Black Box

LE2711C - Switch Black Box - Free user manual and instructions

Find the device manual for free LE2711C Black Box in PDF.

📄 152 pages English EN Download 💬 AI Question
Notice Black Box LE2711C - page 1
Pick your language and provide your email: we'll send you a specifically translated version.

User questions about LE2711C Black Box

0 question about this device. Answer the ones you know or ask your own.

Ask a new question about this device

The email remains private: it is only used to notify you if someone responds to your question.

No questions yet. Be the first to ask one.

Download the instructions for your Switch in PDF format for free! Find your manual LE2711C - Black Box and take your electronic device back in hand. On this page are published all the documents necessary for the use of your device. LE2711C by Black Box.

USER MANUAL LE2711C Black Box

LE2700 Series Industrial Managed Ethernet Switches

User Manual

This Layer 2 modular rackmount managed Gigabit Ethernet switch has four module slots that accommodate 8-port 10/100/1000BASE-T RJ-45 and SFP modules, and 4-port 10GE SFP+ and 100-Mbps fiber ST and fiber SC modules.

Black Box LE2711C - User Manual - 1

natural_image Front view of a black networking device with multiple Ethernet ports and network switches (no visible text or labels)

Trademarks Used in this Manual

Black Box and the Double Diamond logo are registered trademarks of BB Technologies, Inc.

Any other trademarks mentioned in this manual are acknowledged to be the property of the trademark owners.

Disclaimer:

Black Box Network Services shall not be liable for damages of any kind, including, but not limited to, punitive, consequential or cost of cover damages, resulting from any errors in the product information or specifications set forth in this document and Black Box Network Services may revise this document at any time without notice.

We're here to help! If you have any questions about your application or our products, contact Black Box Tech Support at 724-746-5500 or go to blackbox.com and click on "Talk to Black Box."

You'll be live with one of our technical experts in less than 60 seconds.

Federal Communications Commission and Industry Canada Radio Frequency Interference Statements

This equipment generates, uses, and can radiate radio-frequency energy, and if not installed and used properly, that is, in strict accordance with the manufacturer's instructions, may cause interference to radio communication. It has been tested and found to comply with the limits for a Class A computing device in accordance with the specifications in Subpart B of Part 15 of FCC rules, which are designed to provide reasonable protection against such interference when the equipment is operated in a commercial environment. Operation of this equipment in a residential area is likely to cause interference, in which case the user at his own expense will be required to take whatever measures may be necessary to correct the interference.

Changes or modifications not expressly approved by the party responsible for compliance could void the user's authority to operate the equipment.

This digital apparatus does not exceed the Class A limits for radio noise emission from digital apparatus set out in the Radio Interference Regulation of Industry Canada.

2.1 Introduction....10
2.2 Features....10
2.3 What's Included 11
2.4 Hardware Description....12

  1. Hardware Installation....16

3.1 Rackmount Installation 16
3.2 Module Installation....16

3.2.1 RJ-45 Module (LE2720C) 16
3.2.2 SFP Module (LE2721C) 17
3.2.3 100/1000 Mbps SFP Module (LE2722C) or 10G SFP+ Module (LE2731C)....17
3.2.4 Power Module 18

3.3 Wiring 19

3.3.1 Grounding 19
3.3.2 Fault Relay 19
3.3.3 Redundant Power Inputs....19

3.4 Connection....20

3.4.1 Cables....20
3.4.2 SFP 22
3.4.3 B-Ring/B-Chain 22

  1. Redundancy....25

4.1 B-Ring 25

4.1.1 Introduction 25
4.1.2 Configurations 25

4.2 B-Chain 26

4.2.1 Introduction....26
4.2.2 Configurations....26

4.3 MRP....26

4.3.1 Introduction....26
4.3.2 Configurations....26

4.4 STP/RSTP/MSTP 27

4.4.1 STP/RSTP 27
4.4.2 MSTP....30
4.4.3 CIST 33

4.5 Fast Recovery 34

  1. Management....35

5.1 Basic Settings....36

5.1.1 System Information 36
5.1.2 Admin and Password....37
5.1.3 Authentication 37
5.1.4 IP Settings....38
5.1.5 IPv6 Settings 39
5.1.6 HTTPS....39
5.1.7 SSH 40
5.1.8 LLDP 40

5.1.9 Modbus TCP 43
5.1.10 Backup/Restore Configurations 43
5.1.11 Firmware Update....44

5.2 DHCP Server 44

5.2.1 Basic Settings....44
5.2.2 Dynamic Client List....44
5.2.3 Client List 44
5.2.4 Relay Agent....45

5.3 Port Setting 47

5.3.1 Port Control 47
5.3.2 Port Trunk 48
5.3.3 LACP 49
5.3.4 Loop Ground....52

5.4 VLAN....53

5.4.1 VLAN Membership....53
5.4.2 Port Configurations....54
5.4.3 Private VLAN 60

5.5 SNMP 62

5.5.1 SNMP System Configurations....64
5.5.2 SNMP Community Configurations 66
5.5.3 SNMP User Configurations....64
5.5.4 SNMP Group Configurations....66
5.5.5 SNMP View Configurations....66
5.5.6 SNMP Access Configurations....67

5.6 Traffic Prioritization....68

5.6.1 Storm Control....68
5.6.2 Port Classification....69
5.6.3 Port Tag Remaking....70
5.6.4 Port DSCP....71
5.6.5 Port Policing 72
5.6.6 Queue Policing 73
5.6.7 QoS Egress Port Scheduler and Shapers....74
5.6.8 Port Scheduled....76
5.6.9 Port Shaping....76
5.6.10 DSCP Based QoS....77
5.6.11 DSCP Translation....78
5.6.12 DSCP Classification 78
5.6.13 QoS Control List....79
5.6.14 QoS Counters 81
5.6.15 QCL Status....81

