Page 2
ORing warrants that all ORing products are free from defects in material and workmanship for a specified warranty period from the invoice date (5 years for most products). ORing will repair or replace products found by ORing to be defective within this warranty period, with shipment expenses apportioned by ORing and the distributor.
Page 4
Static Client List ..................51 5.2.4 DHCP Relay ....................52 Port Setting ....................54 5.3.1 Port Control ....................55 5.3.2 Port Alias ....................56 5.3.3 Port Trunk ....................57 5.3.4 Loop Protection ..................62 VLAN ......................64 ORing Industrial Networking Corp...
Page 5
Security ......................108 5.8.1 Remote Control Security................108 5.8.2 Device Binding ..................108 5.8.3 ACL ......................114 5.8.4 Authentication, Authorization, and Accounting ........... 126 RADIUS Authentication and Accounting Server Status .......... 129 5.8.5 NAS (802.1x).................... 132 ORing Industrial Networking Corp...
-40 C to 75 C, the device can be managed centrally via ORing’s proprietary Open-Vision platform as well as via Web-based interfaces, Telnet, and console (CLI). The switch is one of the most reliable choices for highly-managed and fiber Ethernet applications.
7. Reset button 8. Power input 9. Console port 10. Link/Act LED for SFP port 11. SFP port 12. Link/action LED for Gigabit Ethernet ports 13. Gigabit Ethernet ports 14. Speed LED for Gigabit Ethernet ports ORing Industrial Networking Corp...
4x100Base-FX ports, SS/MM mode, SC connector. 2.3 Rear Panel On the rear panel of the switch sit four screw holes in square pattern for Din-rail installation. For more information on installation, please refer to 3.1 Din-rail Installation. ORing Industrial Networking Corp...
Then slide the switch onto a DIN-rail from the DIN-rail kit and make sure the switch clicks into the rail firmly. 3.2 Wall-mount Installation The device can be installed on the wall horizontally or vertically using the wall-mount kits in the package. ORing Industrial Networking Corp...
Page 13
Step 1: Screw the two pieces of wall-mount kits onto the back of the switch. The wall-mount kits can be attached to the right and left sides or the top and bottom of the switch. Step 2: Use the switch, with wall mount plates attached, as a guide to mark the correct ORing Industrial Networking Corp...
Follow the steps below to wire redundant power inputs. Step 1: insert the negative/positive wires into the V-/V+ terminals, respectively. ORing Industrial Networking Corp...
With 10/100/1000Base-T(X) cables, pins 1 and 2 are used for transmitting data, and pins 3 and 6 are used for receiving data. 10/100Base-T(X) RJ-45 Pin Assignments: Pin Number Assignment Not used Not used Not used Not used 1000Base-T RJ-45 Pin Assignments: Pin Number Assignment BI_DA+ BI_DA- ORing Industrial Networking Corp...
The switch comes with SFP ports that can connect to other devices using SFP modules. The SFP modules are hot-swappable input/output devices that can be plugged into the SFP ports to connect the switch with the fiber-optic network. Remember that the TX port of Switch A ORing Industrial Networking Corp...
For information about the port setting, please refer to 4.1.2 Configurations. 3. Connect the last switch to the first switch to form a ring topology. ORing Industrial Networking Corp...
Page 18
For more information on port setting, please refer to 4.1.2 Configurations. Once the setting is completed, one of the connections will act as the main path while the other will act as the backup path. ORing Industrial Networking Corp...
Page 19
(see 4.1.2 Configurations). 3. Once the setting is completed, one of the connections will act as the main path, and the other as the backup path. ORing Industrial Networking Corp...
Page 20
IGS-9122GPM_CVTL User Manual ORing Industrial Networking Corp...
4.1 O-Ring 4.1.1 Introduction O-Ring is ORing's proprietary redundant ring technology, with recovery time of less than 30 milliseconds (in full-duplex Gigabit operation) or 10 milliseconds (in full-duplex Fast Ethernet operation) and up to 250 nodes. The ring protocols identify one switch as the master of the network, and then automatically block packets from traveling through any of the network’s...
Page 22
Select a port from the drop-down list to act as the homing port. Save Click to save the configurations. Note: due to heavy loading, setting one switch as ring master and coupling ring at the same time is not recommended. ORing Industrial Networking Corp...
IGS-9122GPM_CVTL User Manual 4.2 O-Chain 4.2.1 Introduction O-Chain is ORing’s revolutionary network redundancy technology which enhances network redundancy for any backbone networks, providing ease-of-use and maximum fault-recovery swiftness, flexibility, compatibility, and cost-effectiveness in a set of network redundancy topologies. The self-healing Ethernet technology designed for distributed and complex...
