Barox L Series Operating Instructions Manual

Barox L Series Operating Instructions Manual

Ry switches
Table of Contents

Advertisement

Operating Instructions
19"- RY-Switches of the L-series
- RY-LGS23-26
- RY-LGSO25-24
- RY-LGSO25-28
- RY-LGSP16-10
- RY-LGSP23-10G
- RY-LGSP23-26/xxx
- RY-LGSP23-28/xxx
- RY-LGSP23-52/xxx
RY-LGSPTR23-26
-
RY Industrial-Switches of the L-series
RY-LPIGE-602GBTME
-
- RY-LPIGE-804GBTME
- RY-LPITE-802GBTME
- RY-LPITE-804GBTME
- RY-804GBTME, without PoE

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the L Series and is the answer not in the manual?

Questions and answers

Summary of Contents for Barox L Series

  • Page 1 Operating Instructions 19"- RY-Switches of the L-series RY Industrial-Switches of the L-series - RY-LGS23-26 RY-LPIGE-602GBTME - RY-LGSO25-24 - RY-LPIGE-804GBTME - RY-LGSO25-28 - RY-LPITE-802GBTME - RY-LGSP16-10 - RY-LPITE-804GBTME - RY-LGSP23-10G - RY-804GBTME, without PoE - RY-LGSP23-26/xxx - RY-LGSP23-28/xxx - RY-LGSP23-52/xxx RY-LGSPTR23-26...
  • Page 2 Kommunikation. Registered trademark barox® is a registered and protected trademark of the barox Kommunikation company. Any other registered trademark or registered brand mentioned in this manual is the property of the respective manufacturer.
  • Page 3: Table Of Contents

    5.1.4. Port Security with Limit Control Settings Use and Protection of IP Functions (Layer 3) 5.2.1. DHCP Server 5.2.2. Protection of DHCP by ARP Inspection 5.2.3. IP Source Guard Protection of the Switch Management and Network Administration (Layer 3–7) 5.3.1. User Management and Configuration barox Kommunikation...
  • Page 4 5.5.3. Supplementary Information regarding the Sending of SNMP Traps Reading SNMP Traps Use of MIB Files for Reading-out and Control of the Switches Control of Switch Functions via SNMP and MIB using the „SET“ Operation Firmware Upgrade Factory Defaults Server Report WARRANTY barox Kommunikation...
  • Page 5: Introduction

    In all situations where a network is required to transmit high -quality video content fast and securely, barox Kommunikation’s range of POWERHAUS switches guarantee pioneering connections. barox Kommunikation designs, coordinates and supplies everything fr om a simple, point-to-point connection to a large area network running multicast applications. Website Information on our full range of switches as well as download links to our data sheets, documentation and the latest firmware are available on our webs ite: www.barox.ch.
  • Page 6: Dms (Device Management System)

    To log in, the user simply enters the user name and password listed above. Once the login process has been successfully completed, the “System Information” page is automatically displayed showing the most important information on the switch. barox Kommunikation...
  • Page 7: System Information

    System Information This page displays the most important information on the switch. Key: Name of the switch model Firmware version Hardware version MAC address barox Kommunikation...
  • Page 8: Set A Static Ip Address Or Use Dhcp

    This method requires using the console cable supplied with the switch. The console port of the switch is an RS232 interface, i.e. a PC/laptop with a serial interface or a USB-RS232 adapter is required. To configure the switch via the CLI port, we recommend using the “PuTT Y” software. http://www.chip.de/downloads/PuTTY_12997392.html barox Kommunikation...
  • Page 9: Gateway Configuration

    Time Configuration The system time used by barox Kommunikation switches can either be configured manually or via an NTP server. The whole purpose of defining the time is to use it in the log file. If an error...
  • Page 10: Ntp (Network Time Protocol)

    If there is no time source available in one’s own network and the time is to be retrieved from an external source via the Internet, it is possible to enter the external NTP server details directly, e.g. 213.209.109.45 at http://www.pool.ntp.org/de/ barox Kommunikation...
  • Page 11: Time Settings

    1) the time is correct and 2) the system switches correctly between summer and winter time. As soon as the switch can access the time and date, the correct date is shown in the “System Date” field. barox Kommunikation...
  • Page 12: Port Configuration

    − whereby no guarantee is supplied that these will function properly. The barox Kommunikation product range includes SFPs for multi and single mode fibres with transmission speeds of 100 Mbps, 1 Gbps and 10 Gbps. Distances of between 550 m and 120 km can be achieved depending on the type of fibre and transmission speed.
  • Page 13: Change Of User Name And Password