5.7 Multicast....82

5.7.1 IGMP Snooping....82
5.7.2 VLAN Configurations of IGMP Snooping....83
5.7.3 IGMP Snooping Status....84
5.7.4 Groups IGMP Snooping Information 85

5.8 Security....85

5.8.1 Remote Control Security Configurations....85
5.8.2 Device Binding 86
5.8.3 ACL Ports 90
5.8.4 AAA....99
5.8.5 RADIUS 100

5.8.6 NAS (802.1x) 105

5.9 Alerts....113

5.9.1 Fault Alarm 113

5.9.2 System Warning 113

5.10 Monitor and Diag 116

5.10.1 MAC Table 116

5.10.2 Port Statistics 119

5.10.3 Port Mirroring.... 121

5.10.4 System Log Information....122

5.10.5 Cable Diagnostics 123

5.10.6 SFP Monitor 124

5.10.7 Ping....124

5.11 Synchronization 126

5.12 Troubleshooting....129

5.12.1 Factory Defaults 129

5.12.2 System Reboot.... 129

5.13 Command Line Interface Management....129

  1. Specifications
Ethernet Standards IEEE 802.3 10BASE-T,IEEE 802.3u 100BASE-TX and 100BASE-FX,IEEE 802.3ab 1000BASE-T,IEEE 802.3z 100BASE-X,IEEE 802.3ae 10 Gigabit Ethernet,IEEE 802.3ad LACP (Link Aggregation Control Protocol),IEEE 802.1p COS (Class of Service),IEEE 802.1q VLAN tagging,IEEE 802.1w RSTP (Rapid Spanning Tree Protocol),IEEE 802.1s MSTP (Multiple Spanning Tree Protocol),IEEE 802.1x authentication,IEEE 801.1AB LLDP (Link Layer Discovery Protocol)
Jumbo Frames Up to 9.6 KB
MAC Table 8 K
Network Redundancy MRP,MSTP (RSTP/STP compatible)
Priority Queues 8
Processing Store-and-forward
Security Features Device binding,Enable/disable ports, MAC based port security,Port-based network access control (802.1x),Single 802.1x and Multiple 802.1x,MAC-based authentication,QoS assignment,Guest VLAN,MAC address limit,TACACS+,VLAN (802.1Q) to segregate and secure network traffic,Radius centralized password management,SNMPv3 encrypted authentication and access security,Https/SSH enhance network security,Web and CLI authentication and authorization,Authorization (15 levels),IP source guard
Software Features IEEE 1588v2 clock synchronization,IEEE 801.1D Bridge, auto MAC address learning/aging and MAC address (static),Multiple Registration Protocol (MRP),MSTP (RSTP/STP compatible),Redundant Ring with recovery time less than 30 ms over 250 units,Quality of Service (802.1p) for real-time traffic,VLAN (802.1Q) with VLAN tagging,IGMP v2/v3 Snooping,Port configuration, status, statistics, monitoring, security,DHCP Server/Client,DHCP Relay,Modbus TCP,DNS client proxy,SMTP Client
Connectors LE2700A, LE2700AE, LE2700UK:RS-232 Serial Console Port: (1) RJ-45 via console cable, 115200 bps, 8, N, 1;Fault contact: 24-VDC, 1-A relay;LE2710C: (4) 100FX SC, works in switch slot 1, 2, or 3;LE2711C: (4) 100FX ST, works in switch slot 1, 2, or 3;LE2720C: (8) 10/100/1000BASE-T RJ-45, works in switch slot 1, 2, or 3;LE2721C: (8) slots for 100/1000-Mbps SFP modules, works in switch slot 1, 2, or 3;LE2722C: (4) slots for 100/1000 Mbps SFP modules, works in switch slot 4 only;LE2731C: (4) slots for 10GE SFP+ modules, works in switch slot 4 only
Indicators LE2700A, LE2700AE, LE2700UK, LE2600LV:(39) LEDs:(1) PWR, (1) PWR1, (1) PWR2, (1) RM, (1) Ring, (1) Fault, (1) Def, (1) Link, (1) SPD,(1) FDX, (1) RMT,(28) Port LEDs;LE2710C, LE2711C, LE2720C:(2) LEDs per port;LE2721C, LE2722C, LE2731C:(1) LED per port;
Environmental Temperature Tolerance:Operating: -40 to +185° F (-40 to +85°C);Storage: -40 to +185° F (-40 to +85°C);Humidity:Operating: 5 to 95%, noncondensing
Power LE2700A, LE2700AE, LE2700UK:Input: Dual 88–264 VAC/100–370 VDC power inputs at terminal block;Consumption (Typ.): 43.5 watts max.;Overload Current Protection: Present;LE2700LV:Input: Dual 20–72 VDC terminal blocks, 3.9 A;LE2700LV-PS:Output: 12 VDC, 3.5 A:Consumption: 40 watts max.;Overload Current Protection: Present
Dimensions1.73"H x 17.32"W x 12.8"D (4.4 x 44 x 32.5 cm), 19" rackmountable
Weight 14.5 lb. (6.6 kg)
Approvals EMI:FCC Part 15,CISPR (EN55022) Class A,EN50155 (EN50121-3-2, EN55011, EN50121-4);EMS:EN61000-4-2 (ESD),EN61000-4-3 (RS),EN61000-4-4 (EFT),EN61000-4-5 (Surge),EN61000-4-6 (CS),EN61000-4-8,EN61000-4-11

2. Overview

2.1 Introduction

The LE2700 Series Industrial Managed Ethernet Switches are ideal for industrial Ethernet applications. Use them to control and monitor equipment at oil/gas wells transmission facilities, water/wastewater, IP security/surveillance cameras and alarms, utilities, or building HVAC systems.

