Korenix JetNet 5428G Series Rackmount Managed Ethernet Switch User Manual Version 1.0 November, 2015 www.korenix.com...
Page 2
Korenix JetNet 5428G Series Rackmount Managed Ethernet Switch User’s Manual Copyright Notice Copyright 2006-2015 Korenix Technology Co., Ltd. All rights reserved. Reproduction in any form or by any means without permission is prohibited.
Page 3
Federal Communications Commission (FCC) Statement This equipment has been tested and found to comply with the limits for a Class A digital device, pursuant to Part 15 of the FCC Rules. These limits are designed to provide reasonable protection against harmful interference when the equipment is operated in a commercial environment.
Index Introduction ......................2 Overview ....................2 Major Features ................... 3 Package List ....................3 Hardware Installation .....................5 Hardware Introduction ................5 Wiring Power Inputs .................. 7 Wiring Digital Output ................8 Wiring Earth Ground ................. 8 Wiring Fast Ethernet Ports ................. 9 Wiring Fiber Ports ..................
Page 5
Korenix SFP family ................155 Korenix Private MIB................157 Revision History ..................158 About Korenix ..................159...
The JetNet 5428G Series, the 19-inch 24+4G Managed Ethernet Ring Switch includes JetNet 5428G-AC and JetNet 5428G-2DC. The JetNet 5428G Series is equipped with 24 10/100 Base-TX ports plus 4 Gigabit RJ45 / MINI GBIC combo ports. JetNet 5428G Series is a special design for control rooms where high-port density and performance are required.
Note: The detail spec is listed in latest datasheet. Please download the latest datasheet in Korenix Web site. Package List Korenix JetNet 5428G Series products are shipped with following items: JetNet 5428G-AC 24+4G Rackmount Managed Ethernet Ring Switch JetNet 5428G...
Page 8
Rack Mount Kit Console Cable If any of the above items are missing or damaged, please contact your local sales representative.
Panel Layout The front panel includes RJ-45 based RS-232 Console Port, USB port, System & Port LEDs, Gigabit Ethernet Port Interfaces and Gigabit Combo Port Interfaces. The back panel of the JetNet 5428G-AC consists of 1 AC power Inputs and 1 Relay Output.
JetNet 5428G-2DC DC Power Input The suggested power input is 24/48DC, the available range is from 18-75VDC. Follow below steps to wire JetNet 5428G-2DC redundant DC power inputs. Insert positive and negative wires into V+ and V- contacts respectively of the terminal block connector.
For AC input, the 3 pin include V+, V- and GND. The GND pin must be connected to the earth ground. For DC input, loosen the earth ground screw by screw drive; then tighten the screw after earth ground wire is connected. Wiring Fast Ethernet Ports JetNet 5428G includes 24 RJ-45 Fast Ethernet ports.
Note: This is a Class 1 Laser/LED product. Don’t stare at the Laser/LED Beam. Wiring Gigabit Combo Ports JetNet 5428G series includes 4 RJ-45 Gigabit Ethernet ports. The speed of the gigabit Ethernet port supports 100Base-TX and 1000Base-TX. JetNet 5428G equips 4 Gigabit SFP ports combo with Gigabit Ethernet RJ-45 ports.
buy a new one. The Pin assignment spec is listed in the appendix. Rack Mounting Installation The Rack Mount Kit is attached inside the package. 2.9.1 Attach the brackets to the device by using the screws provided in the Rack Mount kit. (The picture is JetNet 5628G, the mounting method is the same.) 2.9.2 Mount the device in the 19’...
2.10 Safety Warming 2.2.1 The Equipment intended for installation in a Restricted Access Location. 2.2.2 The warning test is provided in user manual. Below is the information: ”For tilslutning af de ovrige ledere, se medfolgende installationsvejledning”. “Laite on liitettava suojamaadoitus-koskettimilla varustettuun pistorasiaan” „Apparatet ma tilkoples jordet stikkontakt“...
3.3 Preparation for Telnet console Preparation for Serial Console In JetNet 5428G package, Korenix attached one RS-232 RJ-45 to DB-9 console cable. Please attach RS-232 DB-9 connector to your PC COM port, connect the other end to the Console port of the JetNet 5428G. Note: If you lost the cable, please contact with your sales or follow the pin assignment to buy a new one..
3.2.1 Web Interface Korenix web management page is developed by JAVA. It allows you to use a standard web-browser such as Microsoft Internet Explorer, or Mozila, to configure and interrogate the switch from anywhere on the network. Before you attempt to use the embedded web interface to manage switch operation,...
Page 19
3.2.2 Secured Web Interface Korenix web management page also provides secured management HTTPS login. All the configuration commands will be secured and will be hard for the hackers to sniff the login password and configuration commands.
3.3.1 Telnet Korenix JetNet 5428G supports Telnet console. You can connect to the switch by Telnet and the command lines are the same as what you see by RS232 console port. Below are the steps to open Telnet connection to the switch.
Page 21
tool to demonstrate how to login JetNet by SSH. Note: PuTTY is copyright 1997-2006 Simon Tatham. Download PuTTY: http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html The copyright of PuTTY 1. Open SSH Client/PuTTY. In the Session configuration, enter the Host Name (IP Address of your JetNet 5428G) and Port number (default = 22). Choose the “SSH” protocol.
Page 22
3. After few seconds, the SSH connection to JetNet 5428G is opened. You can see the login screen as the below figure. 4. Type the Login Name and its Password. The default Login Name and Password are admin / admin. 5.
Then you can remotely connect to its embedded HTML web pages or Telnet console. Korenix web management page is developed by JAVA. It allows you to use a standard web-browser such as Microsoft Internet Explorer, or Mozila, to configure and interrogate the switch from anywhere on the network.
Command Line Interface Introduction The Command Line Interface (CLI) is the user interface to the switch’s embedded software system. You can view the system information, show the status, configure the switch and receive a response back from the system by keying in a command. There are some different command modes.
Page 25
write Write running configuration to memory, network, or terminal Global Configuration Mode: Press configure terminal in privileged EXEC mode. You can then enter global configuration mode. In global configuration mode, you can configure all the features that the system provides you. Type interface IFNAME/VLAN to enter interface configuration mode, exit to leave.
