to define the set of ports which m ake up the dual-home ports. F IGURE 100 – Using S-Ring and dual-homing, it i.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Dual-Homing Modes There are two modes in which the dual-homing works. The first one is where the ports are “equivalent” i.e. if one port fa ils, the other one take over, however, if the first (failed) port recovers, the active port does not switch back.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25# dualhome ? dualhome : Configures Dual homing Usage dualhome <enter> Magnum6K25# show dualhome Dual Homing Status : DISABLED Magnum6K25# dualhome Magnum6K25(dualhome)## dualhome add port1=10 port2=11 Dual Homing Ports configured Magnum6K25(dualhome)## dualhome enable Dual Homing Enabled.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 192 List of commands in this c ha pter Syntax dualhome – enter the dual-homing configuration sub-system Syntax dualhome <enable|disable> – enable or dis.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Chapter 16 16 – Link Agg re ga tion Contr ol Pr otocol (LA CP) Incr ease Network thr oughput and r eliability ink aggregation Link Aggregation Control Pr otocol (LACP) is part of an IEEE specification (IEEE 802.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE The performance is improved because the capacity of an aggregated link is higher than each individual link alone.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE F IGURE 102 – Some valid LACP configurations. Should trunks be created so as to span mu ltiple ports, a “tru nk mismatch” error message is printed on the console. An example of an incorrect configuration is shown below.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE between the switches and hence the LACPDU cannot be transmitted. This configuration will not work in the LACP m ode. VLAN 20 VLAN 10 Switch 2 Switch 1 F IGURE 105 - In the figure above, there is no common VLAN between the two sets of ports, so packets from one VLAN to another cannot be forwarded.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE F IGURE 106 – This configuration is similar to the prev ious configuration, except there is a common VLAN (VLAN 1) between the two sets of LAC P ports.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 198 F IGURE 108 – LACP, along with RSTP/STP brings redund ancy to the network core or backbone. Using this reliable core with a dual -homed edge switch brings reliabilit y and redundancy to the edge of the network It is recommended not to use LA CP with S-Ring at this time.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE S-Ring 2 S-Ring 1 F IGURE 109 – This architecture is not recommende d LACP can be used for creating a reliable ne twork between two fac ilities connected via a wireless bridge. As shown in the figure belo w, four trunk ports are connected to four wireless bridge pairs.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 200 F IGURE 110 – Creating a reliable infrastruc ture using wireless bridges (bet ween two facilities) and LACP.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE the lowest priority value has the highest priority and is designated a s the primary port. If traffic analysis is required, it is recommende d to mirror the primary port (and physically disconnect the other ports if all traffic needs to be captured).
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 15 32768 Link Down Magnum6K25(lacp)## ad d port=12 Port(s) added succ es sfully. Magnum6K25(lacp)## sh ow lacp Orphan Ports: Port Priority Trunk ========== ======.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 203 The output of the LACP command in the network shown below F IGURE 112 – The network for the ‘show lacp’ command listed below In the figure shown above, Switch 1 has ports 11 and 15 forming the fi rst trunk, connecting to Switch 3.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 204 ========== =========== 17 32768 Primary Port 23 32768 Member Port F IGURE 113 – LACP information over a network List of commands in this c ha pter Syntax la.
Chapter 17 17 – Quality of Ser vice Prioritize traf fic in a network uality of Service (QoS) refers to the capa bility of a network to provide different priorities to different types of traffic.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE the packet into one of the two qu eues, and depending on the precedence levels the queue could be rearranged to meet the QoS requirements. QoS refers to the level of preferential tr eatment a packet recei ves when it is being sent through a network.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE IP Pr ecedence IP Precedence utilizes the three pr ecedence bits in the IPv4 head er's Type of Service (ToS) field to specify class of service for each packet. You can partition traffic in up to eight classes of service using IP precedence.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Not all packets received on a port have high priority. IGMP and BPDU packets have high priority by default. The Magnum 6K family of switches has the capability to set the priorities based on three different functions.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax set-weight weight=<0-7> - sets the port priority weight for All the ports. Once the weight is set, all the ports will be the same weight across the switch. The valid value for weight is 0-7. A weight is a number calculated from the IP precedence setting for a packet.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 210 Syntax show qos [type=<port|tag|tos>] [port=<port|list|range>] – displays the QoS settings Sometimes it is necessary to change the prio rity of the packets going out of a switch. For example, when a packet is received untagged and has to be transmitted with an addition of the 802.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 211 10 | Port | DOWN 11 | None | DOWN 13 | None | DOWN 14 | None | DOWN 15 | None | DOWN Magnum6K25(qos)## show qos type=port ========== ================ ====== P.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 212 Magnum6K25(qos)## show qos type=tag ============== ================= ========= PORT | Pri for VPT | STATUS | 76543210 | ==== ============ ==== = =============.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 213 Magnum6K25(qos)## show qos ============== ================= ========= PORT | QOS | STATUS ======= ==================== = ============ 1 | None | UP 2 | None |.
