Table of Contents

Advertisement

Quick Links

IFS NS2503-24P/2C

User Manual

P/N 1072568 • REV 00.04 • ISS 10SEP12

Advertisement

Table of Contents
loading

Summary of Contents for Interlogix IFS NS2503-24P/2C

  • Page 1: I Fs Ns2503-24P/2C User Manual

    IFS NS2503-24P/2C User Manual P/N 1072568 • REV 00.04 • ISS 10SEP12...
  • Page 2 Trademarks and patents The Interlogix name and logo are trademarks of UTC Fire & Security. The IFS name and logo are trademarks of UTC Fire & Security.
  • Page 3: Table Of Contents

    User’s Manual of NS2503-24P/2C TABLE OF CONTENTS I FS NS2503-24P/2C USER MANUAL ................1 1 . INTRODUCTION ......................8 1 .1 Package Contents ..........................8 1 .2 Product Description..........................9 1 .3 How to Use This Manual........................11 1 .4 Product Features..........................12 1 .5 Product Specification ........................14 2 .
  • Page 4 User’s Manual of NS2503-24P/2C 4 .2.4 SNMP Configuration........................42 4 .2.5 Syslong Setting.......................... 50 4 .2.6 System Log..........................51 4 .2.7 SNTP Setting ..........................52 4 .2.8 Firmware Upgrade........................53 4 .2.9 Configuration Backup ........................ 55 4 .2.10 Factory Default ........................57 4 .2.11 System Reboot ........................
  • Page 5 User’s Manual of NS2503-24P/2C 4 .8.4 STP System Configuration ...................... 107 4 .8.5 Port Configuration........................111 4 .9 DHCP Relay & Option 82 ........................ 113 4 .10 LLDP ............................... 115 4 .10.1 Port Configuration........................115 4 .10.2 Per Port Configuration ......................116 4 .11 Access Control List ........................
  • Page 6 User’s Manual of NS2503-24P/2C 6 .5.3 Advanced 802.1Q VLAN Configuration................... 158 6 .6 Misc Configuration.......................... 161 6 .7 Administration Configuration ......................161 6 .7.1 Change Username / Password....................161 6 .7.2 IP Configuration ........................162 6 .7.3 Reboot switch .......................... 163 6 .7.4 Reset to Default........................
  • Page 7 User’s Manual of NS2503-24P/2C 8 . POWER OVER ETHERNET OVERVIEW..............198 W hat is PoE? ............................198 T he PoE Provision Process ......................... 199 S tages of powering up a PoE link..................... 200 L ine Detection........................... 200 C lassification............................. 200 S tart-up .............................
  • Page 8: Introduction

    User’s Manual of NS2503-24P/2C 1. Introduction The IFS Layer 2 Managed Switch NS2503-24P/2C has 24 10/100Mbps 802.3at compliant PoE ports, with two Gigabit TP/SFP fiber optical combo ports and robust layer 2 features. The NS2503-24P/2C also provides IEEE 802.3af / IEEE 802.3at Power over Ethernet standards to fill various PoE applications.
  • Page 9: Product Description

    User’s Manual of NS2503-24P/2C 1.2 Product Description Power over Ethernet The PoE in-line power following the standard IEEE 802.3af and IEEE 802.3at enables the Managed Switch to power up to 24 IEEE 802.3af PoE devices or 11 IEEE 802.3at PoE devices at the distance of up to 100 meters through the 4-pair Cat 5/5e UTP wire (assuming devices use max limits of these standards;...
  • Page 10 User’s Manual of NS2503-24P/2C Powerful Security The Managed Switch offers comprehensive Access Control List (ACL) for enforcing security to the edge. Its protection mechanisms comprises of Port-based 802.1X user and device authentication. Moreover, the switch provides MAC filter and Static MAC for enforcing security policies to the edge. The administrators can now construct highly secured corporate networks with considerably less time and effort than before.
  • Page 11: How To Use This Manual

    User’s Manual of NS2503-24P/2C 1.3 How to Use This Manual This User Manual is structured as follows: Section 2, INSTALLATION The section explains the functions of the Switch and how to physically install the Managed Switch. Section 3, SWITCH MANAGEMENT The section contains the information about the software function of the Managed Switch.
  • Page 12: Product Features

    User’s Manual of NS2503-24P/2C 1.4 Product Features Physical Port 24-Port 10/100Base-TX Fast Ethernet ports with IEEE 802.3af / IEEE 802.3at PoE injector 2 10/100/1000Base-T TP combo interfaces 2 1000Base-X mini-GBIC/SFP slots, shared with Port-25 and Port-26 Reset button for system management 1 RS-232 male DB9 console interface for Switch basic management and setup Power over Ethernet Complies with IEEE 802.3af / IEEE 802.3at Power over Ethernet End-Span PSE...
  • Page 13 User’s Manual of NS2503-24P/2C − Cisco ether-channel (Static Trunk) Spanning Tree Protocol STP, IEEE 802.1D (Classic Spanning Tree Protocol) MSTP, IEEE 802.1s (Multiple Spanning Tree Protocol, spanning tree by VLAN) Port Mirroring to monitor the incoming or outgoing traffic on a particular port Quality of Service 4 priority queues on all switch ports Traffic classification:...
  • Page 14: Product Specification

    User’s Manual of NS2503-24P/2C 1.5 Product Specification NS2503-24P/2C Product 24-Port 10/100Mbps + 2 Gigabit TP / SFP Managed 802.3at PoE Switch Hardware Specification 24 10/ 100Base-TX RJ-45 Auto-MDI/MDI-X ports 10/100Mbps Copper Ports 2 10/100/1000Mbps RJ-45 Auto-MDI/MDI-X ports 1000Mbps Copper Ports 2 1000Base-SX/LX/BX, shared with Port-25~Port-26 SFP/mini-GBIC Slots Store-and-Forward...
  • Page 15 User’s Manual of NS2503-24P/2C Auto-negotiation 10/100/1000Mbps full and half duplex mode selection Flow Control disable / enable Display each port’s speed duplex mode, link status and Flow control status. Port Status Auto negotiation status, trunk status. TX / RX / Both Port Mirroring 1 to 1 monitor Ingress / Egress Rate Control...
  • Page 16: Installation

    User’s Manual of NS2503-24P/2C 2. INSTALLATION This section describes the hardware features and installation of the Managed Switch on the desktop or rack mount. For easier management and control of the Managed Switch, familiarize yourself with its display indicators, and ports. Front panel illustrations in this chapter display the unit LED indicators.
  • Page 17: Led Indications

    User’s Manual of NS2503-24P/2C ■ Reset button On the left side of the front panel, the reset button is designed for rebooting the Managed Switch without a power cycle. The following is the summary table of Reset button functions: Reset Button Pressed and Released Function About 5 seconds Reboot the Managed Switch.
  • Page 18 User’s Manual of NS2503-24P/2C Per 10/100Mbps port, PoE interfaces (Port-1 to Por-24) Color Function Illuminates: To indicate the link through that port is successfully established. LNK/ACT Green To indicate that the Switch is actively sending or receiving data over that port. Blink: Illuminates: To indicate the port is providing 52V DC in-line power.
  • Page 19: Switch Rear Panel

    User’s Manual of NS2503-24P/2C 2.1.3 Switch Rear Panel The rear panel of the Managed Switch indicates an AC inlet power socket, which works with an input power range from 100 to 240V AC, 50-60Hz. Figure 2-3 shows the rear panel of the Managed Switch. NS2503-24P/2C Rear Panel Figure 2-3: NS2503-24P/2C Rear Panel.
  • Page 20: Install The Switch

    User’s Manual of NS2503-24P/2C 2.2 Install the Switch This section describes how to install the Managed Switch and make connections to it. Please read the following topics and perform the procedures in the order being presented. 2.2.1 Desktop Installation To install the Managed Switch on desktop or shelf, please follows these steps: Step1: Attach the rubber feet to the recessed areas on the bottom of the Managed Switch.
  • Page 21: Rack Mounting

    User’s Manual of NS2503-24P/2C 2.2.2 Rack Mounting To install the Managed Switch in a 19-inch standard rack, please follows the instructions described below. Step1: Place the Managed Switch on a hard flat surface, with the front panel positioned towards the front side. Step2: Attach the rack-mount bracket to each side of the Managed Switch with supplied screws attached to the package.
  • Page 22: Installing The Sfp Transceiver

    User’s Manual of NS2503-24P/2C 2.2.3 Installing the SFP transceiver The sections describe how to plug-in an SFP transceiver into an SFP slot. The SFP transceivers are hot-swappable. You can plug-in and out the transceiver to/from any SFP port without a need to shut down the Managed Switch.
  • Page 23 User’s Manual of NS2503-24P/2C Before connecting the other switches, workstation or Media Converter: Make sure both sides use the same SFP transceiver, for example: 1000Base-SX to 1000Base-SX, 1000Base-LX to 1000Base-LX. make sure the fiber-optic cable type match the SFP transceiver model. To connect to 1000Base-SX SFP transceiver, use the multi-mode fiber cable- with one side must be male duplex LC connector type.
  • Page 24: Switch Management

    User’s Manual of NS2503-24P/2C 3. SWITCH MANAGEMENT This chapter explains the methods that you can use to configure management access to the Managed Switch. It describes the types of management applications and the communication and management protocols that deliver data between your management device (work-station or personal computer) and the system.
  • Page 25: Management Access Overview