Page 26
when you want to enter certain interface configuration mode. Type exit to leave. Type ? to see the command list Available command lists of the global configuration mode. Switch(config)# interface fa1 Switch(config-if)# acceptable Configure 802.1Q acceptable frame types of a port. auto-negotiation Enable auto-negotiation state of a given port description...
Page 27
Summary of the 5 command modes. Command Main Function Enter and Exit Method Prompt Mode User EXEC This is the first level of access. Enter: Login successfully Switch> User can ping, telnet remote Exit: exit to logout. device, and show some basic Next mode: Type enable to information enter privileged EXEC mode.
Page 29
Here are some useful commands for you to see these available commands. Save your time in typing and avoid typing error. ? To see all the available commands in this mode. It helps you to see the next command you can/should type as well. Switch(config)# interface (?) IFNAME Interface's name vlan...
Basic Setting The Basic Setting group provides you to configure switch information, IP address, User name/Password of the system. It also allows you to do firmware upgrade, backup and restore configuration, reload factory default, and reboot the system. Following commands are included in this group: 4.2.1 Switch Setting 4.2.2 Admin Password 4.2.3 IP Configuration...
Page 31
address or other information of the administrator. The available characters you can input are 64. System OID: The SNMP object ID of the switch. You can follow the path to find its private MIB in MIB browser. (Note: When you attempt to view private MIB, you should compile private MIB files into your MIB browser first.) System Description: JetNet 5428G Industrial Managed Switch is the name of this product.
Page 32
4.2.3 IP Configuration This function allows users to configure the switch’s IP address settings. DHCP Client: You can select to Enable or Disable DHCP Client function. When DHCP Client function is enabled, an IP address will be assigned to the switch from the network’s DHCP server.
Page 33
IPv6 Address field: typing new IPv6 address in this field. Prefix:the size of subnet or netwok, and it equivalent to the subnetmask, but writtenin different.The default subnet mask length is 64bits, and writen in decimal value -64. Add: after add new IPv6 address and prefix, don’t forget click icon-“Add”to apply new address to system.
Page 34
*Note: Please enable one synchronization protocol (PTP/NTP) only. JetNet 5428G series also provides Daylight Saving function for some territories use.
Page 35
Manual Setting: User can select “Manual setting” to change time as user wants. User also can click the button “Get Time from PC” to get PC’s time setting for switch. After click the “Get Time from PC” and apply the setting, the System time display the same time as your PC’s time.
Page 36
16 (GMT-04:00) Caracas, La Paz 17 (GMT-04:00) Santiago 18 (GMT-03:00) NewFoundland 19 (GMT-03:00) Brasilia 20 (GMT-03:00) Buenos Aires, Georgetown 21 (GMT-03:00) Greenland 22 (GMT-02:00) Mid-Atlantic 23 (GMT-01:00) Azores 24 (GMT-01:00) Cape Verde Is. 25 (GMT) Casablanca, Monrovia 26 (GMT) Greenwich Mean Time: Dublin, Edinburgh, Lisbon, London 27 (GMT+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna 28 (GMT+01:00) Belgrade, Bratislava, Budapest, Ljubljana, Prague 29 (GMT+01:00) Brussels, Copenhagen, Madrid, Paris...
Page 37
74 (GMT+13:00) Nuku’alofa Daylight Saving Time: Set when Enable Daylight Saving Time start and end, during the Daylight Saving Time, the device’s time is one hour earlier than the actual time. Once you finish your configuration, click on Apply to apply your configuration. 4.2.5 Jumbo Frame What is Jumbo Frame?
Page 38
After selecting to enable DHCP Server function, type in the Network IP address for the DHCP server IP pool, Subnet Mask, Default Gateway address and Lease Time for client. Once you have finished the configuration, click Apply to apply your configuration Excluded Address: You can type a specific address into the IP Address field for the DHCP server reserved IP address.
Page 39
DHCP Leased Entries: JetNet 5428G provides an assigned IP address list for user check. It will show the MAC and IP address that was assigned by JetNet 5428G. Click the Reload button to refresh the listing. Option82 IP Address Configuration: The DHCP can assign IP address according to DHCP Option82 which sent from DHCP Relay Agent.
Page 40
DHCP Relay Agent: The DHCP Relay Agent is also known as DHCP Option 82. It can help relay the DHCP Request to remote DHCP server located in different subnet. Note: The DHCP Server can not work with DHCP Relay Agent at the same time. Relay Agent: Choose Enable or Disable the relay agent.
Page 41
4.2.7 Backup and Restore With Backup command, you can save current configuration file saved in the switch’s flash to admin PC or TFTP server. This will allow you to go to Restore command later to restore the configuration file back to the switch. Before you restore the configuration file, you must place the backup configuration file in the PC or TFTP server.
Page 42
Startup Configuration File: After you saved the running-config to flash, the new settings will be kept and work after power cycle. You can use show startup-config to view it in CLI. The Backup command can only backup such configuration file to your PC or TFTP server. Technical Tip: Default Configuration File: The switch provides the default configuration file in the system.
Page 43
Note that the folders of the path to the target file do not allow you to input space key. Figure 4.2.5.3 Backup/Restore Configuration – TFTP Server mode Type the IP address of TFTP Server IP. Then click on Backup/Restore. Note: point to the wrong file will cause the entire configuration missed USB mode: please select the file to Backup configuration file name, or to Restore Configuration.
Page 44
In this section, you can update the latest firmware for your switch. Korenix provides the latest firmware in Korenix Web site. The new firmware may include new features, bug fixes or other software changes. We’ll also provide the release notes for the update as well. For technical viewpoint, we suggest you use the latest firmware before installing the switch to the customer site.
Page 45
Figure 4.2.6.3 Error Message due to the file error or not a firmware for the switch. Before upgrading firmware, please check the file name and switch model name first and carefully. Korenix switch provide protection when upgrading incorrect firmware file, the system would not crash even download the incorrect firmware. Even we have the protection, we still ask you don’t try/test upgrade incorrect firmware;...
Page 46
Type the IP address of TFTP Server and Firmware File Name. Then click on Upgrade to start the process. After finishing transmitting the firmware, the system will copy the firmware file and replace the firmware in the flash. The CLI show …… until the process is finished. Figure 4.2.8.6 Firmware Upgrade –...
