User Manual DES-3528 Product Model: Layer 2 Managed Stackable Fast Ethernet Switch Release 1.2...
Page 2
Reproduction in any manner whatsoever without the written permission of D-Link Computer Corporation is strictly forbidden. Trademarks used in this text: D-Link and the D-LINK logo are trademarks of D-Link Computer Corporation; Microsoft and Windows are registered trademarks of Microsoft Corporation.
Page 3
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual FCC Warning This equipment has been tested and found to comply with the limits for a Class A digital device, pursuant to Part 15 of the FCC Rules. These limits are designed to provide reasonable protection against harmful interference when the equipment is operated in a commercial environment.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Table of Contents Preface ......................................x Intended Readers................................... xi Typographical Conventions ...................................xi Notes, Notices, and Cautions ................................ xi Safety Instructions ..................................xii Safety Cautions ......................................xii General Precautions for Rack-Mountable Products ............................ xiii Protecting Against Electrostatic Discharge ..............................xiv...
Page 5
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Introduction....................................18 Login to Web Manager ....................................18 Web-based User Interface .....................................19 Web Pages........................................20 Configuration ..............................21 Device Information ..................................22 System Information..................................22 Serial Port Settings..................................23 IP Address....................................23 Port Configuration..................................
Page 6
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual SNMP Host Table ......................................53 SNMP Engine ID ......................................53 SNMP Trap Configuration ....................................54 Time Range Settings ..................................54 Single IP Settings..................................55 SIM Settings........................................56 Topology ........................................57 Tool Tips........................................60 Right-Click........................................61 Menu Bar ........................................63...
Page 7
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual MLD Snooping Settings....................................94 Port Mirror ....................................96 Loopback Detection Settings ............................... 97 Spanning Tree ....................................98 STP Bridge Global Settings ..................................100 STP Port Settings ......................................102 MST Configuration Identification................................103 STP Instance Settings....................................104...
Page 8
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual IMP Entry Settings......................................131 DHCP Snooping Entries .....................................132 MAC Block List......................................132 Port Security....................................132 Port Security Settings....................................132 Port Security FDB Entries...................................133 DHCP Server Screening Settings............................... 134 DHCP Screening Port Settings..................................134 DHCP Offer Filtering....................................135...
Page 9
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Web-based Access Control Settings................................165 Web-based Access Control User Settings ..............................166 JWAC (Japanese Web-based Access Control)........................... 167 JWAC Global Settings ....................................167 JWAC Port Settings ....................................169 JWAC User Account....................................170 NetBIOS Filtering ..................................170 NetBIOS Filtering Settings ..................................170...
Page 10
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual JWAC Host Table ..................................232 MAC Address Table .................................. 233 System Log ....................................233 Save Services and Tools..........................235 Save Configuration ID 1 ................................235 Save Configuration ID 2 ................................236 Save Log ....................................
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Preface The DES-3528 Manual is divided into sections that describe the system installation and operating instructions with examples. Section 1, Introduction – Describes the Switch and its features.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Intended Readers The DES-3528 Manual contains information for setup and management of the Switch. This manual is intended for network managers familiar with network management concepts and terminology.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Safety Instructions Use the following safety guidelines to ensure your own personal safety and to help protect your system from potential damage. Throughout this document, the caution icon ( ) is used to indicate cautions and precautions that you need to review and follow.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual ratings label. The voltage and current rating of the cable should be greater than the ratings marked on the product. • To help prevent electric shock, plug the system and peripheral power cables into properly grounded electrical outlets.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual CAUTION: Never defeat the ground conductor or operate the equipment in the absence of a suitably installed ground conductor. Contact the appropriate electrical inspection authority or an electrician if you are uncertain that suitable grounding is available.
Side Panel Description Gigabit Combo Ports The DES-3528 layer 2 Fast Ethernet switch is a member of the D-Link xStack family. Ranging from 10/100Mbps edge switches to core gigabit switches, the xStack switch family has been future-proof designed to provide a stacking architecture with fault tolerance, flexibility, port density, robust security and maximum throughput with a user-friendly management interface for the networking professional.
Switch's settings for priority queuing, VLANs, and port trunk groups, port monitoring, and port speed. NOTE: For the remainder of this manual, all hardware versions of the DES-3528 switch will be referred to as simply the Switch or the DES-3528.
LED Indicators The Switch supports LED indicators for Power, Console, RPS and Port LEDs. The following shows the LED indicators for the DES-3528 switch along with an explanation of each indicator. LEDs and there corresponding meanings are displayed below. Figure 1- 2. LED Indicators on DES-3528 switch...
Page 19
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Solid Light RPS is in Use Green Light Off RPS Off Solid Light When the device is the stacking master. Master(MS) Green Light Off Not the Stacking Master.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Rear Panel Description The rear panel of the Switch contains an AC power connector. Figure 1- 3. Rear panel view of the DES-3528 The AC power connector is a standard three-pronged connector that supports the power cord. Plug-in the female connector of the provided power cord into this socket, and the male side of the cord into a power outlet.
Page 21
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 1- 6. Installing the SFP Module...
Four rubber feet with adhesive backing RS-232 console cable If any item is found missing or damaged, please contact your local D-Link Reseller for replacement. Before You Connect to the Network The site where you install the Switch may greatly affect its performance. Please follow these guidelines for setting up the Switch.
Attach these cushioning feet on the bottom at each corner of the device. Allow enough ventilation space between the Switch and any other objects in the vicinity. Figure 2- 1. Preparing the DES-3528 for installation on a desktop or shelf Installing the Switch in a Rack The Switch can be mounted in a standard 19"...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Mounting the Switch in a Standard 19" Rack CAUTION: Installing systems in a rack without the front and side stabilizers installed could cause the rack to tip over, potentially resulting in bodily injury under certain circumstances. Therefore, always install the stabilizers before installing components in the rack.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Section 3 Connecting the Switch Switch to End Node Switch to Hub or Switch Connecting To Network Backbone or Server NOTE: All 24 high-performance NWay Ethernet ports can support both MDI-II and MDI-X connections.
Page 26
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 3- 2. DES-3528 connected to a normal (non-Uplink) port on a hub or switch using a straight or crossover cable...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Connecting To Network Backbone or Server The two SFP combo ports are ideal for linking to a network backbone or server. The copper ports operate at a speed of 1000, 100 or 10Mbps in full or half duplex mode.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Section 4 Introduction to Switch Management Management Options Web-based Management Interface SNMP-Based Management Managing User Accounts Command Line Console Interface through the Serial Port Connecting the Console Port (RS-232 DCE)
12. Enter the commands to complete your desired tasks. Many commands require administrator-level access privileges. Read the next section for more information on setting up user accounts. See the DES-3528 CLI Manual on the documentation CD for a list of all commands and additional information on using the CLI.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual First Time Connecting to the Switch The Switch supports user-based security that can allow you to prevent unauthorized users from accessing the Switch or changing its settings. This section tells how to log onto the Switch.
The DES-3528 supports SNMP versions 1, 2c, and 3. You can specify which version of SNMP you want to use to monitor and control the Switch. The three versions of SNMP vary in the level of security provided between the management station and the network device.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Identifier (OID) associated with a specific MIB. An additional layer of security is available for SNMP v.3 in that SNMP messages may be encrypted. To read more about how to configure SNMP v.3 settings for the Switch read the section entitled Management.
Page 33
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Starting at the command line prompt, enter the commands config ipif System ipaddress xxx.xxx.xxx.xxx/yyy.yyy.yyy.yyy Where the x's represent the IP address to be assigned to the IP interface named System and the y's represent the corresponding subnet mask.
Area 1 Select the folder or window to be displayed. The folder icons can be opened to display the hyper- linked window buttons and subfolders contained within them. Click the D-Link logo to go to the D- Link website. Area 2 Presents a graphical near real-time image of the front panel of the Switch.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual configuration. Area 3 Presents switch information based on your selection and the entry of configuration data. NOTICE: Any changes made to the Switch configuration during the current session must be saved in the Save Changes web menu (explained below) or use the command line interface (CLI) command save.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Section 6 Configuration System Information Serial Port Settings IP Address Port Configuration Static ARP Settings User Accounts System Log Configuration System Severity Settings DHCP/BOOTP Relay MAC Address Aging Time...
This window contains the main settings for all major functions on the Switch and appears automatically when you log on. To return to the Device Information window, click the DES-3528 Web Management Tool folder. The Device Information window shows the Switch’s MAC Address (assigned by the factory and unchangeable), the Boot PROM Version, Firmware Version, and Hardware Version.
The IP address may initially be set using the console interface prior to connecting to it through the Ethernet. If the Switch IP address has not yet been changed, read the introduction of the DES-3528 CLI Manual or return to Section 4 of this manual for more information.