The LE2700 Series Industrial Managed Ethernet Switches are scalable, flexible, cost-effective, and reliable. The 4-Slot Chassis is a Layer 2 modular rackmount managed Gigabit Ethernet switch with four module slots. 8-port 10/100/1000BASE-T RJ-45 and SFP modules, and 4-port 10GE SFP+ and 100-Mbps fiber ST and fiber SC modules are also available.

Figure 2-1. Available models.

Part Number Description
LE2700A Industrial Managed Ethernet Switch, 4-Slot Chassis, US
LE2700AE Industrial Managed Ethernet Switch, 4-Slot Chassis, EU
LE2700UK Industrial Managed Ethernet Switch, 4-Slot Chassis, UK
LE2700LV Industrial Managed Ethernet Switch - 4-Slot, Low-Voltage
LE2710C 4-port 100FX multimode 2 km SC module, works in switch slot 1, 2, or 3
LE2711C 4-port 100FX multimode 2 km ST module, works in switch slot 1, 2, or 3
LE2720C 8-port 10/100/1000BASE-T RJ-45 module, works in switch slot 1, 2, or 3
LE2721C 8-port 100/1000 Mbps SFP module, works in switch slot 1, 2, or 3
LE2722C 4-port 100/1000 Mbps SFP module, works in switch slot 4 only
LE2731C 4-port 10 GE SFP+ module, works in switch slot 4 only
LE2700-LV Industrial Managed Ethernet Switch Power Supply - 4-Slot, Low-Voltage

2.2 Features

  • Modular design with dual power supplies enables flexible network planning by allowing users to add capacity as demand increases. Choose the right quantity, speed, and range of interfaces for the application. Purchase the capacity you need when you need it.
  • Environmentally hardened case withstands operating temperatures of -40 to +185° F (-40 to +85° C).
  • Managed switch enables you to configure and monitor installations remotely.
    • Supports Web, SNMP, and console user interfaces.
  • Choose from copper, fiber, 10/100/1000-Mbps, and 10GE interfaces.
  • Complies with IEEE 802.3az energy efficient standards.
  • Manages traffic with 802.1p/q tagged frames.
  • Handles jumbo frames.
    • Supports IEEE 1588v2 synchronization.
  • Accommodates high availability protocols, including xSTP, link aggregation, and redundant ring protocols.
    • Supports IP multicast snooping with IGMPv2/3.
  • Authenticates ACLs, TACACS+, and 802.1x users.

2.3 What's Included

Your package should include the following items. If anything is missing or damaged, contact Black Box Technical Support at 724-746-5500 or info@blackbox.com.

LE2700A:

• LE2700 Series Industrial Managed Ethernet Switch with power supply
• U.S. power cord

LE2700AE:

• LE2700 Series Industrial Managed Ethernet Switch with power supply
- EU. power cord

LE2700UK:

• LE2700 Series Industrial Managed Ethernet Switch with power supply
- UK power cord

LE2700LV:

• LE2700 Series Industrial Managed Ethernet Switch with low-voltage power supply
• U.S. power cord

LE2700LV-PS:

• LE2700 Series Industrial Managed Ethernet Switch Power Supply - Low-Voltage

LE2710C:

4-port 100FX multimode 2 km SC module, works in switch slot 1, 2, or 3

LE2711C

4-port 100FX multimode 2 km ST module, works in switch slot 1, 2, or 3

LE2720C:

8-port 10/100/1000BASE-T RJ-45 module, works in switch slot 1, 2, or 3

LE2721C:

8-port 100/1000 Mbps SFP module, works in switch slot 1, 2, or 3

LE2722C:

4-port 100/1000 Mbps SFP module, works in switch slot 4 only

LE2731C:

4-port 10 GE SFP+ module, works in switch slot 4 only

You can download this user manual from the Black Box Web site.

To download from the Web site:

  1. Go to www.blackbox.com
  2. Enter the part number (LE2700A) in the search box:

Black Box LE2711C - To download from the Web site: - 1

text_image United States Hello Sign to or Register Account Search Block Box products SUPPORT ABOUT Talk with an Export
  1. Click on the "Resources" tab on the product page, and select the document you wish to download.

2.4 Hardware Description

Black Box LE2711C - Hardware Description - 1

flowchart
graph LR
    A["Device Icon"] --> B["Slot 1"]
    B --> C["Slot 2"]
    C --> D["Slot 3"]
    D --> E["Slot 4"]

LE2710C, LE2711C, LE2720C, or LE2721C

installs in slot 1, 2, or 3

10-Gigabit module (LE2731C) or

100/1000-Mbps Ethernet module

(LE2722C) installs in slot 4 only

Figure 2-1. Front panel.
Black Box LE2711C - Hardware Description - 2

flowchart
graph TD
    A["Power 1"] --> B["Power module slot 1"]
    C["Power 2"] --> D["Power module slot 2"]
    E["Power module installed in slot 1"] --> F["Power module installed in slot 2"]
    G["Power module installed in slot 2"] --> H["Power module installed in slot 1"]

Figure 2-2. Back panel.

On the rear panel of the switch are two panel module slots and one terminal block. The terminal blocks include two power pairs for redundant power supply.

Black Box LE2711C - Hardware Description - 3

text_image 2 Front view 3 45 1 6 Rear view 8 7
Table 2-2. LE2700 Series Industrial Managed Ethernet Switches Components2
NumberComponent Description
1Model nameName of product
2System and Port status LEDsSystem LEDs include PWR/PWR1/PWR2/R.M/Ring/Fault/DEF. Port LEDs include LINK/SPD/FDX/port number.
3Serial console portLinks to console for management.
4Reset buttonPress Reset for 3 seconds to reset and 5 seconds to return to factory default.
5LED mode button To change port LED mode, press the Mode button.
6Ethernet module slotsEnable different RJ-45/SFP modular combinations based on your needs.
7Power input module slots Houses power input modules.
8Terminal block Links to DC connector.