214 18 – IGMP Multicast traf fic on a network nternet G roup M anagement P rotocol (IGMP) is defined in RF C 1112 as the standard for IP multicasting in the Internet. It is used to establish host memberships in particular multicast groups on a single network.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE The creation of transient groups and the maintenance of group membership information is the responsibility of "multicast agents", entities th at reside in internet gateways or other special- purpose hosts.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE F IGURE 118 – IGMP concepts – advantages of using IGMP • PCs 1 and 4, switch 2, and all of the routers are members of an IP multicast group. (The routers operate as queriers.) • Switch 1 ignores IGMP traffic and does not distinguish between IP multicast group members and non-members.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE The next figure (below) shows a network running IP multicasting using IGMP without a multicast router. In this case, the IGMP-configured switch runs as a querier. PCs 2, 5, and 6 are members of the same IP multicast group.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE groups in the IP address range of 224.0.0.0 to 224.0.0.255 will always be flooded because addresses in this range are “well known” or “reser ved” addresses.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE traffic only goes to the ports requesting the traf fic. The Magnum 6K family of switches, using IGMP-L2, can perform the similar tasks a Layer 3 device performs for IGMP. For a Layer 2 IGMP environment, all Magnum 6K fa mily of switches have to be enabled in the IGMP-L2.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE With IGMP-L2 enabled on all Magnum 6K family of switches, this situation as shown above is prevented. This is explained in the figure below.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Since the query and the join information is exchanged between the neighboring switches, the topology does not matter. The design issue to consider is the timing difference between a topology recovery and IGMP refresh (recovery).
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE group del ip=<group ip> - delete ports from a specific IGMP broadcast group Magnum6K25# igmp Magnum6K25(igmp)## igmp enable IGMP is enabled Magnum6K25(igmp).
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE The output of “show igmp” provide useful inform ation. The following information is provided: IGMP State shows if IGMP is turned on (Enable) or off (Disable). Immediate Leave provides a mechanism for a particular host that wants to leave a multicast group.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE • Auto – lets IGMP control whether the port should or should not participate sending multicast traffic • Block – manually configures the port to always bl.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 10 Forwarding 11 Forwarding 12 Forwarding 13 Auto 14 Blocking 15 Blocking 16 Blocking Magnum6K25(igmp)## igmp enable IGMP is enabled Magnum6K25(igmp)## show-router RouterIp PortNo Timer ------------ -------------- -- ---------- 10.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 226 Querier Response Interval : 10 Magnum6K25(igmp)## set-querier disable IGMP querier status is disabled Magnum6K25(igmp)## show igmp IGMP State : Enabled Immedi.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 227 GroupIp PortNo Timer Vlanid LeavePending ------------ -------------- -- -------------- -- -------------- -- -------------- -- -- 0.0.0.0 1 155 1 0 239.0.1.10 10 STATIC 0 0 239.0.1.10 11 STATIC 0 0 239.0.1.10 12 STATIC 0 0 239.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 228 Magnum6K25(igm p)## mode normal IGMP set to Normal Mode. Magnum6K25(igm p)## exit Magnum6K25# F IGURE 126 - Setting IGMP-L2 List of commands in this c ha pter.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 229 group address, 224.0.0.1. The defa ult value is 125 seconds. The vali d range can be from 60 to 127 seconds. set-qri interval=<value> - Syntax The query.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Chapter 19 19 – GVRP Generic Attribute Registration Protocol ( GARP) VLAN Registration Protocol (GVRP) eneric A ttribute R egistration P rotocol (GARP) and VLAN registration over GARP is called GVRP. GVRP is defined in the IE EE 802.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE the default VLAN set to untagged and configure other static VLANs on the ports as either “Tagged or Forbid ” .
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE If a static VLAN is configured on at leas t one port of a switch, and that port has established a link with another device, then all other ports of that switch will send advertisements for that VLAN.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE • If there is no static VLAN with the adve rtised VID on the receiving port, then dynamically create a VLAN with the same VID as in the advertisement, and allow.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE ========== ================ ================= = VLAN ID | NAME | VLAN STATUS ========== ================ ================= = 1 | Default VLAN | Static Active 2 | .