Page 47
4.2.9 Load Default In this section, you can reset all the configurations of the switch to default setting. Click on Reset the system will then reset all configurations to default setting. The system will show you popup message window after finishing this command. Default setting will work after rebooting the switch.
Page 48
Command Line Switch Setting Switch(config)# hostname System Name WORD Network name of this system Switch(config)# hostname JN5428G Switch(config)# Switch(config)# snmp-server location Taipei System Location Switch(config)# snmp-server contact korecare@korenix.com System Contact Switch# show snmp-server name Display Switch Switch# show snmp-server location...
Page 49
MAC Address : 001277FF0000 Manufacturing Date : 2015/11/04 Software Information : Loader Version : 2.0.0.3 Firmware Version : 0.0.11-20151111-09:02:40 Copyright 2006-2015 Korenix Technology Co., Ltd. Switc # show hardware led led information mac mac address Switch# show hardware mac MAC Address : 00:12:77:FF:01:B0...
Page 50
Switch# show running-config ……… interface vlan1 ip address 192.168.10.8/24 no shutdown ip route 0.0.0.0/0 192.168.10.254/24 Switch(config)# interface vlan1 IPv6 Address/Prefix Switch(config-if)# ipv6 address 2001:0db8:85a3::8a2e:0370:7334/64 Switch(config)# ipv6 route 0::0/0 IPv6 Gateway 2001:0db8:85a3::8a2e:0370:FFFE Switch(config)#no ipv6 route 0::0/0 Remove IPv6 2001:0db8:85a3::8a2e:0370:FFFE Gateway Switch# show running-config Display ………...
Page 51
Dublin, Edinburgh, Lisbon, London Switch# show clock timezone clock timezone (26) (GMT) Greenwich Mean Time: Dublin, Edinburgh, Lisbon, London Switch# show ptpd PTPd is enabled Mode: Slave Jumbo Frame Type the maximum MTU to enable Jumbo Frame: Jumbo Frame Switch(config)# system mtu 1518 2000 2032 9712 (with VLAN tag) Switch(config)# system mtu 9712 Disable Jumbo Frame:...
Page 52
MACADDR MAC address IP and MAC binding Switch(config-dhcp)# ip dhcp static 0012.7700.0001 A.B.C.D leased IP address Switch(config-dhcp)# ip dhcp static 0012.7700.0001 192.168.10.99 Switch(config-dhcp)# ip dhcp option82 circuit-id DHCP Server – string string input (using "any" if you don't want to specify Option82 binding CID) hexadecimal input...
Page 53
Leased Address List IP Address MAC Address Leased Time Remains --------------- -------------- -------------------- Switch# show ip dhcp relay DHCP Relay Information DHCP Relay Agent ON IP helper-address : 192.168.10.200 Re-forwarding policy: Replace Backup and Restore Switch# copy startup-config tftp: 192.168.10.33/default.conf Backup Startup Writing Configuration [OK] Configuration file...
Port Configuration Port Configuration group enables you to enable/disable port state, or configure port auto-negotiation, speed, and duplex, flow control, rate limit control and port aggregation settings. It also allows you to view port status and aggregation information. Following commands are included in this group: 4.3.1 Understand the port mapping 4.3.2 Port Control 4.3.3 Port Status...
Page 56
Select the port you want to configure and make changes to the port. In State column, you can enable or disable the state of this port. Once you disable, the port stop to link to the other end and stop to forward any traffic. The default setting is Enable which means all the ports are workable when you receive the device.
Page 57
Speed/Duplex: Current working status of the port. Flow Control: The state of the flow control. Note: The UI can display vendor name, wave length and distance of all Korenix Gigabit SFP transceiver family. If you see Unknown information, it may mean that the vendor doesn’t provide their information or that the information of their transceiver can’t be read.
Page 58
Figure 4.3.4.1 shows you the Limit Rate of Ingress and Egress. You can type the volume in the blank. The volume of the JetNet 5428G is step by 8Kbps.
Page 59
4.3.5 Storm Control The Storm Control is similar to Rate Control. Rate Control filters all the traffic over the threshold you input by UI. Storm Control allows user to define the Rate for specific Packet Types. Figure 4.3.5.1 Packet type: You can assign the Rate for specific packet types based on packet number per second.
Page 60
The aggregated ports can interconnect to the other switch which also supports Port Trunking. Korenix Supports 2 types of port trunking. One is Static Trunk, the other is 802.3ad. When the other end uses 802.3ad LACP, you should assign 802.3ad LACP to the trunk.
Page 61
dst-ip -> load distribution is based on the destination IP address src-dst-ip -> load distribution is based on the source and destination IP address Extended setting in CLI: Port Priority: The command allows you to change the port priority setting of the specific port.
Page 62
Link Down: When LACP is enabled, member ports of LACP group which are not linked up will be displayed in the Link Down column. 4.3.7 Command Lines for Port Configuration Feature Command Line Port Control Switch(config-if)# shutdown -> Disable port state Port Control –...
Page 63
Rate Control Switch(config-if)# rate-limit Rate Control – egress Outgoing packets Ingress or Egress ingress Incoming packets Note: To enable rate control, you should select the Ingress or Egress rule first; then assign the packet type and bandwidth. Switch(config-if)# rate-limit ingress bandwidth Rate Contr–l - <0-1000000>...
Page 64
SWITCH(config-if)# lacp LACP – Port Setting port-priority LACP priority for physical interfaces timeout assigns an administrative LACP timeout SWITCH(config-if)# lacp port-priority <1-65535> Valid port priority range–1 - 65535 (default is 32768) SWITCH(config-if)# lacp timeout long specifies a long timeout value (default) short specifies a short timeout value SWITCH(config-if)# lacp timeout short Set lacp port timeout ok.
MultiRing Technology. The Ring ports can be LACP/Port Trunking ports, after aggregated ports to a group, the group of ports can act as the Ring port of the Ring. This is Korenix Pattened TrunkRing Technology. Advanced Rapid Dual Homing(RDH) technology also facilitates JetNet switch to connect with a core managed switch easily and conveniently.