Page 40
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual management station that will access the Switch. The Switch will allow management access from stations with the same VID listed here. NOTE: The Switch's factory default IP address is 10.90.90.90 with a subnet mask of 255.0.0.0 and a default gateway of 0.0.0.0.
Page 41
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Port Configuration This section contains information for configuring various attributes and properties for individual physical ports, including port speed and flow control. Port Settings Click Configuration > Port Configuration > Port Settings to display the following window: To configure switch ports: 1.
Page 43
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual a 1000BASE-T cable for connection between the Switch port and other device capable of a gigabit connection. The master setting (1000M/Full_M) will allow the port to advertise capabilities related to duplex, speed and physical layer type.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Port Description The Switch supports a port description feature where the user may name various ports on the Switch. To assign names to various ports, click Configuration > Port Configuration > Port Description to view the following window: Use the From and To pull-down menu to choose a port or range of ports to describe, and then enter a description of the port(s).
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Port Error Disabled The following window will display the information about ports that have had their connection status disabled, for reasons such as STP loopback detection or link down status. To view this window, click Configuration > Port Configuration >...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Static ARP Settings The Address Resolution Protocol (ARP) is a TCP/IP protocol that converts IP addresses into physical addresses. This table allows network managers to view, define, modify and delete ARP information for specific devices. Static entries can be defined in the ARP Table.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual User Accounts Use the User Account Management window to control user privileges, create new users and view existing User Accounts. To view this window, click Configuration > User Accounts.
Page 48
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual The following table summarizes the Admin, Operator and User privileges: Management Admin Operator User Configuration Read-only Network Monitoring Read-only Community Strings and Trap Stations Read-only Update Firmware and Configuration Files...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual System Log Configuration This section contains information for configuring various attributes and properties for System Log Configurations, including System Log Settings and System Log Host. System Log Settings This window allows the user to enable or disable the System Log and specify the System Log Save Mode Settings.
Page 50
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Facility Some of the operating system daemons and processes have been assigned Facility values. Processes and daemons that have not been explicitly assigned a Facility may use any of the "local use"...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual System Severity Settings The Switch can be configured to allow alerts be logged or sent as a trap to an SNMP agent or both. The level at which the alert triggers either a log entry or a trap message can be set as well.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual DHCP/BOOTP Relay The relay hops count limit allows the maximum number of hops (routers) that the DHCP/BOOTP messages can be relayed through to be set. If a packet’s hop count is more than the hop count limit, the packet is dropped. The range is between 1 and 16 hops, with a default value of 4.
Page 53
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual check and policy settings will have no effect. DHCP Relay Agent This field can be toggled between Enabled and Disabled using the pull-down menu. It is Information Option 82 used to enable or disable the Switches ability to check the validity of the packet’s option 82...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual The Implementation of DHCP Information Option 82 in the DES-3528 Switch. The config dhcp_relay option_82 command configures the DHCP relay agent information option 82 setting of the switch. The formats for the circuit ID sub-option and the remote ID sub-option are as follows: NOTE: For the circuit ID sub-option of a standalone switch, the module field is always zero.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 6- 15. DHCP/BOOTP Relay Interface Settings and DHCP/BOOTP Relay Interface Table window The following parameters may be configured or viewed. Parameter Description Interface The IP interface on the Switch that will be connected directly to the Server.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Web Settings Web-based management is Enabled by default. If you choose to disable this by selecting Disabled, you will lose the ability to configure the system through the web interface as soon as these settings are applied.
States the user who downloaded the firmware. This field may read “Anonymous” or “Unknown” for users that are unidentified. Dual Configuration Settings The following window is used to configure firmware information set in the Switch. The xStack DES-3528 has the capability to store two firmware images in its memory.
Page 58
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual To access this table, click Configuration > Dual Configuration Settings: Figure 6- 23. Dual Configuration Settings This window holds the following information: Parameter Description States the ID number of the configuration file located in the Switch’s memory. The Switch can store two configuration files for use.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Ping Test Ping is a small program that sends ICMP Echo packets to the IP address you specify. The destination node then responds to or "echoes" the packets sent from the Switch. This is very useful to verify connectivity between the Switch and other nodes on the network.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual SNTP Settings Time Settings To configure the time settings for the Switch, click Configuration > SNTP Settings > Time Settings: Figure 6- 25. Time Settings window The following parameters can be set or are displayed:...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual TimeZone Settings The following window is used to configure time zones and Daylight Savings time settings for SNTP. To configure the time Zone Settings for the Switch, click Configuration > SNTP Settings > TimeZone Settings: Figure 6- 26.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Week From: Month Enter the month DST will start on. From: Time in Enter the time of day that DST will start on. HH:MM To: Which Week of Enter the week of the month the DST will end.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Parameter Description State Enable or disable MAC notification globally on the Switch. Interval The time in seconds between notifications. (1-2147483647 sec) History Size The maximum number of entries listed in the history log used for notification. Up to 500 entries (1-500) can be specified.
The DES-3528 supports the SNMP versions 1, 2c, and 3. The default SNMP setting is disabled. You must enable SNMP. Once SNMP is enabled you can choose which version you want to use to monitor and control the Switch. The three versions of SNMP vary in the level of security provided between the management station and the network device.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual SNMP Global State Use this table to globally enable or disable the SNMP Settings on the switch. To view this window, click Configuration > SNMP Settings > SNMP Global State: Figure 6- 29.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual SNMP Group Table An SNMP Group created with this table maps SNMP users (identified in the SNMP User Table) to the views created in the previous menu. To view this window, click Configuration > SNMP Settings > SNMP Group Table: Figure 6- 31.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual SNMP User Table This window displays all of the SNMP User's currently configured on the Switch and also allows you to add new users. To view this window, click Configuration > SNMP Settings > SNMP User Table: Figure 6- 32.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual To implement changes made, click Apply. SNMP Community Table Use this table to view existing SNMP Community Table configurations and to create a SNMP community string to define the relationship between the SNMP manager and an agent. The community string acts like a password to permit access to the agent on the Switch.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual SNMP Host Table Use the SNMP Host Table window to set up SNMP trap recipients. To configure SNMP Host Table entries, click Configuration > SNMP Settings > SNMP Host Table: Figure 6- 34.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual SNMP Trap Configuration The following window is used to enable and disable trap settings for the SNMP function on the Switch. To view this window for configuration, click Configuration > SNMP Settings > SNMP Trap Configuration: Figure 6-36.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Single IP Settings Simply put, D-Link Single IP Management is a concept that will stack switches together over Ethernet instead of using stacking ports or modules. There are some advantages in implementing the "Single IP Management" feature: 1.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual The Upgrade to v1.6 To better improve SIM management, the DES-3528 Switch has been upgraded to version 1.6 in this release. Many improvements have been made, including: 1. The Commander Switch (CS) now has the capability to automatically rediscover member switches that have left the SIM group, either through a reboot or web malfunction.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 6- 39. Single IP Settings window (enabled) The following parameters can be set: Parameters Description SIM State Use the pull-down menu to either enable or disable the SIM state on the Switch. Disabled will render all SIM functions on the Switch inoperable.
Page 74
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 6- 40. Single IP Management window - Tree View The Tree View window holds the following information under the Data tab: Parameter Description Device Name This field will display the Device Name of the switches in the SIM group configured by the user. If no Device Name is configured by the name, it will be given the name default and tagged with the last six digits of the MAC Address to identify it.
Page 75
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 6- 41. Topology view This window will display how the devices within the Single IP Management Group are connected to other groups and devices. Possible icons in this screen are as follows:...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Tool Tips In the Topology view window, the mouse plays an important role in configuration and in viewing device information. Setting the mouse cursor over a specific device in the topology window (tool tip) will display the same information about a specific device as the Tree view does.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Right-Click Right-clicking on a device will allow the user to perform various functions, depending on the role of the Switch in the SIM group and the icon associated with it.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Commander Switch Icon Figure 6- 46. Right-Clicking a Commander Icon The following options may appear for the user to configure: Collapse - To collapse the group that will be represented by a single icon.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Add to group - Add a candidate to a group. Clicking this option will reveal the following dialog for the user to enter a password for authentication from the Candidate Switch before being added to the SIM group. Click OK to enter the password or Cancel to exit the window.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 6- 52. About window Firmware Upgrade This screen is used to upgrade firmware from the Commander Switch to the Member Switch. Member Switches will be listed in the table and will be specified by Port (port on the CS where the MS resides), MAC Address, Model Name and Version.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Upload Log The following window is used to upload log files from SIM member switches to a specified PC. To upload a log file, enter the Server IP address of the SIM member switch and then enter a Path\Filename on your PC where you wish to save this file.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual dependent on such time critical data, such as video conferencing, can be severely and adversely affected by even very small delays in transmission. Network devices that are in compliance with the IEEE 802.1p standard have the ability to recognize the priority level of data packets.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Egress port - A port on a switch where packets are flowing out of the Switch, either to another switch or to an end station, and tagging decisions must be made.