50 devices and will enable a back-up link in 80ms (adjustable to max. 200ms/500ms). 4.3.2 Configurations Label Description Enable Enables the MRP function Manager Every MRP topology needs a MRP manager. One MRP topology can only have a Manager. If two or more switches are ORing Industrial Networking Corp...
50 seconds, RSTP can shorten the time to 5 to 6 seconds. In other words, RSTP provides faster spanning tree convergence after a topology changes. The switch supports STP and will auto detect the connected device running on STP or RSTP protocols. 4.4.1 STP Bridge Setting ORing Industrial Networking Corp...
2 x (Forward Delay Time value –1) > = Max Age value >= 2 x (Hello Time value +1) 4.4.2 MSTI Mapping This page allows you to examine and adjust the configuration of STP MSTI. This function will ORing Industrial Networking Corp...
MSTI. (Range: 1-4094) 4.4.3 MSTI Priorities You can configure the bridge priority for the CIST and any configured MSTI. Remember that RSTP will look up each MST Instance as a single bridge node. ORing Industrial Networking Corp...
IGS-9122GPM_CVTL User Manual Label Description Instance identifier to configure. MSTI The priority of a spanning tree instance. Priority 4.4.4 CIST Ports This page allows you to configure CIST ports including physical and aggregated ports. ORing Industrial Networking Corp...
Page 29
BPDU's are received on the port. Restricted – Role Enabling this function will prevent the port from being selected as Root Port for the CIST or any MSTI, even if it has the best ORing Industrial Networking Corp...
This page allows you to configure STA attributes for interfaces in a specific MSTI, including path cost, and port priority. You may use a different priority or path cost for ports of the same media type to indicate the preferred path. ORing Industrial Networking Corp...
Page 31
As this parameter is used by the STA to determine the best path between devices, lower values are suggested for ports attached to faster media, and higher values for ports with slower media. (Path cost takes precedence over port ORing Industrial Networking Corp...
Spanning Tree network. Root Cost: the path cost from the root port on this switch to the root device. The cost for the root bridge zero. For all ORing Industrial Networking Corp...
Page 33
(i.e., root port), connecting a LAN through the bridge to the root bridge (i.e., designated port); or is an alternate or backup port that may provide connectivity if other bridges, bridge ports, or LANs fail or are removed. ORing Industrial Networking Corp...
RSTP states. Uptime The time since the bridge port was last initialized. 4.4.7 Port Status This page shows the STA functional status of participating ports. ORing Industrial Networking Corp...
RSTP: the number of RSTP Configuration BPDUs received/ transmitted on a port. RTP: the number of legacy STP Configuration BPDU's received/ transmitted on a port. TCN: the number of (legacy) Topology Change Notification ORing Industrial Networking Corp...
Label Description Enable Activate fast recovery mode. Recovery Priority Specify the recovery priority for each port. Save Click to save the configurations. ORing Industrial Networking Corp...
Type http:// and the IP address of the switch. Press Enter. The login screen appears. Type in the username and password. The default username and password is admin. Click Enter or OK button and the main interface of the management page appears. ORing Industrial Networking Corp...
5.1 Basic Settings The Basic Settings page allows you to configure the basic functions of the switch. 5.1.1 System Information This page shows the general information of the switch. ORing Industrial Networking Corp...
Click to undo any changes made locally and revert to previously Reset saved values. 5.1.2 Admin Password This page allows you to configure the system password required to access the web pages or log in from CLI. ORing Industrial Networking Corp...
If none of the configured authentication servers are active, the Fallback local user database is used for authentication. This is only possible if Authentication Method is set to a value other than none or local. Save Click to save changes ORing Industrial Networking Corp...
IP Router is 192.168.10.254. Provides the managed VLAN ID. The allowed range is 1 through VLAN ID 4095. Save Click to save changes. Click to undo any changes made locally and revert to previously Reset saved values. ORing Industrial Networking Corp...
It can also represent a legally valid IPv4 address. For example, '::192.1.2.34'. Save Click to save changes Reset Click to undo any changes made locally and revert to previously ORing Industrial Networking Corp...
Specify the acronym of the time zone. Disabled: disable daylight saving time function. Recurring: with this enabled, summer time will start and end on Daylight Saving Time the specified days every year. You need to set the start, end, and offset times. ORing Industrial Networking Corp...
SSH (Secure Shell) is a cryptographic network protocol intended for secure data transmission and remote access by creating a secure channel between two networked PCs. You can configure the SSH mode in the following page. Label Description ORing Industrial Networking Corp...
This page allows you to examine and configure current LLDP port settings. ORing Industrial Networking Corp...
