Page 1
Operating Instructions 19"- RY-Switches of the L-series RY Industrial-Switches of the L-series - RY-LGS23-26 RY-LPIGE-602GBTME - RY-LGSO25-24 - RY-LPIGE-804GBTME - RY-LGSO25-28 - RY-LPITE-802GBTME - RY-LGSP16-10 - RY-LPITE-804GBTME - RY-LGSP23-10G - RY-804GBTME, without PoE - RY-LGSP23-26/xxx - RY-LGSP23-28/xxx - RY-LGSP23-52/xxx RY-LGSPTR23-26...
Page 2
Kommunikation. Registered trademark barox® is a registered and protected trademark of the barox Kommunikation company. Any other registered trademark or registered brand mentioned in this manual is the property of the respective manufacturer.
5.1.4. Port Security with Limit Control Settings Use and Protection of IP Functions (Layer 3) 5.2.1. DHCP Server 5.2.2. Protection of DHCP by ARP Inspection 5.2.3. IP Source Guard Protection of the Switch Management and Network Administration (Layer 3–7) 5.3.1. User Management and Configuration barox Kommunikation...
Page 4
5.5.3. Supplementary Information regarding the Sending of SNMP Traps Reading SNMP Traps Use of MIB Files for Reading-out and Control of the Switches Control of Switch Functions via SNMP and MIB using the „SET“ Operation Firmware Upgrade Factory Defaults Server Report WARRANTY barox Kommunikation...
In all situations where a network is required to transmit high -quality video content fast and securely, barox Kommunikation’s range of POWERHAUS switches guarantee pioneering connections. barox Kommunikation designs, coordinates and supplies everything fr om a simple, point-to-point connection to a large area network running multicast applications. Website Information on our full range of switches as well as download links to our data sheets, documentation and the latest firmware are available on our webs ite: www.barox.ch.
To log in, the user simply enters the user name and password listed above. Once the login process has been successfully completed, the “System Information” page is automatically displayed showing the most important information on the switch. barox Kommunikation...
System Information This page displays the most important information on the switch. Key: Name of the switch model Firmware version Hardware version MAC address barox Kommunikation...
This method requires using the console cable supplied with the switch. The console port of the switch is an RS232 interface, i.e. a PC/laptop with a serial interface or a USB-RS232 adapter is required. To configure the switch via the CLI port, we recommend using the “PuTT Y” software. http://www.chip.de/downloads/PuTTY_12997392.html barox Kommunikation...
Time Configuration The system time used by barox Kommunikation switches can either be configured manually or via an NTP server. The whole purpose of defining the time is to use it in the log file. If an error...
If there is no time source available in one’s own network and the time is to be retrieved from an external source via the Internet, it is possible to enter the external NTP server details directly, e.g. 213.209.109.45 at http://www.pool.ntp.org/de/ barox Kommunikation...
1) the time is correct and 2) the system switches correctly between summer and winter time. As soon as the switch can access the time and date, the correct date is shown in the “System Date” field. barox Kommunikation...
− whereby no guarantee is supplied that these will function properly. The barox Kommunikation product range includes SFPs for multi and single mode fibres with transmission speeds of 100 Mbps, 1 Gbps and 10 Gbps. Distances of between 550 m and 120 km can be achieved depending on the type of fibre and transmission speed.
Change of User Name and Password barox Kommunikation switches offer the option of generating a number of u sers with different rights. Up to 15 different levels can be defined. Level 15 is the highest level and is intended to be used by the administrators.
“Shutdown Time” shows how long a port is to remain disabled, should a l oop be detected. Possible time entries: 0 – 604,800 s (7 days). If “0” is entered here, the port will remain deactivated until the switch is rebooted. barox Kommunikation...
RSTP is supported by all switch manufacturers - making it compatible with third-party manufacturers. The switch factory default is set to “Bridge Priority” 32768. If the switch is to act as master, the Bridge Priority must be set to “0”. All the other values can be left as they are. barox Kommunikation...
In the above example, the network consists of two central switches (A+B) and 5 other switches that form the ring. All in all, 21 cameras have been installed − each supplying 5 Mbps of video data, i.e. a total of over 100 Mbps of data. barox Kommunikation...
Page 17
➔ Wherever possible, one should aim to realise a configuration that corresponds to the one illustrated in the above image. barox Kommunikation...
(e.g. PoE cameras) can be monitored and rebooted, if required. The PoE chip in the camera can also be reset. This makes sense, for example, in cases where a camera shows no picture although it can be pinged. barox Kommunikation...
= according to the value stated in the “Maximum Power (W)” column Allocation LLDP-Med = ditto Class mode, pulls the information via LLDP (where possible) If the terminal device exceeds the predefined power limit, the port turns PoE off. barox Kommunikation...
To avoid this problem, one can configure the individual ports to start up one after the oth er in the following menu. In the example below, ports 1 and 2 are immediately activated − with 2 more ports then being activated every 10 seconds after that. barox Kommunikation...
After 3 failed attempts, PoE to port 1 is turned off and turned back on after 15 seconds. This forces the camera to reboot. 60 seconds after the camera has rebooted, the ping monitoring mechanism will kick in again. barox Kommunikation...