Page 85
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 7- 3. IEEE 802.1Q Tag The EtherType and VLAN ID are inserted after the MAC source address, but before the original EtherType/Length or Logical Link Control. Because the packet is now a bit longer than it was originally, the Cyclic Redundancy Check (CRC) must be recalculated.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Port VLAN ID Packets that are tagged (are carrying the 802.1Q VID information) can be transmitted from one 802.1Q compliant network device to another with the VLAN information intact. This allows 802.1Q VLANs to span network devices (and indeed, the entire network, if all network devices are 802.1Q compliant).
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual same VID) as the ingress port. If it does not, the packet is dropped. If it has the same VID, the packet is forwarded and the destination port transmits it on its attached network segment.
Page 88
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual NOTE: In order to use VLAN segmentation in conjunction with port trunk groups, you can first set the port trunk group(s), and then you may configure VLAN settings. If you wish to change the port trunk grouping with VLANs already in place, you will not need to reconfigure the VLAN settings after changing the port trunk group settings.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Double VLANs Double or Q-in-Q VLANs allow network providers to expand their VLAN configurations to place customer VLANs within a larger inclusive VLAN, which adds a new layer to the VLAN configuration. This basically lets large ISP's create L2 Virtual Private Networks and also create transparent LANs for their customers, which will connect two or more customer LAN points without over-complicating configurations on the client's side.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Customer VLANs using SPVLANs, thus greatly regulating traffic and routing on the Service Provider switch. This information is then routed to the Service Provider’s main network and regarded there as one VLAN, with one set of protocols and one routing behavior.
Page 91
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual NOTE: After all IP interfaces are set for your configurations, VLANs on the switch can be routed without any additional steps. Figure 7- 8. 802.1Q VLAN window – Add/Edit VLAN Tab To return to the 802.1Q VLAN window, click the VLAN List Tab at the top of the window.
Page 92
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual The following fields can then be set in either the Add/Edit VLAN or Edit 802.1Q VLAN windows: Parameter Description VID (VLAN ID) Allows the entry of a VLAN ID, or displays the VLAN ID of an existing VLAN in the Edit window.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 7- 11. 802.1Q VLAN window – VLAN Batch Settings window The following fields can be set in the VLAN Batch Settings windows: Parameter Description VID List (e.g 2-5) Enter a VLAN ID List that can be added, deleted or configured.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual QinQ This function allows the user to enable or disable the QinQ function. QinQ is designed for service providers to carry traffic from multiple users across a network. QinQ is used to maintain customer specific VLAN and Layer 2 protocol configurations even when the same VLAN ID is being used by different customers.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual the packet will be assigned to the PVID of the received port. Outer TPID The Outer TPID is used for learning and switching packets. The Outer TPID constructs and inserts the outer tag into the packet based on the VLAN ID and Inner Priority.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual 802.1v Protocol VLAN 802.1v Protocol Group Settings The table allows the user to create Protocol VLAN groups and add protocols to that group. The 802.1v Protocol VLAN Group Settings supports multiple VLANs for each protocol and allows the user to configure the untagged ports of different protocols on the same physical port.
Page 97
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 7- 15. Protocol VLAN Settings window The following fields can be set: Parameter Description Group ID Click the corresponding radio button to select a previously configured Group ID from the drop- down menu.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual GVRP Settings The table allows the user to determine whether the Switch will share its VLAN configuration information with other GARP VLAN Registration Protocol (GVRP) enabled switches. In addition, Ingress Checking can be used to limit traffic by filtering incoming packets whose PVID do not match the PVID of the port.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Type between Tagged Only, which means only VLAN tagged frames will be accepted, and Admit_All, which mean both tagged and untagged frames will be accepted. Admit_All is enabled by default.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual MAC-based VLAN Settings This table is used to create new MAC Based VLAN entries and search, edit and delete existing entries. To view this window click L2 Features > MAC-based VLAN Settings: Figure 7- 19.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Port Trunking Understanding Port Trunk Groups Port trunk groups are used to combine a number of ports together to make a single high-bandwidth data pipeline. DES-3500 Series supports up to 8 port trunk groups with 2 to 8 ports in each group. A potential bit rate of 8000 Mbps can be achieved.
Page 102
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual same VLAN, and their STP status, static multicast, traffic control; traffic segmentation and 802.1p default priority configurations must be identical. Port locking, port mirroring and 802.1X must not be enabled on the trunk group. Fur- ther, the aggregated links must all be of the same speed and should be configured as full duplex.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual LACP Port Settings The LACP Port Settings window is used to create port trunking groups on the Switch. Using the following window, the user may set which ports will be active and passive in processing and sending LACP control frames.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Traffic Segmentation Traffic segmentation is used to limit traffic flow from a single port to a group of ports on either a single switch or a group of ports on another switch in a switch stack. This method of segmenting the flow of traffic is similar to using VLANs to limit traffic, but is more restrictive.
IGMP messages passing through the Switch. In order to use IGMP Snooping it must first be enabled for the entire Switch (see the DES-3528 Web Management Tool). You may then fine-tune the settings for each VLAN using the IGMP Snooping link in the L2 Features folder.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Query Interval The Query Interval field is used to set the time (in seconds) between transmitting IGMP (1-65535) queries. Entries between 1 and 65535 seconds are allowed. Default = 125.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual VID (2-4094) This is the VLAN ID that, along with the VLAN Name, identifies the VLAN the user wishes to modify the IGMP Snooping Settings for. State Use the drop-down menu to toggle between Enabled and Disabled.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 7- 30. IP Multicast Address Group List Settings – Group List window Enter the multicast Address List starting with the lowest in the range, and click Add. To return to the IP Multicast Profile Settings window, click the <<Back button.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 7- 32. Multicast Filtering Mode window To add a new Multicast Filter enter the information and click Apply, to search for an entry click Search, and to view all the VLANs click the View All button.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual MLD Snooping Settings Multicast Listener Discovery (MLD) Snooping is an IPv6 function used similarly to IGMP snooping in IPv4. It is used to discover ports on a VLAN that are requesting multicast data. Instead of flooding all ports on a selected VLAN with multicast traffic, MLD snooping will only forward multicast data to ports that wish to receive this data through the use of queries and reports produced by the requesting ports and the source of the multicast traffic.
Page 111
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 7- 35. MLD Snooping Settings – Edit Window The following parameters may be viewed or modified: Parameter Description VLAN ID This is the VLAN ID that, along with the VLAN Name, identifies the VLAN for which to modify the MLD Snooping Settings.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual State Used to enable or disable MLD snooping for the specified VLAN. This field is Disabled by default. Querier Router Behavior This read-only field describes the current querier state of the Switch, whether Querier, which will send out Multicast Listener Query Messages to links, or Non- Querier, which will not send out Multicast Listener Query Messages.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Loopback Detection Settings The Loopback Detection function is used to detect the loop created by a specific port. This feature is used to temporarily shutdown a port on the Switch when a CTP (Configuration Testing Protocol) packet has been looped back to the switch.
802.1d STP will be familiar to most networking professionals. However, since 802.1w RSTP has been recently introduced to D-Link managed Ethernet switches, a brief introduction to the technology is provided below followed by a description of how to set up 802.1d STP and 802.1w RSTP.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual P2P Port A P2P port is also capable of rapid transition. P2P ports may be used to connect to other bridges. Under RSTP, all ports operating in full-duplex mode are considered to be P2P ports, unless manually overridden through configuration.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual STP Bridge Global Settings To open the following window, click L2 features > Spanning Tree > STP Bridge Global Settings. Figure 7- 38. STP Bridge Global Settings window...