    User’s Manual of NS2503-24P/2C 3.2 Management Access Overview The Managed Switch gives you the flexibility to access and manage it using any or all of the following methods: Web browser interface An external SNMP-based network management application An administration console The administration console and Web browser interface support are embedded in the Managed Switch software and are available for immediate use.
  • Page 26: Web Management

    User’s Manual of NS2503-24P/2C 3.3 Web Management The Managed Switch offers management features that allow users to manage the Managed Switch from anywhere on the network through a standard browser such as Microsoft Internet Explorer. After you set up your IP address for the switch, you can access the Managed Switch's Web interface applications directly in your Web browser by entering the IP address of the Managed Switch.
  • Page 27: Snmp-Based Network Management

    User’s Manual of NS2503-24P/2C 3.4 SNMP-Based Network Management You can use an external SNMP-based application to configure and manage the Managed Switch, such as SNMPc Network Manager, HP Openview Network Node Management (NNM) or What’sup Gold. This management method requires the SNMP agent on the switch and the SNMP Network Management Station to use the same community string.
  • Page 28 User’s Manual of NS2503-24P/2C Figure 3-5: Terminal Parameter Settings You can change these settings, if desired, after you log on. This management method is often preferred because you can remain connected and monitor the system during system reboots. Also, certain error messages are sent to the serial port, regardless of the interface through which the associated action was initiated.
  • Page 29: Protocols

    User’s Manual of NS2503-24P/2C 3.6 Protocols The Managed Switch supports the following protocols: Virtual terminal protocols, such as Telnet Simple Network Management Protocol (SNMP) 3.6.1 Virtual Terminal Protocols A virtual terminal protocol is a software program, such as Telnet, that allows you to establish a management session from a Macintosh, a PC, or a UNIX workstation.
  • Page 30: Web-Based Management

    User’s Manual of NS2503-24P/2C 4. Web-Based Management This section introduces the configuration and functions of the Web-Based management. 4.1 About Web-based Management The Managed Switch offers management features that allow users to manage the Managed Switch from anywhere on the network through a standard browser such as Microsoft Internet Explorer.
  • Page 31: Requirements

    User’s Manual of NS2503-24P/2C 4.1.1 Requirements • The operating system of subscriber PC: Windows XP/2003, Vista, Windows 7, MAC OS X , Linux, Fedora, Ubuntu or other platform compatible with TCP/IP protocols. • Workstation installed with Ethernet NIC (Network Card). •...
  • Page 32 User’s Manual of NS2503-24P/2C Figure 4-1-2: Web Main Page Screenshot The Switch Menu on the left of the Web page let you access all the commands and statistics the Switch provides. Now, you can use the Web management interface to continue the switch management or manage the Managed Switch by Web interface.
  • Page 33: Main Web Page

    User’s Manual of NS2503-24P/2C 4.1.3 Main WEB PAGE The Managed Switch provides a Web-based browser interface for configuring and managing it. This interface allows you to access the Managed Switch using the Web browser of your choice. This chapter describes how to use the Managed Switch’s Web browser interface to configure and manage it.
  • Page 34 User’s Manual of NS2503-24P/2C Figure 4-1-4: Managed Switch Main Functions Menu Screenshot...
  • Page 35: System

    User’s Manual of NS2503-24P/2C 4.2 System Use the System menu items to display and configure basic administrative details of the Managed Switch. Under System the following topics are provided to configure and view the system information: This section has the following items: Provides basic system description, including contact information.
  • Page 36: System Information

    User’s Manual of NS2503-24P/2C 4.2.1 System Information In System information, it has two parts of setting – Basic and Misc Config. We will describe the configure detail in following. 4.2.1.1 Basic The Basic System Info page provides information for the current device information. Basic System Info page helps a switch administrator to identify the model name, firmware / hardware version and MAC address.
  • Page 37 User’s Manual of NS2503-24P/2C 4.2.1.2 Misc Config Choose Misc Config from System Information of Managed Switch, the screen in Figure 4-2-2 appears. Figure 4-2-2: Switch Misc Config Screenshot The page includes the following fields: Object Description Type the number of seconds that an inactive MAC address remains in the MAC Address Age-out switch’s address table.
  • Page 38 User’s Manual of NS2503-24P/2C • IP Multicast • Control Packets • Flooded Unicast / Multicast Packets Provide Collision Retry Forever function”Disable” or 16, 32, 48 collision numbers on Managed Switch. If this function is disabled, when a packet meet a collision, the Managed Switch will retry 6 times before discard the packets.
  • Page 39: Ip Configuration

    User’s Manual of NS2503-24P/2C 4.2.2 IP Configuration The Managed Switch is a network device which needs to be assigned an IP address for being identified on the network. Users have to decide on an IP address for the Managed Switch. IP address overview What is an IP address? Each device (such as a computer) which participates in an IP network needs a unique "address"...
  • Page 40 User’s Manual of NS2503-24P/2C The page includes the following fields: Object Description Enable or disable the DHCP client function. When DHCP function is enabled, the Managed Switch will be assigned an IP address from the network DHCP server. The default IP address will be replaced DHCP by the assigned IP address on DHCP server.
  • Page 41: Console Port Info

    User’s Manual of NS2503-24P/2C 4.2.3 Console Port Info The Managed Switch provide local console interface for switch command line management, console port info contains console baud rate information and the screen in Figure 4-2-4 appears. Figure 4-2-4: Console Information Screenshot The page includes the following fields: Object Description...
  • Page 42: Snmp Configuration

    User’s Manual of NS2503-24P/2C 4.2.4 SNMP Configuration 4.2.4.1 SNMP Overview The Simple Network Management Protocol (SNMP) is an application layer protocol that facilitates the exchange of management information between network devices. It is part of the Transmission Control Protocol/Internet Protocol (TCP/IP) protocol suite.
  • Page 43 User’s Manual of NS2503-24P/2C SNMP community An SNMP community is the group that devices and management stations running SNMP belong to. It helps define where information is sent. The community name is used to identify the group. A SNMP device or agent may belong to more than one SNMP community.
  • Page 44 User’s Manual of NS2503-24P/2C The page includes the following fields: Object Description Here you can define the new community string set and remove the unwanted Community Strings: community string. String: Fill the name string. RO: Read only. Enables requests accompanied by this community string to display MIB-object information.
  • Page 45: Snmpv3 Groups

    User’s Manual of NS2503-24P/2C 4.2.4.4 Trap Managers A trap manager is a management station that receives the trap messages generated by the switch. If no trap manager is defined, no traps will be issued. To define a management station as a trap manager, assign an IP address, enter the SNMP community strings, and select the SNMP trap version.
  • Page 46 User’s Manual of NS2503-24P/2C The page includes the following fields: Object Description Group Name: A string identifying the group name that this entry should belong to. The allowed string length is 1 to 15. Indicates the security model that this entry should belong to. Possible security V1 | V2c | USM models are: •...
  • Page 47: Snmpv3 Access

    User’s Manual of NS2503-24P/2C The page includes the following fields: Object Description View Name: A string identifying the view name that this entry should belong to. The allowed string length is 1 to 15. Indicates the view type that this entry should belong to. Possible view type are: Included | Excluded: •...
  • Page 48 User’s Manual of NS2503-24P/2C The page includes the following fields: Object Description A string identifying the group name that this entry should belong to. Group Name: The allowed string length is 1 to 15. Indicates the security model that this entry should belong to. Possible security models are: •...
  • Page 49 User’s Manual of NS2503-24P/2C 4.2.4.8 SNMP V3 usm-user Configure SNMPv3 users table on this page. The entry index keys are Engine ID and User Name. The SNMPv3 Users Configuration screen in Figure 4-2-12 appears. Figure 4-2-12: SNMP Configuration Interface Screenshot The page includes the following fields: Object Description...
  • Page 50: Syslong Setting

    User’s Manual of NS2503-24P/2C 4.2.5 Syslong Setting The Syslog Setting page allows you to configure the logging of messages that are sent to remote syslog servers or other management stations. You can also limit the event messages sent to only those messages below a specified level. Figure 4-2-13: Syslog Setting Screenshot The page includes the following fields: Object...
  • Page 51: System Log

    User’s Manual of NS2503-24P/2C 4.2.6 System Log It provides the functions allowing the user to update the switch firmware via the Trivial File Transfer Protocol (TFTP) server. Before updating, make sure the TFTP server is ready and the firmware image is located on the TFTP server. Figure 4-2-14: System Log Screenshot The page includes the following fields: Object...
  • Page 52: Sntp Setting

    User’s Manual of NS2503-24P/2C 4.2.7 SNTP Setting It provides the functions allowing the user to update the switch firmware via the Trivial File Transfer Protocol (TFTP) server. Before updating, make sure the TFTP server is ready and the firmware image is located on the TFTP server. Figure 4-2-15: SNTP Setting Screenshot The page includes the following fields: Object...
  • Page 53: Firmware Upgrade