This means that all changes need to be permanently saved. There are two ways to do this: Diskette symbol on each screen Maintenance/Configuration/Save startup-config menu item Save Configuration barox Kommunikation...
The opposite scenario is uploading a configuration file to the switch. In this case, the path where the file is stored and the respective file type need to be specified. As a rule, this is the “startup- config file”. barox Kommunikation...
(and deactivated at the other switches), resp. Attention shall be paid as some functions can only be used in a limited way and this method is recommended in case of a homogenous structure using barox switches. The master switch can be determined using the IP address in the line „Controller IP“.
Page 25
The connection to a device can be checked − even across a row of switches − simply by clicking on the “Online”, resp. “Offline” symbol in the “Status” column. Should there be in interruption anywhere in the connection chain, this can be seen here. The same information can be checked using the “Maintenance/Diagnostics” menu. barox Kommunikation...
PoE requirement, in as far as the device is a PoE appliance, can also be read. Additionally, by clicking on “Login”, the device can be directly accessed or diagnostics on the connection carried out. The PoE appliance can also be easily rebooted by simply click ing on the “PoE Reboot” icon. barox Kommunikation...
Page 27
IP and MAC address to return and will set the new camera back to the default IP address over and over again despite this having the same IP address. This occurs because the new camera has a different MAC address. barox Kommunikation...
Page 28
Two conditions must be fulfilled for this representation: a) RSTP as ring protocol b) The ring only consists of RY switches supporting the DMS barox Kommunikation...
Page 29
− done. Map View The same function is also possible using Map View. The background image is directly generated using Google Maps. This requires an internet connection and Google licences for using the service. barox Kommunikation...
The path and file name must be entered in the “Floor Image” menu and then uploaded using “Add”. The uploaded plans are then listed in the lower section of the web page. Up to 50 files can be saved. Diagnostics This function was described and explained on page 25 under the heading “Devices List”. barox Kommunikation...
Page 31
This may be extremely useful when looking for the cause of errors, for example, if one sees that at 12 a.m. a large volume of data was generated at port 2 when there were problems with the recording process. barox Kommunikation...
GUI as illustrated thereafter. Some applications require the adjustments of the Ethernet frame sizes. This can also be done in the menu section „Ports Configuration” in the field „Maximum Frame Size” as described in the following screenshot. barox Kommunikation...
5.1.2. Information regarding the general consideration of the bandwidth demand The consideration of the following items is recommended when planning the bandwidth demand and the related deployment of suitable barox switches: Deployment of the required Ethernet standards (10/100/1000/10000) under consideration of possible terminal device upgrades Planning of reserves, scaled at the backplane power of the switch ->...
The use of Limit Control is recommended where unmanaged switches with terminal devices are connected to the barox switch. Basically this function prevents the blocking o f the network communication of further unwanted IP/Ethernet terminals which are connected to free ports of the unmanaged switches.
The setting of the IP address pool, which shall enable the distribution of 50 addresses, i.e. in the range of 192.168.10.100 – 192.168.10.150 by stating the surrounding addresses and IP ranges (exclusion procedure) to the IP clients in the respective VLAN is shown in the following screenshot. barox Kommunikation...
Page 36
Following this a DHCP service name is determined and confirmed. Following the determination of the name the settings are called up by selecting the name as shown below. The following configuration appears upon call-up of the pool name. barox Kommunikation...
At first the Snooping function is generally activated in the menu Snooping Mode as shown below. Furthermore settings can be chosen for the trustworthy switch ports. The mode must be set to „Trusted“ for the inspection function to work. barox Kommunikation...
Page 38
IP addresses by the DHCP service the clients and their layer 2 and 3 characteristics become visible in the dynamic ARP inspection t able and can subsequently be translated into the static ARP inspection table. barox Kommunikation...
Page 39
The following screenshot shows a static entry. An IP address is reserved for the client according to the table. barox Kommunikation...
The switch will block the port‘s network communication where the connected device does not comply with the allocated MAC and IP address. This means, that the attacker must know the MAC address and IP address of the device for gaini ng access to the network. barox Kommunikation...
It is generally recommended not to change the default values. Such rights should be allocated when generating new users . Information: Scaling the rights of a further user on the basis of authorisation and competencies is helpful. barox Kommunikation...
Change of port 80, information: Please pay attention to the port information when accessing via a browser! Access via HTTPs provides the highest level of protection due to the encryption of the connection. The following example shows the entry of the management address using a changed port barox Kommunikation...
The http option should be disabled where this mode is activated. The switch GUI is called up in the browser using the HTTPS protocol phrase https://192.168.XX(IhreManagement IP):1234(IhrPort) in the URL field. Following this the browser communication to t he management interface is effected using encryption. barox Kommunikation...
Generation of the certificate for later use, which can be downloaded and installed using the browser. Upload of an externally generated certificate The browser access is effected following the installation of the certificate and determina tion of the HTTPs authentication method via the HTTPs protocol barox Kommunikation...