    Change of User Name and Password barox Kommunikation switches offer the option of generating a number of u sers with different rights. Up to 15 different levels can be defined. Level 15 is the highest level and is intended to be used by the administrators.
  • Page 14: Loop Protection

    “Shutdown Time” shows how long a port is to remain disabled, should a l oop be detected. Possible time entries: 0 – 604,800 s (7 days). If “0” is entered here, the port will remain deactivated until the switch is rebooted. barox Kommunikation...
  • Page 15: Ring Configuration

    RSTP is supported by all switch manufacturers - making it compatible with third-party manufacturers. The switch factory default is set to “Bridge Priority” 32768. If the switch is to act as master, the Bridge Priority must be set to “0”. All the other values can be left as they are. barox Kommunikation...
  • Page 16: Port Configuration

    In the above example, the network consists of two central switches (A+B) and 5 other switches that form the ring. All in all, 21 cameras have been installed − each supplying 5 Mbps of video data, i.e. a total of over 100 Mbps of data. barox Kommunikation...
  • Page 17 ➔ Wherever possible, one should aim to realise a configuration that corresponds to the one illustrated in the above image. barox Kommunikation...
  • Page 18: Vlan Configuration

    (e.g. PoE cameras) can be monitored and rebooted, if required. The PoE chip in the camera can also be reset. This makes sense, for example, in cases where a camera shows no picture although it can be pinged. barox Kommunikation...
  • Page 19: Poe Configuration

    = according to the value stated in the “Maximum Power (W)” column Allocation LLDP-Med = ditto Class mode, pulls the information via LLDP (where possible) If the terminal device exceeds the predefined power limit, the port turns PoE off. barox Kommunikation...
  • Page 20: Poe Power Delay

    To avoid this problem, one can configure the individual ports to start up one after the oth er in the following menu. In the example below, ports 1 and 2 are immediately activated − with 2 more ports then being activated every 10 seconds after that. barox Kommunikation...
  • Page 21: Poe Schedule

    After 3 failed attempts, PoE to port 1 is turned off and turned back on after 15 seconds. This forces the camera to reboot. 60 seconds after the camera has rebooted, the ping monitoring mechanism will kick in again. barox Kommunikation...
  • Page 22: Poe Chip Reset Schedule

    This means that all changes need to be permanently saved. There are two ways to do this: Diskette symbol on each screen Maintenance/Configuration/Save startup-config menu item Save Configuration barox Kommunikation...
  • Page 23: Download Configuration

    The opposite scenario is uploading a configuration file to the switch. In this case, the path where the file is stored and the respective file type need to be specified. As a rule, this is the “startup- config file”. barox Kommunikation...
  • Page 24: Dms Device Management System

    (and deactivated at the other switches), resp. Attention shall be paid as some functions can only be used in a limited way and this method is recommended in case of a homogenous structure using barox switches. The master switch can be determined using the IP address in the line „Controller IP“.
  • Page 25 The connection to a device can be checked − even across a row of switches − simply by clicking on the “Online”, resp. “Offline” symbol in the “Status” column. Should there be in interruption anywhere in the connection chain, this can be seen here. The same information can be checked using the “Maintenance/Diagnostics” menu. barox Kommunikation...
  • Page 26: Graphical Monitoring

    PoE requirement, in as far as the device is a PoE appliance, can also be read. Additionally, by clicking on “Login”, the device can be directly accessed or diagnostics on the connection carried out. The PoE appliance can also be easily rebooted by simply click ing on the “PoE Reboot” icon. barox Kommunikation...
  • Page 27 IP and MAC address to return and will set the new camera back to the default IP address over and over again despite this having the same IP address. This occurs because the new camera has a different MAC address. barox Kommunikation...
  • Page 28 Two conditions must be fulfilled for this representation: a) RSTP as ring protocol b) The ring only consists of RY switches supporting the DMS barox Kommunikation...
  • Page 29 − done. Map View The same function is also possible using Map View. The background image is directly generated using Google Maps. This requires an internet connection and Google licences for using the service. barox Kommunikation...
  • Page 30: Maintenance

    The path and file name must be entered in the “Floor Image” menu and then uploaded using “Add”. The uploaded plans are then listed in the lower section of the web page. Up to 50 files can be saved. Diagnostics This function was described and explained on page 25 under the heading “Devices List”. barox Kommunikation...
  • Page 31 This may be extremely useful when looking for the cause of errors, for example, if one sees that at 12 a.m. a large volume of data was generated at port 2 when there were problems with the recording process. barox Kommunikation...
  • Page 32: Switch Management In The Security Focus

    GUI as illustrated thereafter. Some applications require the adjustments of the Ethernet frame sizes. This can also be done in the menu section „Ports Configuration” in the field „Maximum Frame Size” as described in the following screenshot. barox Kommunikation...
  • Page 33: Information Regarding The General Consideration Of The Bandwidth Demand