Page 117
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Max Hops (1-20) Used to set the number of hops between devices in a spanning tree region before the BPDU (bridge protocol data unit) packet sent by the Switch will be discarded. Each switch on the hop count will reduce the hop count by one until the value reaches zero.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual STP Port Settings STP can be set up on a port per port basis. To view the following window click L2 Features > Spanning Tree > STP Port Settings: Figure 7- 39.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Migrate Setting this parameter as Yes will set the ports to send out BPDU packets to other bridges, requesting information on their STP setting If the Switch is configured for RSTP, the port will be capable to migrate from 802.1d STP to 802.1w RSTP.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual The window above contains the following information: Parameter Description Configuration Name A previously configured name set on the Switch to uniquely identify the MSTI (Multiple Spanning Tree Instance). If a configuration name is not set, this field will show the MAC address to the device running MSTP.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 7- 42. STP Instance Settings - View window MSTP Port Information This window displays the current MSTP Port Information and can be used to update the port configuration for an MSTI ID.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Forwarding & Filtering This folder contains windows for Unicast Forwarding and Multicast Forwarding. Unicast Forwarding To view this window, Click L2 Features > Forwarding & Filtering > Unicast Forwarding.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual chosen, the port will not be a member of the Static Multicast Group. Egress - The port is a static member of the multicast group. Click Apply to implement the changes made. To delete an entry in the Static Multicast Forwarding Table, click the corresponding Delete button.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual LLDP Notification LLDP Notification Interval is used to send notifications to configured SNMP trap receiver(s) when Interval (5-3600) an LLDP change is detected in an advertisement received on the port from an LLDP neighbor.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual LLDP Management Address List To view this window, Click L2 Features > LLDP > LLDP Management Address List Figure 7- 48. LLDP Management Address List window The following parameters can be set:...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Parameter Description From Port/To Use the pull-down menu to select a range of ports to be configured. Port Port Description Use the drop-down menu to enable or disable port description.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 7- 52. LLDP Statistics System window LLDP Local Port Information LLDP Local Port Information window displays the information on a per port basis in the local port brief table shown below.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 7- 54. LLDP Local Port Information (Show Normal) window Use the drop-down menu to select a port and click Find the information will be displayed on the lower half of the window.
CoS until there are no more packets for this CoS. The other CoS queues that have been given a nonzero value, and depending upon the weight, will follow a common weighted round-robin scheme. Remember that the xStack DES-3528 has eight priority queues (and eight Classes of Service) for each port on the Switch.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual HOL Blocking Pevention This window is used to enable HOL Prevention Settings on the Switch. To view this table Click QoS > HOL Prevention Settings Figure 8- 2. HOL Prevention Settings window...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Click Apply to set the bandwidth control for the selected ports. Results of configured Bandwidth Settings will be displayed in the Bandwidth Control Table on the lower half of the window.
Page 134
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Parameter Description Traffic Control Settings From Port/To A consecutive group of ports may be configured starting with the selected port. Port Action Select the method of traffic Control from the pull-down menu. The choices are: Drop –...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual NOTE: Ports that are in the Shutdown forever mode will be seen as Discarding in Spanning Tree windows and implementations though these ports will still be forwarding BPDUs to the Switch’s CPU.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual 802.1p User Priority The Switch allows the assignment of a user priority to each of the 802.1p priorities. To view this window click QoS > 802.1p User Priority.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Use the weighted round-robin (WRR) algorithm to handle packets in an even distribution in priority classes of service. Click Apply to implement changes made. NOTE: The settings you assign to the queues, numbers 0-7, represent the IEEE 802.1p priority tag number.
Page 138
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual The following parameters may be set: Parameter Description From port/To port A consecutive group of ports may be configured starting with the selected port. Class ID Select the Class ID, from 0-7, to configure for the SRED parameters. Selecting all will set the parameters configured here for all CoS queues.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual SRED Drop Counter To view this window click QoS > SRED > SRED Drop Counter Figure 8- 9. SRED Drop Counter window DSCP Trust Settings This window is used to enable DSCP Trust Settings.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual DSCP Map Settings This window is used to enable DSCP Map Settings. To view this window click QoS > SRED > DSCP Map Settings Figure 8- 11. DSCP Map Settings window...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual 802.1p Map Settings This window is used to enable 802.1p Map Settings. To view this window click QoS > SRED > 802.1p Map Settings Figure 8- 12. DSCP Map Settings window...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Section 9 Security Safeguard Engine Trusted Host IP-MAC-Port Binding Port Security DHCP Server Screening 802.1X SSL Settings Access Authentication Control MAC-based Access Control Web Authentication JWAC NetBIOS Filtering Settings...
Page 143
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual If the second checking third checking If the fourth interval reveals If the Switch detects interval reveals there are interval reveals there are the packet flooding has too many packets, it...
IP-MAC binding entries is dependant on chip capability (e.g. the ARP table size) and storage size of the device. For the xStack DES-3528 switch, Active and inactive entries use the same database. The maximum entry number is 511. The creation of authorized users can be manually configured by CLI or Web. The...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual IMP Global Settings This window is used to enable or disable the ACL mode, Trap Log State and DHCP Snoop state on the switch. When the user enables the ACL Mode for IP-MAC Binding it will create two Access Profile Entries on the Switch. The Trap/Log field will enable and disable the sending of trap log messages for IP-MAC binding.
Page 146
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 9- 5. IMP Port Settings window The following fields can be set or modified: Parameter Description From Port…To Port Select a port or range of ports to set for IP-MAC Binding.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual trapped by the CPU needs to be forwarded by the software. This setting controls the forwarding behavior in this situation. Max Entry Specifies the maximum number of IP-MAC-Port Binding entries. By default, per port max entry is 5.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual DHCP Snooping Entries This table is used to view dynamic entries on specific ports. To view particular port settings, enter the port number and click Find. To view all entries click View All, and to delete an entry, click Clear.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 9- 9. Port Security Settings window The following parameters can be set: Parameter Description A consecutive group of ports may be configured starting with the selected port.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 9- 10. Port Security FDB Entries window DHCP Server Screening Settings This function allows the user to not only restrict all DHCP Server packets but also to receive any specified DHCP server packet by any specified DHCP client, it is useful when one or more DHCP servers are present on the network and both provide DHCP services to different distinct groups of clients.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual The user may set the following parameters: Parameter Description From Port/To Port A consecutive group of ports may be configured starting with the selected port. State Choose Enabled to enable the DHCP server or Disabled to disable. The default is Disabled.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual 802.1X 802.1x Port-Based and MAC-Based Access Control The IEEE 802.1x standard is a security measure for authorizing and authenticating users to gain access to various wired or wireless devices on a specified Local Area Network by using a Client and Server based access control model.
Page 153
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Authentication Server The Authentication Server is a remote device that is connected to the same network as the Client and Authenticator, must be running a RADIUS Server program and must be configured properly on the Authenticator (Switch). Clients connected to a port on the Switch must be authenticated by the Authentication Server (RADIUS) before attaining any services offered by the Switch on the LAN.
Figure 9- 18. The 802.1x Authentication Process The D-Link implementation of 802.1x allows network administrators to choose between two types of Access Control used on the Switch, which are: 1. Port-Based Access Control – This method requires only one user to be authenticated per port by a remote RADIUS server to allow the remaining users on the same port access to the network.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Understanding 802.1x Port-based and MAC-based Network Access Control The original intent behind the development of 802.1X was to leverage the characteristics of point-to-point in LANs. As any single LAN segment in such infrastructures has no more than two devices attached to it, one of which is a Bridge Port.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual 802.1X Force Disconnect To configure the 802.1X Force Disconnect, click Security > 802.1X > 802.1X Force Disconnect Figure 9- 21. 802.1X Force Disconnect window Use the drop down menu to select either Port or MAC Address and enter the corresponding information, click Force Disconnect for the changes to take effect.
Page 158
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual QuietPeriod This allows you to set the number of seconds that the Switch remains in the quiet state following (0-65535) a failed authentication exchange with the client. The default setting is 60 seconds.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual 802.1X User To create a new 802.1X User enter a user name and password then reconfirm the password and click Apply, the new user will be displayed in the lower half of the table. To delete an entry click the corresponding Delete button.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Initialize Port(s) This window allows you to initialize ports for the 802.1X Settings. This window will appear in the folder when the “enable 802.1x” command is entered into the command line interface.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Guest VLAN On 802.1x security enabled networks, there is a need for non 802.1x supported devices to gain limited access to the network, due to lack of the proper 802.1x software or incompatible...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Guest VLAN Configuration To view the following window click, Security > 802.1X > Guest VLAN Figure 9- 28. Guest VLAN window The following fields may be modified to enable the 802.1x Guest VLAN:...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual These three parameters are uniquely assembled in four choices on the Switch to create a three-layered encryption code for secure communication between the server and the host. The user may implement any one or combination of the ciphersuites available, yet different ciphersuites will affect the security level and the performance of the secured connection.
Page 164
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Cache Timeout This field will set the time between a new key exchange between a client and a host using (60-86400) the SSL function. A new SSL session is established every time the client and host go through a key exchange.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual SSH is an abbreviation of Secure Shell, which is a program allowing secure remote login and secure network services over an insecure network. It allows a secure login to remote host computers, a safe method of executing commands on a remote end node, and will provide secure encrypted and authenticated communication between two non-trusted hosts.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual security shell encryptions. The available options are Never, 10 min, 30 min, and 60 min. The default setting is Never. Click Apply to implement changes made. SSH Authmode and Algorithm Settings The SSH Algorithm window allows the configuration of the desired types of SSH algorithms used for authentication encryption.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Cast128-CBC Use the pull-down to enable or disable the Cast128 encryption algorithm with Cipher Block Chaining. The default is enabled. Twofish128 Use the pull-down to enable or disable the twofish128 encryption algorithm. The default is enabled.