Page 67
4.4.1 STP Configuration This page allows select the STP mode and configuring the global STP/RSTP Bridge Configuration. The STP mode includes the STP, RSTP, MSTP and Disable. Please select the STP mode for your system first. The default mode is RSTP enabled. After select the STP or RSTP mode, continue to configure the global Bridge parameters for STP and RSTP.
Page 68
Since different RSTP aware switches may have their own mechanism to calculate the message age. So that this is most possibly occurred when interoperate different vendors’ RSTP aware switches together. The maximum volume of the Korenix RSTP domain is 23, configure the MAX Age lower than 23 is recommended.
Page 69
decides which port should be blocked by priority in a LAN. Link Type: There are 3 types for you select. Auto, P2P and Share. Some of the rapid state transitions that are possible within RSTP depend upon whether the port of concern can only be connected to another bridge (i.e. it is served by a point-to-point LAN segment), or if it can be connected to two or more bridges (i.e.
Page 70
4.4.3 RSTP Info This page allows you to see the information of the root switch and port status. Root Information: You can see root Bridge ID, Root Priority, Root Port, Root Path Cost and the Max Age, Hello Time and Forward Delay of BPDU sent from the root switch. Port Information: You can see port Role, Port State, Path Cost, Port Priority, Oper P2P mode, Oper edge port mode and Aggregated(ID/Type).
Page 71
each of the assigned VLAN groups. An Internal Spanning Tree (IST) is used to connect all the MSTP switches within an MST region. An MST Region may contain multiple MSTP Instances. The figure shows there are 2 VLANs/MSTP Instances and each instance has its Root and forwarding paths.
Page 72
To configure the MSTP setting, the STP Mode of the STP Configuration page should be changed to MSTP mode first. After enabled MSTP mode, then you can go to the MSTP Configuration pages. MSTP Region Configuration This page allows configure the Region Name and its Revision, mapping the VLAN to Instance and check current MST Instance configuration.
Page 73
Instance ID: Select the Instance ID, the available number is 1-15. VLAN Group: Type the VLAN ID you want mapping to the instance. Instance Priority: Assign the priority to the instance. After finish your configuration, click on Add to apply your settings. Current MST Instance Configuration This page allows you to see the current MST Instance Configuration you added.
Page 74
Path Cost: Enter a number between 1 and 200,000,000. This value represents the “cost” of the path to the other bridge from the transmitting bridge at the specified port. Priority: Enter a value between 0 and 240, using multiples of 16. This is the value that decides which port should be blocked by priority in a LAN.
Page 75
Multiple Super Ring (MSR) technology is Korenix’s 3 generation Ring redundancy technology. This is patented and protected by Korenix and is used in countries all over the world. MSR ranks the fastest restore and failover time in the world, 0 ms for restore and about milliseconds level for failover for 100Base-TX copper port.
Page 76
Ring Port2: Assign another port for ring connection Path Cost: Change the Path Cost of Ring Port2 Rapid Dual Homing: Rapid Dual Homing is an important feature of Korenix 3 generation Ring redundancy technology. When you want to connect multiple RSR or form redundant topology with other vendors,RDH could allow you to have maximum 7 multiple links for redundancy without any problem.
Page 77
the same, when dual home to the same foreing network. The Extension ID range from 0 to 7. With the combination of Extension ID(0 to 7) and Ring ID(0 to 31), we can now support up to 256(8*32) different dual homing rings In Dual Homing I released with JetNet 4000/4500 series, you have to configure additional port as Dual Homing port to two uplink switches.
Page 78
This page shows the MSR information. ID: Ring ID. Version: which version of this ring, this field could be Rapid Super Ring or Super Chain Role: This Switch is RM or nonRM Status: If this field is Normal which means the redundancy is approved. If any one of the link in this Ring is broken, then the status will be Abnormal.
Page 79
ERPS: Enable or disable ERPS function. ERPS Configuration: Version: ERPS has version 1 and 2. Now we just suport ERPSv1 Node State: The current state of the node, Idle and Protection. Node Role: The rlole of the node, RPL owner and Ring node. The RPL owner is an Ethernet ring node adjacent to the RPL.
Page 80
mst the multiple spanning-tree protocol (802.1s) Bridge Priority Switch(config)# spanning-tree priority <0-61440> valid range is 0 to 61440 in multiple of 4096 Switch(config)# spanning-tree priority 4096 Bridge Times Switch(config)# spanning-tree bridge-times (forward Delay) (max-age) (Hello Time) Switch(config)# spanning-tree bridge-times 15 20 2 This command allows you configure all the timing in one time.
Page 81
Revision 65535 Instance Vlans Mapped -------- -------------------------------------- 1,4-4094 Config HMAC-MD5 Digest: 0xB41829F9030A054FB74EF7A8587FF58D ------------------------------------------------ Remove Region Switch(config-mst)# no Name name name configure revision revision configure instance the mst instance Switch(config-mst)# no name Remove Instance Switch(config-mst)# no instance example <1-15> target instance number Switch(config-mst)# no instance 2 Show Pending MST Switch(config-mst)# show pending...
Page 82
Root Times : max-age 20, hello-time 2, forward-delay 15 Bridge Address : 0012.77ee.eeee Priority : 32768 Bridge Times : max-age 20, hello-time 2, forward-delay 15 BPDU transmission-limit : 3 Port Role State Cost Prio.Nbr Type Aggregated ------ ---------- ---------- -------- ---------- ------------ ------------ fa1 Designated Forwarding 200000 128.1...
Page 83
Port Role State Cost Prio.Nbr Type ------ ---------- ---------- -------- ---------- ------------------ fa1 Designated Forwarding 200000 128.1 P2P Internal(MSTP) Internal(MSTP) fa2 Designated Forwarding 200000 128.2 P2P ###### MST01 vlans mapped: 2 Bridge address 0012.77ee.eeee priority 32768 (sysid 1) Root this switch for MST01 Port Role State...
Page 84
Stop Multiple Super Ring success. Change Ring name Switch(config-multiple-super-ring)# name MSR1 Note: Default Ring name is “Ring1”, 1 is the Ring ID. Super Ring Version Switch(config-multiple-super-ring)# version default set default to rapid super ring rapid-super-ring rapid super ring Switch(config-multiple-super-ring)# version rapid-super-ring Priority Switch(config-multiple-super-ring)# priority <0-255>...
