Layer-2 switches, software version 4.0 (254 pages)
Summary of Contents for NETGEAR FSM726v2 - 10/100 Mbps Managed Switch
Page 1
700 Series Software Manual v2.1 NETGEAR, Inc. 4500 Great America Parkway Santa Clara, CA 95054 USA Phone 1-888-NETGEAR 202-10132-01 September 2005...
Defective or damaged merchandise can be returned to your point-of-purchase representative. NETGEAR maintains a World Wide Web home page that you can access at the uniform resource locator (URL) http:// www.NETGEAR.com. A direct connection to the Internet and a Web browser such as Internet Explorer or Netscape are...
Contents Chapter 1 About This Guide Audience .........................1-1 Why the Document was Created ..................1-1 How to Use This Document ....................1-1 Typographical Conventions ....................1-2 Special Message Formats ....................1-2 Features of the HTML Version of this Manual ..............1-3 How to Print this Manual ....................1-4 Chapter 2 Switch Management Overview Management Access Overview ..................1-1...
Page 4
Main Menu> Set-Up> GBIC ...................3-10 Main Menu> Tools ......................3-11 Main Menu> Security ....................3-12 Main Menu> Advanced ....................3-12 Main Menu> Advanced> Port Mirroring ..............3-14 Main Menu> Advanced> Port Trunking ..............3-15 Main Menu> Advanced> Virtual Cable Tester ............3-15 Main Menu> Advanced> Advanced Security ............3-16 Main Menu>...
Page 5
Main Menu> Advanced> SNMP> Host Table ..........3-30 Main Menu> Advanced> SNMP> Trap Settings ..........3-30 Chapter 5 Web-Based Management Interface Web Based Management Overview ................4-2 System Information ......................4-3 Status Menus ........................4-4 Status > Switch Statistics ..................4-5 Status > Port Statistics .....................4-7 Status >...
Page 7
Show Multimedia ......................5-7 Show Running-Config ....................5-7 Show SNMP ......................5-8 Show Spanning Tree ....................5-9 Show System ......................5-10 Show Trunking ....................... 5-11 Show VLAN ......................5-11 Configure ........................5-13 DiffServ ........................5-13 Dot1x ........................5-14 Exit .........................5-15 Interface .........................5-15 CoS (Class or Service) ..................5-16 Exit ........................5-16 Flow Control ....................5-17 Mirror .......................5-17 No ........................5-18...
Page 8
Save ........................5-30 Restore ......................5-30 Web .........................5-30 Telnet .......................5-30 Username ......................5-31 Password ......................5-31 Firmware boot ....................5-31 Firmware TFTP-IP ...................5-32 Firmware TFTP-File ..................5-32 RADIUS ......................5-32 Reset .......................5-33 Stat-Reset ......................5-34 VLAN ........................5-34 Appendix A Virtual Local Area Network VLAN Behavior in a 700 Series Managed Switch ............A-2 Appendix B Cabling Guidelines Fast Ethernet Cable Guidelines ..................
Chapter 1 About This Guide Thank you for purchasing the NETGEAR ™ 700 Series Switches. Audience This reference manual assumes that the reader has basic-to-intermediate computer and Internet skills. However, basic computer network, Internet, and wireless technology tutorial information is provided in the Appendices.
This manual is written for the 700 Series Switches according to these specifications: Table 1-1. Manual Specifications Product Version 700 Series Switches Manual Publication Date September 2005 Note: Product updates are available on the NETGEAR, Inc. Web site at http:// www.netgear.com/support/main.asp. About This Guide...
Management Access Overview • SNMP Access • Protocols Management Access Overview Your NETGEAR 700 Series Switches gives you the flexibility to access and manage the switch using any or all of the following methods: • An administration console • Web browser interface •...
For a more detailed discussion of the Administration Console, see Chapter 4. For a more detailed discussion of the Web Browser Interface, see Chapter Protocols Your NETGEAR 700 Series Switches supports the following protocols: • Virtual terminal protocols, such as Telnet • SNMP Switch Management Overview...
Macintosh, a PC, or a UNIX workstation. Because Telnet runs over TCP/IP, you must have at least one IP address configured on a NETGEAR 700 Series Switches before you can establish access to it with a virtual terminal protocol.
Page 14
700 Series Software Manual v2.1 This management method requires the SNMP agent on the switch and the SNMP Network Management Station to use the same community string and that the SNMP Network Management Station is entered in the SNMP Host table on the switch. This management method, in fact, uses two community strings: the GET community string and the SET community string.
Page 15
700 Series Software Manual v2.1 Switch Management Overview...
Chapter 3 Software Upgrade Procedure As networking technology advances, NETGEAR will release new versions of the software that runs the switch. These software releases will provide new capabilities that can extend the useful life of your switch. This manual is updated whenever there is a change in either the first or second positions of the software version number.
Page 17
700 Series Software Manual v2.1 Restart the system via the Tools > Reset command. Bootstrap will retrieve the new software image then pass control to it. The system executes the new software image. The previous software image in non-volatile memory will not be replaced by the new software image.
Page 18
700 Series Software Manual v2.1 Software Upgrade Procedure...
Chapter 4 Administration Console Telnet Interface The administration console is an internal, character-oriented, VT-100/ANSI menu-driven user interface for performing management activities. Using this method, you can view the administration console from a terminal, PC, Apple Macintosh, or UNIX workstation connected to the switch’s console port.
Page 20
700 Series Software Manual v2.1 Examples of terminal-emulation programs include: • HyperTerminal, which is included with Microsoft Windows operating systems • ZTerm for the Apple Macintosh • TIP for UNIX workstations This example describes how to set up the connection using a HyperTerminal on a PC, but other systems follow similar steps.