Page 46
LLDP information received from its neighbors. LLDP Neighbors This page provides a status overview for all LLDP neighbors. The following table contains information for each port on which an LLDP neighbor is detected. The columns include the following information: ORing Industrial Networking Corp...
Page 47
Port Statistics This page provides an overview of all LLDP traffic. Two types of counters are shown. Global counters will apply settings to the whole switch stack, while local counters will apply settings to specified switches. ORing Industrial Networking Corp...
Page 48
"too many neighbors" in the LLDP standard. LLDP frames require a new entry in the table if Chassis ID or Remote Port ID is not included in the table. Entries are removed from the ORing Industrial Networking Corp...
When the NTP client is enabled, the switch regularly sends a request for a time update to a configured time server. A maximum of five time servers are supported. The switch will attempt to poll each server in the configured sequence. ORing Industrial Networking Corp...
The protocol is commonly used in SCADA systems for communications between a human-machine interface (HMI) and programmable logic controllers. This page enables you to enable and disable Modbus TCP support of the switch. ORing Industrial Networking Corp...
5.2.1 Settings This page allows you to set up DHCP settings for the switch. You can check the Enabled checkbox to activate the function. Once the box is checked, you will be able to input ORing Industrial Networking Corp...
You can assign a specific IP address within the dynamic IP range to a specific port. When a device is connected to the port and requests for dynamic IP assigning, the switch will assign the IP address that has previously been assigned to the connected device. ORing Industrial Networking Corp...
Indicates the DHCP relay server IP address. A DHCP relay agent is used to forward and transfer DHCP messages between the clients and the server when they are not in the same subnet domain. Relay Information Mode Indicates the existing DHCP relay information mode. The ORing Industrial Networking Corp...
Page 54
Keep: keep the original relay information when a DHCP message containing the information is received. Drop: drop the package when a DHCP message containing the information is received. The relay statistics shows the information of relayed packets of the switch. ORing Industrial Networking Corp...
The number of packets whose relay agent information is retained Drop Agent Option The number of packets dropped when received messages contain relay agent information. 5.3 Port Setting Port Setting allows you to manage individual ports of the switch, including traffic, power, and trunks. ORing Industrial Networking Corp...
The Rx and Tx settings are determined by the result of the last auto-negotiation. You can check the Configured column to use flow control. This setting is related to the setting of Configured Link Speed. ORing Industrial Networking Corp...
Click to refresh the page. Any changes made locally will be Refresh undone. 5.3.2 Port Alias You can assign a port alias name for each port to enable easy identification of the devices connected to the port. ORing Industrial Networking Corp...
IP address, or uncheck to disable. By default, IP Address is enabled. TCP/UDP Port Calculates the destination port of the frame. You can check this Number box to enable the TCP/UDP port number, or uncheck to disable. By default, TCP/UDP Port Number is enabled. ORing Industrial Networking Corp...
Page 59
This page allows you to enable LACP functions to group ports together to form single virtual links and change associated settings, thereby increasing the bandwidth between the switch and other LACP-compatible devices. ORing Industrial Networking Corp...
Page 60
(speak if spoken to). Save Click to save changes Click to undo changes made locally and revert to previous Reset values LACP System Status This page provides a status overview for all LACP instances. ORing Industrial Networking Corp...
Page 61
The format is: "Switch ID:Port". Refresh Click to refresh the page immediately Check to enable an automatic refresh of the page at regular Auto-refresh intervals LACP Port Status This page provides an overview of the LACP status for all ports. ORing Industrial Networking Corp...
Page 62
The partner’s port number associated with the port Refresh Click to refresh the page immediately Check to enable an automatic refresh of the page at regular Auto-refresh intervals LACP Port Statistics This page provides an overview of the LACP statistics for all ports. ORing Industrial Networking Corp...
This function will send a control frame on the participating ports, and the switch monitors inbound traffic to see if the frame is looped back. When receiving loop packets, the port will be disabled automatically, preventing the loop attack from affecting other network devices. ORing Industrial Networking Corp...
Page 64
Shutdown Port, Shutdown Port, and Log or Log Only. Tx Mode Controls whether the port is actively generating loop protection PDUs or only passively look for looped PDUs. This page shows the status of loop protection. ORing Industrial Networking Corp...
After clicking Save, the new VLAN will be enabled on the selected Add New VLAN switch stack but contains no port members. A VLAN without any port members on any stack will be deleted when you click Save. Click Delete to undo the addition of new VLANs. ORing Industrial Networking Corp...
VLAN of the frame, the frame will be discarded. By default, ingress filtering is disabled (no check mark). Determines whether the port accepts all frames or only Frame Type tagged/untagged frames. This parameter affects VLAN ingress processing. If the port only accepts tagged frames, untagged ORing Industrial Networking Corp...