B-Ring provides two 10 Gigabit modules and four Gigabit Ethernet modules to meet your demand for high speed. For applications requiring long-distance data transmission, B-Ring also provides several fiber modules to meet your needs. Please refer to the following table for available modules.

The modules are not hot-swappable. Be sure to turn off power before changing modules; otherwise, the system will not detect newly inserted modules.

Table 2-3. Switch Modules.

Part NumberDescription
LE2710C 4-port100FX multimode 2 km SC module, installs in switch slot 1, 2, or 3
LE 2711C 4-port100FX multimode 2 km ST module, installs in switch slot 1, 2, or 3
LE2720C 8-port10/100/1000BASE-T RJ-45 module, installs in switch slot 1, 2, or 3
LE2721C 8-port100/1000 Mbps SFP module, installs in switch slot 1, 2, or 3
LE2722C 4-port100/1000 Mbps SFP module, installs in switch slot 4 only
LE2731C 4-port10 GE SFP+ module, installs in switch slot 4 only
Figure 2-4. SFP Modules.
Part NumberDescription Compatible Switch Modules
LFP401 SFP, 155-Mbps Fiber with Extended Diagnostics, 850-nm Multimode, LC, 2 kmLE2721C, LE2722C
LFP402 SFP, 155-Mbps Fiber with Extended Diagnostics, 1310-nm Multimode, LC, 2 kmLE2721C, LE2722C
LFP403SFP, 155-Mbps Fiber with Extended Diagnostics, 1310-nm, Single-Mode, LC, 30 kmLE2721C, LE2722C
LFP404 SFP, 155-Mbps Fiber with Extended Diagnostics, 1310-nm Single-Mode, Plus, LC, 60 kmLE2721C, LE2722C
LFP411 SFP, 1.25-Gbps Fiber with Extended Diagnostics, 850-nm Multimode, LC, 300 mLE2721C, LE2722C, LE2731C
LFP412SFP, 1.25-Gbps Fiber with Extended Diagnostics, 1310-nm Multimode, LC, 2 kmLE2721C, LE2722C, LE2731C
LFP413SFP, 1.25-Gbps Fiber with Extended Diagnostics, 1310-nm Single-Mode, LC, 10 kmLE2721C, LE2722C, LE2731C
LFP414SFP, 1.25-Gbps Fiber with Extended Diagnostics, 1310-nm Single-Mode, LC, 30 kmLE2721C, LE2722C, LE2731C
LFP415SFP with SerDes Interface, 1.25 Gbps, Copper, 1000BASE-T, Extended DiagnosticsLE2721C, LE2722C, LE2731C
LSP42110GBASE-SR SFP+, 850-nm Multimode, 300 m, LCLE2731C
LSP42210GBASE-SR SFP+, 1310-nm Single-Mode, 10 km, LCLE2731C

Available power supplies include:

  • Spare Power Supply for the LE2700 Series Industrial Managed Ethernet Switch Chassis (LE2700-PS)
  • Spare Power Supply for the LE2700 Series Industrial Managed Ethernet Switch Chassis (LE2700LV-PS)
Table 2-5. LE2700 Series Industrial Managed Ethernet Switches LEDs.
NumberLEDColorStatusDescription
1PWR Green OnDC power on
Green Blinking Upgrading firmware
2PW1GreenOnDC power module 1 activated
3PW2GreenOnDC power module 2 activated
4R.M. GreenOnRing Master
5Ring Green OnRing enabled
GreenSlowly blinkingRing structure is broken (i.e. part of the ring is disconnected)
Green Fast blinkingRing disabled
6FaultAmberOnErrors (power failure or port malfunctioning)
7DEFGreenOnSystem reset to default
8RMT Green OnAccessed remotely
9LNK Green OnPort link up
10SPDGreenBlinkingData transmitted
11FDXAmberOnPort works under full duplex

3. Hardware Installation

3.1 Rackmount Installation

The switch comes with two rackmount kits to allow you to fasten the switch to a rack in any environment.

Follow the steps below to install the switch to a rack.

Step 1: Install left and right front mounting brackets to the switch using 4 M3 screws on each side provided with switch.

Step 2: With front brackets orientated in front of the rack, nest front and rear brackets together. Fasten together using remaining M4 screws into counter sunk holes.

Step 3: Fasten the front mounting bracket to the front of the rack.

Black Box LE2711C - Rackmount Installation - 1

natural_image Technical line drawing showing a device with mounting bracket and a blue arrow indicating transformation (no text or symbols)

Figure 3-1. Installing the module.

3.2 Module Installation

3.2.1 RJ-45 Module (LE2720C)

Each LE2700 Series Industrial Managed Ethernet Switches switch supports a maximum of three RJ-45 modules, giving you a total of 24 RJ-45 ports. Follow the steps bellow for installation.

Step 1: Switch off the power of the switch.

Step 2: Insert the modules in Slot 1, 2, and 3 respectively.

Step 3: Switch on the power of the switch.

Black Box LE2711C - RJ-45 Module (LE2720C) - 1

flowchart
graph TD
    A["Slot 1"] --> B["Slot 2"]
    B --> C["Slot 3"]
    C --> D["Slot 4"]
    D --> E["Slot 4"]
    E --> F["1 2 3 4 5 6 7"]
    F --> G["1 2 3 4 5 6 7"]
    G --> H["1 2 3 4 5 6 7"]
    H --> I["1 2 3 4 5 6 7"]

Figure 3-3. RJ-45 module.