Page 85
Extension ID : 0 Up Link : Auto Detect (N/A) Super Chain : Disabled Chain Role : N/A Chain Edge Port : N/A Statistics : Watchdog sent 0, received 0, missed Link Up sent 0, received Link Down sent 0, received Role Transition count 0 Ring State Transition count 1 Ring ID is optional.
Page 86
ring-node ERPS ring node Switch(config)# erps ring-port PORT1 The ring port 1 Switch(config)# erps rpl ring-port Assign ring port as RPL Switch(config)# erps control-channel <1-4095> The VLAN ID of control channel, valid range is from 1 to 4094 Switch(config)# erps timer wtr-timer WTR(Wait-to-restore) Timer guard-timer Guard Timer...
Layer 2 switch, without actually disconnecting these devices from their original switches. JetNet 5428G Series Industrial Ethernet Switch supports 802.1Q VLAN. 802.1Q VLAN is also known as Tag-Based VLAN. This Tag-Based VLAN allows VLAN to be created across different switches (see Figure 1).
Page 88
VLAN Configuration group enables you to Add/Remove VLAN, configure QinQ, port Ingress/Egress parameters and view VLAN table. VLAN Configuration group enables you to Add/Remove VLAN, configure port Ingress/Egress parameters and view VLAN table. Following commands are included in this group: 4.5.1 VLAN Port Configuration 4.5.2 VLAN Configuration 4.5.3 GVRP Configuration...
Page 89
Tunnel Mode: This is the new command for QinQ. The command includes None, 802.1Q Tunnel and 802.1Q Tunnel Uplink. The figure shows the relationship between 802.1Q Tunnel and 802.1Q Tunnel Uplink. Following is the modes you can select. None: Remian VLAN setting, no QinQ. 802.1Q Tunnel: The QinQ command applied to the ports which connect to the C-VLAN.
Page 90
Figure 4.5.2.1 Web UI of the VLAN Configuration. Management VLAN ID: The switch supports management VLAN. The management VLAN ID is the VLAN ID of the CPU interface so that only member ports of the management VLAN can ping and access the switch. The default management VLAN ID is 1.
Page 91
remain in Unused until you add ports to the VLAN. Note: Before you change the management VLAN ID by Web and Telnet, remember that the port attached by the administrator should be the member port of the management VLAN; otherwise the administrator can’t access the switch via the network. Note: Currently JetNet 5428G supports max 256 group VLAN.
Page 92
Steps to configure Egress rules: Select the VLAN ID. Entry of the selected VLAN turns to light blue. Assign Egress rule of the ports to U or T. Press Apply to apply the setting. If you want to remove one VLAN, select the VLAN entry. Then press Remove button. 4.5.3 GVRP configuration GVRP allows users to set-up VLANs automatically rather than manual configuration on...
Page 93
Name: Name of the VLAN. Status: Static shows this is a manually configured static VLAN. Unused means this VLAN is created by UI/CLI and has no member ports. This VLAN is not workable yet. Dynamic means this VLAN is learnt by GVRP. After created the VLAN, the status of this VLAN will remain in Unused status until you add ports to the VLAN.
Private VLAN The private VLAN helps to resolve the primary VLAN ID shortage, client ports’ isolation and network security issues. The Private VLAN provides primary and secondary VLAN within a single switch. Primary VLAN: The uplink port is usually the primary VLAN. A primary VLAN contains promiscuous ports that can communicate with lower Secondary VLANs.
Page 98
Community: The VLAN is the Community VLAN. The member ports of the VLAN can communicate with each other. 4.6.2 PVLAN Port Configuration PVLAN Port Configuration page allows configure Port Configuration and Private VLAN Association. Private VLAN Association Secondary VLAN: After the Isolated and Community VLAN Type is assigned in Private VLAN Configuration page, the VLANs are belonged to the Secondary VLAN and displayed here.
Page 99
For example: 1. VLAN Create: VLAN 2-5 are created in VLAN Configuration page. 2. Private VLAN Type: VLAN 2-5 has its Private VLAN Type configured in Private VLAN Configuration page. VLAN 2 is belonged to Primary VLAN. VLAN 3-5 are belonged to secondary VLAN (Isolated or Community). 3.
Page 100
4.6.3 PVLAN Information This page allows you to see the Private VLAN information. 4.6.4 CLI Command of the PVLAN Command Lines of the Private VLAN configuration Feature Command Line Private VLAN Configuration Create VLAN Switch(config)# vlan 2 vlan 2 success Switch(config-vlan)# End current mode and change to enable mode exit...
Page 101
primary Configure the VLAN as a primary private VLAN Primary Type Switch(config-vlan)# private-vlan primary Switch(config-vlan)# no private-vlan primary <cr> Isolated Type Switch(config-vlan)# private-vlan isolated Switch(config-vlan)# no private-vlan isolated <cr> Community Type Switch(config-vlan)# private-vlan community <cr> Private VLAN Port Configuraiton Go to the port Switch(config)# interface (port_number, ex: gi9) configuraiton Switch(config-if)# switchport private-vlan...
Page 102
Community gi10(P),gi8(C) Community gi10(P),fa7(C),gi9(I) PVLAN Type Switch# show vlan private-vlan type Vlan Type Ports ---- ----------------- ----------------- primary gi10 isolated community community fa7,gi9 primary Host List Switch# show vlan private-vlan port-list Ports Mode Vlan ----- ----------- ---- normal normal normal normal normal normal...
Traffic Prioritization Quality of Service (QoS) provides traffic prioritization mechanism which allows users to deliver better service to certain flows. QoS can also help to alleviate congestion problems and ensure high-priority traffic is delivered first. This section allows you to configure Traffic Prioritization settings for each port with regard to setting priorities.
Page 105
In JetNet, users can freely assign the mapping table or follow the suggestion of the 802.1p standard. Korenix uses 802.p suggestion as default values. You can find CoS values 1 and 2 are mapped to physical Queue 0, the lowest queue. CoS values 0 and 3 are mapped to physical Queue 1, the low/normal physical queue.