700 Series Software Manual v2.1 When the following screen appears, make sure that the port setting are as follows: Baud Rate: 9600 Data Bits: Parity: None Stop Bits: Flow Control: None Figure 4-4: Connection Settings Click OK. The HyperTerminal window will open and you should be connected to the switch. If you do not see the welcome screen or a system menu, press the return key.
Page 22
700 Series Software Manual v2.1 There are several characteristics to the CMI pages that are necessary to know before proceeding to use it. The TAB key or the arrow keys may be used to move within menus and sub-screens. At the bottom of every screen are some key commands available for that particular screen, as well as some helpful information.
700 Series Software Manual v2.1 Main Menu> System This screen displays the main menu System Information options. The user-definable options are: System Name, System Contact, System Location, IP Address, Default Gateway, and Subnet Mask. The System OID option is used for production testing. Figure 4-6: System Information Main Menu>...
700 Series Software Manual v2.1 Figure 4-7: Switch Statistics Main Menu> Status >Reset Statistics The Reset Statistics menu allows you to reset the statistics counter to zero. When you choose this option, a prompt will appear asking you for a confirmation. Once the confirmation is made, the statistics counters will be reset to zero.
700 Series Software Manual v2.1 Figure 4-9: Address Manager: MAC Address Table Main Menu> Set-Up There are four sub-menus under the Set-Up menu: • System Configuration • IP Configuration • Port Configuration • GBIC Main Menu> Set-Up> System Configuration The System Configuration allows you to enter a number of system-related information for easy reference in the future.
700 Series Software Manual v2.1 Figure 4-10: System Configuration Main Menu> Set-Up> IP Configuration This menu manages the IP related information of the system. IP Assignment Mode. You can manually enter IP-related information: • Bootstrap Protocol, which allows the switch to discover its own IP address from a BootP server on the network •...
700 Series Software Manual v2.1 Main Menu> Set-Up> Port Configuration On this page, you can set up the port characteristics related to link operations. All of the parameters on this page are toggle settings. To change, or toggle, between options, press Ctrl-M to move the curser to the ports field and simply press the space bar when the appropriate option is highlighted.
700 Series Software Manual v2.1 Enabling auto-negotiation on a port allows a port to sense the communication speed and negotiate the duplex mode (full duplex or half duplex) automatically. The ports will select the highest possible throughput. The port can auto-negotiate with any port that is compliant with IEEE 802.3u. If the other port is not IEEE802.3u compliant, the port will default to half-duplex, 10 Mbps mode.
700 Series Software Manual v2.1 Note: Enabling the GBIC connector for a Gigabit Ethernet port disables the built-in 1000BASE-T port. Main Menu> Tools These system tools are provided: • Save Configuration to NVRAM • Restore Factory Values • Reset Switch After making changes to any of the information on the screens in the console interface, you must save the changed settings to NVRAM.
Figure 4-15: Security Note: Using telnet, you can only enable/disable the web interface. You cannot enable/disable the telnet interface. If you forget your password, contact NETGEAR technical support at 1-888-NETGEAR (in North America). Main Menu> Advanced The Advanced page allows professional users to operate more complicated features of the device, which include VLAN, Spanning Tree, Port Trunking, Multimedia support (IGMP), traffic prioritization, SNMP, and port mirroring.
Page 31
700 Series Software Manual v2.1 • Port Trunking: A feature that allows multiple links between switches to work as one virtual link (aggregate link). Trunks can be defined for similar port types only. For example, a 10/100 port cannot form a Port Trunk with a gigabit port. For 10/100 ports, trunks can only be formed within the same bank.
700 Series Software Manual v2.1 • Spanning Tree: Spanning Tree Protocol (STP) ensures that only one path at a time is active between any two network nodes. There are maybe more than two physical path between any two nodes for redundant paths; STP ensures only one physical path is active and the others are blocked.
700 Series Software Manual v2.1 Main Menu> Advanced> Port Trunking Port Trunking is a feature that allows multiple links between switches to work as one virtual link or aggregate link. Figure 4-17: Port Trunking Trunks can be defined for similar port types only. For example, a 10/100 port cannot form a Port Trunk with a gigabit port.
700 Series Software Manual v2.1 The results are reported for the selected port. The test can take up to one minute. Note: Only the console menu will let you run the virtual cable tester on any port. Other management interfaces require port access and therefore cannot reliably test the cable continuity of the port they are using to access the switch.
700 Series Software Manual v2.1 Figure 4-20: Port-Based Authentication 802.1x port-based authentication provides RADIUS client authentication and data encryption features (see Appendix C, “802.1x Port-Based Authentication Overview”). If you have a RADIUS server on your network, you can have authentication of port access done through the RADIUS server.
700 Series Software Manual v2.1 Menu choices are Per Port Lockdown or Table. You can enable lockdown of a specific port in the Per Port Lockdown page. The Table page has two functions, which allow you to Remove or Query entries from the MAC Address Lockdown Table.
700 Series Software Manual v2.1 • Last Saved option. The system will boot from non-volatile memory. This option will automatically show up after the ‘Net & save’ option is selected and the unit is reset. Main Menu> Advanced> Advanced Tools> Configuration Management This menu allows you to save your configuration, in case you want to keep a copy for back-up purposes.
700 Series Software Manual v2.1 There are two means to differentiate traffic with this switch- VLAN tags or Differentiated Service Code Points (DSCP) in the header of data packets. By using either the VLAN tags (port-based) or DSCP (DiffServ), you can configure the switch so that certain traffic will take priority over less critical traffic.