Page 67
2. If the TPID of tagged frame is not the Egress Rule. 0x8100 (ex. 0x88A8), it will be discarded. C-port When the port receives untagged frames, The TPID of a frame ORing Industrial Networking Corp...
Page 68
2. If the TPID of tagged frame is not the user via Ethertype 0x88A8 (ex. 0x8100), it will be discarded. for Custom S-ports. Below are the illustrations of different port types: ORing Industrial Networking Corp...
Page 69
IGS-9122GPM_CVTL User Manual ORing Industrial Networking Corp...
Page 70
IGS-9122GPM_CVTL User Manual Examples of VLAN Settings VLAN Access Mode: Switch Port 7 is VLAN Access mode = Untagged 20 Port 8 is VLAN Access mode = Untagged 10 Below are the switch settings. ORing Industrial Networking Corp...
Page 71
IGS-9122GPM_CVTL User Manual VLAN 1Q Trunk Mode: Switch Port 1 = VLAN 1Qtrunk mode = tagged 10, 20 Port 2 = VLAN 1Qtrunk mode = tagged 10, 20 Below are the switch settings. ORing Industrial Networking Corp...
Page 72
Port 1 VLAN Hybrid mode = untagged 10 Tagged 10, 20 Below are the switch settings. VLAN QinQ Mode: VLAN QinQ mode is usually adopted when there are unknown VLANs, as shown in the figure below VLAN “X” = Unknown VLAN ORing Industrial Networking Corp...
Page 73
IGS-9122GPM_CVTL User Manual 9000 Series Port 1 VLAN Settings: VLAN ID Settings When setting the management VLAN, only the same VLAN ID port can be used to control the switch. 9000 ies VLAN Settings: ORing Industrial Networking Corp...
Indicates the ID of this particular private VLAN. A row of check boxes for each port is displayed for each private Port Members VLAN ID. You can check the box to include a port in a private ORing Industrial Networking Corp...
By default, port isolation is disabled for all ports. 5.5 SNMP SNMP (Simple Network Management Protocol) is a protocol for managing devices on IP networks. It is mainly used network management systems to monitor the operational status of ORing Industrial Networking Corp...
Indicates the SNMPv3 engine ID. The string must contain an even number between 10 and 64 hexadecimal digits, but all-zeros and Engine ID all-'F's are not allowed. Change of the Engine ID will clear all original local users. ORing Industrial Networking Corp...
Page 77
16-bit groups of contiguous zeros; but it can only appear once. It also uses a following legally IPv4 address. For example, '::192.1.2.34'. Trap Authentication Indicates the SNMP entity is permitted to generate authentication ORing Industrial Networking Corp...
Check to delete the entry. It will be deleted during the next save. Indicates the community access string to permit access to SNMPv3 Community agent. The allowed string length is 1 to 32, and only ASCII characters from 33 to 126 are allowed. ORing Industrial Networking Corp...
Possible security models include: NoAuth, NoPriv: no authentication and none privacy Security Level Auth, NoPriv: Authentication and no privacy Auth, Priv: Authentication and privacy The value of security level cannot be modified if the entry already ORing Industrial Networking Corp...
SNMP group uses. Each SNMP group name and security model pair must be unique. This page allows you to configure the SNMPv3 group table. The entry index keys are Security Model and Security Name. ORing Industrial Networking Corp...
You can specify specific areas of the MIB that can be accessed or denied based on the entries or create and delete entries in the View table in this page. The entry index keys are View Name and OID Subtree. ORing Industrial Networking Corp...
The allowed string length is 1 to 32, and only ASCII characters from 33 to 126 are allowed. Indicates the security model that this entry should belong to. Security Model Possible security models include: any: Accepted any security model (v1|v2c|usm). ORing Industrial Networking Corp...
Note: frames sent to the CPU of the switch are always limited to approximately 4 kpps. For example, broadcasts in the management VLAN are limited to this rate. The management VLAN is configured on the IP setup page. ORing Industrial Networking Corp...
QoS class, queue, and priority. A QoS class QoS Class of 0 (zero) has the lowest priority. If the port is VLAN aware and the frame is tagged, then the frame is classified to a QoS class that is based on the PCP ORing Industrial Networking Corp...
Page 85
DEI value. Shows the classification mode for tagged frames on this port Disabled: Use default QoS class and DP level for tagged Tag Class frames Enabled: Use mapped versions of PCP and DEI for tagged ORing Industrial Networking Corp...