SNMP traps. The following steps shall show the use of an SNMP Community. Activation of the SNMP v2 Function The mode should be generally enabled and SNMP v2 should be selected in the SNM P configuration. Furthermore the names for the read and write communities are determined. barox Kommunikation...
Trap Destination Port -> Entry of the port at the recipient Trap Inform Mode -> Disabled in this example Trap Inform Timeout (seconds) -> 3 is entered (Standard) Trap Inform Retry Times -> 5 (Standard) Following this the settings are confirmed by clicking „Apply“. barox Kommunikation...
Page 47
Step 2: Following the generation of a new configuration such configuration is opened by selecting th e name. barox Kommunikation...
Page 48
Activation of the SNMP Trap Function The general mode must be enabled following completion of the trap configuration. barox Kommunikation...
Some events − such like e.g. port events − must also be set accordingly in the port configuration. ATTENTION: For industrial switches, this setting can be found under Configuration/System/Alarm Notification. Further information regarding the reading and testing of the configuration can be found in „5.6 Reading-out SNMP Traps“. barox Kommunikation...
SNMP traps. The following steps shall demonstrate the use of authentication and password protection. 5.5.1. Activation of the SNMP v3 Function The mode should be generally enabled and SNMP v3 should be selected in the SNMP configuration. barox Kommunikation...
Page 52
Generation of a dedicated Community When generating the community the setting of source IP and mask can remain as 0.0.0.0 in each case. This enables the transmission and the receipt of SNMP messages across several subnetworks. barox Kommunikation...
Page 53
„Auth, Priv“ shall also be set along with the determination of the user name. When selecting the authentication „MD5“ and the privacy protocol DES attention shall be paid as the length of both passwords must be at least eight characters (numbers and character combinations). barox Kommunikation...
Page 54
Setting the View Configuration At the beginning the View Name is determined. Setting the OID to a value „.1“ is recommended providing all SNMP-relevant messages can be viewed. This enables the complete view to all distributed OIDs. barox Kommunikation...
„Read View Name“ and „Write View Name“. 5.5.2. SNMP Trap Configuration Prior to the configuration of new trap settings attention should be paid, that the global setting of the trap mode is disabled. barox Kommunikation...
Page 56
Trap Security Name -> Currently only „None“ can be selected Following this the settings are confirmed by clicking „Apply“. Following the confirmation of the configuration a note is displayed, that a respective Security Name should be set. This is configured in step 2. barox Kommunikation...
Page 57
Step 2: Following the generation of a new configuration such configuration is opened by selecting the name. Now the entry „Trap Security Name“ can be set to the SNMP user name. barox Kommunikation...
Page 58
Activation of the SNMP Trap Function The general mode must be enabled following completion of the trap configuration. barox Kommunikation...
Some events − such like e.g. port events − must also be set accordingly in the port configuration. Further information on reading-out and testing the configuration can be found in „5.6 reading SNMP Traps“. barox Kommunikation...
Reading SNMP Traps Various parameters of the barox switch configurations can be rea d out and set, resp., using the SNMP protocol. So-called „SNMP/MIB Browser” are basically required for doing so. But also network-/recording-/ sniffer software can be utilised to read SNMP transmissions.
Page 61
View of the information in the SNMP browser: PoE camera is connected again / PD device is online: Recording of the information, which is sent by the switch: barox Kommunikation...
Step 1: Import of the MIB File During the import attention must be paid for selecting the suitable MIB file for the respective switch. The required MIB files can be identified by their prefix „mib“. barox Kommunikation...
Page 63
* Please pay attention to the respective software vendor‘s licencing conditions when using the software! Following the successful import the MIB structures are available as shown below. barox Kommunikation...
Control of Switch Functions via SNMP and MIB using the „SET“ Operation The „SET” operation via the SNMP protocol can be a further method for controlling barox switches. The basic SNMP configurations at the switch and of the MIB browser are preconditions.
Page 65
„OK“. A respective success message is generated upon a successful operation. Following the upgrade the new firmware is immediately available. Any old firmware can very simply be re-activated in the menu „Firmware Selection“ where the old firmware shall be applied again for some reason. barox Kommunikation...
New features are also introduced. Following the upgrade the new firmware is immediately available. Any old firmware can very simply be re-activated in the menu „Firmware Selection” where the old firmware shall be applied again for some reason. barox Kommunikation...
This is done either via the “Maintenance/Factory Defaults” menu or by pressing the reset button at the front (for longer than 10 seconds). Checking the “Keep IP setup” box ensures that the switch retains the configured IP address. Otherwise, everything is reset to the factory defaults. barox Kommunikation...
8 S e r v e r R e p o r t When submitting a request for support, the server report should also be provided. This contains a description of the whole configuration as well as useful information for the support technician. Excerpt from a Server Report barox Kommunikation...
Kommunikation shall remedy any product defects caused by poor material quality and/or a machining error of which barox Kommunikation is notified during the warranty period. barox Kommunikation shall then decide at their own discretion what measures to take to alleviate the defect. The warranty for any repaired or replaced components shall then continue to apply for the remaining warranty period.
Need help?
Do you have a question about the L Series and is the answer not in the manual?
Questions and answers