700 Series Software Manual v2.1 There are 64 different tags available. This menu maps the various DSCP tags to the two output queues on each port. Main Menu> Advanced> Traffic Management> Broadcast Control Broadcast control lets you set a threshold for the number of broadcast packets sent over a port. Figure 4-26: Broadcast Control Main Menu>...
700 Series Software Manual v2.1 Figure 4-28: VLAN Administration To add a VLAN, enter a unique numeric VLAN ID and then enter a unique VLAN name. To remove a port or an entire VLAN, just press Ctrl-X anywhere on the line of the VLAN. Main Menu>...
700 Series Software Manual v2.1 Figure 4-30: PVID Settings This screen allows you to specify the PVID for each port. The number next to each port indicates which PVID is set for each port. Following industry standards, PVID 1 is the default PVID. Main Menu>...
700 Series Software Manual v2.1 Figure 4-32: Spanning Tree: Bridge Settings When Spanning tree is used in conjunction with a set of aggregated ports, otherwise known as a port trunking, Spanning Tree will treat the trunk as a single virtual port. •...
700 Series Software Manual v2.1 Table 4-1. STP Port Setting Parameters PARAMETERS RANGE DESCRIPTION Prty (Priority) 0-255 STP uses this to determine which path (which port) to use for forwarding. The port with the lowest number has the highest priority. Cost 1-65535 The switch uses this to determine which port is the forwarding port...
700 Series Software Manual v2.1 Figure 4-34: MAC Main Menu> Advanced> MAC Address Manager> Aging Time The aging time is the amount of time that an entry is kept in the bridge tables prior to being purged (or aged). The range (in parentheses) represents the minimum and the maximum values that the timer can be set.
700 Series Software Manual v2.1 Main Menu> Advanced> Multimedia Support In networks where multimedia applications generate multicast traffic, Internet Group Multicast Protocol (IGMP) can greatly reduce unnecessary bandwidth usage by limiting traffic forwarding that is otherwise broadcast to the whole network. Enabling IGMP will allow individual ports to detect IGMP queries, report packets, and manage IP multicast traffic through the switch.
700 Series Software Manual v2.1 Figure 4-37: Static Multicast Administration The Static Multicast Administration menu lets you create individual groups by entering MAC addresses for your static multicast group. The membership of each group is configured in the Static Multicast Membership menu. Main Menu>...
700 Series Software Manual v2.1 Main Menu> Advanced> SNMP Figure 4-39: SNMP Management You can manage this switch using the Simple Network Management Protocol (SNMP) from a network management station. To do so, you must configure your switch to participate in the SNMP community and you must add the SNMP host agent to the host table.
700 Series Software Manual v2.1 These community strings need to be set prior to setting host access, as the host table depends on the existence of community strings. The public string has GET privileges by default. Main Menu> Advanced> SNMP> Host Table The screen, shown in Figure 6-29, grants a host the access rights to the switch.
Page 49
700 Series Software Manual v2.1 Main Menu> Advanced> Command Line A user interface that allows you to configure the switch via a command line interface. See Chapter 6 for information about the Command Line Interface (CLI) Administration Console Telnet Interface 4-31...
Chapter 5 Web-Based Management Interface Your NETGEAR 700 Series Switches provides a built-in browser interface that lets you configure and manage it remotely using a standard Web browser such as Microsoft Internet Explorer 5.0 or later or Netscape Navigator 6.0 or later.
700 Series Software Manual v2.1 Web Based Management Overview The 6 menu options available are: System, Status, Set-up, Tools, Security, and Advanced. There is a help menu in the top of right side of screen; you can click the ‘help’ or the question mark to read the help menu.
700 Series Software Manual v2.1 System Information Figure 5-2: System information page This welcome page displays system information, such as: • System Description • System Name • System Contact • System Location • Current Local Time (according to your computer) •...
700 Series Software Manual v2.1 These parameters are not editable from this screen. Some of these can be modified in the Set Up> System Configuration page or the Set Up> IP Configuration page. Status Menus The Status page contains the following menu choices: Figure 5-3: Status Menu navigation •...
700 Series Software Manual v2.1 Status > Switch Statistics The Switch Statistics Chart allows you to compare one type of statistic across all the ports. You can reset the counters in the Reset Statistics page. Figure 5-4: Switch Statistics You can configure the following options on the Switch Statistics Chart: •...
Page 56
700 Series Software Manual v2.1 • Outbound Non-unicast Packet Rate: Transmitted non-unicast packet per second. • Outbound Discard Rate: Transmitted and is discarded packet per second. • Outbound Error Rate: Transmitted error packet per second. • Ethernet Undersize Packet Rate: Less than 64byte length packet per second. •...
700 Series Software Manual v2.1 Status > Port Statistics Figure 5-5: Port Statistics The Port Statistics Chart shows all the statistic types for one port over time. You can reset the counters in the Reset Statistics page. • Port The port on which data will be monitored. •...
700 Series Software Manual v2.1 • Outbound Discards: Transmitted and is being discarded packet • Outbound Errors: Transmitted and is an Error packet. • Ethernet Undersize Packets: Less than 64byte length packet • Ethernet Oversize Packets: more than 1518 byte length packet. Status >...
700 Series Software Manual v2.1 Status > Most Active Ports Figure 5-7: Error Statistics This page allows you to view the transmission and reception utilization of top 10 ports. It is especially useful when you want to see the potential bottlenecks in the switch. A bottleneck is a port with egress traffic closing to line rate.
700 Series Software Manual v2.1 Status > Reset Statistics Figure 5-8: Statistics Counter Reset The Reset Statistics screen lets you reset all statistics counters of the switch. By pressing on the Reset button, all counters will be set to 0. Status >...