Classified: use classified PCP/DEI values Mode Default: use default PCP/DEI values Mapped: use mapped versions of QoS class and DP level Click on an entry in the Port field will take you to the configuration page of the remarking mode ORing Industrial Networking Corp...
Page 87
You can choose three tag remarking modes including Classified, Default, and Mapped. Classified will use classified PCP (Priority Code Point or User Priority) and DEI (Drop Eligible Indicator) values. Default will use default PCP/DEI values. Mapped will use mapped versions of QoS class and drop precedence level. ORing Industrial Networking Corp...
DSCP value of the data packet and put the packet into different queues before transmission, such as high priority and most efficient transmission. With such QoS functions, you can ensure low-latency for critical traffic. This page allows you to configure DSCP settings for each port. ORing Industrial Networking Corp...
When the traffic rate exceeds the configured maximum rate, policing drops or remarks the excess traffic. This page allows you to configure Policer for all switch ports. ORing Industrial Networking Corp...
Mbps, fps, or kfps. The default value is kbps. If Flow Control is enabled and the port is in Flow Control mode, Flow Control then pause frames are sent instead of being discarded. 5.6.6 Queue Policing ORing Industrial Networking Corp...
The SP algorithm is preferred when the received packets contain high priority data, such as voice and video. ORing Industrial Networking Corp...
Page 92
IGS-9122GPM_CVTL User Manual Click on the port number will lead to the following page. ORing Industrial Networking Corp...
Page 93
A queue is given an amount of bandwidth regardless of the incoming traffic on that port. Queue with larger weights will have more guaranteed bandwidth than others with smaller weights. ORing Industrial Networking Corp...
Page 94
Allows the queue to use excess bandwidth Excess Configures the weight of each queue. The default value is 17. Queue Scheduler This value is restricted to 1 to 100. This parameter is only shown if Weight Scheduler Mode is set to Weighted. ORing Industrial Networking Corp...
When configuring port shaping on an interface, you specify a value indicating the maximum amount of traffic allowable for the interface. This value must be less than the maximum bandwidth for that interface. ORing Industrial Networking Corp...
Check to trust a specific DSCP value. Only frames with trusted DSCP values are mapped to a specific QoS class and drop Trust precedence level. Frames with untrusted DSCP values are treated as a non-IP frame. ORing Industrial Networking Corp...
2. Classify: Enable Classification at ingress side as defined in the QoS Port DSCP Configuration table. Configurable engress parameters include; Egress Remap DP0: R e-maps DP0 field to selected DSCP value. DP0 indicates a drop precedence with a low priority. You can select the ORing Industrial Networking Corp...
This page shows all the QCE (Quality Control Entries) for a given QCL. You can edit or add new QoS control entries in this page. A QCE consists of several parameters. These parameters vary with the frame type you select. ORing Industrial Networking Corp...
Page 99
This option can only be used to filter Ethernet II formatted packets. You can choose Ethernet type as Any or Specific which allows you to specify a value ranging from 0x600 to 0xFFFF. The default value is Any. ORing Industrial Networking Corp...
Page 100
Any. SNAP SNAP (SubNetwork Access Protocol) can be distinguished by an OUI and a Protocol ID. If the OUI is hexadecimal 000000, the protocol ID is the Ethernet type (EtherType) field value for the ORing Industrial Networking Corp...
Page 101
IP Fragment: indicates whether or not fragmented packets are accepted. Fragmentation can ensure data pass through a network device whose maximum transfer unit is smaller than the original packet’s size. ORing Industrial Networking Corp...
Page 102
Valid Drop Precedence Level value can be (0-1) or Default. Valid DSCP value can be (0-63, BE, CS1-CS7, EF or AF11-AF43) or Default. Default means that the default classified value is not modified by this QCE. ORing Industrial Networking Corp...
The switch port number to which the following settings will be Port applied. There are 8 QoS queues per port. Q0 is the lowest priority Rx / Tx The number of received and transmitted packets per queue ORing Industrial Networking Corp...
Description User Indicates the QCL user QCE# Indicates the index of QCE Indicates the type of frame to look for incoming frames. Possible Frame Type frame types are: Any: the QCE will match all frame type. ORing Industrial Networking Corp...
Per Page field. By default, the page will show the first 20 entries from the beginning of the VLAN table. The first displayed will be the one with the lowest VLAN ID found in the VLAN Table. ORing Industrial Networking Corp...
Check to enable IGMP snooping for individual VLAN. Up to 32 Enable VLANs can be selected. IGMP Querier Check to enable the IGMP Querier in the VLAN 5.7.3 IGMP Snooping Status This page provides IGMP snooping status. ORing Industrial Networking Corp...