    User’s Manual of NS2503-24P/2C 4.2.8 Firmware Upgrade It provides the functions allowing the user to update the switch firmware via the Trivial File Transfer Protocol (TFTP) server. Before updating, make sure the TFTP server is ready and the firmware image is located on the TFTP server. 4.2.8.1 TFTP Firmware Upgrade The Firmware Upgrade page provides the functions to allow a user to update the Managed Switch firmware from the TFTP server in the network.
  • Page 54 User’s Manual of NS2503-24P/2C 4.2.8.2 HTTP Firmware Upgrade The HTTP Firmware Upgrade page contains fields for downloading system image files from the Local File browser to the device. The Web Firmware Upgrade screen in Figure 4-2-17 appears. Figure 4-2-17: HTTP Firmware Upgrade Interface Screenshot To open Firmware Upgrade screen perform the following: Click System ->...
  • Page 55: Configuration Backup

    User’s Manual of NS2503-24P/2C Select on the firmware then click “Upload”, the Software Upload Progress would show the file upload status. Firmware upgrade needs several minutes. Please wait a while, and then manually refresh the webpage. 4.2.9 Configuration Backup 4.2.9.1 TFTP Restore Configuration You can restore a previous backup configuration from the TFTP server to recover the settings.
  • Page 56: Tftp Backup Configuration

    User’s Manual of NS2503-24P/2C 4.2.9.2 TFTP Backup Configuration You can back up the current configuration from flash ROM to the TFTP server for the purpose of recovering the configuration later. It helps you to avoid wasting time on configuring the settings by backing up the configuration. Figure 4-2-20: Configuration Backup Interface Screenshot The page includes the following fields: Object...
  • Page 57: Factory Default

    User’s Manual of NS2503-24P/2C 4.2.10 Factory Default Default Reset switch to default configuration. Click to reset all configurations to the default value. Figure 4-2-21: Factory Default Interface Screenshot 4.2.11 System Reboot Reboot Reboot the switch in software reset. Click to reboot the system. Figure 4-2-22: System Reboot Interface Screenshot...
  • Page 58: Port Configuration

    User’s Manual of NS2503-24P/2C 4.3 Port Configuration Use the Port Configuration Menu to display or configure the Managed Switch's ports. This section has the following items: Configures port connection settings Port Control Display the current Port link status and speed etc. Port Status Lists Ethernet and RMON port statistics Port Statistics...
  • Page 59 User’s Manual of NS2503-24P/2C automatically. When you set it as Force, you have to set the speed and duplex mode manually. It is available for selecting when the Negotiation column is set as Force. When Speed: the Negotiation column is set as Auto, this column is read-only. It is available for selecting when the Negotiation column is set as Force.
  • Page 60: Rate Control

    User’s Manual of NS2503-24P/2C 4.3.2 Rate Control This page provides rate control on each port - it contains Ingress and Egress items and the unit is 128Kbps. The rate control screen is displayed as in Figure 4-3-2. Figure 4-3-2: Rate Control Interface Screenshot The page includes the following fields: Object Description...
  • Page 61 User’s Manual of NS2503-24P/2C summary table, you can know status of each port clear at a glance, like per port description, Port Link Up/Link Down status, negotiation, Link Speed, Duplex mode and Flow Control, security, jumbo frame. Figure 4-3-3: Port Status Interface Screenshot...
  • Page 62: Port Statistics

    User’s Manual of NS2503-24P/2C 4.3.4 Port Statistics The following chart provides the current statistic information which displays the real-time packet transfer status for each port. The user might use the information to plan and implement the network, or check and find the problem when the collision or heavy traffic occurs.
  • Page 63: Port Sniffer

    User’s Manual of NS2503-24P/2C 4.3.5 Port Sniffer The Port Sniffer (mirroring) is a method for monitor traffic in switched networks. Traffic through a port can be monitored by one specific port. That is, traffic goes in or out a monitored port will be duplicated into sniffer port. Figure 4-3-5: Port Mirror application Configuring the port mirroring by assigning a source port from which to copy all packets and a destination port where those packets will be sent.
  • Page 64 User’s Manual of NS2503-24P/2C Figure 4-3-6: Port Sniffer Interface Screenshot The page includes the following fields: Object Description Select a sniffer mode: • Disable • Rx Sniffer Type: • Tx • Both It means the Analysis port can be used to see the traffic on another port you want Analysis (Monitoring) Port: to monitor.
  • Page 65: Protect Port

    User’s Manual of NS2503-24P/2C 4.3.6 Protect Port There are two protected port groups; ports in different groups can't communicate. In the same group, protected ports can't communicate with each other, but can communicate with unprotected ports. Unprotected ports can communicate with any ports, including protected ports Figure 4-3-7: Protected Port Setting Web Interface Screenshot The page includes the following fields: Object...
  • Page 66: Remote Ping

    User’s Manual of NS2503-24P/2C 4.3.7 Remote Ping The Remote Ping allows user to check the device connection status via ping. Figure 4-3-8: Remote Ping interface The page includes the following fields: Object Description Allows user to define the IP address of remote device. Remote IP Address Allows user to define ping packet size.
  • Page 67: Vlan Configuration

    User’s Manual of NS2503-24P/2C Click “Save” button to save Remote Ping configuration. User can use ping function even not save configuration, but after WEB page be refreshed the Save configuration clear. Click “Reset” button will reset all Remote Ping configuration and save Reset automatically.
  • Page 68 User’s Manual of NS2503-24P/2C - Tagging - The act of putting 802.1Q VLAN information into the header of a packet. - Untagging - The act of stripping 802.1Q VLAN information out of the packet header. 802.1Q VLAN Tags The figure below shows the 802.1Q VLAN tag. There are four additional octets inserted after the source MAC address. Their presence is indicated by a value of 0x8100 in the Ether Type field.
  • Page 69: Static Vlan Configuration

    User’s Manual of NS2503-24P/2C Default VLANs The Managed Switch initially configures one VLAN, VID = 1, called "default." The factory default setting assigns all ports on the Switch to the "default". As new VLAN are configured in Port-based mode, their respective member ports are removed from the "default."...
  • Page 70: Port-Based Vlan

    User’s Manual of NS2503-24P/2C 4.4.3 Port-based VLAN Packets can go among only members of the same VLAN group. Note all unselected ports are treated as belonging to another single VLAN. If the port-based VLAN enabled, the VLAN-tagging is ignored. In order for an end station to send packets to different VLANs, it itself has to be either capable of tagging packets it sends with VLAN tags or attached to a VLAN-aware bridge that is capable of classifying and tagging the packet with different VLAN ID based on not only default PVID but also other information about the packet, such as the protocol.
  • Page 71 User’s Manual of NS2503-24P/2C By adding ports to the VLAN you have created one port-based VLAN group completely. Figure 4-4-3: Static VLAN Interface Screenshot The page includes the following fields: Object Description Use this optional field to specify a name for the VLAN. It can be up to 16 VLAN Name alphanumeric characters long, including blanks.
  • Page 72: Q Vlan

    User’s Manual of NS2503-24P/2C 4.4.4 802.1Q VLAN Tagged-based VLAN is an IEEE 802.1Q specification standard. Therefore, it is possible to create a VLAN across devices from different switch vendors. IEEE 802.1Q VLAN uses a technique to insert a "tag" into the Ethernet frames. Tag contains a VLAN Identifier (VID) that indicates the VLAN numbers.
  • Page 73: Vlan Group Configuration

    User’s Manual of NS2503-24P/2C 4.4.4.1 VLAN Group Configuration VLAN Group Configuration Figure 4-4-4: VLAN Group Configuration Interface Screenshot Click the hyperlink "VLAN” \ “Static VLAN" to enter the VLAN configuration interface. Select “802.1Q” at the VLAN Operation Mode, to enable the 802.1Q VLAN function. Click Add to create a new VLAN group or Edit to manage the existing VLAN groups.
  • Page 74 User’s Manual of NS2503-24P/2C Figure 4-4-5: VLAN Group Configuration Interface Screenshot Select specific port as member port and the screen in Figure 4-4-6 appears. After setup completed, please press “Apply” button to take effect. Please press “Back” for return to VLAN configuration screen to add other VLAN group, the screen in Figure 4-33 appears.
  • Page 75 User’s Manual of NS2503-24P/2C Figure 4-4-6: 802.1Q VLAN Setting Interface Screenshot The page includes the following fields: Object Description Use this optional field to specify a name for the VLAN. It can be up to 16 VLAN Name alphanumeric characters long, including blanks. You can configure the ID number of the VLAN by this item.
  • Page 76: Vlan Filter

    User’s Manual of NS2503-24P/2C 4.4.4.2 VLAN Filter 802.1Q VLAN Port Configuration This page is used for configuring the Switch port VLAN. The VLAN per Port Configuration page contains fields for managing ports that are part of a VLAN. The port default VLAN ID (PVID) is configured on the VLAN Port Configuration page. All untagged packets arriving to the device are tagged by the ports PVID.
  • Page 77: Gvrp Vlan

    User’s Manual of NS2503-24P/2C Drop untagged frame. Disable: Accepts all Packets. Ingress Filtering 2 Enable: Only packet with a matching VLAN ID can be allowed to go through the port. Apply button Press the button to save the configuration. 4.4.5 GVRP VLAN GVRP (GARP VLAN Registration Protocol or Generic VLAN Registration Protocol) is a protocol that facilitates control of virtual local area networks (VLANs) within a larger network.
  • Page 78: Gvrp Setting