700 Series Software Manual v2.1 • Link: A green triangle pointing up indicates a valid link, while a red triangle pointing down indicates no link. • On/Off: Indicates if the port is enabled or disabled by the Administrator. • State: This refers to the Spanning Tree state of the port.
700 Series Software Manual v2.1 Set-up Menu There are four kinds of configuration in the Setup page: Figure 5-11: Setup menu • “Set-up> System Configuration” on page 4-12 • “Set-up> IP Configuration” on page 4-13 • “Set-up> Port Configuration” on page 4-14 •...
700 Series Software Manual v2.1 This page will allow access to the system information parameters. To do so: Enter System Name, System Contact, or System Location. Click Apply to change the System Configuration and save it in NVRAM. Reset the system to implement the changes (> Save Configuration). Set-up>...
700 Series Software Manual v2.1 Click Apply to change the IP settings Save Configuration to NVRAM and reset the system to implement the changes (Tools > Save Configuration). Set-up> Port Configuration Figure 5-14: Port Configuration This menu allows you can configure the status of each port. •...
700 Series Software Manual v2.1 • Flow Control: Indicates whether Flow Control support is set for automatic (Auto) or off (Disabled) Set-up> GBIC This page allows you to choose the port type for the gigabit ports. The default is 1000BASE-T (RJ-45).
700 Series Software Manual v2.1 Tools Menu The Tools page contains functions to maintain your switch. Figure 5-16: Tools Menu There is a firmware upgrade; the means to save current settings to non-volatile memory (NVRAM); as well as software reset mechanism. The page has two sub-pages: •...
700 Series Software Manual v2.1 After making any changes to the screens within the Web Interface, you can save the changed settings to NVRAM. If changes are not saved to NVRAM, then they will be lost during the next switch reset or reboot. Tools>...
700 Series Software Manual v2.1 Tools> Device Reset Figure 5-19: Device Reset In this screen you can reset (power cycle) the switch. Reset the switch by selecting 'Reset' Security> Passwords Figure 5-20: Security Menu 5-18 Web-Based Management Interface...
700 Series Software Manual v2.1 The user name and password can be up to 20 characters and are case sensitive. The password entered is encrypted on the screen and will display as a sequence of asterisks (*). The factory default password is in lower case letters.
Page 70
700 Series Software Manual v2.1 • “Advanced > Disable Advanced Alerting” on page 4-22 • “Advanced > Port Mirroring” on page 4-22 • “Advanced > Port Trunking” on page 4-23 • “Advanced > Virtual Cable Tester” on page 4-23 • “Advanced>...
Page 71
700 Series Software Manual v2.1 • Advanced Tools: You can upgrade the software of the switch or save/load the switch configuration file to/from a TFTP server. • Traffic Management (CoS): Class of Service (CoS), also referred to as Quality of Service (QoS), is a way of managing traffic in a network, by treating different types of traffic with different levels of service priority.
700 Series Software Manual v2.1 Advanced > Disable Advanced Alerting Figure 5-22: Advanced > Disable Advanced Alerting To prevent accidental use, warnings appear when an advanced feature is selected. This screen allows experienced users to bypass these warnings during a browser session. The warnings will be re-activated at the next browser session in case another, less experienced user is accessing the switch.
700 Series Software Manual v2.1 Port mirroring is a feature to help in the debugging of a network. This web interface page allows the enabling or disabling of port mirroring and the setting of source and monitor ports. The monitor port will show a copy of every packet that arrives or leaves the source port. Advanced >...
700 Series Software Manual v2.1 Figure 5-25: Virtual Cable Tester The results are reported for the selected port. The test can take up to one minute. Note: Only the console menu will let you run the virtual cable tester on any port. Other management interfaces require port access and therefore cannot reliably test the cable continuity of the port they are using to access the switch.
700 Series Software Manual v2.1 Advanced > Advanced Security > System Authentication Figure 5-26: System Authentication This menu option allows you to configure the advanced security settings of the switch to limit the access to the management interface. There are two advanced security options beyond the basic password protection: RADIUS client authentication and IP Filtering.
700 Series Software Manual v2.1 Figure 5-27: Port-Based Authentication 802.1x port-based authentication provides RADIUS client authentication and data encryption features (see Appendix C, “802.1x Port-Based Authentication Overview”). If you have a RADIUS server on your network, you can have authentication of port access done through the RADIUS server.
700 Series Software Manual v2.1 Figure 5-28: Trusted MAC Address Table Advanced > Advanced Security > MAC Address Lockdown Table This page shows all of the locked down MAC addresses that the switch has learned. To use the lockdown feature, you have to enable it first. After triggering the lockdown function, the maximum number of MAC addresses that a system can learn is 1024.
700 Series Software Manual v2.1 Figure 5-29: MAC Address Lockdown Table Advanced > Advanced Tools Use the advanced tools menu to upgrade the software for the switch through a variety of options using the TFTP protocol and to customize the configuration file of the switch. These are tasks that require advanced expertise.
700 Series Software Manual v2.1 Advanced > Advanced Tools > Software Upgrade Figure 5-30: Advanced Tools, Software Upgrade menu This menu provides you with the ability to upgrade the software for the switch through a variety of options using TFTP protocol. If new improvements to the switch software become available, this menu enables you to upgrade to the new software.
700 Series Software Manual v2.1 The system will boot from non-volatile memory. This option will automatically show up after the ‘Net & save’ option is selected and the unit is reset. Advanced > Advanced Tools > Configuration Management Figure 5-31: Configuration Management Warning: Do not edit your configuration file.