Information about entries in the IGMP Group Table is shown in this page. The IGMP Group Table is sorted first by VLAN ID, and then by group. Label Description VLAN ID The VLAN ID of the group Groups The group address of the group displayed Port Members Ports under this group ORing Industrial Networking Corp...
Check to delete entries. 5.8.2 Device Binding Device binding is ORing's proprietary technology which binds the IP/MAC address of a device with a specified Ethernet port. If the IP/MAC address of the device connected to the Ethernet port does not conform to the binding requirements, the device will be locked for security concerns.
Page 110
Specifies IP address of the device. Device Specifies MAC address of the device. Address Alias IP Address This page provides alias IP address configuration. Some devices might have more than one IP addresses. You could specify other IP addresses here. ORing Industrial Networking Corp...
Page 111
Alive-checking packets will be sent to the device to probe if the device is running. If the switch receives no response from the device, actions will be taken according to your configurations. Label Description Link Change Disables or enables the port. ORing Industrial Networking Corp...
Page 112
If packet type is UDP (or TCP), please specify the socket number Socket Number here. The socket number can be a range, from low to high. If the socket number is only one, please fill the same number in the low ORing Industrial Networking Corp...
Page 113
Running: analysis completes and ready for next move. Attacked: DDOS attacks occur. Device Description This page allows you to configure device description settings. Label Description Indicates device types. Possible types are: Device Type ---: no specification. ORing Industrial Networking Corp...
Page 114
Label Description Mode Enables or disables stream monitoring of the port Indicates the action to take when the stream gets low. Possible actions are: Action ---: no action. Log it: simply logs the event. ORing Industrial Networking Corp...
Shutdown Enabled: if a frame is received on the port, the port will be disabled. Disabled: port shut down is disabled. The default value is Disabled. Counter Counts the number of frames that match this ACE. ORing Industrial Networking Corp...
Page 116
An ACE (Access Control Entry) is an element in an access control list (ACL). An ACL can have zero or more ACEs. Each ACE controls or monitors access to an object based on user-defined configurations. Each ACE consists of several parameters which vary with the frame type you have selected. ORing Industrial Networking Corp...
Page 117
IEEE 802.3 descripts the value of length/types should be greater than or equal to 1536 decimal (equal to 0600 hexadecimal). Frame Type ARP: only ARP frames can match the ACE. Notice the ARP frames will not match the ACE with Ethernet type. ORing Industrial Networking Corp...
Page 118
Specifies the shutdown operation of the ACE. The allowed values are: Shutdown Enabled: if a frame matches the ACE, the ingress port will be disabled. Disabled: port shutdown is disabled for the ACE. Counter Indicates the number of times the ACE matched by a frame. ORing Industrial Networking Corp...
Page 119
DMAC value appears. When Specific is selected for the DMAC filter, you can enter a specific destination MAC address. The legal format DMAC Value is "xx-xx-xx-xx-xx-xx". Frames matching the ACE will use this DMAC value. ORing Industrial Networking Corp...
Page 120
Specifies the tag priority for the ACE. A frame matching the ACE will Tag Priority use this tag priority. The allowed number range is 0 to 7. Any means that no tag priority is specified (tag priority is "don't-care"). ORing Industrial Networking Corp...
Page 121
No: IPv4 frames whose options flag is set must not be able to match this entry. IP Option Yes: IPv4 frames whose options flag is set must be able to match this entry. Any: any value is allowed ("don't-care"). SIP Filter Specifies the source IP filter for this ACE. ORing Industrial Networking Corp...
Page 122
DIP mask in dotted decimal notation. Label Description Specifies the available ARP/RARP opcode (OP) flag for the ACE ARP/RARP Any: no ARP/RARP OP flag is specified (OP is "don't-care"). ARP: frame must have ARP/RARP opcode set to ARP. ORing Industrial Networking Corp...
Page 123
Any: any value is allowed ("don't-care"). Specifies whether frames will meet the action according to their RARP SMAC target hardware address field (THA) settings. Match 0: RARP frames where THA is not equal to the SMAC address ORing Industrial Networking Corp...
Page 124
Description Specifies the ICMP filter for the ACE. ICMP Type Filter Any: no ICMP filter is specified (ICMP filter status is "don't-care"). Specific: if you want to filter a specific ICMP filter with the ACE, you ORing Industrial Networking Corp...
Page 125
TCP/UDP source value appears. Range: if you want to filter a specific TCP/UDP source range filter with the ACE, you can enter a specific TCP/UDP source range. A field for entering a TCP/UDP source value appears. ORing Industrial Networking Corp...
Page 126
ACE TCP SYN 0: TCP frames where the SYN field is set must not be able to match this entry. 1: TCP frames where the SYN field is set must be able to match this ORing Industrial Networking Corp...