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE configuration Learn Generate ad vertisements. Forward advertisements for other VLANs Receive advertisements and dynamically join any advertised VLAN Receive adver.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 236 Syntax show gvrp - shows whether GVRP is disabled, along with the current settings for the maximum number of VLANs and the current Primary VLAN Syntax gvrp &l.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 237 Magnum6K25(gvrp)## set-forb id vlan=2 forbid=11-15 Magnum6K25(gvrp)## show-forb id ========== ================ ================= = VLAN ID | FORBIDDEN PORTS =.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 238 List of commands in this c ha pter Syntax show gvrp - shows whether GVRP is disabled, along with the current settings for the maximum number of VLANs and the .
Chapter 20 20 – SNMP Managing y our netw ork using SNMP imple Network Management Protocol (SNMP) enables management of the network. There are many software packages which prov ide a graphical interface and a graphical view of the network and its devices.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Simple Network Management Protocol Version 3 (SNMPv3) – The third version of SNMP, the enhancements made to secure access, different levels of access and security.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Notification host – An SNMP entity to which notifications (traps and informs) are to be sent Notify view – A view name (not to exceed 64 characters) for each .
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE • RMON MIB (RFC 1757) • RMON: groups 1, 2, 3, and 9 (Statistics, Events, Alarms, and History) • Version 1 traps (Warm Start, Cold Start, Li nk Up, Link Down, Authentication Failure, Rising Alarm, Falling Alarm) RFC 1901-1908 – SNMPv2 • RFC 1901, Introduction to Community-Ba sed SNMPv2.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax community [write=<write community>] [read=<read community>] [trap=<trap community>] – set the necessary community strings Syntax authtr.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax com2sec <add|delete> id=<id> [secname=<name> ] [source=<source>] [community=<community>] - a part of the View based Acc ess control model (VACM) as defined in RFC 2275. This specifies the mapping from a source/community pair to a security name.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE SNMP MANAGERS INFO ------------ ------ SNMP TRAP STATIONS INFO ------------ ----------- Magnum6K25# snmp Magnum6K25(snmp)## comm unity write=private read=public S.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE SNMP TRAP STATIONS INFO ------------ ----------- Magnum6K25(snmp)## traps add ty pe=Snmp,Rmon ip=192.168.1.2 Successfully Added.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 6K SNMP Agent supports all (v1/v2c/v3) versions. Magnum6K25# show snmp SNMP v3 Configuration Information ========== ================ === System Name : Magnum6K25 System Location : Fremont, CA System Contact : support@garrettcom.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25(snmpv3)## show-trap ID Trap Type Hos t IP Community Port ========== ================ ================= ==================== = 1 v1 10.21.1.100 -- -- 2 -- -- -- -- 3 -- -- -- -- 4 -- -- -- -- 5 -- -- -- -- Magnum6K25(snmpv3)## show-trap id=1 Trap ID : 1 Trap Type : v1 Host IP : 10.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25(snmpv3)## group add id=1 groupname=v1 model=v1 com2secid=1 Entry is added successfully Magnum6K25(snmpv3)## show-group ID Group Name Sec.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25(snmpv3)## access add id=1 accessname=v1 model=v1 level=noauth read=1 writ e=none notify=none Entry is added successfully Magnum6K25(snmpv3)## show-acce.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25(snmpv3)## show-user id=1 User ID : 1 User Name : jsmith User Type : read-write Auth. Pass s omething Priv.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE The following RMON communities, when defined, enable the specific RMON group as show above. Syntax rmon – enter the RMON configuration mode to setup RMON groups.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax snmpv3 – enter the SNMP V3 configuration mode – note enable SNMP V3 by using the “set snmp” command which follows Syntax show active-snmp – shows.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax trap <add|delete> id=<id> [type=<v 1|v2|inform>] [host=<host-ip>] [community=<string>] [port=<1-65534>] - define the trap and inform manager stations. The station can receive v1, v2 traps and/or inform notifications.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 255 Syntax statistics def-owner=<string> def-comm=<string> - define the RMON statistics group and the community string asso ciated with the group Synt.
Chapter 21 21 – Miscellaneous Commands Impr oving pr oductivity and manageability here are several features built into the Magn um 6K family of switches which help with the overall productivity and manageability of the switch. These items are examined individually in this chapter.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 257 Event ID Event Description Signal Type 1 S-RING OPEN SUSTAINED 2 Cold Start MOMENTARY 3 Warm Start MOMENTARY 4 Link Up MOMENTARY 5 Link Down MOMENTARY 6 Authe.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax period time=<1..10> - sets the duration of relay action for the momentary type signal. This may be needed to adjust to the behavior of the circuit or relay.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 6 Authentication Failure MOMENTARY 7 RMON Raising Alarm MOMENTA RY 8 RMON Falling Alarm MOMENTARY 9 Intruder Alarm MOMENTARY 10 Link Loss Learn Triggered MOMENTAR.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 9 Intruder Alarm MOMENTARY 10 Link Loss Learn Triggered MOMENTARY 11 Broadcast Storm Detected MOMENTARY 12 STP/RSTP Reconfigured MOMENTA RY Magnum6K25(alarm)## al.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE sending and receiving emails, it is extremely beneficial for a network administrator to receive emails in case of faults and alerts. The Magnum 6K family of switches can be setup to send a n email alert when a trap is generated.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE traps – [optional] this is the trap filter. If valu e is “all”, all traps of any type will be sent to this recipient. If value is none, no traps are sent to this recipient. Value can also be a combination of ‘S’ (SNMP), ‘R’ (RMON) and ‘E’ (ENTERPRISE).