700 Series Software Manual v2.1 Advanced > Traffic Management Traffic management covers the methods to improve the performance of your network by differentiating traffic and limiting excess broadcast traffic. There are two means to differentiate traffic with this switch- VLAN tags or using Differentiated Service Code Points (DSCP) in the header of data packets.
700 Series Software Manual v2.1 Advanced > Traffic Management > Broadcast Control Broadcast control lets you set a threshold for the number of broadcast packets sent over a port. Figure 5-33: Broadcast Control menu You can specify each port's threshold or apply the same threshold to all ports simply by entering the number in the Broadcast Control Rate field and clicking Apply to All Ports.
700 Series Software Manual v2.1 Advanced> VLAN> Primary VLAN Figure 5-34: Primary VLAN A ‘U’ or ‘T’ will be displayed for each port assigned to the VLAN, where ‘U’ stands for untagged and ‘T’ for tagged. If a port is an untagged member of a VLAN, the VLAN tag will be striped from the frame before it is sent out that port.
700 Series Software Manual v2.1 Add a port to a VLAN Group: Under the ‘Show VLAN’ drop down menu, select the VLAN you want to edit. Click the box below the port number on the line of the VLAN so that a ‘T’ (tagged) or ‘U’ (untagged) appears.
700 Series Software Manual v2.1 Advanced> Spanning Tree This switch is compliant with IEEE802.1D Spanning Tree Protocol (STP). STP ensures that only one path at a time is active between any two network nodes. There maybe more than one physical path between any two nodes, forming a loop, either created for redundancy or by accident.
700 Series Software Manual v2.1 Spanning Tree can be enabled or disabled in this screen. Enable: There are four other tunable parameters to be addressed when enabled. Hello Time Time between configuration messages sent by the Spanning Tree algorithm Max Age Amount of time before a configuration message is discarded by the system Forward Delay Amount of time system spent transitioning from the ‘learning’...
700 Series Software Manual v2.1 Table 5-1. STP Port Setting Parameters PARAMETERS RANGE DESCRIPTION Prty (Priority) 0-255 STP uses this to determine which path (which port) to use for forwarding. The port with the lowest number has the highest priority. Cost 1-65535 The switch uses this to determine which port is the forwarding port...
700 Series Software Manual v2.1 Advanced> MAC> Address Aging Figure 5-38: MAC > Address Aging Aging Time is a variable that must be configured. Its purpose is to determine the amount of time an entry is held in the forwarding tables while no activity occurs from that address. Entries should be removed to update the table for MAC addresses that have moved or are turned off.
700 Series Software Manual v2.1 Any system, whose MAC address and the port number are listed in this screen, will not be purged from the system’s forwarding table by the aging process. Add a new entry Enter the MAC address and port in the appropriate boxes Click Add Remove an exist entry Highlight that entry in the table, by clicking on the MAC address...
700 Series Software Manual v2.1 • Enable. The system will detect IGMP queries, report packets, and manage IP multicast traffic through the switch • Disable. The switch will forward traffic and disregard any IGMP requests. Advanced>Multimedia Support> Static Multicast Groups Figure 5-41: Multimedia Support >...
700 Series Software Manual v2.1 • 4-Group RMON (RFC1757) Advanced> SNMP> Community Table Figure 5-42: Figure 4-31. SNMP Management: Community Table The administrator can create up to eight different community strings with combinations of GET, SET and TRAP privileges. These community strings need to be set prior to setting host access, as the host table depends on the existence of community strings.
700 Series Software Manual v2.1 The SNMP Host Table screen allows you to add and remove hosts from access rights that have been granted to community groups. The permissions GET, SET and TRAP are assigned to a community name and then these permissions are assigned to individual machines by adding those machines and their IP address to the appropriate community string.
Chapter 6 Command Line Interface The 700 Series Switches features a Command Line Interface (CLI) designed for expert users who are familiar with common CLIs in use in the market. The CLI follows a tiered structure, enabling different commands at different levels or sections of the CLI. Manual Syntax Before discussing the details of the CLI operation, the syntax of the CLI commands used in this manual are listed below:...
700 Series Software Manual v2.1 Once you see the root prompt, you are in CLI mode. If you have a question on what commands you can use, type a question mark ‘?’ at the prompt. A list of available commands will be presented to you. There are five items in the root prompt.
700 Series Software Manual v2.1 Where = the IP address of the destination host <IP Address> Exit command moves you up one level in the CLI structure. For example, when you are in exit configuration mode, and the prompt looks like .
700 Series Software Manual v2.1 Show DiffServ Use the show command to view the priority associated with each DSCP value. diffserv Syntax FSM726# show diffserv An example of the partial output is shown below. DSCP Priority ==== ======== 0 normal 1 normal 2 normal 3 normal...
700 Series Software Manual v2.1 FSM726# show interface Ethernet <x/y> Where = x is the stack number (always 1 in FSM726), y is the port number <x/y> An example of the display output is shown below. FastEthernet1/23 is Up Hardware is Fast Ethernet Auto-duplex (Full), Auto Speed (100), 100BaseTX/FX pvid is: 1 cos is normal...
Page 98
700 Series Software Manual v2.1 Aging Time command is used to display the aging timer of show mac-address-table aging-timer the mac-address-table. Syntax FSM726# show mac-address-table aging-timer Dynamic command displays the dynamically learned MAC show mac-address-table dynamic addresses. Syntax FSM726# show mac-address-table dynamic An example of the display output is shown below.