Page 106
After configuration, press Apply to enable the settings. 4.7.4 DSCP-Priority Mapping This page is to change DSCP values to Priority mapping table. The system provides 0~63 DSCP priority level. Each level can map to one priority ID After configuration, press Apply to enable the settings.
Page 107
4.7.5 CLI Commands of the Traffic Prioritization Command Lines of the Traffic Prioritization configuration Feature Command Line QoS Setting Queue Scheduling – Switch(config)# qos queue-sched Strict Priority Strict Priority wrr Weighted Round Robin Switch(config)# qos queue-sched sp The queue scheduling scheme is setting to Strict Priority. Queue Scheduli–g - Switch(config)# qos queue-sched wrr <1-10>...
Page 108
CoS-Queue Mapping Format Switch(config)# qos cos-map PRIORITY Assign an priority (7 highest) Switch(config)# qos cos-map 1 QUEUE Assign an queue (0-7) Note: Format: qos cos-map priority_value queue_value Map CoS 0 to Queue 1 Switch(config)# qos cos-map 0 1 The CoS to queue mapping is set ok. Map CoS 1 to Queue 0 Switch(config)# qos cos-map 1 0 The CoS to queue mapping is set ok.
Multicast Filtering For multicast filtering, JetNet 5428G uses IGMP Snooping technology. IGMP (Internet Group Management Protocol) is an Internet Protocol that provides a way for internet device to report its multicast group membership to adjacent routers. Multicasting allows one computer on the internet to send data to a multitude of other computers that have identified themselves as being interested in receiving the originating computers data.
Page 111
Snooping function, or select the “IGMP Snooping” global setting for all VLANs. Then press Apply. In the same way, you can also Disable IGMP Snooping for certain VLANs. you can select Filtering Mode on this Page. Filtering Mode Setting: Send to Query Ports: The unknown multicast will be sent to the Query ports. The Query port means the port received the IGMP Query packets.
Page 112
4.8.2 IGMP Query This page allows users to configure IGMP Query feature. Since JetNet 5428G can only be configured by member ports of the management VLAN, IGMP Query can only be enabled on the management VLAN. If you want to run IGMP Snooping feature in several VLANs, you should notice that whether each VLAN has its own IGMP Querier first.
Page 113
Once you finish configuring the settings, click on Apply to apply your configuration. 4.8.4 GMRP Configuration To enable the GMRP configuration, the Global GMRP Configuration should be enabled first. And all the port interfaces should enable GMRP learning as well. Then the switch exchange the IGMP Table with other switches which is also GMRP-aware devices.
Page 114
Global IGMP snooping is enabled globally. Please specify on which vlans IGMP snooping enables Switch(config)# ip igmp snooping <?> immediate-leave leave group when receive a leave message last-member-query-interval the interval for which the switch waits before updating the table entry source-only-learning Source-Only-Learning vlan...
Page 115
version: IGMPv2 query-interval: 125s query-max-response-time: 10s Switch# show running-config …. interface vlan1 ip address 192.168.10.17/24 ip igmp no shutdown ……. Unknown Multicast Send to Query Ports – Switch(config)# ip igmp snooping source-only-learning vlan VLANLIST allowed VLAN list all VLAN Switch(config)# ip igmp snooping source-only-learning vlan 1 IGMP Snooping Source-Only-Learning is enabled on VLAN 1 Discard (Force filtering) Switch(config)# mac-address-table multicast filtering vlan VLANLIST allowed VLAN list...
SNMP Simple Network Management Protocol (SNMP) is a protocol used for exchanging management information between network devices. SNMP is a member of the TCP/IP protocol suite. JetNet 5428G series support SNMP v1 and v2c and V3. An SNMP managed network consists of two main components: agents and a manager.
Page 117
4.9.2 SNMP V3 Profile SNMP v3 can provide more security functions when the user performs remote management through SNMP protocol. It delivers SNMP information to the administrator with user authentication; all of data between JetNet 5428G and the administrator are encrypted to ensure secure communication.
Page 118
This page allows users to Enable SNMP Trap, configure the SNMP Trap server IP, Community name, and trap Version V1 or V2. After configuration, you can see the change of the SNMP pre-defined standard traps and Korenix pre-defined traps. The pre-defined traps can be found in Korenix private MIB.
Page 119
SNMP Trap Enable Trap Switch(config)# snmp-server enable trap Set SNMP trap enable ok. SNMP Trap Server IP Switch(config)# snmp-server host 192.168.10.33 without specific SNMP trap host add OK. community name SNMP Trap Server IP Switch(config)# snmp-server host 192.168.10.33 version 1 with version 1 and private community...
4.10 Security JetNet 5428G provides several security features for you to secure your connection. The Filter Set is also known as Access Control List. The ACL feature includes traditional Port Security and IP Security. Following commands are included in this group: 4.10.1 Filter Set (Access Control List) 4.10.2 IEEE 802.1x 4.10.3 CLI Commands of the Security...
Page 121
MAC Filter (Port Security): The MAC Filter allows user to define the Access Control List for specific MAC address or a group of MAC addresses. Filter ID/Name: The name for this MAC Filter entry. Action: Permit to permit traffic from specified sources. Deny to deny traffic from those sources.
Page 122
Egress Port: Bind the MAC Filter rule to specific front port. Once you finish configuring the ACE settings, click on Add to apply your configuration. You can see below screen is shown. Example of the below Entry: Permit Source MAC “0012.7700.0000” to Destination MAC “0012.7700.0002”. The Permit rule is egress rule and it is bind to Gigabit Ethernet Port 25.
Page 123
Example: IP Standard Access List: This kind of ACL allows user to define filter rules according to the source IP address. IP Extended Access List: This kind of ACL allows user to define filter rules according to the source IP address, destination IP address, Source TCP/UDP port, destination TCP/UDP port and ICMP type and code.
Page 124
Filter ID/Name: The ID or the name for this IP Filter entry. Action: Permit to permit traffic from specified sources. Deny to deny traffic from those sources. Source/Destination Address: Type the source/destination IP address you want configure. Source/Destination Wildcard: This command allows user to define single host or a group of hosts based on the wildcard.