Page 168
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual SSH server for authentication purposes. Choosing this parameter requires the user to input the following information to identify the SSH user. Host Name – Enter an alphanumeric string of no more than 31 characters to identify the remote SSH user.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Access Authentication Control The TACACS/XTACACS/TACACS+/RADIUS commands allow users to secure access to the Switch using the TACACS/XTACACS/TACACS+/RADIUS protocols. When a user logs in to the Switch or tries to access the administrator level privilege, he or she is prompted for a password.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Authentication Policy Settings This command will enable an administrator-defined authentication policy for users trying to access the Switch. When enabled, the device will check the Login Method List and choose a technique for user authentication upon login.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Login Method List Using the pull-down menu, configure an application for normal login on the user level, utilizing a previously configured method list. The user may use the default Method List or other Method List configured by the user.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 9- 37. Authentication Server Group Settings Edit window To add an Authentication Server Host to the list, enter its IP address in the IP Address field, choose the protocol associated with the IP address of the Authentication Server Host and click Add to add this Authentication Server Host to the group.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Configure the following parameters to add an Authentication Server Host: Parameter Description IP Address The IP address of the remote server host the user wishes to add. Port (1-65535) Enter a number between 1 and 65535 to define the virtual port number of the authentication protocol on a server host.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 9- 39. Login Method Lists window The Switch contains one Method List that is set and cannot be removed, yet can be modified. To delete a Login Method List defined by the user, click the corressponding Delete button.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 9- 40. Enable Method List window To delete an Enable Method List defined by the user, click the the Delete button. To modify an Enable Method List, click on its corresponding Edit button.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual To set the Local Enable Password, set the following parameters and click Apply. Parameter Description Old Local Enable If a password was previously configured for this entry, enter it here in order to change it to...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual MAC-Based Access Control The MAC-Based Access Control feature will allow users to configure a list of MAC addresses, either locally or on a remote RADIUS server, to be authenticated by the Switch and given access rights based on the configurations set on the Switch of the target VLAN where these authenticated users are placed.
Page 178
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 9- 43. MAC Based Access Control Settings The following parameters may be viewed or set: Parameter Description Settings State Use the pull-down menu to globally enable or disable the MAC-Based Access Control function on the Switch.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Guest VLAN Member Ports Displays the list of ports that have been configured for the Guest VLAN. Port Settings From Port/To Port Enter the Port range. State Use the pull-down menu to enable or disable the MAC-Based Access Control function on individual ports.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Web Authentication Web-based Access Control is another port based access control method implemented similarily to the 802.1x port based access control method previously stated. This function will allow user...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual 6. If a RADIUS server is to be used for authentication, the user must first establish a RADIUS Server with the appropriate parameters, including the target VLAN, before enabling the Web-based Access Control on the Switch.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual RADIUS server. This VLAN should be pre-configured to have limited access rights to web based authenticated users. Enter the URL of the website that authenticated users placed in the VLAN are directed to once Redirection Page authenticated.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual have selected local as their web based authenticator. Confirmation Re-enter the password. User-VLAN Mapping User Name Enter the user name of a guest authenticated through this process, to be mapped to a previously configured VLAN with limited rights.
Page 184
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual HTTPs Ports This parameter specifies the TCP port that the JWAC Switch listens to and uses to finish the (1-65535) authentication process. This parameter enables or disables JWAC UDP Filtering. When UDP Filtering is Enabled, all...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual JWAC Port Settings To view JWAC port settings for the Switch, click Security > JWAC > JWAC Port Settings. Figure 9- 48. JWAC Port Settings window To set the JWAC on individual ports for the Switch, complete the following fields:...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual JWAC User Account To view JWAC user settings for the Switch, go to the Security > JWAC > JWAC User Account Figure 9- 49. JWAC User Settings window...
Page 187
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 9- 50. NetBIOS Filtering Settings window...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Section 10 ACL Configuration Wizard Access Profile List CPU Access Profile List ACL Finder ACL Flow Meter Access profiles allow you to establish criteria to determine whether or not the Switch will forward packets based on the information contained in each packet's header.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual From Use the drop-down menu to select from MAC Address, IPv4 Address or IPv6. Use the drop-down menu to select from MAC Address, IPv4 Address or IPv6. When IPv6 is selected the user can only enter the IPv6 source address or the IPv6 destination address at any one time.
Page 190
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 10- 3. Add Access Profile (Ethernet) If creating an Ethernet ACL enter the Profile ID and Profile Name and click Select the following window will appear.
Page 191
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 10- 4. Add Ethernet ACL Profile window Click on the boxes at the top of the table, which will then turn red and reveal parameters for configuration. To create a new entry enter the correct information and click Create.
Page 192
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual 802.1p Selecting this option instructs the Switch to examine the 802.1p priority value of each packet header and use this as the, or part of the criterion for forwarding.
Page 193
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 10- 7. Access Profile Ethernet To set the Access Rule for Ethernet, adjust the following parameters and click Apply. Parameter Description Access ID (1-128) Type in a unique identifier number for this access. This value can be set from 1 to 128.
Page 194
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Precedence header. VLAN Name Allows the entry of a name for a previously configured VLAN. 802.1p (0-7) Enter a value from 0 to 7 to specify that the access profile will apply only to packets with this 802.1p priority value.
Page 195
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 10- 10. Add IPv4 ACL Profile Click on the boxes at the top of the table, which will then turn red and reveal parameters for configuration. To create a new entry enter the correct information and click Create.
Page 196
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual (IGMP) field in each frame's header. Select Type to further specify that the access profile will apply an IGMP type value Select TCP to use the TCP port number contained in an incoming packet as the forwarding criterion.
Page 197
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 10- 12. Access Profile Details (IPv4) To return to the Access Profile List click Show All Profiles, to add a rule to a previously configured entry click on the corresponding Add/View Rules, which will reveal the following window.
Page 198
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual its incoming 802.1p user priority re-written to its original value before being forwarded by the Switch. Replace Priority Enter a replace priority manually if you want to re-write the 802.1p default priority of a packet to the value entered in the Priority field, which meets the criteria specified previously in this command, before forwarding it on to the specified CoS queue.
Page 199
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 10- 16. Add IPv6 ACL Profile Click on the boxes at the top of the table, which will then turn red and reveal parameters for configuration. To create a new entry enter the correct information and click Create.
Page 200
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 10- 17. Access Profile List (IPv6) To view the configurations for previously configured entry click on the corresponding Show Details Button which will display the following window.
Page 201
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 10- 19. Access Profile (IPv6) The following parameters may be configured for the IP (IPv4) filter. Parameter Description Access ID (1-128) Type in a unique identifier number for this access. This value can be set from 1 to 128.
Page 202
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Precedence bits field in IPv4. Rx Rate (1-15624) Use this to limit Rx bandwidth for the profile being configured. This rate is implemented using the following equation: 1 value = 64kbit/sec. (ex. If the user selects an Rx rate of 10 then the ingress rate is 640kbit/sec.) The user many select a value between 1 and 15624 or...
Page 203
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 10- 22. Add Packet Content ACL Profile Click on the boxes at the top of the table, which will then turn red and reveal parameters for configuration. To create a new entry enter the correct information and click Create.
Page 204
With this advanced unique Packet Content Mask (also known as Packet Content Access Control List - ACL), the D-Link xStack switch family can effectively mitigate some network attacks like the common ARP Spoofing attack that is wide spread today. This is why the Packet Content ACL is able to inspect any specified content of a packet in different protocol layers.
Page 205
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 10- 2 . Access Profile (Packet Content) The following parameters may be configured for the Packet Content filter. Parameter Description Access ID (1-128) Type in a unique identifier number for this access. This value can be set from 1 to 128.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual tick the No Limit check box. The default setting is No Limit. Tick the check box and enter the name of the Time Range settings that has been previously Time Range Name configured in the Time Range Settings window.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual CPU Access Profile List In the following window, the user may globally enable or disable the CPU Interface Filtering State mechanism by using the radio buttons to change the running state.
Page 208
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 10- 2 . Add CPU ACL Profile window for Ethernet Parameter Description Select Profile ID Use the drop-down menu to select a unique identifier number for this profile set. This value can (1-5) be set from 1 to 5.