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax smtp <enable|disable> - enables or disables SMTP to send SNMP alerts by email Magnum6K25# smtp Magnum6K25(smtp)## show smtp config SMTP Global Configuration ========== ================ ============== Status : Disabled SMTP Server IP : 67.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25(smtp)## add id=2 email=jsmith@g arrettcom.com traps=S events=CF ip=192.168.10.13 Recipien t successfully a dded Magnum6K25(smtp)## show smtp recipients ID E-mail Address SMTP Server Port Traps Events ============== ================= ================ ============ 1 rk@gci,sys@gci.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 265 Magnum6K25# F IGURE 138 – setting SMTP to receive SNMP trap information via email Email alerts can be forwarded to be receiv ed by other devices such as Cell phones, pagers etc. Most interfaces to SMTP are already provided by the cell phone service provider or the paging service provider.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 266 Banner Messa ge essage is available in MNS-6K-SECURE. t one as to deter unauthorized access. Some users may inadvertently connect to the MOTD stands for Message of the Day, a term used by system administrators to show the status f the system or inform the users of uses or abuses on the system.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 267 Please disconnect if you are an unauthorized user. Thanks. MOTD Updated. It will be displayed at next login. Magnum6K25# show motd Motd : This is a secure device. Unaut hori zed access is prohibited. Please disconnect if you are an un auth orized user.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 268 Syntax !! – repeat the last command Syntax !<n> - repeat the “n”th command (a s indicated by a show history) Syntax show history – show the last 25 commands executed – if less than 25 commands are executed, only hown If the user logs out or if the switch time s out – the history is erased.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 269 Magnum 6K 5# se 2 t history ? set history : Set Histo ry Size Usage set history size=<1-100> Groups: All. Magnum 6K25# set history size=100 History Size is Set Magnum6K25# show history 1 : show version 2 : show setup 3 : show serial 4 : show history Magnum6K25# !1 show vers ion MNS-6K-Secure Ver: 14.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 270 $$ : $ Character $r : New Line $b : Space A f ow the system prompt can be setup is shown below. 6K25# snmp ew examples on h Magnum Magnum6K25(snmp)## setvar sysname=Core System variable(s) set successfully Magnum6K25(snmp)## exit Magnum6K25# set prompt $n Core# set prompt $n$b$i Core 192.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 271 F IGURE 143 – Using the ping command Many devices do not respond to ping or block ping commands. Make sure that the target device does respond or the ne twork does allow the ping packets to ropagate through.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 272 System Ev ents All events occurring on the Magnum 6K family of switches are logged. The events can be escription as shown below Code D 0 Emergency (or Fatal) .
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 273 arrettCom recommends that this capability should be used centralize the logs. Magnum6K2 # The system events can be sent to a Syslog server using the Sysl og capabilities in MNS-6K-SECURE.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 274 Do you wish to export the event logs? [ 'Y' or 'N'] Y Successfully uploaded the event log file.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Subsystem Description Severity BRIDGE Unable to delete MAC address from FDB D BRIDGE Unable to insert MAC address to FDB D BRIDGE Bridge init failed for ethx F BR.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Subsystem Description Severity RMON Alarm : internal error , unable to get m emory F RMON Alarm : internal error, unable to get m emory for alarm entry F RMON His.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Subsystem Description Severity TCP/IP Duplicate IP a.b.c.d se nt from MAC address XXXXXX C TCP/IP Unable to allocate memory for an ICMP packet C TCP/IP IP packet from a.b.c.d , with checksum error dropped D TCP/IP Bad IP fragments from a.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Magnum6K25# show address-table Sl# MAC Address Port ------------ -------------- -- -------------- -- --------- 1 01:00:5e:00:00:fb 0 2 00:0c:f1:b9:d1:dc 3 3 33:33.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax show smtp <config|recipients> - config – displays the current SMTP global settings and recipients displays the currently config ured recipients of .
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 280 body – [mandatory] email body Syntax server ip=<ip-addr> [port =<1-65535>] [retry=<0-3>] – configure the global SMTP server settings ip .