    User’s Manual of NS2503-24P/2C 4.4.5.1 GVRP Setting To configure GVRP Enable global GVRP function: select GVRP enable "Enable". Enable port GVRP function: select GVRP checkbox for special port. Figure 4-4-8: GVRP Configuration Interface Screenshot The page includes the following fields: Object Description GVRP:...
  • Page 79 User’s Manual of NS2503-24P/2C 4.4.5.2 GVRP Table The GVRP Table can be used to display dynamic VLANs from being learned via GVRP. Figure 4-4-9: GVRP Table Interface Screenshot The page includes the following fields: Object Description Display the learned VLANs via GVRP protocol on GVRP enabled ports. VLAN ID: The Managed Switch allows displaying up to 128 dynamic VLAN entries.
  • Page 80: Q-In-Q Vlan

    User’s Manual of NS2503-24P/2C 4.4.6 Q-in-Q VLAN ■ IEEE 802.1Q Tunneling (Q-in-Q) IEEE 802.1Q Tunneling (QinQ) is designed for service providers carrying traffic for multiple customers across their networks. QinQ tunneling is used to maintain customer-specific VLAN and Layer 2 protocol configurations even when different customers use the same internal VLAN IDs.
  • Page 81 User’s Manual of NS2503-24P/2C The Managed Switch supports multiple VLAN tags and can therefore be used in MAN applications as a provider bridge, aggregating traffic from numerous independent customer LANs into the MAN (Metro Access Network) space. One of the purposes of the provider bridge is to recognize and use VLAN tags so that the VLANs in the MAN space can be used independent of the customers’...
  • Page 82 User’s Manual of NS2503-24P/2C The page includes the following fields: Object Description Sets the Managed Switch to QinQ mode, and allows the QinQ tunnel port to Enable: be configured. The Managed Switch operates in its normal VLAN mode. Disable: QinQ The default is for the Managed Switch to function in Disable mode.
  • Page 83 User’s Manual of NS2503-24P/2C 4.4.6.2 Q-in-Q Tunnel Setting Business customers of service providers often have specific requirements for VLAN IDs and the number of VLANs to be supported. The VLAN ranges required by different customers in the same service-provider network might overlap, and traffic of customers through the infrastructure might be mixed.
  • Page 84: Trunking

    User’s Manual of NS2503-24P/2C 4.5 Trunking Port trunking is the combination of several ports or network cables to expand the connection speed beyond the limits of any one single port or network cable. The Managed Switch supports two types of port trunk technology: Static Trunk LACP The Link Aggregation Control Protocol (LACP) provides a standardized means for exchanging information between Partner...
  • Page 85: Aggregator Setting

    User’s Manual of NS2503-24P/2C 4.5.1 Aggregator setting This section provides Port Trunk-Aggregator Setting of each port from the Managed Switch, the screen in Figure 4-5-1 appears. Figure 4-5-1: Port Trunk—Aggregator Setting Interface (two ports are added to the left field with LACP enabled) The page includes the following fields: Object Description...
  • Page 86: Aggregator Information

    User’s Manual of NS2503-24P/2C This column field allows the user to type in the total number of active port up to four. With LACP static trunk group, e.g. you assign four ports to be the members of a trunk group whose work ports column field is set as two; the Work ports: exceed ports are standby/redundant ports and can be aggregated if working ports fail.
  • Page 87 User’s Manual of NS2503-24P/2C Figure 4-5-3: Static Trunking Group Information Screenshot The page includes the following fields: Object Description This is a read-only column field that displays the trunk group ID. Group Key: This is a read-only column field that displays the members of this static trunk Port Member: group.
  • Page 88 User’s Manual of NS2503-24P/2C Figure 4-5-4: Aggregation Information of Screenshot Switch 1 Click on the tab of Aggregator Information to check the trunked group information as the illustration shown above after the two switches configured. Switch 2 configuration Set System Priority of the trunk group. For example: 1. Select a trunk group ID by pull down the drop-down menu bar.
  • Page 89 User’s Manual of NS2503-24P/2C Configuration Interface Screenshot Figure 4-5-5: Switch 2 10. Click on the tab of Aggregator Information to check the trunked group information as the illustration shown above after the two switches configured. Aggregator Information Screenshot Figure 4-5-6: Switch 1...
  • Page 90: State Activity

    User’s Manual of NS2503-24P/2C 4.5.3 State Activity Having set up the LACP aggregator on the tab of Aggregator Setting, you can configure the state activity for the members of the LACP trunk group. You can tick or cancel the checkbox beside the state label. When you remove the tick mark of the port and Apply click , the port state activity will change to Passive.
  • Page 91: Forwarding And Filtering

    User’s Manual of NS2503-24P/2C 4.6 Forwarding and Filtering The frames of Ethernet Packets contain a MAC address (SMAC address), which shows the MAC address of the equipment sending the frame. The SMAC address is used by the switch to automatically update the MAC table with these dynamic MAC addresses.
  • Page 92: Static Mac Table

    User’s Manual of NS2503-24P/2C 4.6.2 Static MAC Table You can add a static MAC address that remains in the switch's address table regardless of whether the device is physically connected to the switch. This saves the switch from having to re-learn a device's MAC address when the disconnected or powered-off device is active on the network again.
  • Page 93: Mac Filtering

    User’s Manual of NS2503-24P/2C 4.6.3 MAC Filtering By filtering MAC address, the switch can easily filter the pre-configured MAC address and reduce the un-safety. You can add and delete filtering MAC address. Figure 4-6-3: MAC Filtering Interface Screenshot The page includes the following fields: Object Description Enter the MAC address that you want to filter.
  • Page 94: Igmp Snooping

    User’s Manual of NS2503-24P/2C 4.7 IGMP Snooping 4.7.1 Theory The Internet Group Management Protocol (IGMP) lets host and routers share information about multicast groups memberships. IGMP snooping is a switch feature that monitors the exchange of IGMP messages and copies them to the CPU for feature processing.
  • Page 95 User’s Manual of NS2503-24P/2C Figure 4-7-2: Multicast Flooding Figure 4-7-3: IGMP Snooping Multicast Stream Control...
  • Page 96 User’s Manual of NS2503-24P/2C IGMP Versions 1 and 2 Multicast groups allow members to join or leave at any time. IGMP provides the method for members and multicast routers to communicate when joining or leaving a multicast group. IGMP version 1 is defined in RFC 1112. It has a fixed packet size and no optional data. The format of an IGMP packet is shown below: IGMP Message Format Octets...
  • Page 97 User’s Manual of NS2503-24P/2C Figure 4-7-4: IGMP State Transitions IGMP Querier A router, or multicast-enabled switch, can periodically ask their hosts if they want to receive multicast traffic. If there is more than one router/switch on the LAN performing IP multicasting, one of these devices is elected “querier” and assumes the role of querying the LAN for group members.
  • Page 98: Igmp Configuration

    User’s Manual of NS2503-24P/2C 4.7.2 IGMP Configuration The Managed Switch support IP multicast, you can enable IGMP protocol on web management’s switch setting advanced page, then the IGMP snooping information displays. IP multicast addresses range are from 224.0.0.0 through 239.255.255.255. Figure 4-7-5: IGMP Configuration Interface Screenshot The page includes the following fields: Object...
  • Page 99 User’s Manual of NS2503-24P/2C Enable or disable Fast Leave on the port. IGMP Fast leave: Enable or disable the IGMP query function. The IGMP query information will be IGMP Querier: displayed in IGMP status section. Allows user choosing three IGMP router port modes as follows: Auto: Dynamic IGMP router port mode, where the system detects multicast source then set the port to router port automatically.
  • Page 100: Static Multicast Table

    User’s Manual of NS2503-24P/2C 4.7.3 Static Multicast Table Static Multicast Table is a feature for user to force steaming multicast stream to indicate port. When you add a static multicast address, it remains in the multicast group table, regardless of whether the multicast stream has been joined or hasn’t been joined.
  • Page 101 User’s Manual of NS2503-24P/2C The page includes the following fields: Object Description Allows user to input multicast address group. IP Address: Allows multicast streaming to indicate port. Remove multicast streaming from indicate port. Allows user to input VLAN ID for streaming multicast packet. VLAN ID: Allows user to add static multicast information to IGMP Snooping table.
  • Page 102: Spanning Tree Protocol

    User’s Manual of NS2503-24P/2C 4.8 Spanning Tree Protocol 4.8.1 Theory The Spanning Tree protocol can be used to detect and disable network loops, and to provide backup links between switches, bridges or routers. This allows the switch to interact with other bridging devices in your network to ensure that only one route exists between any two stations on the network, and provide backup links which automatically take over when a primary link goes down.
  • Page 103 User’s Manual of NS2503-24P/2C Bridge Protocol Data Units For STP to arrive at a stable network topology, the following information is used: The unique switch identifier The path cost to the root associated with each switch port The port identifier STP communicates between switches on the network using Bridge Protocol Data Units (BPDUs).
  • Page 104 User’s Manual of NS2503-24P/2C Each port on a switch using STP exists is in one of the following five states: Blocking – the port is blocked from forwarding or receiving packets. Listening – the port is waiting to receive BPDU packets that may tell the port to go back to the blocking state. Learning –...
  • Page 105: Illustration Of Stp

    User’s Manual of NS2503-24P/2C 4.8.2 Illustration of STP A simple illustration of three switches connected in a loop is depicted in the below diagram. In this example, you can anticipate some major network problems if the STP assistance is not applied. Figure 4-8-2: Before Applying the STA Rules If switch A broadcasts a packet to switch B, switch B will broadcast it to switch C, and switch C will broadcast it to back to switch A and so on.
  • Page 106: Stp Parameters