Page 209
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 10- 3 . CPU Access Profile Detail Information window for Ethernet The window shown below is the Add CPU ACL Profile window for IP (IPv4). Figure 10- 31. Add CPU ACL Profile window for IP (IPv4) The following parameters may be configured for the IP (IPv4) filter.
Page 210
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Source IP Mask Enter an IP address mask for the source IP address. Destination IP Mask Enter an IP address mask for the destination IP address. Selecting this option instructs the Switch to examine the protocol type value in each frame's Protocol header.
Page 211
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 10- 33. Add CPU ACL Profile window for IPv6 The following parameters may be configured for the IPv6 filter. Parameter Description Select Profile ID Use the drop-down menu to select a unique identifier number for this profile set. This value can be set from 1 to 5.
Page 212
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Click Apply to set this entry in the Switch’s memory. To view the settings of a previously correctly created profile, click the corresponding Show Details button on the CPU Access Profile List window to view the following window: Figure 10- 3 .
Page 213
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Offset This field will instruct the Switch to mask the packet header beginning with the offset value specified: • 0-15 - Enter a value in hex form to mask the packet from the beginning of the packet to the 15th byte.
Page 214
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 10- 3 . Add Access Rule window for Ethernet To set the Access Rule for Ethernet, adjust the following parameters and click Apply. Parameter Description Access ID (1-100) Type in a unique identifier number for this access.
Page 215
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual To establish the rule for a previously created CPU Access Profile: To configure the Access Rules for IP, open the CPU Access Profile List window and click Add/View Rules for an IP entry.
Page 216
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual To view the settings of a previously correctly configured rule, click the corresponding Show Details button on the CPU Access Rule List window to view the following window: Figure 10- 42.
Page 217
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual To set the Access Rule for IPv6, adjust the following parameters and click Apply. Parameter Description Access ID (1-100) Type in a unique identifier number for this access. This value can be set from 1 to 100.
Page 218
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 10- 47. Add Access Rule window for Packet Content To set the Access Rule for Packet Content, adjust the following parameters and click Apply. Parameter Description Access ID (1-100) Type in a unique identifier number for this access.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 10- 48. CPU Access Rule Detail Information window for Packet Content ACL Finder This window is used to help find a previously configured ACL entry. To search for an entry, enter the profile ID from the drop down menu, select a port that you wish to view, define the state and click Find, the table on the lower half of the screen will display the entries.
Page 220
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 10- 5 . ACL Flow Meter - Add window The following fields may be configured: Parameter Description Use the drop down menu to select the pre-configured Profile ID that will be used to configure the Profile ID Flow Metering parameters.
Page 221
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Action Conform – Specifies the action when the packet is in “green color” mode. • Permit – Permits the packet. • Replace dscp – Change the dscp of the packet Exceed –...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Section 11 Monitoring Device Status CPU Utilization Port Utilization Packet Size Packets Errors Port Access Control Browse ARP Table Browse VLAN Show VLAN Ports Browse Router Port Browse MLD Router Port...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 11- 2. CPU Utilization window To view the CPU utilization by port, use the real-time graphic of the Switch and/or switch stack at the top of the web page by simply clicking on a port.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 11- 3. Port Utilization window To select a port to view these statistics for, select the port by using the Port pull-down menu. The user may also use the real-time graphic of the Switch at the top of the web page by simply clicking on a port.
Page 225
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 11- 4. Packet Size window To view the Packet Size Table window, click the link View Table, which will show the following table: Figure 11- 5. Packet Size Table window...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual The total number of packets (including bad packets) received that were 64 octets in length (excluding framing bits but including FCS octets). The total number of packets (including bad packets) received that were between 65 and 65-127 127 octets in length inclusive (excluding framing bits but including FCS octets).
Page 227
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 11- 6. Received (RX) window (for Bytes and Packets) To view the Received (RX) Table window, click View Table. Figure 11- 7. Received (RX) Table window (for Bytes and Packets)
Page 228
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual value is one second. Record Number Select number of times the Switch will be polled between 20 and 200. The default value is 200. Bytes Counts the number of bytes received on the port.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual UMB_cast (RX) This table displays the UMB_cast RX Packets on the Switch. To select a port to view these statistics for, select the port by using the Port pull-down menu. The user may also use the real-time graphic of the Switch at the top of the web page by simply clicking on a port.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual The following fields may be set or viewed: Parameter Description Port Use the drop-down menu to choose the port that will display statistics. Select the desired setting between 1s and 60s, where "s" stands for seconds. The default Time Interval value is one second.
Page 231
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual To view the Transmitted (TX) Table window, click the link View Table. Figure 11- 1 . Transmitted (TX) Table window (for Bytes and Packets) The following fields may be set or viewed:...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Errors The Web Manager allows port error statistics compiled by the Switch's management agent to be viewed as either a line graph or a table. Four windows are offered.
Page 233
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 11- 1 . Received (RX) Table window (for errors) The following fields can be set: Parameter Description Port Use the drop-down menu to choose the port that will display statistics.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual View Table Clicking this button instructs the Switch to display a table rather than a line graph. View Graphic Clicking this button instructs the Switch to display a line graph rather than a table.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 11- 1 . Transmitted (TX) Table window (for errors) The following fields may be set or viewed: Parameter Description Port Use the drop-down menu to choose the port that will display statistics.
Page 236
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 11- 1 . RADIUS Authentication window The user may also select the desired time interval to update the statistics, between 1s and 60s, where “s” stands for seconds.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Signature attributes received from this server. PendingRequests The number of RADIUS Access-Request packets destined for this server that have not yet timed out or received a response. This variable is incremented when an Access- Request is sent and decremented due to receipt of an Access-Accept, Access-Reject or Access-Challenge, a timeout or retransmission.
Page 238
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual shares a secret. ServerPortNumber The UDP port the client is using to send requests to this server. ClientRoundTripTime The time interval between the most recent Accounting-Response and the Accounting-Request that matched it from this RADIUS accounting server.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Authenticator State The following section describes the 802.1X Status on the Switch. To view the Authenticator State, click Monitoring > Port Access Control > Authenticator State. Figure 11- 18. Authenticator State window (for MAC-based 802.1X)
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 11- 1 . Authenticator State window (for Port-based 802.1X) This window displays the Authenticator State for individual ports on a selected device. A polling interval between 1s and 60s seconds can be set using the drop-down menu at the top of the window and clicking OK.
Page 241
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 11- 20. Authenticator Statistics window The user may also select the desired time interval to update the statistics, between 1s and 60s, where “s” stands for seconds. The default value is one second.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Authenticator Session Statistics This window contains the session statistics objects for the Authenticator PAE associated with each port. An entry appears in this table for each port that supports the Authenticator function.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual System. Time The duration of the session in seconds. Terminate Cause The reason for the session termination. There are eight possible reasons for termination. 1) Supplicant Logoff 2) Port Failure...
Page 244
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual The following fields can be viewed: Parameter Description Port The identification number assigned to the Port by the System in which the Port resides. Connect Enter Counts the number of times that the state machine transitions to the CONNECTING state from any other state.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Bac Auth Success Counts the number of times that the state machine receives an Accept message from the Authentication Server (i.e., aSuccess becomes TRUE, causing a transition from RESPONSE to SUCCESS).
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Show VLAN Ports This window allows the VLAN status for each of the Switch's ports to be viewed by VLAN. Enter a VID (VLAN ID) in the field at the top of the window and click the Find button.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Browse Session Table This window displays the management sessions since the Switch was last rebooted. To view the Browse Session Table window, click Monitoring > Browse Session Table.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual MLD Snooping Group The following window allows the user to view MLD Snooping Groups present on the Switch. MLD Snooping is an IPv6 function comparable to IGMP Snooping for IPv4. The user may browse this table by VLAN Name present in the Switch by entering that VLAN Name in the empty field shown below, and clicking the Find button.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual MAC Address Table This allows the Switch's dynamic MAC address forwarding table to be viewed. When the Switch learns an association between a MAC address and a port number, it makes an entry into its forwarding table. These entries are then used to forward packets through the Switch.