Page 125
4.10.2 Filter Set (Access Control List) After configured the ACL filter rules, remember associate this filter with the physical ports. Then the port has the capability to filter traffic/attach based on the packets lost. 4.10.3 IEEE 802.1x 4.10.3.1 802.1X configuration IEEE 802.1X is the protocol that performing authentication to obtain access to IEEE 802 LANs.
Page 126
System AuthControl: To enable or disable the 802.1x authentication. Authentication Method: Radius is a authentication server that provide key for authentication, with this method, user must connect switch to server. If user select Local for the authentication method, switch use the local user data base which can be create in this page for authentication.
Page 127
Once you finish configuring the settings, click on Apply to apply your configuration. Port control: Force Authorized means this port is authorized; the data is free to in/out. Force unauthorized just opposite, the port is blocked. If users want to control this port with Radius Server, please select Auto for port control.
Page 128
Tx period: the time interval of authentication request. Supplicant Timeout: the timeout for the client authenticating Sever Timeout: The timeout for server response for authenticating. Click Initialize Selected to set the authorize state of selected port to initialize status. Click Reauthenticate Selected to send EAP Request to supplicant to request reauthentication.
Page 129
Negate a command or set its defaults quit Exit current mode and down to previous mode Add IP Standard access Switch(config)# ip access-list list extended Extended access-list standard Standard access-list Switch(config)# ip access-list standard <1-99> Standard IP access-list number <1300-1999> Standard IP access-list number (expanded range) WORD Access-list name...
Page 130
Any Internet Protocol Transmission Control Protocol User Datagram Protocol icmp Internet Control Message Protocol Switch(config-ext-acl)#permit ip A.B.C.D Source address Any source host host A single source host Switch(config-ext-acl)#permit ip 192.168.10.1 A.B.C.D Source wildcard bits Switch(config-ext-acl)#permit ip 192.168.10.1 0.0.0.1 A.B.C.D Destination address Any destination host host A single destination host...
Page 131
radius server-ip Switch(config)# dot1x radius Switch(config)# dot1x radius server-ip 192.168.10.120 key 1234 RADIUS Server Port number NOT given. (default=1812) RADIUS Accounting Port number NOT given. (default=1813) RADIUS Server IP : 192.168.10.120 RADIUS Server Key : 1234 RADIUS Server Port : 1812 RADIUS Accounting Port : 1813 Switch(config)# radius server-ip...
Page 132
ReAuthPeriod : 3600 Seconds QuietPeriod : 60 Seconds TxPeriod : 30 Seconds SupplicantTimeout : 30 Seconds ServerTimeout : 30 Seconds GuestVlan HostMode : Single operControlledDirections : Both adminControlledDirections : Both Switch# show dot1x radius RADIUS Server IP : 192.168.10.100 RADIUS Server Key : radius-key RADIUS Server Port : 1812 RADIUS Accounting Port : 1813 Secondary RADIUS Server IP...
4.11 Warning JetNet 5428G provides several types of Warning features for you to remote monitor the status of end devices or the change of your network. The features include System Log and SMTP E-mail Alert. Following commands are included in this group: 4.11.1 Fault Relay 4.11.2 Event Selection 4.11.3 Syslog Configuration...
Page 134
to short state and continuously ping the target device. When the ping failure occurred, the switch will turn the Relay Output to open state for a period of Reset Time. After the Reset Time timeout, the system will turn the Relay Output to close state. After the Hold Time timer is timeout, the switch system will start ping the target device.
Page 135
Warning Event is sent when….. System Event Device Cold Start Power is cut off and then reconnected. Device Warm Start Reboot the device by CLI or Web UI. Authentication failure An incorrect password, SNMP Community String is entered Time Synchronize Accessing to NTP Server is failure.
Page 136
Once you finish configuring the settings, click on Apply to apply your configuration. Note: When enabling Local or Both mode, you can monitor the system logs in [Monitor and Diag] / [Event Log] page. 4.11.4 SMTP Configuration JetNet 5428G supports E-mail Warning feature. The switch will send the occurred events to remote E-mail server.
Page 137
JetNet (Max. 40 characters) Rcpt E-mail Address 3 The third email address to receive email alert from JetNet (Max. 40 characters) Rcpt E-mail Address 4 The fourth email address to receive email alert from JetNet (Max. 40 characters) Once you finish configuring the settings, click on Apply to apply your configuration. 4.11.5 CLI Commands Command Lines of the Warning configuration Feature...
Page 138
Switch(config)# smtp-server server 192.168.10.100 ACCOUNT SMTP server mail account, ex: admin@korenix.com Switch(config)# smtp-server server 192.168.10.100 admin@korenix.com SMTP Email Alert set Server: 192.168.10.100, Account: admin@korenix.com ok. admin@example. Receiver mail Switch(config)# smtp-server receipt admin@example. SMTP Email Alert set receipt 1: com ok.
4.12 Monitor and Diagnostic JetNet 5428G provides several types of features for you to monitor the status of the switch or diagnostic for you to check the problem when encountering problems related to the switch. The features include MAC Address Table, Port Statistics, Port Mirror, Event Log and Ping.
Page 141
4.12.2 Port Statistics In this page, you can view operation statistics for each port. The statistics that can be viewed include Link Type, Link State, Rx Good, Rx Bad, Rx Abort, Tx Good, Tx Bad and Collision. Rx means the received packet while Tx means the transmitted packets. Note: If you see many Bad, Abort or Collision counts increased, that may mean your network cable is not connected well, the network performance of the port is poor…etc.
Page 142
4.12.3 Port Mirroring Port mirroring (also called port spanning) is a tool that allows you to mirror the traffic from one or more ports onto another port, without disrupting the flow of traffic on the original port. Any traffic that goes into or out of the Source Port(s) will be duplicated at the Destination Port.
Page 143
Once you finish configuring the settings, click on Apply to apply the settings. 4.12.4 Event Log In the 4.10.3, we have introduced System Log feature. When System Log Local mode is selected, JetNet 5428G will record occurred events in local log table. This page shows this log table.
Page 144
description, system description, VLAN ID… Once the link failure, the topology change events can be updated to the NMS as well. The LLDP Port State can display the neighbor ID and IP leant from the connected devices. LLDP: Enable/Disable the LLDP topology discovery information. LLDP Configuration: To configure the related timer of LLDP.