    User’s Manual of NS2503-24P/2C Figure 4-8-3: After Applying the STA Rules 4.8.3 STP Parameters STP Operation Levels The Switch allows for two levels of operation: the switch level and the port level. The switch level forms a spanning tree consisting of links between one or more switches. The port level constructs a spanning tree consisting of groups of one or more ports.
  • Page 107: Stp System Configuration

    User’s Manual of NS2503-24P/2C maximum age timer. The amount time spent by a port in the seconds Forward Delay Timer learning and listening states waiting for a BPDU that may return the port to the blocking state. The following are the user-configurable STP parameters for the port or port group level: Variable Description Default Value...
  • Page 108 User’s Manual of NS2503-24P/2C Figure 4-8-4: STP System Configuration Interface Screenshot The page includes the following fields: Object Description The user must enable the STP function first before configuring the related STP State: parameters. A value used to specify the spanning tree protocol, the original spanning tree Protocol Version protocol (STP, 802.1d) or the multiple spanning tree protocol (MSTP, 802.1s).
  • Page 109 User’s Manual of NS2503-24P/2C Follow the rule as below to configure the MAX Age, Hello Time, and Forward Delay Time. 2 x (Forward Delay Time value –1) > = Max Age value >= 2 x (Hello Time value +1). Each switch in a spanning-tree adopts the Hello Time, Forward Delay time, and Max Age parameters of the root bridge, regardless of how it is configured.
  • Page 110 User’s Manual of NS2503-24P/2C The page includes the following fields: Object Description • Priority The bridge identifier of the root bridge. It is made up from the bridge priority and the base MAC address of the bridge. • MAC Address The bridge identifier of the root bridge.
  • Page 111: Port Configuration

    User’s Manual of NS2503-24P/2C 4.8.5 Port Configuration This web page provides the port configuration interface for STP. You can assign higher or lower priority to each port. Spanning tree protocol will have the port with the higher priority in forwarding state and block other ports to make certain that there is no loop in the LAN.
  • Page 112 User’s Manual of NS2503-24P/2C The rapid state transitions possible within STP are dependent upon whether the port concerned can only be connected to exactly another bridge (i.e. it is served by a point-to-point LAN segment), or can be connected to two or more bridges (i.e.
  • Page 113: Dhcp Relay & Option 82

    User’s Manual of NS2503-24P/2C 4.9 DHCP Relay & Option 82 The Relay Agent Information option (Option82) is inserted by the DHCP relay agent when forwarding client-originated DHCP packets to a DHCP server (RFC 3046). Servers recognizing the Relay Agent Information option may use the information to implement IP address or other parameter assignment policies.
  • Page 114 User’s Manual of NS2503-24P/2C Figure 4-9-1: DHCP Relay and Option 82 Function Interface Screenshot The page includes the following fields: Object Description Enable global option82 function DHCP Option 82 Enable global Relay function DHCP Relay Select the Router Port that is used to connect to the DHCP server in DHCP Option 82 the domain Router Port...
  • Page 115: Lldp

    User’s Manual of NS2503-24P/2C 4.10 LLDP Link Layer Discovery Protocol (LLDP) is used to discover basic information about neighboring devices on the local broadcast domain. LLDP is a Layer 2 protocol that uses periodic broadcasts to advertise information about the sending device. Advertised information is represented in Type Length Value (TLV) format according to the IEEE 802.1ab standard, and can include details such as device identification, capabilities and configuration settings.
  • Page 116: Per Port Configuration

    User’s Manual of NS2503-24P/2C 4.10.2 Per Port Configuration This page allows the user to inspect and configure the current LLDP port settings, the web screen in Figure 4-10-2 appears. Figure 4-10-2: LLDP Function Interface Screenshot The page includes the following fields: Object Description Port Number:...
  • Page 117: Access Control List

    User’s Manual of NS2503-24P/2C 4.11 Access Control List The Access Control List (ACL) is a concept in computer security used to enforce privilege separation. It is a means of determining the appropriate access rights to a given object depending on certain aspects of the process that is making the request, principally the process's user identifier.
  • Page 118 User’s Manual of NS2503-24P/2C The page includes the following fields: IPv4 ACL Object Description Default Vaule 1 ~ 200 Group ID Permit / Deny. Permit Action Permit: Permit packet cross switch. Deny: Drop packet. Any / VID. VLAN Any: Any VLAN id. VID: 1~4094.
  • Page 119 User’s Manual of NS2503-24P/2C Non-IPv4 ACL In ※Packet Type / Binding box should select Non-IPv4 Object Description Default Vaule 1 ~ 200 Group ID Permit / Deny. Permit Action Permit: Permit packet cross switch. Deny: Drop packet. Any / VID. VLAN Any: Any VLAN ID.
  • Page 120: Users Configuration

    User’s Manual of NS2503-24P/2C 4.12 Users Configuration It is allowed to configure the Managed Switch to authenticate users logging into the system for management access using local authentication methods, such as telnet and Web browser. The latest UTC Managed Switch provides totally six different security levels in 3 groups for local user management.
  • Page 121 User’s Manual of NS2503-24P/2C Add / Edit User This page configures a user – add, edit or delete user. Figure 4-12-2: Add New User Configuration Interface Screenshot The page includes the following fields: Object Description Assign Username for the Managed Switch. User Name: Assign the access level of the Managed Switch;...
  • Page 122 User’s Manual of NS2503-24P/2C After change the default password, if you forget the password. Please press the “Reset” button in the front panel of the Managed Switch over 10 seconds and then release, the current setting includes VLAN, will be lost and the Managed Switch will restore to the default mode. The preset user priorities for each function is listed under the section titled Appendix B.
  • Page 123: Mac Limit

    User’s Manual of NS2503-24P/2C 4.13 MAC Limit MAC limit allows users to set a maximum number of MAC addresses to be stored in the MAC address table. The MAC addresses chosen to be stored in MAC address table is the result of first-come-first-save policy. Once a MAC address is stored in the MAC address table, it stays in until it is aged out.
  • Page 124: Mac Limit Port Status

    User’s Manual of NS2503-24P/2C 4.13.2 MAC Limit Port Status This table displays current MAC Limit status of each port. Figure 4-13-2: MAC Limit – MAC Limit Port Status Interface Screenshot The page includes the following fields: Object Description Indicate port 1 to port 24. Port Number Display the current MAC Limit configuration and status of each port.
  • Page 125: Configuration

    User’s Manual of NS2503-24P/2C 4.14 802.1X Configuration 802.1x is an IEEE authentication specification which prevents the client from accessing a wireless access point or wired switch until it provides authority, like the user name and password that are verified by an authentication server (such as RADIUS server).
  • Page 126 User’s Manual of NS2503-24P/2C initial identity/request frame followed by one or more requests for authentication information). Upon receipt of the frame, the client responds with an EAP-response/identity frame. However, if during bootup, the client does not receive an EAP-request/identity frame from the switch, the client can initiate authentication by sending an EAPOL-start frame, which prompts the switch to request the client's identity.
  • Page 127: System Configuration

    User’s Manual of NS2503-24P/2C If the link state of a port transitions from up to down, or if an EAPOL-logoff frame is received, the port returns to the unauthorized state. 4.14.2 System Configuration 802.1x makes use of the physical access characteristics of IEEE802 LAN infrastructures in order to provide a means of authenticating and authorizing devices attached to a LAN port that has point-to-point connection characteristics, and of preventing access to that port in cases in which the authentication and authorization process fails.
  • Page 128 User’s Manual of NS2503-24P/2C Object Description Enable or disable 802.1x protocol. IEEE 802.1x Protocol: Assign the RADIUS Server IP address. Radius Server IP: Set the UDP destination port for authentication requests to the specified RADIUS Server Port: Server. Set the UDP destination port for accounting requests to the specified RADIUS Accounting Port: Server.
  • Page 129: Port Configuration

    User’s Manual of NS2503-24P/2C 4.14.3 802.1x Port Configuration In this page, you can select the specific port and configure the authorization state. The state provides No Authorization, Force Authorized, Force unauthorized, and Authorize. Figure 4-14-5: 802.1x Per Port Setting Interface Screenshot The page includes the following fields: Object Description...
  • Page 130: Misc Configuration

    User’s Manual of NS2503-24P/2C 4.14.4 Misc Configuration In this page, you can change the default configuration for the 802.1x standard: Figure 4-14-6: 802.1x Misc Configuration interface Screenshot The page includes the following fields: Object Description Used to define periods of time during which it will not attempt to acquire a supplicant.
  • Page 131: Qos Configuration

    User’s Manual of NS2503-24P/2C 4.15 QoS Configuration 4.15.1 Understand QoS Quality of Service (QoS) is an advanced traffic prioritization feature that allows you to establish control over network traffic. QoS enables you to assign various grades of network service to different types of traffic, such as multi-media, video, protocol-specific, time critical, and file-backup traffic.
  • Page 132: Qos Configuration