3.2.2 SFP Module (LE2710C, LE2711C, LE2721C)

Each LE2700 Series Industrial Managed Ethernet Switches switch supports a maximum of three SFP modules, giving you a total of 24 SFP ports. Follow the steps bellow for installation.

Step 1: Switch off the power of the switch.

Step 2: Insert the modules in Slot 1, 2, and 3 respectively.

Step 3: Switch on the power of the switch.

Black Box LE2711C - SFP Module (LE2710C, LE2711C, LE2721C) - 1

flowchart
graph TD
    A["Slot 1"] --> B["Slot 2"]
    B --> C["Slot 3"]
    C --> D["Slot 4"]
    E["Slot 4"] --> F["Slot 1"]
    E --> G["Slot 2"]
    E --> H["Slot 3"]
    E --> I["Slot 4"]
    J["Slot 1"] --> K["1"]
    J --> L["2"]
    J --> M["3"]
    J --> N["4"]
    J --> O["5"]
    J --> P["6"]
    J --> Q["7"]
    R["Slot 2"] --> S["1"]
    R --> T["2"]
    R --> U["3"]
    R --> V["4"]
    R --> W["5"]
    R --> X["6"]
    R --> Y["7"]
    Z["Slot 3"] --> AA["1"]
    Z --> AB["2"]
    Z --> AC["3"]
    Z --> AD["4"]
    Z --> AE["5"]
    Z --> AF["6"]
    Z --> AG["7"]
    AH["Slot 4"] --> AI["1"]
    AH --> AJ["2"]
    AH --> AK["3"]
    AH --> AL["4"]

Figure 3-4. SFP module.

3.2.3 100/1000 Mbps SFP Module (LE2722C) or 10G SFP+ Module (LE2731C)

Each LE2700 Series Industrial Managed Ethernet Switches switch supports one 4-port GE SFP or 10G SFP+ module, giving you a total of four GE or 10G ports. Follow the steps bellow for installation. The module can be plugged into the 10-Gigabit Ethernet port of the switch and links the switch with a fiberoptic network.

Follow the steps bellow for installation.

Step 1: Switch off the power of the switch.

Step 2: Insert the module in Slot 4.

Step 3: Switch on the power of the switch.

Black Box LE2711C - 100/1000 Mbps SFP Module (LE2722C) or 10G SFP+ Module (LE2731C) - 1

flowchart
graph TD
    A["Slot 1"] --> B["Slot 2"]
    B --> C["Slot 3"]
    C --> D["Slot 4"]
    D --> E["Final Layout"]
    style A fill:#f9f,stroke:#333
    style B fill:#f9f,stroke:#333
    style C fill:#f9f,stroke:#333
    style D fill:#f9f,stroke:#333
    style E fill:#ccf,stroke:#333

Figure 3-5. 10G SFP+ module.

CAUTION:

  1. The 10G slot can accommodate a Gigabit or 10G module (LE2722C or LE2731C); therefore, do not insert the LE2722C or LE2731C module in other slots.
  2. Removing and installing an Ethernet module can shorten its useful life. Do not remove and insert the modules more often than is absolutely necessary.

3.2.4 Power Module

Each LE2700 Series Industrial Managed Ethernet Switches switch supports a maximum of two power modules. Follow the steps bellow for installation.

Step 1: Switch off the power of the switch.

Step 2: Insert the modules in Power 1 and 2 slots respectively.

Step 3: Switch on the power of the switch.

Black Box LE2711C - Power Module - 1

flowchart
graph TD
    A["Power 1"] --> C["Output: 50Watts, 12V = 4.2A"]
    B["Power 2"] --> C
    C --> D["Output: 88-384VAC/100-370VDC - 1.3A Output: 50Watts, 12V = 4.2A"]

Figure 3-6. Power module.

3.3 Wiring

WARNING:

Do not disconnect modules or wires unless power has been switched off or the area is known to be non-hazardous. The devices may only be connected to the supply voltage shown on the type plate.

ATTENTION:

  1. Be sure to disconnect the power cord before installing and/or wiring your switches.
  2. Calculate the maximum possible current in each power wire and common wire. Observe all electrical codes dictating the maximum current allowable for each wire size.
  3. If the current goes above the maximum ratings, the wiring could overheat, causing serious damage to your equipment.
  4. Use separate paths to route wiring for power and devices. If power wiring and device wiring paths must cross, make sure the wires are perpendicular at the intersection point.
  5. Do not run signal or communications wiring and power wiring through the same wire conduit. To avoid interference, wires with different signal characteristics should be routed separately.
  6. You can use the type of signal transmitted through a wire to determine which wires should be kept separate. The rule of thumb is that wiring sharing similar electrical characteristics can be bundled together.

  7. Separate input wiring from output wiring.

  8. Label the wiring to all devices in the system.

3.3.1 Grounding

Grounding and wire routing help limit the effects of noise due to electromagnetic interference (EMI). Run the ground connection from the ground screws to the grounding surface prior to connecting devices.

3.3.2 Fault Relay

The relay contact of the 2-pin terminal block connector is used to detect user-configured events. The two wires attached to the fault contacts form an open circuit when a user-configured event is triggered. If a user-configured event does not occur, the fault circuit remains closed.

3.3.3 Redundant Power Inputs

The LE2700 Series Industrial Managed Ethernet Switches switches support dual redundant power supplies, Power Supply 1 (PWR1) and Power Supply 2 (PWR2). The connections for PWR1, PWR2 and the RELAY are located on the terminal block.

Step 1: Insert the negative/positive DC wires into the V-/V+ terminals, respectively.

Step 2: To keep the DC wires from pulling loose, use a small flat-blade screwdriver to tighten the wire-clamp screws on the front of the terminal block connector.

Step 3: Insert the plastic terminal block connector prongs into the terminal block receptor.