700 Series Software Manual v2.1 Show Mirror command displays mirroring configurations of the switch. Primarily, it shows show mirror which ports are mirroring and being mirrored. Syntax FSM726# show mirror An example of the output is shown below. Port Mirroring is: Enabled Source: 1/23 Monitor: 1/1 Show Multimedia...
700 Series Software Manual v2.1 Syntax FSM726# show snmp Show Spanning Tree The show spanning tree command displays the status and topology of the spanning-tree configuration, as well as spanning-tree state of each port. Brief command gives a brief summary of the spanning-tree status. show spanning-tree brief Syntax FSM726# show spanning-tree brief...
700 Series Software Manual v2.1 Interface command displays the spanning tree state of a show spanning-tree interface particular port. Syntax FSM726# show spanning-tree interface ethernet <x/y> Where = x is the stack number (always 1 in the case with FSM726), and y is the port number. <x/y>...
700 Series Software Manual v2.1 RADIUS Server IP Address: 0.0.0.0 Shared Secret is: Hardware Version: RA Boot ROM Version: 1.2 (2495) Software Version: 1.0.4 (2505) Next Boot from: Last Saved TFTP Server IP Address: 0.0.0.0 TFTP Path/Filename: IP Filtering is: Disabled Show Trunking command displays the trunking state of the switch.
Page 104
700 Series Software Manual v2.1 ---- -------------------------------- --------- ------------------------------- 1 Netgear active Untagged: Fa1/4,Fa1/5,Fa1/7,Fa1/11, Fa1/12,Fa1/13,Fa1/14,Fa1/15, Fa1/19,Fa1/20,Fa1/21,Fa1/22, Fa1/23 3 Company active Tagged: Gi1/25, Gi1/26 VLAN command displays information on membership of individual VLANs. show vlan Syntax FSM726# show vlan [cr | VLAN index #] Where = a carriage return.
700 Series Software Manual v2.1 Normal Normal Normal Configure The information that can be configured falls into the following categories: • DiffServ – DiffServ settings. See “DiffServ” on page 5-13 • Dot1x – 802.1x settings. See “Dot1x” on page 5-14. •...
700 Series Software Manual v2.1 Where = The DSCP value, which ranges from 0-63 <DSCP> = The priority associated with the defined DSCP value. The available options are <Priority> normal and high For example, suppose you want to set DSCP 33 to high, the command to do so would be: FSM726(config)# diffserv 33 high Dot1x The RADIUS Server IP Address must be configured first before enabling 802.1x.
700 Series Software Manual v2.1 Exit command takes you out of the CLI mode by one level. For example, when you are in exit configuration mode, and the prompt looks like By entering at the FSM726(config)# exit prompt, you will exit the configuration mode and be taken back to the root level, where the prompt looks like When you enter the command at the root level, you will return to the...
700 Series Software Manual v2.1 CoS (Class or Service) Class of Service (CoS) is a way of managing traffic in a network by treating different types of traffic with different levels of service priority. Higher priority traffic gets faster treatment during times of switch congestion.
700 Series Software Manual v2.1 Flow Control This command enables flow control on this particular port. Syntax FSM726(config-if)# flow-ctrl Help command displays instructions on how to access help on the CLI. help Syntax FSM726(config-if)# Help To access Help on a specific command, you enter a question mark behind the command in question, then a list of available options will be presented to you.
700 Series Software Manual v2.1 command negates one of your previously given commands. Syntax FSM726(config-if)# no <commands> Where = the command which you wish to negate. <command> For example, suppose you previously turned on flow control on this particular interface by using command, and you changed your mind and wish to turn it off.
700 Series Software Manual v2.1 FSM726(config-if)# Shutdown Spanning Tree command lets you configure the variables of the port that affects its spanning-tree spanning-tree operation, items such as port cost and priority is configured through this command. Syntax FSM726(config-if)# spanning-tree [cost <1-65535> | port-priority <0-255> | fastlink ] Where = the cost of the port, ranges from 1-65535 Cost <1-65535>...
700 Series Software Manual v2.1 = setting the VLAN membership to tagged mode. VLAN tagged <VLAN Membership> Membership ranges from 1-4094 = setting the VLAN membership to untagged mode. VLAN untagged <VLAN Membership> Membership ranges from 1-4094 For example, suppose this particular port belongs in VLAN 64 and 32. You wish to configure it so that it operates in tagged mode in VLAN 64, but in untagged mode in VLAN 32, the command to do so would be: FSM726(config-if)# switchport access vlan tagged 64...
700 Series Software Manual v2.1 = removing this particular port from a trunk. The trunk number ranges from remove <trunk #> 1-4. For example, to add this particular port to trunk 4 by entering FSM726(config-if)# trunking add 4 By the same token, to remove this port from trunk 4, you would enter FSM726(config-if)# trunking remove 4 Mac-address-table command lets you configure the operation and maintenance of the...
700 Series Software Manual v2.1 = The Ethernet interface associated with the MAC address <ethernet interface number> you specified. The interface number is expressed in x/y format, where x is the stack number (always 1 in the case with FSM726), and y is the port number. Multicast-Static You can use this menu to configure permanently reachable multicast groups.
700 Series Software Manual v2.1 IGMP command enables Internet Group Management Protocol on the switch. multimedia igmp Syntax FSM726(config)# multimedia igmp command enables High Priority Optimization (HPO). This means that as multimedia hpo traffic flows through the switch, if there is a conflict between maximizing high priority traffic or ensuring flow control, the switch will favor the high priority traffic.
Page 116
700 Series Software Manual v2.1 Syntax. FSM726(config)# snmp server community <name> [ro | rw |wo | trap] Where = the name of the community <name> = the privilege associated with this community. [ro | rw |wo |trap] = read only. = read-write access = read-only = trap allowed...