    User’s Manual of NS2503-24P/2C 4.15.2 QoS Configuration QoS settings allow customization of packet priority in order to facilitate delivery of data traffic that might be affected by latency problems. When CoS / 802.1p Tag Priority is applied, the Switch recognizes 802.1Q VLAN tag packets and extracts the VLAN tagged packets with User Priority value.
  • Page 133 User’s Manual of NS2503-24P/2C The table includes the following fields: Object Description The sequence of packets sent is depend on arrival order. First Come First Service The high priority packets sent before low priority packets. All High before Low Select the preference given to packets in the switch's higher-priority queue. These options represent the number of higher priority packets sent before one lower priority packet is sent.
  • Page 134 User’s Manual of NS2503-24P/2C 4.15.2.2 QoS PerPort Configuration Configure the priority level for each port. With the drop-down selection item of Priority Type above being selected as Port-based, this control item will then be available to set the queuing policy for each port. Figure 4-15-3: QoS Configuration –...
  • Page 135: Tos/Dscp

    User’s Manual of NS2503-24P/2C 4.15.3 TOS/DSCP TOS/DSCP priority is obtained through a 6-bit Type-of-Service (TOS) or Differentiated Service Code Point (DSCP) to 3-bit priority mapping. The Type of Service (TOS) octet in the IPv4 header is divided into three parts; Precedence (3 bits), TOS (4 bits), and MBZ (1 bit).
  • Page 136 User’s Manual of NS2503-24P/2C 4.15.3.1 TOS/DSCP Configuration The TOS/DSCP page provides fields for defining output queue to specific DSCP fields. When TCP/IP’s TOS/DSCP mode is applied, the Managed Switch recognizes TCP/IP Differentiated Service Codepoint (DSCP) priority information from the DS-field defined in RFC2474.
  • Page 137 User’s Manual of NS2503-24P/2C Figure 4-15-6 : QoS Configuration – TOS/DSCP Port Status Interface Screenshot The table includes the following fields: Object Description Indicate port 1 to port 10. Port Number Enable / Disable TOS/DSCP map to 802.1p priority on specify port. TOS/DSCP Status Press this button to take affect.
  • Page 138: Power Over Ethernet

    User’s Manual of NS2503-24P/2C 4.16 Power over Ethernet Providing up to 24 PoE, in-line power interface, the NS2503-24P/2C PoE Switch can easily build a power central-controlled IP phone system, IP Camera system, AP group for the enterprise. For instance, 24camera / AP can be easily installed around the corner in the company for surveillance demands or build a wireless roaming environment in the office.
  • Page 139: 2Ns2503-24P/2C Power Management

    User’s Manual of NS2503-24P/2C 4.16.2 NS2503-24P/2C Power Management In a power over Ethernet system, operating power is applied from a power source (PSU-power supply unit) over the LAN infrastructure to powered devices (PDs), which are connected to ports. Under some conditions, the total output power required by PDs can exceed the maximum available power provided by the PSU.
  • Page 140 User’s Manual of NS2503-24P/2C The page includes the following fields: Object Description Allows user enable or disable PoE function. It enables or disables the power System PoE Admin Mode on all of the PoE ports. Display current PoE power supply working status. PoE PSU Status Display the current operating temperature of PoE chip unit 1.
  • Page 141 User’s Manual of NS2503-24P/2C Class 0 is the default for PDs. However, to improve power management at the Device class PSE, the PD may opt to provide a signature for Class 1 to 3. The PD is classified based on power. The classification of the PD is the maximum power that the PD will draw across all input voltages and operational modes.
  • Page 142 User’s Manual of NS2503-24P/2C PD Classifications A PD may be classified by the PSE based on the classification information provided by the PD. The intent of PD classification is to provide information about the maximum power required by the PD during operation. Class 0 is the default for PDs. However, to improve power management at the PSE, the PD may opt to provide a signature for Class 1 to 3.
  • Page 143: Poe Schedule

    User’s Manual of NS2503-24P/2C 4.16.3 PoE Schedule PoE Schedule allows user to scheduling PoE power supply. User has to define when system supplies PoE power from a time table as following screen shot, and there are 4 profiles totally for user applying PoE power supply strategy. The web screen in Figure 4-16-3 appears.
  • Page 144 User’s Manual of NS2503-24P/2C Figure 4-16-4: PoE Configuration Interface...
  • Page 145: Console Management

    User’s Manual of NS2503-24P/2C 5. CONSOLE MANAGEMENT The Managed Switch is equipped with a RS-232 DB9 connector as default. And support telnet management. 5.1 Login in the Console Interface To configure the system via console mode, connect a serial cable to a COM port on a PC or notebook computer and to RJ-45 type serial (console) port of the Managed Switch.
  • Page 146: Configure Ip Address

    User’s Manual of NS2503-24P/2C 5.2 Configure IP address The Managed Switch is shipped with the following default IP address. IP Address : 192.168.0.100 Subnet Mask : 255.255.255.0 To check the current IP address or modify a new IP address for the Switch, please use the following procedures: Show the current IP address On ”Switch# ”...
  • Page 147: Commands Level

    User’s Manual of NS2503-24P/2C Configure IP address On “Switch(config)# ” prompt, enter the following command and press <Enter>. As show in Figure 5-2-2. Switch(config)# ip address 192.168.1.100 255.255.255.0 Switch(config)# ip default-gateway 192.168.1.254 The previous command would apply the follow settings for the Switch. IP: 192.168.1.100 Subnet Mask: 255.255.255.0 Gateway: 192.168.1.254...
  • Page 148 User’s Manual of NS2503-24P/2C The user commands available at the user level are a subset of those available at the Begin a session Enter logout or User EXEC privileged level. switch> with your switch. quit. Use this mode to: • Perform basic tests. •...
  • Page 149: Command Line Interface

    User’s Manual of NS2503-24P/2C 6. COMMAND LINE INTERFACE 6.1 Operation Notice To enter the “configuration” mode, you need to be in the privileged mode, and then types in the command configure: Switch# configure Switch (config) # 6.1.1. Command Line Editing Keys Function ;...
  • Page 150: System Commands

    User’s Manual of NS2503-24P/2C 6.2 System Commands show running-config Description: Display the running configuration of the switch. copy running-config startup-config Description: Backup the switch configuration. erase startup-config Description: Reset to default factory settings at next boot time. clear arp Description: <ip-addr>...
  • Page 151: Switch Static Configuration

    User’s Manual of NS2503-24P/2C 6.3 Switch Static Configuration 6.3.1 Port Configuration and show status port state Turn the port state on or off. Syntax: port state <on | off> [<port-list>] Parameters: <port-list> specifies the ports to be turn on or off. If not entered, all ports are turn on or off. port nego Description: Set port negotiation.
  • Page 152: Port Jumboframe

    User’s Manual of NS2503-24P/2C <port-list> specifies the ports to be set. If not entered, all ports are set. port jumboframe Description: Set port jumbo frame. When port jumbo frame is enable, the port forward jumbo frame packet Syntax: port jumboframe <enable | disable> [<port-list>] Parameters: <port-list>...
  • Page 153 User’s Manual of NS2503-24P/2C ---------------------------------------------------------------------- TxGoodPkt: 0 TxBadPkt: 0 RxGoodPkt: 0 RxBadPkt: 0 TxAbort: 0 Collision: 0 DropPkt: 0 ---------------------------------------------------------------------- Port Information ---------------------------------------------------------------------- TxGoodPkt: 0 TxBadPkt: 0 RxGoodPkt: 0 RxBadPkt: 0 TxAbort: 0 Collision: 0 DropPkt: 0 ---------------------------------------------------------------------- Port Information ---------------------------------------------------------------------- --More-- show port protection...
  • Page 154: Trunk Configuration

    User’s Manual of NS2503-24P/2C 6.4 Trunk Configuration Trunk allows the switch to combine ports so that they function like a single high-speed link. It can be used to increase the bandwidth to some devices to provide a high-speed link. For example, trunk is useful when making connections between switches or connecting servers to the switch.
  • Page 155: Show Lacp

    User’s Manual of NS2503-24P/2C lacp system-priority Description: Set LACP system priority. Syntax: lacp system-priority <1..65535> Parameters: <1..65535> specifies the LACP system priority. no lacp system-priority Description: Set LACP system priority to the default value 32768. show lacp status Description: Show LACP enable/disable status and system priority. show lacp Description: Show LACP information.
  • Page 156: Vlan Configuration

    User’s Manual of NS2503-24P/2C 6.5 VLAN Configuration 6.5.1 Virtual LANs A Virtual LAN (VLAN) is a logical network group that limits the broadcast domain. It allows you to isolate network traffic so only members of the VLAN receive traffic from the same VLAN members. Basically, creating a VLAN within a switch is logically equivalent of reconnecting a group of network devices to another Layer 2 switch.
  • Page 157: Vlan Mode: Port-Based

    User’s Manual of NS2503-24P/2C The Managed Switch support both Port-based VLAN and Tag-based (802.1Q) VLAN modes. The default configuration is tag-based (802.1Q) VLAN. In the 802.1Q VLAN, initially, all ports on the switch belong to default VLAN, VID is 1. You cannot delete the default VLAN group in 802.1Q VLAN mode.
  • Page 158: Vlan Add

    User’s Manual of NS2503-24P/2C 6.5.3 Advanced 802.1Q VLAN Configuration Ingress filters configuration When a packet was received on a port, you can govern the switch to drop it or not if it is an untagged packet. Furthermore, if the received packet is tagged but not belonging to the same VALN group of the receiving port, you can also control the switch to forward or drop the packet.
  • Page 159: Show Vlan