Black Box LE2711C - Redundant Power Inputs - 1

text_image Power-1 Input Power-2 Input POWER1 POWER2 FAIL RLY COM V+IL V-IN V+IL V-IN GND1 Earth GND GND2 Full Close Full Open Ground of Power-1 Earth Ground Ground of Power-2 Fault Relay

Figure 3-7. Redundant power inputs.

3.4 Connection

3.4.1 Cables

1000/100BASE-TX/10BASE-T Pin Assignments

The LE2700 Series Industrial Managed Ethernet Switches switches come with standard Ethernet ports. According to the link type, the switch uses CAT 3, 4, 5,5e UTP cables to connect to any other network devices (PCs, servers, switches, routers, or hubs). Refer to the following table for cable specifications.

Table 3-1. Cable types and specifications.
Cable Type Max.Length Connector
10BASE-T CAT3, 4, 5 100-ohm UTP 328 ft. (100 m) RJ-45
100BASE-TX CAT5100-ohm UTP UTP 328 ft. (100 m) RJ-45
1000BASE-TXCAT5/CAT5e 100-ohm UTPUTP 328 ft. (100 m)RJ-45

With 1000/100BASE-TX/10BASE-T cables, pins 1 and 2 are used for transmitting data, and pins 3 and 6 are used for receiving data.

Table 3-2. 10/100BASE-T RJ-45 pin assignments.
Pin NumberAssignment
1 TD+
2 TD-
3 RD+
4 Not used
5 Not used
6 RD-
7 Not used
8 Not used
Table 3-3. 1000BASE-T RJ-45 pin assignments.
Pin NumberAssignment
1 BI_DA+
2 BI_DA-
3 BI_DB+
4 BI_DC+
5 BI_DC-
6 BI_DB-
7 BI_DD+
8 BI_DD-

The LE2700 series switches support auto MDI/MDI-X operation. You can use a cable to connect the switch to a PC. Table 3-4 shows the 10BASE-T/100BASE-TX MDI and MDI-X port pinouts.

Table 3-4. 10/100BASE-T MDI/MDI-X Pin Assignments.
Pin NumberMDI port MDI-X port
1TD+(transmit) RD+(receive)
2TD-(transmit) RD-(receive)
3RD+(receive) TD+(transmit)
4Not used Not used
5Not used Not used
6RD-(receive) TD-(transmit)
7Not used Not used
8Not used Not used
Table 3-5. 1000BASE-T MDI/MDI-X Pin Assignments.
Pin Number MDI port MDI-X port
1 BI_DA+ BI_DB+
2 BI_DA- BI_DB-
3 BI_DB+ BI_DA+
4 BI_DC+ BI_DD+
5BI_DC-BI_DD-
6 BI_DB-BI_DA-
7 BI_DD+BI_DC+
8BI_DD-BI_DC-

NOTE: "+" and "-" signs represent the polarity of the wires that make up each wire pair.

RS-232 port wiring

You can manage the LE2700 Series Switch via console ports using a RS-232 cable (included). Connect the port to a PC via the RS-232 cable with a DB9 female connector. The DB9 female connector of the RS-232 cable should be connected to the PC while the other end of the cable (RJ-45 connector) should be connected to the console port of the switch.

Table 3-6. RS-232 port wiring.
PC Pinout (Male) AssignmentRS-232 with DB9 Female ConnectorDB9 to RJ-45
Pin #2 RDPin #2 TDPin #2
Pin #3 TDPin #3 RDPin #3
Pin #5 GDPin #5 GDPin #5

Black Box LE2711C - RS-232 port wiring - 1

text_image DB9 Male Shield Signal Ground 5 9 Ring Indicator DTE Ready 4 Clear to Send Transmitted Data 3 Received Data 2 Request to Send Received Line Signal Detect 1 DCE Ready DB9 Female Received by DTE Device 1 DCE Ready Transmitted from DTE Device 2 Clear to Send Received Data 3 8 Request to Send DTE Ready 4 Signal Ground 5 Ring Indicator Shield Received by DCE Device Transmitted from DCE Device

Figure 3-8. RS-232 port wiring diagram.

3.4.2 SFP

The switch comes with fiber optical ports that can connect to other devices using SFP modules. The fiber optical ports are in multimode (0 to 550 m, 850 nm with 50/125- m, 62.5/125- m fiber) and single-mode with LC connectors. Remember to connect the TX port of Switch A should be connected to the RX port of Switch B.

Black Box LE2711C - SFP - 1

text_image Switch A Switch B Fiber

Figure 3-9. Fiber optic ports.

3.4.3 B-Ring/B-Chain

B-Ring

You can connect three or more switches to form a ring topology to gain network redundancy capabilities through the following steps.

  1. Connect each switch to form a daisychain using an Ethernet cable.
  2. Set one of the connected switches to be the master and make sure the port setting of each connected switch on the management page corresponds to the physical ports connected. For information about the port setting, please refer to Section 4.1.2, Configuration.
  3. Connect the last switch to the first switch to form a ring topology.

Black Box LE2711C - B-Ring - 1

text_image B-Ring

Figure 3-10. B-Ring.

Coupling Ring

If you already have two B-Ring topologies and would like to connect the rings, you can form them into a coupling ring. All you need to do is select two switches from each ring to be connected, for example, switch A and B from Ring 1 and switch C and D from ring 2. Decide which port on each switch to be used as the coupling port and then link them together, for example, port 1 of switch A to port 2 of switch C and port 1 of switch B to port 2 of switch D. Then, enable Coupling Ring option by checking the checkbox on the management page and select the coupling ring in correspondence to the connected port. For more information on port setting, refer to Section 4.1.2, Configuration. Once the setting is completed, one of the connections will act as the main path while the other will act as the backup path.