AAA server is RADIUS (Remote Authentication Dial-In User Service). RADIUS is a protocol used between the switch and the authentication server. This page allows you to configure common settings for an authentication server. ORing Industrial Networking Corp...
Page 128
The NAD then establishes or terminates the user's connection. The NAD may then forward accounting information to the RADIUS server to document the transaction; the RADIUS server may store or forward this information as needed to support billing for the services provided. ORing Industrial Networking Corp...
Page 129
The secret - up to 29 characters long - shared between the RADIUS authentication server and the switch stack. Label Description The RADIUS accounting server number for which the configuration below applies. ORing Industrial Networking Corp...
Disabled: the server is disabled. Status Not Ready: the server is enabled, but IP communication is not yet up and running. Ready: the server is enabled, IP communications are built, and the RADIUS module is ready to accept access attempts. ORing Industrial Networking Corp...
Page 131
When you click on the port number in RADIUS Overview page, you will see this pages showing the access statistics of the authentication and accounting servers. Use the server drop-down list to switch between the backend servers to show related details. ORing Industrial Networking Corp...
Page 132
IGS-9122GPM_CVTL User Manual Label Description RADIUS authentication server packet counters. There are seven ‘receive’ and four ‘transmit’ counters. Packet Counters This section contains information about the state of the server and the latest round-trip time. Other Info ORing Industrial Networking Corp...
A NAS (Network Access Server) is an access gateway between an external communications network and an internal network. For example, when the user dials into the ISP, he/she will be given access to the Internet after being authorized by the access server. The authentication ORing Industrial Networking Corp...
Page 134
This scenario will loop forever. Therefore, the server timeout should be smaller than the supplicant's EAPOL Start frame retransmission rate. ORing Industrial Networking Corp...
Page 135
The disadvantage is that MAC addresses can be spoofed by malicious users, equipment whose MAC address is a valid RADIUS user can be used by anyone, and only the MD5-Challenge method is supported. 802.1X and MAC-Based authentication configurations consist of two sections: system- and port-wide. ORing Industrial Networking Corp...
Page 136
Determines the period, in seconds, after which a connected client Reauthentication must re-authenticated. This only active Period Reauthentication Enabled checkbox is checked. Valid range of the value is 1 to 3600 seconds. Determines the time for retransmission of Request Identity EAPOL Timeout EAPOL frames. ORing Industrial Networking Corp...
Page 137
In this mode, the switch will send one EAPOL Success frame Admin State when the port link is up, and any client on the port will be allowed network access without authentication. Force Unauthorized In this mode, the switch will send one EAPOL Failure frame when ORing Industrial Networking Corp...
Page 138
EAPOL Start frame from the supplicant. Since the server has not failed (because the X seconds have not expired), the same server will be contacted when the next backend authentication server request from the switch This scenario will ORing Industrial Networking Corp...
Page 139
Each supplicant is authenticated individually and secured in the MAC table using the Port Security module. In Multi 802.1X it is not possible to use the multicast BPDU MAC ORing Industrial Networking Corp...
Page 140
The advantage of MAC-based authentication over port-based 802.1X is that several clients can be connected to the same port (e.g. through a 3rd party switch or a hub) and still require individual authentication, and that the clients don't need special ORing Industrial Networking Corp...
Page 141
Reinitialize: forces a reinitialization of the clients on the port and hence a reauthentication immediately. The clients will transfer to the unauthorized state while the reauthentication is in progress. ORing Industrial Networking Corp...
Page 142
This page provides detailed IEEE 802.1X statistics for a specific switch port using port-based authentication. For MAC-based ports, only the statistics of selected backend server statistics will be shown. Use the drop-down list to select which port details to be displayed. ORing Industrial Networking Corp...
As Syslog messages are UDP-based, the sender and receiver will not be aware of it if the packet is lost due to network disconnection and no UDP packet will be resent. ORing Industrial Networking Corp...
Page 144
DNS functions, it also can be a host name. SMTP Setting SMTP (Simple Mail Transfer Protocol) is a protocol for transmitting e-mails across the Internet. By setting up SMTP alert, the device will send a notification e-mail when a user-defined event occurs. ORing Industrial Networking Corp...
Page 145
Event Selection The device supports both SYSLOG and SMTP alerts. Check the corresponding box to enable the system event warning method you want. Please note that the checkboxes will gray out if SYSLOG or SMTP is disabled. ORing Industrial Networking Corp...
MAC table are added or removed manually and cannot age out by themselves. Entries in a dynamic MAC tablet will age out after a configured aging time. Such entries can be added by learning or manual configuration. ORing Industrial Networking Corp...