APPENDIX 1 APPENDIX 1 - Command listing by Chapter A rich envir onment – this A ppendix provides a r ef er ence to the commands by chapter Chapter 2 – Getting Star ted Syntax ipconfig [ip=<ip-a.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax useraccess groups – displays the current groups Syntax help <command string> - help for a specific command Syntax command <Enter> - options f.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE bootcfg=<enable|disable> - valid with type=bootp only. This option allows the switch to load the configuration file from the BootP server.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax saveconf mode=<serial|tftp|ftp> [<ipaddress>] [file=<name>] – saves the configuration on the network usin g tftp, ftp or serial protoco.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax tftp <get|put> [type=<app|confi g|oldconf| script|hosts|log>] [host=<hostname>] [ip=<ipa ddress>] [file=<filename>] – uploa.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax show sysconfig – reviews settabl e system parameters Syntax show time – shows the system time Syntax show timezone – shows the system timezone Syntax.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax – addlease ip=<ip> mac=<mac> [leasetime=<lease time (1..10)>] – add a specific host with a specific IP address Syntax - reserve-ip ip.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax signal port=<num|list|range> <none|log|trap|logandtrap> - port to monitor and signal to send in case of breach of port security Syntax ps <e.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax clear <history|log [1..5 |informational |activity |critical |fatal |debug] |terminal |arp|portstats|addr] – clear command to clear various aspe cts of.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE transmit – [optional] This is the transmit pe riod, this is the time in seconds the authenticator waits to transmit another reque st for identification from the supplicant.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Chapter 10 – P or t mir r oring and setup Syntax show port-mirror – display port mirror settings Syntax port-mirror <enter> - configure port mirror sett.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax start vlan=<name|number|list|range> activate the VLAN configuration Syntax save save the configuration (inclu ding the VLAN configuration) Syntax edi.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax port port=<number|list|range > status=<enable|disable> - specific ports may not need to participate in STP process.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax priority [port=<number|list|ran ge>] value=<0-255 | 0-65535> - specifies the port or switch level priority. When a port(s) are specified the priority is associated with ports and their value is 0 - 255.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax lll del port=<port|list|range> - disable LLL on the list of specified ports Syntax show lll – display the status of LLL Syntax rstp – STP Configu.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE priority, the higher the priority. The port with the hi ghest p riority is the primary port (over which certain types of traffic like IGMP is transmitted) Syntax .
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax group add ip=<group ip> port=<num ber|list|range> vlan=<vlanid> - add ports to a specific IGMP broadcast group del ip=<group ip> - .
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax set-forbid vlan=<tag vlanid> fo rbid=<port-number|list|range> - sets the forbid GVRP capability on the ports specified Syntax show-forbid – d.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax authtrap <enable|disable> - enables or disables authen tication traps generation Syntax show-authtrap - displays the current value of authentication t rap status. Syntax deftrap community =<string> - defines the default community string to be used when sending traps.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE to 5 users to be added. Right now, the MNS-6K agent only support noauth and auth-md5 for v3 authentication and auth-d es for priv authentication Syntax show-user .
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Syntax smtp – configure the SNMP alerts to be sent via email Syntax show smtp <config|recipients> - config – displays the current SMTP global settings a.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 302 subject – [mandatory] email subject or title body – [mandatory] email body Syntax server ip=<ip-addr> [port =<1-65535>] [retry=<0-3>] .
APPENDIX 2 APPENDIX 2 - Commands sor ted alpha beticall y Command Description !! repeat the last command !<n> repeat the “n”th command (as indicated by a show history) <command string>.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description add port=<number|list|range> [priority=<0-65535>] add the specified list of ports to form the logical LACP trunk. Default value for priority is 32768. The lower the value assigned to priority, the higher the priority.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description clear <history|log [1..5 |informational |activity |critical |fatal |debug] |terminal |arp|portstats|addr] clear command to clear various as.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description del event=<event-id|list|range|all> disables ala rm action in response to the specified event ID del port=<number|list|range> delete specified ports from the LACP membership. Requires the lacp module.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description enable <user-name> changing the privilege level engineid string = <string> Every agent has to have an engineID (name) to be able to respond to SNMPv3 messages. The default engine ID value is “6K_v3Engine”.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description group <add|delete> id=<id> [groupname=<name>] [model=<v1|v2c|usm>] [com2secid=<com2sec-id>] a part of the View based Access control model (VACM) as defined in RFC 2275.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description lll <enable|disable> enable or disable LLL on the switch lll add port=<port|list|range> enable LLL on the list of specified ports .