Page 117
700 Series Software Manual v2.1 FSM726(config)# snmp-server name <switch name> Where = the name you wantwant to give to the switch <switch name> Host command is used to specify hosts to receive SNMP notifications. host Syntax FSM726(config)# snmp-server host <host name> <host IP address> <community string> Where = the name of the host that is to receive SNMP notifications.
700 Series Software Manual v2.1 Spanning Tree Spanning Tree Protocol (STP) ensures that only one path at a time is active between any two network nodes. There are maybe more than two physical path between any two nodes for redundant paths; STP ensures only one physical path is active and the others are blocked. STP will prevent an inadvertent loop in a network, which can disable your network due to a “Broadcast storm”, the result of a broadcast message traveling through the loop again and again.
700 Series Software Manual v2.1 Priority Use the command to set the STP priority priority Syntax FSM726(config)# spanning-tree priority <priority> Where = is the STP priority. This number ranges from 0 – 65535. <priority> System command configures important system items such as IP addresses, password security, system and firmware upgrade.
700 Series Software Manual v2.1 FSM726(config)# system config-tftp ip <IP address> Where = the IP address of the TFTP server. <IP address> Config-tftp Path/File command lets you configure the path and the filename of the config-tftp path/file configuration file to be loaded/saved. Syntax FSM726(config)# system config-tftp path/file <path&filename>...
700 Series Software Manual v2.1 IP-filter address allows you to enter and remove IP address from the approved list. Use IP-filter address the No command to remove an IP address. Syntax FSM726(config)# system ip-filter address <IP-address> Where = an IP address that is authorized to access the management. <IP address>...
700 Series Software Manual v2.1 Syntax FSM726(config)# system gateway <default gateway> Where = the IP address of the default gateway <default gateway> Save command is used to save the configuration to NVRAM once you have made changes. save Syntax FSM726(config)# system save Restore command is used to restore all configurations back to factory default value.
700 Series Software Manual v2.1 Username Use the command to create a new user for the switch. username Syntax FSM726(config)# system username <username> Where = the user name you wish to set up for accessing the switch. Please note that this <username>...
700 Series Software Manual v2.1 Warning: The previous image in non-volatile memory will be lost when the procedure completes. • Last Saved option The system will boot from non-volatile memory. This option will automatically show up after the ‘Net & save’ option is selected and the unit is reset. Syntax FSM726(config)# system firmware boot [net-tftp | net-and-save | last saved] Firmware TFTP-IP...
700 Series Software Manual v2.1 Syntax FSM726(config)# system radius authen-mode [local | local-then-remote | remote] Where = authentication is performed locally and not through an external RADIUS server Local = Authentication is performed locally first, then by an external RADIUS Local-then-remote server = Authentication is performed by a remote server and not locally.
700 Series Software Manual v2.1 Stat-Reset Use the command to reset all of the statistics counters in the switch. Stat-Reset Syntax FSM726(config)# system stat-reset VLAN command is used to configure VLAN database parameters. config VLAN Syntax FSM726(config)# VLAN ... 6-34 Command Line Interface...
Appendix A Virtual Local Area Network A Local Area Network (LAN) can generally be defined as a broadcast domain. Hubs, bridges or switches in the same physical segment or segments connect all end node devices. End nodes can communicate with each other without the need for a router. Routers connect LANs together, routing the traffic to appropriate port.
700 Series Software Manual v2.1 VLAN Behavior in a 700 Series Managed Switch Packets received by the switch will be treated in the following way: When an untagged packet enters a port, it will be automatically tagged with the port’s default VLAN ID tag number.
Page 129
700 Series Software Manual v2.1 To allow untagged packets to participate in the ‘First’ VLAN, make sure to change the Port VLAN IDs for the relevant ports. Access the PVID Settings page then use the space bar to add an ‘X’ indicating which Port VLAN ID is assigned to which port.
Page 130
700 Series Software Manual v2.1 Virtual Local Area Network...
Appendix B Cabling Guidelines This appendix provides specifications for cables used with a NETGEAR 700 Series Switches. Fast Ethernet Cable Guidelines Fast Ethernet uses UTP cable, as specified in the IEEE 802.3u standard for 100BASE-TX.The specification requires Category 5 UTP cable consisting of either two-pair or four-pair twisted insulated copper conductors bound in a single plastic sheath.
700 Series Software Manual v2.1 Category 5 Cable Category 5 distributed cable that meets ANSI/EIA/TIA-568-A building wiring standards can be a maximum of 328 feet (ft.) or 100 meters (m) in length, divided as follows: 20 ft. (6 m) between the hub and the patch panel (if used) 295 ft.
700 Series Software Manual v2.1 Table-B-1. Electrical Requirements of Category 5 Cable SPECIFICATIONS CATEGORY 5 CABLE REQUIREMENTS Number of pairs Four Impedance 100 ± 15% Mutual capacitance at 1 KHz 5.6 nF per 100 m Maximum attenuation at 4 MHz: 8.2 (dB per 100 m, at 20°...
700 Series Software Manual v2.1 Figure B-2 illustrates crossover twisted pair cable. Figure B-2: Crossover Twisted-Pair Cable Patch Panels and Cables If you are using patch panels, make sure that they meet the 100BASE-TX requirements. Use Category 5 UTP cable for all patch cables and work area cables to ensure that your UTP patch cable rating meets or exceeds the distribution cable rating.