Page 250
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure 11- 3 . System Log window The Switch can record event information in its own logs, to designated SNMP trap receiving stations, and to the PC connected to the console manager. Click Next to go to the next page of the System Log window. Clicking Clear will allow the user to clear the Switch History Log.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Section 12 Save Services and Tools Save Configuration ID 1 Save Configuration ID 2 Save Log Save All Configuration File Backup & Restore Upload Log File Reset Download Firmware Reboot System The four Save windows include: Save Configuration 1, Save Configuration 2, Save Log, and Save All.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Save Configuration ID 2 Open the Save drop-down menu at the top of the Web manager and click Save Configuration ID 2 to open the following window: Figure 12- 2. Save Configuration ID 2 window...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Configuration File Backup & Restore The Switch supports dual image storage for configuration file backup and restoration. The firmware and configuration images are indexed by ID number 1 or 2. To change the boot firmware image, use the Configuration ID drop-down menu to select the desired configuration file to backup or restore.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Download Firmware The following window is used to download firmware for the Switch. Figure 12- 8. Download Firmware window Enter the Server IP address in the first field and and specify the path/file name of the firmware in the second field.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Appendix A Technical Specifications General IEEE 802.3 10BASE-T Ethernet Protocols IEEE 802.3u 100BASE-TX Fast Ethernet IEEE 802.3ab 1000BASE-T Gigabit Ethernet IEEE 802.3z Gibabit Ethernet. (SFP “Mini GBIC”) IEEE 802.1D Spanning Tree IEEE 802.1D/S/W Spanning Tree...
Page 256
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Physical and Environmental Input: Internal Power Supply 100~240V, AC/1.5A, 50~60Hz Output: 12V, 5A (Max) Power Consumption Max. 20.5 watts Operating Temperature 0 - 45°C Storage Temperature -40 - 70°C Humidity Operation Relative Humidity: 20 - 80% non-condensing.
Page 257
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual When there is reception or transmission Blinking Amber (i.e. Activity—Act) of data occurring at an Ethernet connected port. Light off No link When there is a secure 1000Mbps Solid Green connection (or link) at any of the ports.
Page 258
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Feature Detailed Description DCE RS-232 DB-9 for out-of-band configuration of the software features. Console Port Compliant to following standards: • IEEE 802.3 compliance • IEEE 802.3u compliance 24 x 10/100BaseT ports •...
Page 259
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual 1000BASE-T ports compliant to following standards: • IEEE 802.3 compliance • IEEE 802.3u compliance 2 1000BASE-T ports in the rear • IEEE 802.3ab compliance panel • Support Full-Duplex operations •...
IP address is known. This protocol is vulnerable because it can spoof the IP and MAC information in the ARP packets to attack a LAN (known as ARP spoofing). This document is intended to introduce ARP protocol, ARP spoofing attacks, and the counter measure brought by D-Link's switches to counter the ARP spoofing attack. •...
Page 261
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Destination Source address Ether-type address FF-FF-FF-FF-FF-FF 00-20-5C-01-11-11 Table-2 (Ethernet frame format) When the switch receives the frame, it will check the “Source Address” in the Ethernet frame’s header. If the address is not in its Forwarding Table, the switch will learn PC A’s MAC and the associated port into its Forwarding Table.
Page 262
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Figure-3 When PC B replies to the ARP request, its MAC address will be written into “Target H/W Address” in the ARP payload shown in Table-3. The ARP reply will be then encapsulated into the Ethernet frame again and sent back to the sender.
Page 263
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual How ARP spoofing attacks a network ARP spoofing, also known as ARP poisoning, is a method to attack an Ethernet network which may allow an attacker to sniff data frames on a LAN, modify the traffic, or stop the traffic altogether (known as a Denial of Service - DoS attack).
Page 264
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Gratuitous ARP Ethernet Header Destination Source Ethernet H/W type Protocol Protocol Operation Sender H/W Sender Target H/W Target address address type type address address address protocol address protocol...
Page 265
2. The switch will deny all other ARP packets which claim they are from the gateway’s IP. The design of Packet Content ACL on DES-3528 series enables users to inspect any offset_chunk. An offset_chunk is a 4-byte block in a HEX format which is utilized to match the individual field in an Ethernet frame. Each profile is allowed to contain up to a maximum of 4 offset_chunks.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Appendix C System Log Entries The following table lists all possible entries and their corresponding meanings that will appear in the System Log of this Switch. Event Category...
Page 269
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Log message upload Log message upload by console was Warning was unsuccessful unsuccessful! (Username: <username>) Interface Port link up Port <unitID:portNum> link up, <link state> Informational Port link down Port <unitID:portNum>...
Page 270
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual BPDU Loop Back on BPDU Loop Back on Port <unitID:portNum> Warning port Spanning Tree Spanning Tree Protocol is enabled Informational Protocol is enabled Spanning Tree Spanning Tree Protocol is disabled...
Page 271
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Successful login Successful login through Telnet from <userIP> Informational through Telnet authenticated by AAA local method (Username: authenticated by AAA <username>, MAC: <macaddr>) local method Login failed through Login failed through Telnet from <userIP>...
Page 272
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Successful login Successful login through Web(SSL) from Informational through Web(SSL) <userIP> authenticated by AAA server authenticated by AAA <serverIP> (Username: <username>, MAC: server <macaddr>) Login failed through Login failed through Web(SSL) from <userIP>...
Page 273
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Enable Admin failed Enable Admin failed through Telnet from Warning through Telnet <userIP> authenticated by AAA local_enable authenticated by AAA method (Username: <username>, MAC: local_enable method <macaddr>) Successful Enable...
Page 274
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Enable Admin failed Enable Admin failed through Telnet from Warning through Telnet <userIP> authenticated by AAA server authenticated by AAA <serverIP> (Username: <username>, MAC: server <macaddr>) Successful Enable...
Page 275
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual user due to AAA configuration (Username: <username>,MAC: server timeout or <mac>) improper configuration. Login failed through Login failed through SSH from <userIP> due to Warning SSH from user due to...
Page 276
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual IP-MAC- Unauthenticated ip Unauthenticated IP-MAC address and Warning PORT address and discard discarded by ip mac port binding (IP: <ipaddr>, Binding by ip mac port binding MAC: <macaddr>, Port <portNum>)
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Appendix D Cable Lengths Use the following table to as a guide for the maximum cable lengths. Standard Media Type Maximum Distance 1000BASE-LX, Single-mode fiber module 10km 1000BASE-SX, Multi-mode fiber module...
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Appendix E Glossary 1000BASE-SX: A short laser wavelength on multimode fiber optic cable for a maximum length of 2000 meters 1000BASE-LX: A long wavelength for a "long haul" fiber optic cable for a maximum length of 10 kilometers 1000BASE-T: 1000Mbps Ethernet implementation over Category 5E cable.
Page 279
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual half duplex: A system that allows packets to be transmitted and received, but not at the same time. Contrast with full duplex. IP address: Internet Protocol address. A unique identifier for a device attached to a network using TCP/IP. The address is written as four octets separated with full-stops (periods), and is made up of a network section, an optional subnet section and a host section.
Page 280
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual UDP - User Datagram Protocol: An Internet standard protocol that allows an application program on one device to send a datagram to an application program on another device.
Page 281
The customer must submit with the product as part of the claim a written description of the Hardware defect or Software nonconformance in sufficient detail to allow D-Link to confirm the same, along with proof of purchase of the product (such as a copy of the dated purchase invoice for the product) if the product is not registered.
Page 282
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual charges shall be prepaid by D-Link if you use an address in the United States, otherwise we will ship the product to you freight collect. Expedited shipping is available upon request and provided shipping charges are prepaid by the customer.
DES-3528 Series Layer 2 Stackable Fast Ethernet Managed Switch User Manual Product Registration Register your D-Link product online at http://support.dlink.com/register/ Product registration is entirely voluntary and failure to complete or return this form will not diminish your warranty rights.
Page 284
Warranty terms for D-LINK xStack products: All D-Link xStack products* are supplied with a 5 year warranty as standard. To enable the Limited Lifetime Warranty on this product you must register the product, within the first three months of purchase**, on the following website: http://www.dlink.biz/productregistration/...
Page 285
To the extent allowed by local law, the remedies in this warranty statement are customer’s sole and exclusive remedies. Except as indicated above, in no event will D-Link or its suppliers be liable for loss of data or for indirect, special, incidental, consequential (including lost profit or data), or other damage, whether based in a contract, tort, or otherwise.
Such repair or replacement will be rendered by D-Link at an Authorized D-Link Service Office. The replacement Hardware need not be new or of an identical make, model or part; D-Link may in its discretion may replace the defective Hardware (or any part thereof) with any reconditioned product that D-Link reasonably determines is substantially equivalent (or superior) in all material respects to the defective Hardware.
Page 287
Registration Card. The Registration Card provided at the back of this manual must be completed and returned to an Authorized D-Link Service Office for each D-Link product within ninety (90) days after the product is purchased and/or licensed. The addresses/telephone/fax list of the nearest Authorized D-Link Service Office is provided in the back of this manual.
RELATING TO WARRANTY SERVICE, OR ARISING OUT OF ANY BREACH OF THIS LIMITED WARRANTY, EVEN IF D-LINK HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. THE SOLE REMEDY FOR A BREACH OF THE FOREGOING LIMITED WARRANTY IS REPAIR, REPLACEMENT OR REFUND OF THE DEFECTIVE OR NON-CONFORMING PRODUCT.