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description port-mirror <enter> configure port mirror settings port-security configure port security settings priority [port=<number|list|range>] value=<0-255 | 0-65535> specifies the port or switch level priority.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description rmon enter the RMON configuration mode to setup RMON groups and communities rstp enter the RSTP configuration mode rstp <enable|disable>.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description set date year=<2001-2035> month=<1- 12> day=<1-31> [format=<mmddyyyy|ddmmyyyy|yyyy mmdd>] sets the date and the format.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description set stp type=<stp|rstp> Set the switch to support RSTP or change it back to STP. Need to save and reboot the switch after this command s.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description setport port=<num|list|range> [status=<enable|disable>] [control=<auto|for ceauth|forceunauth> ] [initialize=<assert|deassert>] setting the port characteristic for an 802.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description set-qi interval=<value> The IGMP querier router periodically sends general host-query messages. These messages are sent to ask for group membership information. This is sent to the all-system multicast group address, 224.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description set-untag port=<port|list|range> priority=<high|low> tag=<0-7> The 802.1p user priority assigned to unt agged received packe.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description show address-table displays which mac address is associated with which port for packet switching show active-stp status whether STP or RSTP is.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description show host display the hosts table entries show igmp IGMP operation status show ip-access display all trusted hosts show ipconfig shows the IP .
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description show snmp displays the SNMP configuration information show sntpsrv display the status of SNTP server show ssh display ssh setting.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description show-router displays detected IGMP-enabled rout er ports show-stats port=<num> displays 802.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description snmp enter the SNMP Configuration mode snmpv3 enter the SNMP V3 configuration mode – note enable SNMP V3 by using the “set snmp” command.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description start vlan=<name|numb er|list|range> activate the VLAN configuration static vlan=<VID> convert a dynamic VLAN to a static VLAN sta.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description telnet <ipaddress> [port=<port number>] telnet from the switch. The IP address can be an IPv4 address or an IPv6 address timers fo.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE Command Description user <add|delete> id=<id> [username=<name>] [usertype=<readonly|readwrite>] [authpass=<pass-phrase>] [privpass=&.
MAGNUM 6K SWITCHES, MNS-6K USER GUIDE 325 Intentionally left blank.
APPENDIX 3 APPENDIX 3 - Daylight Sa vings No time lik e the pr esent... Daylight Sa vings Time Magnum6K Switches provide a way to automatically adjust the system clock for Daylight Savings Time (DST) changes.
DAYLIGHT SAVINGS TIME 327 Australia, Belgium, Canada, Chile, Cuba, Egypt, France, Finland, Germany, Greece, Iraq, Italy, London, Namibia, Portugal, Russia, Spai n, Sweden, Switzerland, Syria, USA Note – as of Release 3.
APPENDIX 4 APPENDIX 4 – Br o wser Cer tificates You shouldn't overestimate the I.Q. of crooks — NYT: Stuart A. Baker, General Counsel for the NSA There is no security on this earth.
BROWSER CERTIFICATES Using Mo zilla Fir efo x (v er . 3.x) Mozilla Firefox version 3.x ensures that the user validate the certificate before it allows the user to proceed to the site when the address (URL) does not match the information in the self signed certificate.
BROWSER CERTIFICATES F IGURE 150 – Mozilla Firefox tries to warn the user agai n about the dangers of sites with improper certificates Once the “Add Exception” button is displayed, make sure you click on it.
BROWSER CERTIFICATES F IGURE 151 – Firefox forces you to get the certificat e before it lets you access the site Notice that the browser points out that valid sites such as banks, online web stores, government sites, secure sites etc. will not ask you to do that.
BROWSER CERTIFICATES F IGURE 152 – Here, you can view the certificate, perm anently make an ex ception and confirm the exception. The locations to do tho se are identified in this figure The self signed certificate from GarrettCom is shown in the next figure.
BROWSER CERTIFICATES F IGURE 153 – Self signed certificate from GarrettCom Inc for MNS-6K Once accepted, the user does not need to go through these steps again. Using Inter net Explor er (v er 7.x) Internet Explorer version 7.x provides a warning when the certificates do not match.
BROWSER CERTIFICATES 334 F IGURE 154 – Using IE 7 Using Other Br o wser s There are many other browsers such as Opera, Safari which are also widely used. There are similar mechanisms built into these browsers to inspect the certificate and create an exception.
APPENDIX 5 APPENDIX 5 – Upda ting MNS-6K Softw ar e Keep up to date.... The steps required to update the MNS-6K so ftware on your Magnum switch are listed.
UPDATING MNS-6K – STEP 1 Ste p 1 1. Getting Star ted Decide w hich version to use….. his document describes how to upgrade the MNS -6K software on a Magnum 6K switch. The methods described for updating the MNS-6K software are either locally at the console port on the Magnum 6K switch or remotely over the network using FTP or TFTP.