Page 147
An example of such a module is MAC-Based authentication under 802.1X. ORing Industrial Networking Corp...
Page 148
VLAN ID, MAC address, and port members for the new entry. Entry Click Save to save the changes. MAC Table Status Each page shows up to 999 entries from the MAC table, with a default value of 20, selected by ORing Industrial Networking Corp...
The MAC address of the entry. VLAN The VLAN ID of the entry. Port Members The ports that are members of the entry. 5.10.2 Port Statistics Traffic Overview This page provides an overview of general traffic statistics for all switch ports. ORing Industrial Networking Corp...
Page 150
The displayed counters include the total number for receive and transmit, the size for receive and transmit, and the errors for receive and transmit. Detailed Statistics – Total Receive & Transmit ORing Industrial Networking Corp...
Page 151
The number of MAC Control frames received or transmitted on this Rx and Tx Pause port that have an opcode indicating a PAUSE operation. Rx Drops The number of frames dropped due to insufficient receiving buffer or ORing Industrial Networking Corp...
The traffic to be copied to the mirror port can be all frames received on a given port (also known as ingress or source mirroring) or all frames transmitted on a given port (also known as egress or destination mirroring). The port to which the monitored traffic is copied is called mirror port. ORing Industrial Networking Corp...
Updates system log entries, starting from the current entry ID. Clear Flushes all system log entries. |<< Updates system log entries, starting from the first available entry ID << Updates system log entries, ending at the last entry currently ORing Industrial Networking Corp...
Cable Status Port: port number. Pair: the status of the cable pair. Length: the length (in meters) of the cable pair. 5.10.6 SFP Monitor SFP modules with DDM (Digital Diagnostic Monitoring) function can measure the temperature ORing Industrial Networking Corp...
64 bytes from ::10.10.132.20: icmp_seq=2, time=0ms 64 bytes from ::10.10.132.20: icmp_seq=3, time=0ms 64 bytes from ::10.10.132.20: icmp_seq=4, time=0ms Sent 5 packets, received 5 OK, 0 bad You can configure the following properties of the issued ICMP packets ORing Industrial Networking Corp...
5.11.1 PTP PTP External Clock Mode is a protocol for synchronizing clocks throughout a computer network. On a local area network, it achieves clock accuracy in the sub-microsecond range, making it suitable for measurement and control systems. ORing Industrial Networking Corp...
Page 157
Indicates the type of the clock instance. There are five device types. Ord-Bound: ordinary/boundary clock. P2p Transp: peer-to-peer transparent clock. E2e Transp: end-to-end transparent clock. Master Only: master only. Slave Only: slave only. Port List Set check mark for each port configured for this Clock Instance. ORing Industrial Networking Corp...
Page 158
Port Type != Unaware and PortVLAN mode == None, and the port is member of the VLAN. VLAN identifiers used for tagging the PTP frames. Priority code point values used for PTP frames. You can click on Status link to read the details of your configuration. ORing Industrial Networking Corp...
Click to return to the Port State page without resetting. 5.12.2 System Reboot You can reset the stack switch on this page. After reset, the system will boot normally as if you have powered on the devices ORing Industrial Networking Corp...
Page 160
IGS-9122GPM_CVTL User Manual Label Description Click to reboot device. Click to return to the Port State page without rebooting. ORing Industrial Networking Corp...
Follow the steps below to access the console via RS-232 serial cable. Step 1: On Windows desktop, click on Start -> Programs -> Accessories -> Communications -> Hyper Terminal Step 2. Input a name for the new connection. ORing Industrial Networking Corp...
Page 162
IGS-9122GPM_CVTL User Manual Step 3. Select a COM port in the drop-down list. Step 4. A pop-up window that indicates COM port properties appears, including bits per second, data bits, parity, stop bits, and flow control. ORing Industrial Networking Corp...
Page 163
Step 5. The console login screen will appear. Use the keyboard to enter the Username and Password (same as the password for Web browsers), then press Enter. CLI Management by Telnet You can can use TELNETto configure the switch. The default values are: IP Address: 192.168.10.1 ORing Industrial Networking Corp...
Page 164
Step 1. Telnet to the IP address of the switch from the Run window by inputingcommands (or from the MS-DOS prompt) as below. Step 2. The Login screen will appear. Use the keyboard to enter the Username and Password (same as the password for Web browser), and then press Enter. ORing Industrial Networking Corp...
Page 165
IGS-9122GPM_CVTL User Manual Commander Groups ORing Industrial Networking Corp...
Need help?
Do you have a question about the IGS-9122GPM and is the answer not in the manual?
Questions and answers