700 Series Software Manual v2.1 Note: Flat “silver satin” telephone cable may have the same RJ-45 plug. However, using telephone cable results in excessive collisions, causing the attached port to be partitioned or disconnected from the network. Using 1000BASE-T Gigabit Ethernet over Category 5 Cable When using the new 1000BASE-T standard, the limitations of cable installations and the steps necessary to ensure optimum performance must be considered.
700 Series Software Manual v2.1 Unlike 10BASE-T and 100BASE-TX, which use only two of the four pairs of wires within the Category 5, 1000BASE-T uses all four pairs of the twisted pair. Make sure all wires are tested ⎯ this is important. Factors that affect the return loss are: The number of transition points, as there is a connection via an RJ-45 to another connector, a patch panel, or device at each transition point.
Page 137
700 Series Software Manual v2.1 Figure B-4 shows the RJ-45 plug and RJ-45 connector. Figure B-4: RJ-45 Plug and RJ-45 Connector with Built-in LEDs Table B-2 lists the pin assignments for the 10/100 Mbps RJ-45 plug and the RJ-45 connector. Table-B-2.
700 Series Software Manual v2.1 Table-B-3. 100/1000 Mbps RJ-45 Plug and RJ-45 Connector Pin Assignments CHANNEL DESCRIPTION Rx/Tx Data + Rx/Tx Data Rx/Tx Data + Rx/Tx Data Rx/Tx Data + Rx/Tx Data Rx/Tx Data + Rx/Tx Data Conclusion For optimum performance of your 1000BASE-T product, it is important to fully qualify your cable installation and ensure it meets or exceeds ANSI/EIA/TIA-568-A:1995 or ISO/IEC 11801:1995 Category 5 specifications.
Appendix C 802.1x Port-Based Authentication Overview This appendix provides an overview of802.1x security and configuration. Understanding 802.1x Port Based Network Access Control 802.1x is well on its way to becoming an industry standard, and provides an effective wired and wireless LAN security solution. Windows XP implements 802.1x natively, and the 700 Series Switches supports 802.1x.
Page 140
700 Series Software Manual v2.1 The client sends an EAP-start message. This begins a series of message exchanges to authenticate the client. The access point replies with an EAP-request identity message. The client sends an EAP-response packet containing the identity to the authentication server. The authentication server uses a specific authentication algorithm to verify the client's identity.
Page 141
700 Series Software Manual v2.1 Initial 802.1x communications begin with an unauthenticated supplicant (i.e., client device) attempting to connect with an authenticator (i.e., 802.11 access point). The access point responds by enabling a port for passing only EAP packets from the client to an authentication server located on the wired side of the access point.
Glossary Use the list below to find definitions for technical terms used in this manual. 10BASE-T The IEEE specification for 10 Mbps Ethernet over Category 3, 4, or 5 twisted-pair cable. 100BASE-FX The IEEE specification for 100 Mbps Fast Ethernet over fiber-optic cable. 100BASE-TX The IEEE specification for 100 Mbps Fast Ethernet over Category 5 twisted-pair cable.
Page 144
700 Series Software Manual v2.1 also Reverse ARP (RARP) which can be used by a host to discover its IP address. In this case, the host broadcasts its physical address and a RARP server replies with the host's IP address. Auto-negotiation A feature that allows twisted-pair ports to advertise their capabilities for speed, duplex and flow control.
Page 145
700 Series Software Manual v2.1 Capacity planning Determining whether current solutions can satisfy future demands. Capacity planning includes evaluating potential workload and infrastructure changes. Certificate Authority A Certificate Authority is a trusted third-party organization or company that issues digital certificates used to create digital signatures and public-private key pairs.
Page 146
.com, .edu, .uk, etc. For example, in the address mail.NETGEAR.com, mail is a server name and NETGEAR.com is the domain. Short for digital subscriber line, but is commonly used in reference to the asymmetric version of this technology (ADSL) that allows data to be sent over existing copper telephone lines at data rates of from 1.5...
Page 147
700 Series Software Manual v2.1 Filtering The process of screening a packet for certain characteristics, such as source address, destination address, or protocol. Filtering is used to determine whether traffic is to be forwarded, and can also prevent unauthorized access to a network or network devices. Flow control A congestion- control mechanism.
Page 148
700 Series Software Manual v2.1 Ranges of addresses are assigned by Internic, an organization formed for this purpose. IP multicast Sending data to distributed servers on a multicast backbone. For large amounts of data, IP Multicast is more efficient than normal Internet transmissions, because the server can broadcast a message to many recipients simultaneously.
Page 149
700 Series Software Manual v2.1 MD5 creates digital signatures using a one-way hash function, meaning that it takes a message and converts it into a fixed string of digits, also called a message digest. When using a one-way hash function, one can compare a calculated message digest against the message digest that is decrypted with a public key to verify that the message hasn't been tampered with.
Page 150
700 Series Software Manual v2.1 Port monitoring The ability to monitor the traffic passing through a port on a device to analyze network characteristics and perform troubleshooting. Port speed The speed that a port on a device uses to communicate with another device or the network. Port trunking The ability to combine multiple ports on a device to create a single, high-bandwidth connection.
Page 151
700 Series Software Manual v2.1 Spanning Tree Protocol (STP) A protocol that finds the most efficient path between segments of a multi-looped, bridged network. STP allows redundant switches and bridges to be used for network resilience, without the broadcast storms associated with looping.
Page 152
700 Series Software Manual v2.1 A long distance link used to extend or connect remotely located local area networks. The Internet is a large WAN. wide area network WAN. A long distance link used to extend or connect remotely located local area networks. The Internet is a large WAN.
Need help?
Do you have a question about the FSM726v2 - 10/100 Mbps Managed Switch and is the answer not in the manual?
Questions and answers