UPDATING MNS-6K – STEP 1 2) Enough disk space to store and retrieve the configuration files as well as copy software files from GarrettCom. We recomme nd at least 15MB of disk space for this purpose 3) Connection to the Internet. Make sure the connection does n ot block FTP file transfers 4) IP address of the switch that is being upgraded.
UPDATING MNS-6K – STEP 1 b) If the site uses another socket number for ftp connections, use the socket number at the end of the URL. For example, if the network administrator has setup a firewall to use socket number 1684, the URL would be as follows: ftp://ftp.
UPDATING MNS-6K – STEP 1 F IGURE 155 – Accessing the GarrettCom site for download. Note – if the browser does not support th e login prompt, you ca n type in the user name and password on the URL as follows: ftp://m6kuser:m6kuser@ftp.garrettcom.
UPDATING MNS-6K – STEP 1 F IGURE 156 – Select the proper version to use after successful login 4) Navigate to the folder MNS-6K. See Figure 3. (There are other folders with additional software, MIBs as well as additional useful information for the Magnum-6K switches which you may want to use later.
UPDATING MNS-6K – STEP 1 341 F IGURE 158 – Use the copy command to copy t he files to the proper location 6) Make sure you remember where the files are stored as these files will be needed for the next step. Ne xt steps 1) Access the GarrettCom Magnum 6K switch.
UPDATING SOFTWARE – STEP 2 Ste p 2 2. Pr eparing to load the software Backup y our existing configuration….. nce the MNS-6K software is downloaded fr om the GarrettCom site, it is strongly recommended that the existing configuration of the switch is preserved before the MNS-6K software upgrade is performed.
UPDATING SOFTWARE – STEP 2 343 F IGURE 159 - HyperTerminal screen showing the serial settings Netw or k Access Prerequisites - a PC (or workst ation/computer) with telnet sof tware and the IP address of the Magnum 6K switch (or DNS name associated with the switch) to be upgraded.
UPDATING SOFTWARE – STEP 2 1) Serial file transfer capability such as X-m odem or equivalent 2) TFTP server 3) FTP server As a good practice, GarrettCom recommends that y ou should have all these capabilities ava ilable on your local computer if you plan to upgrade additional sw itches as well as switches in the future.
UPDATING SOFTWARE – STEP 2 F IGURE 162 – Invoke the “Receive File” to start the Xmodem transfer pr ogram. In the figure above the Windows XP based HyperTerminal screen is shown Once the “Rec.
UPDATING SOFTWARE – STEP 2 F IGURE 164 – Status window for Xmodem (using HyperTerminal under Windows XP) When the file transfer is completed, the window shown in Figure 10 exits and the completion message is displayed as shown in Figure 11.
UPDATING SOFTWARE – STEP 2 347 This will save the file 6kconfig-10.11 to the specified IP address (192.168.10.99) in the default TFTP fo lder. Using FTP would be the sa me as Figure 12, except replace 'mode=tftp' with 'mode=ftp' In some situations (e.
UPDATING SOFTWARE – STEP 3 Ste p 3 3. Loading the MNS-6K softw are Load the new version of the MNS-6K image….. T this stage, the Magnum MNS-6K sof tware has been downloaded from the GarrettCom site, and the config uration saved. The Magnum-6K switch is now ready to upload the new MNS-6K software image.
UPDATING SOFTWARE – STEP 3 Serial Connection Prerequisites - make sure the di rectory and the file name of the MNS-6K software image downloaded in steps 1 and 2 is known. To use the serial c onnection to update the MNS-6K image, the command dialog is shown below: Magnum6K25# show ve rsion MNS-6K-Secure Ve r: 14.
UPDATING SOFTWARE – STEP 3 Upgrade is Succes sful. Please rebo ot Magnum 6Kxx to start the ap plication Magnum6K25# reboot Proceed on rebooting the swit ch? [ 'Y' or 'N' ] Y Do you wish to save current configuration? [ 'Y' or 'N' ] Y (The switch will now reboot.
UPDATING SOFTWARE – STEP 3 351 Magnum6K25# show ve rsion MNS-6K-Secure Ve r: 14.1 Date:Jul 2 8 2008 Time:07:5 1:45 Build ID 1217 245902 Magnum6K25# upgrade mode=tftp 192.168.10.99 file=Rel4.2.bin Do you wish to upgrade th e image? [ 'Y' or 'N'] Y Upgrade is Successful.
UPDATING SOFTWARE – STEP 4 Ste p 4 4. (Optional Step) R estoring the configur a tion Optionally , r estore back the original conf iguration and update the boot code….. t this optional step, the original configuration has been saved, MNS-6K image copied from the www.
UPDATING SOFTWARE – STEP 4 353 Upda ting boot code o v er the networ k As discussed in step 1 – selecting the proper version , with either upgrade path (to Version 2.