Page 145
Modbus/TCP that it can be polled through Ethernet. Thus the Modbus/TCP master can read or write the Modbus registers provided by the Industrial Ethernet Switch. Korenix JetNet 5428G implements the Modbus/TCP registers into the latest firmware. The registers include the System information, firmware information, IP address, interfaces’...
Page 146
Word 1 Lo byte = ‘N’ Word 2 Hi byte = ‘e’ Word 2 Lo byte = ‘t’ Word 3 Hi byte = ‘5’ Word 3 Lo byte = ‘4’ Word 4 Lo byte = ‘2’ Word 4 Hi byte = ‘8’ Word 5 Lo byte = ‘G’...
Page 147
Word 0 Hi byte = 0x01 Word 0 Lo byte = 0x02 Word 1 Hi byte = 0x03 Word 1 Lo byte = 0x04 Word 2 Hi byte = 0x05 Word 2 Lo byte = 0x06 0x020F to 241 words Reserved address space 0x2FF 0x0300...
Page 148
0x0000:Off 0x0001:On 0xFFFF: unavailable 0x0411 1 word 0x0000:Off 0x0001:On 0xFFFF: unavailable 0x0412 1 word 0x0000:Off 0x0001:On 0xFFFF: unavailable 0x0413 1 word 0x0000:Off 0x0001:On 0xFFFF: unavailable 0x0414 to 12 words Reserved address space 0x041F 0x0420 1 word 0x0000:Off 0x0001:On 0x0421 1 word 0x0000:Off 0x0001:On 0x0422...
Page 149
0x1240 to 1 word Duplex 0x125F 0x0000: half 0x0001: full 0x0003: auto (half) 0x0004: auto (full) 0x0005: auto 0xFFFF: unavailable 0x1260 to 1 word Speed 0x127F 0x0001: 10 0x0002: 100 0x0003: 1000 0x0004: 2500 0x0005: 10000 0x0101: auto 10 0x0102: auto 100 0x0103: auto 1000 0x0104: auto 2500 0x0105: auto 10000...
Page 150
0xFFFF: unavailable 0x1340 to 1 word Loopback Mode 0x135F 0x0000: none 0x0001: MAC 0x0002: PHY 0xFFFF: unavailable 0x1360 to 1 word STP Status 0x137F 0x0000: disabled 0x0001: blocking 0x0002: listening 0x0003: learning 0x0004: forwarding 0x1380 to 1 word Default CoS Value for untagged packets 0x139F 0x13A0 to 1 word...
Page 151
0x1800 to 1 words Temperature 0x181F 0x1820 to 2 words Alarm Temperature 0x185F 0x1860 to 1 words Tx power 0x187F 0x1880 to 2 words Warning Tx power 0x18BF 0x18C0 to 1 words Rx power 0x18DF 0x18E0 to 2 words Warning Rx power 0x191F 0x1920 to 1760 words...
Page 152
0x22FF 0x2300 to 2 words RxError 0x233F 0x2340 to 2 words FCSError 0x237F 0x2380 to 2 words Collisions 0x23BF 0x23C0 to 2 words Dropped Frames 0x23FF 0x2400 to 2 words Last Activated SysUpTime 0x243F 0x2440 to 191 words Reserved address space 0x24FF Outbound packet information 0x2500 to...
Page 153
0x2800 to 2 words FCSError 0x283F 0x2840 to 447 words Reserved address space 0x29FF Number of frames received and transmitted with a length(in octets) 0x2A00 to 2 words 0x2A3F 0x2A40 to 2 words 65 to 127 0x2A7F 0x2A80 to 2 words 128 to 255 0x2ABF 0x2AC0 to...
Page 154
000f.b079.ca3b Dynamic 0012.7701.0386 Dynamic 0012.7710.0101 Static 0012.7710.0102 Static 0012.77ff.0100 Management ***** MULTICAST MAC ADDRESS ***** Vlan Mac Address Status Ports ---- --------------- ---- ------- -------------------------- 0100.5e40.0800 0100.5e7f.fffa fa4,fa6 Show MAC Address Switch# show mac-address-table dynamic Table – Dynamic Learnt Destination Address Address Type Vlan Destination Port MAC addresses...
Page 155
Mirror source fa1-2 both set ok. Note: Select source port list and TX/RX/Both mode. Select Destination Port Switch(config)# mirror destination fa6 both Mirror destination fa6 both set ok Display Switch# show mirror Mirror Status : Enabled Ingress Monitor Destination P rt : fa6 Egress Monitor Destination P rt : fa6 Ingress Source Po ts :fa1,fa2, Egress Source Po ts :fa1,fa2,...
4.13 Device Front Panel Device Front Panel command allows you to see LED status of the switch. You can see LED and link status of the Power, Alarm(DO), R.S. and Ports. Feature On / Link UP Off / Link Down Note Power Green...
4.14 Save to Flash Save Configuration allows you to save any configuration you just made to the Flash. Powering off the switch without clicking on Save Configuration will cause loss of new settings. After selecting Save Configuration, click on Save to Flash to save your new configuration.
4.15 Logout The switch provides 2 logout methods. The web connection will be logged out if you don’t input any command after 30 seconds. The Logout command allows you to manually logout the web connection. Click on Yes to logout, No to go back the configuration page. Command Lines: Feature Command Line...
Korenix certificated SFP transceivers when you constructing your network. Korenix will keep on certificating and updating the certificated SFP transceivers in Korenix web site and purchase list. You can refer to the web site to get the latest information about SFP transceivers.
SNMP. But, since some commands can’t be found in standard MIB, Korenix provides Private MIB to meet up the need. Compile the private MIB file by your SNMP tool. You can then use it. Private MIB can be found in product CD or downloaded from Korenix Web site.
Less Time At Work! Fewer Budget on applications! The Korenix business idea is to let you spend less time at work and fewer budget on your applications. Do you really want to go through all the troubles but still end up with low quality products and lousy services? Definitely not! This is why you need Korenix.
Need help?
Do you have a question about the JetNet 5428G Series and is the answer not in the manual?
Questions and answers