    User’s Manual of NS2503-24P/2C This VLAN entry has four members (from port1 to port4) and all members are untagged. no vlan Description: Delete VLAN entry. Syntax: no vlan <1-4094> Parameters: <1-4094> specifies the VLAN id or group id (if port based VLAN). e.g.
  • Page 160: Show Vlan Filter

    User’s Manual of NS2503-24P/2C Switch(config)# show vlan pvid Port | PVID -----------+------- Port1 | 1 Port2 | 1 Port3 | 1 Port4 | 1 Port5 | 1 Port6 | 1 Port7 | 1 Port8 | 1 Port9 | 1 Port10 | 1 Trk1 | 1 vlan filter Description:...
  • Page 161: Misc Configuration

    User’s Manual of NS2503-24P/2C 6.6 Misc Configuration no mac-age-time Description: Set MAC address age-out time. Syntax: [no] mac-age-time Enable or disable MAC address age-out. mac-age-time <6..1572858> Parameters: <6..1572858> specifies the MAC address age-out time. Must be divisible by 6. Type the number of seconds that an inactive MAC address remains in the switch’s address table.
  • Page 162: Ip Configuration

    User’s Manual of NS2503-24P/2C no hostname Reset the switch name to factory default setting. [no] password Description: Set or remove username and password for manager or operator. Syntax: [no] password <manager | operator | all> Parameters: The manager username and password is also used by the web UI. 6.7.2 IP Configuration User can configure the IP setting and fill in the new value.
  • Page 163: Reboot Switch

    User’s Manual of NS2503-24P/2C If you set this command, the switch will reboot. show dhcp Description: show dhcp enable/disable. 6.7.3 Reboot switch boot Description: Reboot (warm-start) the switch. 6.7.4 Reset to Default erase startup-config Description: Reset configurations to default factory settings at next boot time. 6.7.5 TFTP Update Firmware copy tftp firmware Description:...
  • Page 164: Restore Configure File

    User’s Manual of NS2503-24P/2C 6.7.6 Restore Configure File copy tftp <running-config | flash> Description: Retrieve configuration from the TFTP server. If the remote file is the text file of CLI commands, use the keyword running-config. If the remote file is the configuration flash image of the switch instead, use the keyword flash. Syntax: copy tftp <running-config | flash>...
  • Page 165: Port Mirroring Configuration

    User’s Manual of NS2503-24P/2C 6.9 Port Mirroring Configuration Port monitoring is a feature to redirect the traffic occurred on every port to a designated monitoring port on the switch. With this feature, the network administrator can monitor and analyze the traffic on the entire LAN segment. In the Managed Switch, you can specify one port to be the monitored ports and any single port to be the monitoring port.
  • Page 166: Quality Of Service

    User’s Manual of NS2503-24P/2C 6.10 Quality of Service There are four transmission queues with different priorities in the Managed Switch: Highest, SecHigh, SecLow and Lowest. The Managed Switch will take packets from the four queues according to its QoS mode setting. If the QoS mode was set to “Disable”, the Managed Switch will not perform QoS on its switched network.
  • Page 167: Per Port Priority

    User’s Manual of NS2503-24P/2C e.g. Switch(config)# show qos QoS configurations: QoS mode: weighted round robin Highest weight: 8 Second High weight: 4 Second Low weight: 2 Lowest weight: 1 802.1p priority[0-7]: Lowest Lowest SecLow SecLow SecHigh SecHigh Highest Highest 6.10.2 Per Port Priority port priority Description: Set port priority.
  • Page 168: Show Filter

    User’s Manual of NS2503-24P/2C 00:03:63:F7:80:7F 1 | Dynamic | 9 show mac-address table static Description: Display static MAC address table entries. show mac-address-table multicast Description: Display multicast related MAC address table. smac-address-table static Description: Set static unicast or multicast MAC address in secondary MAC address table. If multicast MAC address (address beginning with 01:00:5E) is supplied, the last parameter must be port-list.
  • Page 169: Stp/Mstp Commands

    User’s Manual of NS2503-24P/2C 6.12 STP/MSTP Commands [no] spanning-tree Description: Enable or disable spanning-tree. spanning-tree forward-delay Description: Set spanning tree forward delay of CIST, in seconds. Syntax: spanning-tree forward-delay <4-30> Parameters: <4-30> specifies the forward delay, in seconds. Default value is 15. The parameters must enforce the following relationships: 2*(hello-time + 1) <= maximum-age <= 2*(forward-delay - 1) spanning-tree hello-time...
  • Page 170 User’s Manual of NS2503-24P/2C show spanning-tree Description: Show spanning-tree information. show spanning-tree port Description: Show spanning tree per port information. Syntax: show spanning-tree port [<port-list>] Parameters: <port-list> specifies the port to be shown. Null means all ports. [no] spanning-tree debug Description: Enable or disable spanning tree debugging information.
  • Page 171 User’s Manual of NS2503-24P/2C <1-200000000> specifies port path cost. <port-list> specifies the ports to be set. Null means all ports. spanning-tree port priority Description: Set spanning tree port priority of CIST. Syntax: spanning-tree port priority <0-240> [<port-list>] Parameters: <0-240> specifies the port priority. The value must be in steps of 16. <port-list>...
  • Page 172 User’s Manual of NS2503-24P/2C spanning-tree mst <0-15> vlan [<vlan-list>] Description: Set MSTI to map VLAN list. Syntax: spanning-tree mst <0-15> vlan [<vlan-list>] Parameters: <0-15> specifies the MSTI instance ID. <vlan-list> specifies the mapped VLAN list. Null means all VLANs. spanning-tree mst <0-15> port path-cost <1-200000000> [<port-list>] Description: Set spanning tree port path cost of MSTI.
  • Page 173 User’s Manual of NS2503-24P/2C show spanning-tree mst <0-15> Description: Show MST instance information. Syntax: show spanning-tree mst <0-15> Parameters: <0-15> specifies the MSTI instance ID. show spanning-tree mst <0-15> port <1-10> Description: Show specific port information of MST instance. Syntax: show spanning-tree mst <0-15>...
  • Page 174: Snmp

    User’s Manual of NS2503-24P/2C 6.13 SNMP Any Network Management running the simple Network Management Protocol (SNMP) can be management the switch. 6.13.1 System Options Snmp /no snmp Description: Enable or disable SNMP. Show snmp status Description: Show the enable or disable status of SNMP. snmp system-name Description: Set agent system name string.
  • Page 175: Trap Managers

    User’s Manual of NS2503-24P/2C Parameters: <community-str> specifies the community string. e.g. snmp community read-all-only public no snmp community Description: Delete SNMP community string. Syntax: no snmp community <community-str> Parameters: <community-str> specifies the community string. e.g. no snmp community public show snmp community Description: Show SNMP community strings.
  • Page 176: Igmp Fastleave

    User’s Manual of NS2503-24P/2C igmp fastleave Description: Enable/disable IGMP snooping fast leave. If enable, switch will fast delete member who send leave report, else wait one sec. Syntax: [no] igmp fastleave igmp querier Description: Enable/disable IGMP snooping querier. Syntax: [no] igmp querier igmp CrossVLAN Description: Enable/disable IGMP snooping CrossVLAN...
  • Page 177: Protocol

    User’s Manual of NS2503-24P/2C 6.15 802.1x Protocol dot1x Description: Enable or disable 802.1x. Syntax: [no] dot1x radius-server host Description: Set radius server IP, port number, and accounting port number. Syntax: radius-server host <ip-addr> <1024..65535> <1024..65535> Parameters: <ip-addr> specifies server’s IP address. The first <1024..65535>...
  • Page 178 User’s Manual of NS2503-24P/2C dot1x timeout supplicant Description: Set 802.1x supplicant timeout (default: 30 seconds) Syntax: dot1x timeout supplicant <1..300> Parameters: <1..300> specifies the supplicant timeout, in seconds. dot1x timeout radius-server Description: Set radius server timeout (default: 30 seconds). Syntax: dot1x timeout radius-server <1..300>...
  • Page 179: Show Dot1X

    User’s Manual of NS2503-24P/2C Parameters: <1..10> specifies the maximum request retries. dot1x timeout re-authperiod Description: Set 802.1x re-auth period (default: 3600 seconds). Syntax: dot1x timeout re-authperiod <30..65535> Parameters: <30..65535> specifies the re-auth period, in seconds. show dot1x Description: Show 802.1x information, quiet period, Tx period, supplicant timeout, server timeout, maximum requests, and re-auth period. dot1x port Description: Set 802.1x per port information.
  • Page 180: Access Control List

    User’s Manual of NS2503-24P/2C 6.16 Access Control List Packets can be forwarded or dropped by ACL rules include Ipv4 or non-Ipv4. The Managed Switch can be used to block packets by maintaining a table of packet fragments indexed by source and destination IP address, protocol, and so on 6.16.1 Ipv4 ACL commands no acl Description:...
  • Page 181: Non-Ipv4 Acl Commands

    User’s Manual of NS2503-24P/2C <1-220> specifies the group id. (permit|deny) specifies the action. permit: permit packet cross switch; deny: drop packet. <0-4094> specifies the VLAN id. 0 means don't care. <0-255> specifies the IP protocol. 0 means don't care. A.B.C.D specifies the Source IP address. 0.0.0.0 means don't care. A.B.C.D specifies the Mask.
  • Page 182: Binding