UPDATING SOFTWARE – STEP 4 354 Intentionally left blank.
INDEX Inde x !!, 302 !<n>, 302 802.1d, 147, 151, 159, 160, 162, 165, 172, 293 802.1q, 230 802.1Q, 132, 147 802.1w, 159, 160, 165, 175 802.1x, 106, 107, 108, 109, 114 , 289 access, 46, 61, 102, 1.
INDEX com2sec, 244, 248, 254, 299 community, 243, 253, 298, 305 community string, 239 config, 56, 57, 81, 82, 83, 284, 285, 286, 307, 324 config startip, 81, 83, 286 configure, 70, 104, 134, 285, 287 .
INDEX 223, 224, 227, 228, 240, 241, 244, 249, 252, 254, 255, 267, 281, 297, 299, 300, 304, 307, 308, 315, 318, 319, 322, 324 group add, 249 GSSAPI, 46 gvrp, 236, 297 GVRP, 230, 232 GVRP BPDUs, 230 hel.
INDEX MIB, 109, 215, 239, 244, 251, 254, 299 mode, 221, 227, 229 mode L2, 227 mode normal, 228 modes of operation, 25 MOMENTARY, 256, 257, 258, 25 9, 260 more, 62, 70 MOTD, 266 NAS, 116 NTLM, 46 oldco.
INDEX RFC 2273, 242 RFC 2274, 242 RFC 2275, 242 RFC 3164, 96, 97, 272 RFC 3315, 77 RFC 3396, 77 RFC 4251, 45 RFC 4252, 46 RFC 4253, 45 RFC 4254, 46 RFC 4256, 46 RFC 4391, 77 RFC 4541, 221 RFC 821, 260.
INDEX set serial, 50, 68, 283 set snmp, 242, 244, 253, 298 set stp, 151, 161, 172, 183, 185, 186, 293, 294, 295 set time, 52, 68, 283 set timeformat, 53, 68, 283 set timezone, 52, 68, 283 set vlan, 13.
INDEX show active-snmp, 242, 244, 246, 253, 298 show active-stp, 151, 162, 167 , 172, 183, 185, 186, 293, 294, 295 show active-vlan, 138 show address-table, 277, 278 show alarm, 258, 259, 260, 300 sho.
INDEX show-com2sec, 248 show-deftrap, 243, 247, 253, 299 show-forbid, 236, 237, 298 show-forceversion, 166, 168, 169, 172, 293 show-group, 223, 228, 244, 249, 254, 297, 299 show-port, 112, 113, 136, 1.
INDEX 363 172, 173, 174, 175, 176, 177, 178, 179, 180, 181, 182, 183, 184, 185, 186, 198, 210, 257, 259, 260, 292, 293, 294, 295, 307, 309, 313, 317, 319, 322, 323 stp enable, 151, 154 STP Path cost, .
Un punto importante, dopo l’acquisto del dispositivo (o anche prima di acquisto) è quello di leggere il manuale. Dobbiamo farlo per diversi motivi semplici:
Se non hai ancora comprato il GarrettCom MNS-6K-SECURE 14.1.4 è un buon momento per familiarizzare con i dati di base del prodotto. Prime consultare le pagine iniziali del manuale d’uso, che si trova al di sopra. Dovresti trovare lì i dati tecnici più importanti del GarrettCom MNS-6K-SECURE 14.1.4 - in questo modo è possibile verificare se l’apparecchio soddisfa le tue esigenze. Esplorando le pagine segenti del manuali d’uso GarrettCom MNS-6K-SECURE 14.1.4 imparerai tutte le caratteristiche del prodotto e le informazioni sul suo funzionamento. Le informazioni sul GarrettCom MNS-6K-SECURE 14.1.4 ti aiuteranno sicuramente a prendere una decisione relativa all’acquisto.
In una situazione in cui hai già il GarrettCom MNS-6K-SECURE 14.1.4, ma non hai ancora letto il manuale d’uso, dovresti farlo per le ragioni sopra descritte. Saprai quindi se hai correttamente usato le funzioni disponibili, e se hai commesso errori che possono ridurre la durata di vita del GarrettCom MNS-6K-SECURE 14.1.4.
Tuttavia, uno dei ruoli più importanti per l’utente svolti dal manuale d’uso è quello di aiutare a risolvere i problemi con il GarrettCom MNS-6K-SECURE 14.1.4. Quasi sempre, ci troverai Troubleshooting, cioè i guasti più frequenti e malfunzionamenti del dispositivo GarrettCom MNS-6K-SECURE 14.1.4 insieme con le istruzioni su come risolverli. Anche se non si riesci a risolvere il problema, il manuale d’uso ti mostrerà il percorso di ulteriori procedimenti – il contatto con il centro servizio clienti o il servizio più vicino.