    5.1.2. Information regarding the general consideration of the bandwidth demand The consideration of the following items is recommended when planning the bandwidth demand and the related deployment of suitable barox switches: Deployment of the required Ethernet standards (10/100/1000/10000) under consideration of possible terminal device upgrades Planning of reserves, scaled at the backplane power of the switch ->...
  • Page 34: Port Security With Limit Control Settings

    The use of Limit Control is recommended where unmanaged switches with terminal devices are connected to the barox switch. Basically this function prevents the blocking o f the network communication of further unwanted IP/Ethernet terminals which are connected to free ports of the unmanaged switches.
  • Page 35: Use And Protection Of Ip Functions (Layer 3)

    The setting of the IP address pool, which shall enable the distribution of 50 addresses, i.e. in the range of 192.168.10.100 – 192.168.10.150 by stating the surrounding addresses and IP ranges (exclusion procedure) to the IP clients in the respective VLAN is shown in the following screenshot. barox Kommunikation...
  • Page 36 Following this a DHCP service name is determined and confirmed. Following the determination of the name the settings are called up by selecting the name as shown below. The following configuration appears upon call-up of the pool name. barox Kommunikation...
  • Page 37: Protection Of Dhcp By Arp Inspection

    At first the Snooping function is generally activated in the menu Snooping Mode as shown below. Furthermore settings can be chosen for the trustworthy switch ports. The mode must be set to „Trusted“ for the inspection function to work. barox Kommunikation...
  • Page 38 IP addresses by the DHCP service the clients and their layer 2 and 3 characteristics become visible in the dynamic ARP inspection t able and can subsequently be translated into the static ARP inspection table. barox Kommunikation...
  • Page 39 The following screenshot shows a static entry. An IP address is reserved for the client according to the table. barox Kommunikation...
  • Page 40: Ip Source Guard

    The switch will block the port‘s network communication where the connected device does not comply with the allocated MAC and IP address. This means, that the attacker must know the MAC address and IP address of the device for gaini ng access to the network. barox Kommunikation...
  • Page 41: Protection Of The Switch Management And Network Administration (Layer 3-7)

    It is generally recommended not to change the default values. Such rights should be allocated when generating new users . Information: Scaling the rights of a further user on the basis of authorisation and competencies is helpful. barox Kommunikation...
  • Page 42: Deployment And Authentication Settings Using The Switch Management

    Change of port 80, information: Please pay attention to the port information when accessing via a browser! Access via HTTPs provides the highest level of protection due to the encryption of the connection. The following example shows the entry of the management address using a changed port barox Kommunikation...
  • Page 43: Access Management And Use Of Https

    The http option should be disabled where this mode is activated. The switch GUI is called up in the browser using the HTTPS protocol phrase https://192.168.XX(IhreManagement IP):1234(IhrPort) in the URL field. Following this the browser communication to t he management interface is effected using encryption. barox Kommunikation...
  • Page 44: Configuration And Use Of Certificate-Based Access To The Management

    Generation of the certificate for later use, which can be downloaded and installed using the browser. Upload of an externally generated certificate The browser access is effected following the installation of the certificate and determina tion of the HTTPs authentication method via the HTTPs protocol barox Kommunikation...
  • Page 45: Snmp - Monitoring- And Administration Function

    SNMP traps. The following steps shall show the use of an SNMP Community. Activation of the SNMP v2 Function The mode should be generally enabled and SNMP v2 should be selected in the SNM P configuration. Furthermore the names for the read and write communities are determined. barox Kommunikation...
  • Page 46: Snmp Trap Configuration

    Trap Destination Port -> Entry of the port at the recipient Trap Inform Mode -> Disabled in this example Trap Inform Timeout (seconds) -> 3 is entered (Standard) Trap Inform Retry Times -> 5 (Standard) Following this the settings are confirmed by clicking „Apply“. barox Kommunikation...
  • Page 47 Step 2: Following the generation of a new configuration such configuration is opened by selecting th e name. barox Kommunikation...
  • Page 48 Activation of the SNMP Trap Function The general mode must be enabled following completion of the trap configuration. barox Kommunikation...
  • Page 49: Supplementary Information Regarding The Sending Of Snmp Traps

    Some events − such like e.g. port events − must also be set accordingly in the port configuration. ATTENTION: For industrial switches, this setting can be found under Configuration/System/Alarm Notification. Further information regarding the reading and testing of the configuration can be found in „5.6 Reading-out SNMP Traps“. barox Kommunikation...
  • Page 50 Kommunikation...
  • Page 51: Snmp V3 Configuration