Tech Support Technical Support You can find software updates and user documentation on the D-Link website. D-Link provides free technical support for customers within the United States and within Canada for the duration of the service period, and warranty confirmation service, during the warranty period on this product.
Page 290
Technical Support You can find software updates and user documentation on the D-Link websites. If you require product support, we encourage you to browse our FAQ section on the Web Site before contacting the Support line. We have many FAQ’s which we hope will provide you a speedy resolution for your problem.
Page 291
Technische Unterstützung Aktualisierte Versionen von Software und Benutzerhandbuch finden Sie auf der Website von D-Link. D-Link bietet kostenfreie technische Unterstützung für Kunden innerhalb Deutschlands, Österreichs, der Schweiz und Osteuropas. Unsere Kunden können technische Unterstützung über unsere Website, per E-Mail oder telefonisch anfordern.
Vous trouverez la documentation et les logiciels les plus récents sur le site web D-Link. Vous pouvez contacter le service technique de D-Link par notre site internet ou par téléphone. Assistance technique D-Link par téléphone: 0 820 0803 03 0,12 €/min...
Page 293
Puede encontrar las últimas versiones de software así como documentación técnica en el sitio web de D-Link. D-Link ofrece asistencia técnica gratuita para clientes residentes en España durante el periodo de garantía del producto. Asistencia Técnica de D-Link por teléfono: +34 902 30 45 45 0,067 €/min...
Page 294
Supporto tecnico Gli ultimi aggiornamenti e la documentazione sono disponibili sul sito D-Link. Supporto Tecnico dal lunedì al venerdì dalle ore 9.00 alle ore 19.00 con orario continuato Telefono: 199400057 Web: http://www.dlink.it/support...
Page 295
Technical Support You can find software updates and user documentation on the D-Link website. D-Link provides free technical support for customers within Benelux for the duration of the warranty period on this product. Benelux customers can contact D-Link technical support through our website, or by phone.
Pomoc techniczna Najnowsze wersje oprogramowania i dokumentacji użytkownika można znaleźć w serwisie internetowym firmy D-Link. D-Link zapewnia bezpłatną pomoc techniczną klientom w Polsce w okresie gwarancyjnym produktu. Klienci z Polski mogą się kontaktować z działem pomocy technicznej firmy D-Link za pośrednictwem Internetu lub telefonicznie.
Page 297
Technická podpora Aktualizované verze software a uživatelských příruček najdete na webové stránce firmy D-Link. D-Link poskytuje svým zákazníkům bezplatnou technickou podporu Zákazníci mohou kontaktovat oddělení technické podpory přes webové stránky, mailem nebo telefonicky Telefon: 225 281 553 Land Line 1,78 CZK/min - Mobile 5.40 CZK/min Telefonická...
Page 298
Technikai Támogatás Meghajtó programokat és frissítéseket a D-Link Magyarország weblapjáról tölthet le. Tel: 06 1 461-3001 Fax: 06 1 461-3004 Land Line 14,99 HUG/min - Mobile 49.99,HUF/min Web: http://www.dlink.hu E-mail: support@dlink.hu...
Page 299
Teknisk Support Du kan finne programvare oppdateringer og bruker dokumentasjon på D-Links web sider. D-Link tilbyr sine kunder gratis teknisk support under produktets garantitid. Kunder kan kontakte D-Links teknisk support via våre hjemmesider, eller på tlf. D-Link Teknisk telefon Support:...
Page 300
Teknisk Support Du finder software opdateringer og bruger- dokumentation på D-Link’s hjemmeside. D-Link tilbyder gratis teknisk support til kunder i Danmark i hele produktets garantiperiode. Danske kunder kan kontakte D-Link’s tekniske support via vores hjemmeside eller telefonisk. D-Link teknisk support over telefonen: Tlf.
Page 301
Teknistä tukea asiakkaille Suomessa D-Link tarjoaa teknistä tukea asiakkailleen. Tuotteen takuun voimassaoloajan. Tekninen tuki palvelee seuraavasti: numerosta : 0800-114 677 Arkisin klo. 9 - 21 Internetin kautta: Web: http://www.dlink.fi...
Page 302
Teknisk Support På vår hemsida kan du hitta mer information om mjukvaru uppdateringar och annan användarinformation. D-Link tillhandahåller teknisk support till kunder i Sverige under hela garantitiden för denna produkt. D-Link Teknisk Support via telefon: 0770-33 00 35 Vardagar 08.00-20.00 D-Link Teknisk Support via Internet: Web: http://www.dlink.se...
Page 303
Você pode encontrar atualizações de software e documentação de utilizador no site de D-Link Portugal http://www.dlink.pt. A D-Link fornece suporte técnico gratuito para clientes no Portugal durante o período de vigência de garantia deste produto. Assistência Técnica da D-Link na Internet: Web: http://www.dlink.pt...
Page 304
Τεχνική Υποστήριξη Μπορείτε να βρείτε software updates και πληροφορίες για τη χρήση των προϊόντων στις ιστοσελίδες της D-Link Η D-Link προσφέρει στους πελάτες της δωρεάν υποστήριξη στον Ελλαδικό χώρο Μπορείτε να επικοινωνείτε µε το τµήµα τεχνικής υποστήριξης µέσω της ιστοσελίδας ή µέσω τηλεφώνου...
Page 305
Tehnička podrška Hvala vam na odabiru D-Link proizvoda. Za dodatne informacije, podršku i upute za korištenje uređaja, molimo vas da posjetite D-Link internetsku stranicu na www.dlink.eu Web: www.dlink.biz/hr...
Page 306
Tehnična podpora Zahvaljujemo se vam, ker ste izbrali D-Link proizvod. Za vse nadaljnje informacije, podporo ter navodila za uporabo prosimo obiščite D-Link - ovo spletno stran www.dlink.eu Web: www.dlink.biz/sl...
Page 307
Suport tehnica Vă mulţumim pentru alegerea produselor D-Link. Pentru mai multe informaţii, suport şi manuale ale produselor vă rugăm să vizitaţi site-ul D- Link www.dlink.eu Web: www.dlink.ro...
Page 308
Technical Support You can find software updates and user documentation on the D-Link website. Tech Support for customers in Australia: Tel: 1300-766-868 Monday to Friday 8:00am to 8:00pm EST Saturday 9:00am to 1:00pm EST http://www.dlink.com.au e-mail: support@dlink.com.au India: Tel: 1800-222-002 Monday to Friday 9:30AM to 7:00PM http://www.dlink.co.in/support/productsupport.aspx...
Page 309
Technical Support You can find software updates and user documentation on the D-Link website. Tech Support for customers in Egypt: Tel: +202-2919035 or +202-2919047 Sunday to Thursday 9:00am to 5:00pm http://support.dlink-me.com e-mail: amostafa@dlink-me.com Iran: Tel: +98-21-88822613 Sunday to Thursday 9:00am to 6:00pm http://support.dlink-me.com...
Page 310
Техническая поддержка Обновления программного обеспечения и документация доступны на Интернет-сайте D-Link. D-Link предоставляет бесплатную поддержку для клиентов в течение гарантийного срока. Клиенты могут обратиться в группу технической поддержки D-Link по телефону или через Интернет. Техническая поддержка D-Link: +495-744-00-99 Техническая поддержка через Интернет...
Page 311
El servicio de soporte técnico tiene presencia en numerosos países de la Región Latino América, y presta asistencia gratuita a todos los clientes de D-Link, en forma telefónica e internet, a través de la casilla soporte@dlinkla.com Soporte Técnico Help Desk Argentina: Teléfono: 0800-12235465 Lunes a Viernes 09:00 am a 22:00 pm...
Page 312
Você pode encontrar atualizações de software e documentação de usuário no site da D-Link Brasil www.dlinkbrasil.com.br. A D-Link fornece suporte técnico gratuito para clientes no Brasil durante o período de vigência da garantia deste produto. Suporte Técnico para clientes no Brasil: Telefone São Paulo +11-2185-9301...
Page 314
Dukungan Teknis Update perangkat lunak dan dokumentasi pengguna dapat diperoleh pada situs web D-Link. Dukungan Teknis untuk pelanggan: Dukungan Teknis D-Link melalui telepon: Tel: +62-21-5731610 Dukungan Teknis D-Link melalui Internet: Email : support@dlink.co.id Website : http://support.dlink.co.id...
8. What category best describes your company? Aerospace Engineering Education Finance Hospital Legal Insurance/Real Estate Manufacturing Retail/Chainstore/Wholesale Government Transportation/Utilities/Communication System house/company Other________________________________ 9. Would you recommend your D-Link product to a friend? Don't know yet 10. Your comments on this product?_________________________________________________________...