    User’s Manual of NS2503-24P/2C 6.17 Binding Let device that has specific IP address and MAC address can use network. We can set specific IP address, MAC address, VLAN id and port id to bind, and device can cross switch if all conditions match. 6.17.1 SIP/SMAC binding commands bind Description:...
  • Page 183 User’s Manual of NS2503-24P/2C Parameters: <1-220> specifies the group id. A.B.C.D specifies the MAC address. <0-4094> specifies the VLAN id. 0 means don't care. A.B.C.D specifies the Source IP address. 0.0.0.0 means don't care. A.B.C.D specifies the IP Address. <1-10> specifies the Port id. e.g.
  • Page 184: Power Over Ethernet Commands

    User’s Manual of NS2503-24P/2C 6.18 Power over Ethernet Commands Show System Power over Ethernet information show poe Show PoE port information show poe status Enabling or disabling the PoE power supply over temperature protection poe temperature-protection Configure System PoE power limit mode information poe limit-mode Enabling or disabling the port POE injects function poe enable...
  • Page 185 User’s Manual of NS2503-24P/2C show poe status Description: Show per PoE port information Command Level Global Configuration Syntax: show poe status [<port-list>] Parameters: <port-list> specifies the ports to be set. If not entered, all ports are set. Example 1: Switch(config)# show poe status 1 Power Current Device...
  • Page 186: Configure Poe Over Temperature Protection

    User’s Manual of NS2503-24P/2C 6.18.2 Configure PoE Over Temperature Protection poe temperature-protection enable Description: Configure PoE over temperature protection to enable or disable Command Level Global Configuration Syntax: poe temperature-protection { enable } Parameters: <Enable > Enable PoE power budget change automatically by detected PoE unit temperature <Disable >...
  • Page 187: Configure Poe -- System

    User’s Manual of NS2503-24P/2C 6.18.3 Configure PoE -- System poe limit-mode Description: Configure System PoE power limit mode information Command Level Global Configuration Syntax: poe limit-mode { classification / consumption} Parameters: < classification > Deliver PoE power by port priority setting and device PoE power level <...
  • Page 188 User’s Manual of NS2503-24P/2C Example: Switch(config)# poe limit-mode consumption Switch(config)# show poe Maximum Available Power :360Watts POE Admin mode :Enable Temperature Unit1 :34C/93F Temperature Unit2 :37C/98F Over Temperature :Enable PoE Power Consumption : 0 Watts Temperature Threshold Usage Usage Threshold : 100% PoE Power limit mode : Consumption...
  • Page 189 User’s Manual of NS2503-24P/2C poe admin-mode Description: Configure System PoE Admin mode information Command Level Global Configuration Syntax: poe admin-mode { enable / disable } [no] poe admin-mode Parameters: <enable > Enable POE <disable > Disable POE. Example: Switch(config)# poe admin-mode enable Switch(config)# show poe Maximum Available Power :360Watts...
  • Page 190 User’s Manual of NS2503-24P/2C Switch (config)# poe admin-mode disable Switch(config)# show poe Maximum Available Power :360Watts POE Admin mode :Disable Temperature Unit1 :34C/93F Temperature Unit2 :37C/98F Over Temperature :Enable PoE Power Consumption : 0 Watts Temperature Threshold Usage Usage Threshold : 100% PoE Power limit mode : Consumption...
  • Page 191 User’s Manual of NS2503-24P/2C poe temperature Description: Configure System PoE Temperature Threshold information Command Level Global Configuration Syntax: poe temperature { thershold } {0-100} Parameters: <thershold> Thershold <0-100> Temperature Threshold: 0~100 C Example: Switch(config)# poe temperature threshold 60 Switch(config)# show poe Maximum Available Power :360Watts POE Admin mode...
  • Page 192 User’s Manual of NS2503-24P/2C poe usage Description: Configure System PoE Usage Threshold information Command Level Global Configuration Syntax: poe usage { thershold } {0-100} Parameters: <thershold> Thershold <0-100> Usage Threshold: 0~100% Example: Switch(config)# poe usage threshold 10 Switch(config)# show poe Maximum Available Power :360Watts POE Admin mode...
  • Page 193: Configure Poe -- Port

    User’s Manual of NS2503-24P/2C 6.18.4 Configure PoE -- Port poe enable Description: Enabling or disabling the port POE injects function. Command Level: Global Configuration Syntax: poe enable [<port-list>] [no] poe enable [<port-list>] Parameters: <port-list> specifies the ports to be set. If not entered, all ports are set. Example: (config)# poe enable 1 Switch...
  • Page 194: Poe Priority

    User’s Manual of NS2503-24P/2C poe priority Description: Set port priority for the power supply management. Command Level: Global Configuration Syntax: poe priority { Critical | High | Low} [<port-list>] Parameters: {Critical | High | Low} • Critical — Indicates that operating the powered device is high. •...
  • Page 195 User’s Manual of NS2503-24P/2C poe power-mode Description: Set poe power mode for the power supply management Command Level Global Configuration Syntax: poe power-mode{ 802.3af / 802.3at } [<port-list>] Parameters: <802.3af> <802.3af > Set maximum PoE output capability to 15.4Watts <802.3at> <802.3at > Set maximum PoE output capability to 30.8Watts <LIST>...
  • Page 196: Switch Operation

    User’s Manual of NS2503-24P/2C 7. SWITCH OPERATION 7.1 Address Table The Switch is implemented with an address table. This address table composed of many entries. Each entry is used to store the address information of some node in network, including MAC address, port no, etc. This in-formation comes from the learning process of Ethernet Switch.
  • Page 197: Auto-Negotiation

    User’s Manual of NS2503-24P/2C 7.5 Auto-Negotiation The STP ports on the Switch have built-in "Auto-negotiation". This technology automatically sets the best possible bandwidth when a connection is established with another network device (usually at Power On or Reset). This is done by detect the modes and speeds at the second of both device is connected and capable of, both 10Base-T and 100Base-TX devices can connect with the port in either Half- or Full-Duplex mode.
  • Page 198: Power Over Ethernet Overview

    User’s Manual of NS2503-24P/2C 8. POWER OVER ETHERNET OVERVIEW What is PoE? Based on the global standard IEEE 802.3af, PoE is a technology for wired Ethernet, the most widely installed local area network technology adopted today. PoE allows the electrical power necessary for the operation of each end-device to be carried by data cables rather than by separate power cords.
  • Page 199: The Poe Provision Process

    User’s Manual of NS2503-24P/2C Figure 2 - Power Supplied over the Data Pins When to install PoE? Consider the following scenarios: • • You're planning to install the latest VoIP Phone system to minimize cabling building costs when your company moves into new offices next month.
  • Page 200: Stages Of Powering Up A Poe Link

    User’s Manual of NS2503-24P/2C Stages of powering up a PoE link Volts specified Volts managed Stage Action per 802.3af by chipset Measure whether powered device has the correct signature 2.7-10.0 1.8–10.0 Detection resistance of 15–33 kΩ Measure which power level class the resistor indicates 14.5-20.5 12.5–25.0 Classification...
  • Page 201 User’s Manual of NS2503-24P/2C DC Disconnect DC Disconnect detection involves measurement of current. Naturally, a disconnected PD stops consuming current, which can be inspected by the PSE. The PSE must therefore disconnect power within 300 to 400 ms from the current flow stop. The lower time boundary is important to prevent shutdown due to random fluctuations.
  • Page 202: Trouble Shooting

    User’s Manual of NS2503-24P/2C 9. TROUBLE SHOOTING This chapter contains information to help you solve problems. If the Ethernet Switch is not functioning properly, make sure the Ethernet Switch was set up according to instructions in this manual. ■ The Link LED is not lit Solution: Check the cable connection and remove duplex mode of the Ethernet Switch ■...
  • Page 203: Appendix A-Rj-45 Pin Assignment

    User’s Manual of NS2503-24P/2C Appendix A—RJ-45 Pin Assignment A.1 Switch's RJ-45 Pin Assignments 1000Mbps, 1000Base T Contact MDI-X BI_DA+ BI_DB+ BI_DA- BI_DB- BI_DB+ BI_DA+ BI_DC+ BI_DD+ BI_DC- BI_DD- BI_DB- BI_DA- BI_DD+ BI_DC+ BI_DD- BI_DC- Implicit implementation of the crossover function within a twisted-pair cable, or at a wiring panel, while not expressly forbidden, is beyond the scope of this standard.
  • Page 204 User’s Manual of NS2503-24P/2C The standard cable, RJ-45 pin assignment The standard RJ-45 receptacle/connector There are 8 wires on a standard UTP/STP cable and each wire is color-coded. The following shows the pin allocation and color of straight cable and crossover cable connection: Straight Cable SIDE 1 SIDE2...
  • Page 205: Appendix B: Local User Access Level Table

    User’s Manual of NS2503-24P/2C APPENDIX B: Local User Access Level Table Model NS2503-24P/2C Group Name Master Security User Level Admin Viewer Admin Viewer Admin Viewer Main Function System Information Change Change Change View Only View Only Not Accessable Misc Config Change Change Change...
  • Page 206 User’s Manual of NS2503-24P/2C Group Name Master Security User Level Admin Viewer Admin Viewer Admin Viewer Main Function Aggregator Setting Change Change Change View Only Change Not Accessable Aggregator Information Change Change Change View Only Change Not Accessable Trunking State Activity Change Change Change...

Table of Contents