Black Box LE2711C - Coupling Ring - 1

flowchart
graph TD
    A["Switch A"] -->|B-Ring| B["Main Path"]
    B -->|B-Ring| C["Switch C"]
    C -->|B-Ring| D["Switch D"]
    D -->|B-Ring| E["Switch B"]
    style A fill:#f9f,stroke:#333
    style B fill:#ccf,stroke:#333
    style C fill:#cfc,stroke:#333
    style D fill:#fcc,stroke:#333
    style E fill:#cff,stroke:#333

Figure 3-11. Coupling ring.

Dual Homing

If you want to connect your ring topology to a RSTP network environment, you can use dual homing. Choose two switches (Switch A & B) from the ring for connecting to the switches in the RSTP network (Ciscos switches). The connection of one of the switches (Switch A or B) will act as the primary path, while the other will act as the backup path that is activated when the primary path connection fails.

Black Box LE2711C - Dual Homing - 1

flowchart
graph TD
    A["Switch A"] -->|Main Path| B["Switch B"]
    B -->|Backup Path| C["Control Center RSTP"]
    C -->|Main Path| B
    B -->|B-Ring| D["Output Interface"]
    style A fill:#f9f,stroke:#333
    style C fill:#ccf,stroke:#333
    style B fill:#cfc,stroke:#333
    style D fill:#fcc,stroke:#333

Figure 3-12. Dual homing.

B-Chain

When connecting multiple B-Rings to meet your expansion demand, you can create an B-Chain topology through the following steps.

  1. Select two switches from the chain (Switch A & B) that you want to connect to the B-Ring and connect them to the switches in the ring (Switch C & D).
  2. In correspondence to the port connected to the ring, configure an edge port for both of the connected switches in the chain by checking the box in the management page (see Section 4.1.2, Configuration).

  3. Once the setting is completed, one of the connections will act as the main path, and the other as the backup path.

Black Box LE2711C - B-Chain - 1

flowchart
graph TD
    SwitchA["Switch A"] --> EdgePort1["Edge port"]
    SwitchB["Switch B"] --> EdgePort2["Edge port"]
    SwitchC["Switch C"] --> EdgePort3["Edge port"]
    SwitchD["Switch D"] --> EdgePort4["Edge port"]
    BRing["B-Ring"] --> EdgePort1
    BRing --> EdgePort2
    BRing --> EdgePort3
    BRing --> EdgePort4

Figure 3-13. B-Chain.

4. Redundancy

Redundancy for minimized system downtime is one of the most important concerns for industrial networking devices. Hence, B-Ring has developed proprietary redundancy technologies including B-Ring, O-RSTP, and Open-Ring featuring faster recovery time than existing redundancy technologies widely used in commercial applications, such as STP, RSTP, and MSTP. B-Ring's proprietary redundancy technologies not only support different networking topologies, but also assure the reliability of the network.

4.1 B-Ring

4.1.1 Introduction

B-Ring is a proprietary redundant ring technology, with recovery time of less than 10 milliseconds and up to 250 nodes. The ring protocols identify one switch as the master of the network, and then automatically block packets from traveling through any of the network's redundant loops. If one branch of the ring gets disconnected from the rest of the network, the protocol automatically readjusts the ring so that the part of the network that was disconnected can reestablish contact with the rest of the network. The B-Ring redundant ring technology can protect mission-critical applications from network interruptions or temporary malfunction with its fast recover technology.

4.1.2 Configurations

B-Ring supports three ring topologies: Ring Master, Coupling Ring, and Dual Homing. You can configure the settings in the interface below.

Table 4-1. Configuration screen components.
Label Description
Redundant Ring Check to enable B-Ring topology.
Ring MasterOnly one ring master is allowed in a ring. However, if more than one switch are set to enable Ring Master, the switch with the lowest MAC address will be the active ring master and the others will be backup masters.
1st Ring Port The primary port when the switch is ring master.
2nd Ring Port The backup port when the switch is ring master.
Coupling Ring Check to enable Coupling Ring. Coupling Ring can divide a big ring into two smaller rings to avoid network topology changes affecting all switches. It is a good method for connecting two rings.
Coupling PortPorts for connecting multiple rings. A coupling ring needs four switches to build an active and a backup link.Links formed by the coupling ports will run in active/backup mode.
Dual Homing Check to enable Dual Homing. When Dual Homing is enabled, the ring will be connected to normal switches through two RSTP links (ex: backbone Switch). The two links work in active/backup mode, and connect each ring to the normal switches in RSTP mode.
Apply Click to apply the configurations.

NOTE: Do not set one switch as ring master and coupling ring at the same time, because this could cause heavy loading.

4.2 B-Chain

4.2.1 Introduction

B-Chain is Black Box's revolutionary network redundancy technology which enhances network redundancy for any backbone networks, providing ease-of-use and maximum fault-recovery swiftness, flexibility, compatibility, and cost-effectiveness in a set of network redundancy topologies. The self-healing Ethernet technology designed for distributed and complex industrial networks enables the network to recover in less than 10 ms for up to 250 switches if at any time a segment of the chain fails.

B-Chain allows multiple redundant rings of different redundancy protocols to join and function together as a large and the most robust network topologies. It can create multiple redundant networks beyond the limitations of current redundant ring technologies.

4.2.2 Configurations

B-Chain is very easy to configure and manage. Only one edge port of the edge switch needs to be defined. Other switches beside them just need to have B-Chain enabled.

Table 4-2. B-Chain screen options.
Label Description
Enable Check to enable B-Chain function
1st Ring Port The first port connecting to the ring.
2nd Ring Port The second port connecting to the ring.
Edge Port A B-Chain topology must begin with edge ports. The ports with a smaller switch MAC address will serve as the backup link and RM LED will light up.