    SNMP traps. The following steps shall demonstrate the use of authentication and password protection. 5.5.1. Activation of the SNMP v3 Function The mode should be generally enabled and SNMP v3 should be selected in the SNMP configuration. barox Kommunikation...
  • Page 52 Generation of a dedicated Community When generating the community the setting of source IP and mask can remain as 0.0.0.0 in each case. This enables the transmission and the receipt of SNMP messages across several subnetworks. barox Kommunikation...
  • Page 53 „Auth, Priv“ shall also be set along with the determination of the user name. When selecting the authentication „MD5“ and the privacy protocol DES attention shall be paid as the length of both passwords must be at least eight characters (numbers and character combinations). barox Kommunikation...
  • Page 54 Setting the View Configuration At the beginning the View Name is determined. Setting the OID to a value „.1“ is recommended providing all SNMP-relevant messages can be viewed. This enables the complete view to all distributed OIDs. barox Kommunikation...
  • Page 55: Snmp Trap Configuration

    „Read View Name“ and „Write View Name“. 5.5.2. SNMP Trap Configuration Prior to the configuration of new trap settings attention should be paid, that the global setting of the trap mode is disabled. barox Kommunikation...
  • Page 56 Trap Security Name -> Currently only „None“ can be selected Following this the settings are confirmed by clicking „Apply“. Following the confirmation of the configuration a note is displayed, that a respective Security Name should be set. This is configured in step 2. barox Kommunikation...
  • Page 57 Step 2: Following the generation of a new configuration such configuration is opened by selecting the name. Now the entry „Trap Security Name“ can be set to the SNMP user name. barox Kommunikation...
  • Page 58 Activation of the SNMP Trap Function The general mode must be enabled following completion of the trap configuration. barox Kommunikation...
  • Page 59: Supplementary Information Regarding The Sending Of Snmp Traps

    Some events − such like e.g. port events − must also be set accordingly in the port configuration. Further information on reading-out and testing the configuration can be found in „5.6 reading SNMP Traps“. barox Kommunikation...
  • Page 60: Reading Snmp Traps

    Reading SNMP Traps Various parameters of the barox switch configurations can be rea d out and set, resp., using the SNMP protocol. So-called „SNMP/MIB Browser” are basically required for doing so. But also network-/recording-/ sniffer software can be utilised to read SNMP transmissions.
  • Page 61 View of the information in the SNMP browser: PoE camera is connected again / PD device is online: Recording of the information, which is sent by the switch: barox Kommunikation...
  • Page 62: Use Of Mib Files For Reading-Out And Control Of The Switches

    Step 1: Import of the MIB File During the import attention must be paid for selecting the suitable MIB file for the respective switch. The required MIB files can be identified by their prefix „mib“. barox Kommunikation...
  • Page 63 * Please pay attention to the respective software vendor‘s licencing conditions when using the software! Following the successful import the MIB structures are available as shown below. barox Kommunikation...
  • Page 64: Control Of Switch Functions Via Snmp And Mib Using The „Set" Operation

    Control of Switch Functions via SNMP and MIB using the „SET“ Operation The „SET” operation via the SNMP protocol can be a further method for controlling barox switches. The basic SNMP configurations at the switch and of the MIB browser are preconditions.
  • Page 65 „OK“. A respective success message is generated upon a successful operation. Following the upgrade the new firmware is immediately available. Any old firmware can very simply be re-activated in the menu „Firmware Selection“ where the old firmware shall be applied again for some reason. barox Kommunikation...
  • Page 66: Firmware Upgrade

    New features are also introduced. Following the upgrade the new firmware is immediately available. Any old firmware can very simply be re-activated in the menu „Firmware Selection” where the old firmware shall be applied again for some reason. barox Kommunikation...
  • Page 67: Factory Defaults

    This is done either via the “Maintenance/Factory Defaults” menu or by pressing the reset button at the front (for longer than 10 seconds). Checking the “Keep IP setup” box ensures that the switch retains the configured IP address. Otherwise, everything is reset to the factory defaults. barox Kommunikation...
  • Page 68: Server Report

    8 S e r v e r R e p o r t When submitting a request for support, the server report should also be provided. This contains a description of the whole configuration as well as useful information for the support technician. Excerpt from a Server Report barox Kommunikation...
  • Page 69: Warranty

    Kommunikation shall remedy any product defects caused by poor material quality and/or a machining error of which barox Kommunikation is notified during the warranty period. barox Kommunikation shall then decide at their own discretion what measures to take to alleviate the defect. The warranty for any repaired or replaced components shall then continue to apply for the remaining warranty period.

Table of Contents