4.3 MRP

4.3.1 Introduction

MRP (Media Redundancy Protocol) is an industry standard for high-availability Ethernet networks. MRP allowing Ethernet switches in ring configuration to recover from failure rapidly to ensure seamless data transmission. A MRP ring (IEC 62439) can support up to 50 devices and will enable a back-up link in 80ms (adjustable to max. 200ms/500ms).

4.3.2 Configurations

Black Box LE2711C - Configurations - 1

text_image MRP Enable ■ Manager ■ React on Link Change 1st Ring Port Port 7 LinkDown 2nd Ring Port Port 8 Forwarding Apply

Figure 4-1. MRP screen.

Table 4-3. MRP configuration screen options.
Label Description
Enable Enables the MRP function
Manager Every MRP topology needs a MRP manager. One MRP topology can only have a Manager. If two or more switches are set to be Manager, the MRP topology will fail.
React on Link Change (Advanced mode)Faster mode. Enabling this function will cause MRP topology to converge more rapidly. This function only can be set in MRP manager switch.
1st Ring Port Chooses the port which connects to the MRP ring
2nd Ring Port Chooses the port which connects to the MRP ring

4.4 STP/RSTP/MSTP

4.4.1 STP/RSTP

STP (Spanning Tree Protocol), and its advanced versions RSTP (Rapid Spanning Tree Protocol) and MSTP (Multiple Spanning Tree Protocol), are designed to prevent network loops and provide network redundancy. Network loops occur frequently in large networks as when two or more paths run to the same destination, broadcast packets may get in to an infinite loop and hence causing congestion in the network. STP can identify the best path to the destination, and block all other paths. The blocked links will stay connected but inactive. When the best path fails, the blocked links will be activated. Compared to STP which recovers a link in 30 to 50 seconds, RSTP can shorten the time to 5 to 6 seconds.

STP Bridge Status

This page shows the status for all STP bridge instances.

Black Box LE2711C - STP Bridge Status - 1

text_image STP Bridges Auto-refresh □ Refresh MSTI Bridge ID Root Topology Topology ID Port Cost Flag Change Last 80:00-00:1E:94:FF:FF:FF 80:00-00:1E:94:FF:FF:FF - 0 Steady -

Figure 4-2. STP bridge screen.

Table 4-4. STP bridge screen options.
Label Description
MSTI The bridge instance. You can also link to the STP detailed bridge status.
Bridge ID The bridge ID of this bridge instance.
Root ID The bridge ID of the currently selected root bridge.
Root Port The switch port currently assigned the root port role.
Root CostRoot path cost. For a root bridge, this is zero. For other bridges, it is the sum of port path costs on the least cost path to the Root Bridge.
Topology Flag The current state of the Topology Change Flag for the bridge instance.
Topology Change Last The time since last Topology Change occurred.
RefreshClick to refresh the page immediately.
Auto-refreshCheck this box to enable an automatic refresh of the page at regular intervals.

STP Port Status

This page displays the STP port status for the currently selected switch.

PortCIST RoleCIST StateUptime
1Non-STPForwarding-
2Non-STPForwarding-
3Non-STPForwarding-
4Non-STPForwarding-
5Non-STPForwarding-
6Non-STPForwarding-
7Non-STPForwarding-
8Non-STPForwarding-
9Non-STPForwarding-
10Non-STPForwarding-
11Non-STPForwarding-
12Non-STPForwarding-

Figure 4-3. STP Port Status screen.

Table 4-5. STP Port Status screen options.
Label Description
Port The switch port number to which the following settings will be applied.
CIST RoleThe current STP port role of the CIST port. The values include: AlternatePort, BackupPort, RootPort, and DesignatedPort.
StateThe current STP port state of the CIST port. The values include: Blocking, Learning, and Forwarding.
Uptime The time since the bridge port is last initialized.
Refresh Click to refresh the page immediately.
Auto-refreshCheck this box to enable an automatic refresh of the page at regular intervals.

STP Statistics

This page displays the STP port statistics for the currently selected switch.

PortTransmittedReceivedDiscarded
MSTPRSTPSTPTCNMSTPRSTPSTPTCNUnknownIllegal
No ports enabled

Figure 4-4. STP statistics screen.

Table 4-6. STP statistics screen options.
Label Description
Port The switch port number to which the following settings will be applied.
RSTP The number of RSTP configuration BPDUs received/transmitted on the port.
STP The number of legacy STP configuration BPDUs received/transmitted on the port.
TCNThe number of (legacy) topology change notification BPDUs received/transmitted on the port.
Discarded Unknown The number of unknown spanning tree BPDUs received (and discarded) on the port.
Discarded IllegalThe number of illegal spanning tree BPDUs received (and discarded) on the port.
Refresh Click to refresh the page immediately.
Auto-refresh Check to enable an automatic refresh of the page at regular intervals.

STP Bridge Configurations

Black Box LE2711C - STP Bridge Configurations - 1

text_image STP Bridge Configuration Basic Settings Protocol Version MSTP Forward Delay 15 Max Age 20 Maximum Hop Count 20 Transmit Hold Count 6

Figure 4-5. STP Bridge Configuration screen.

Table 4-7. STP Bridge Configuration screen options.
Label Description
Protocol Version The version of the STP protocol. Valid values include STP, RSTP, and MSTP.
Forward DelayThe delay used by STP bridges to transit root and designated ports to forwarding (used in STP compatible mode). The range of valid values is 4 to 30 seconds.
Max AgeThe maximum time the information transmitted by the root bridge is considered valid. The range of valid values is 6 to 40 seconds, and Max Age must be <= (FwdDelay-1)*2.
Maximum Hop CountThis defines the initial value of remaining hops for MSTI information generated at the boundary of an MSTI region. It defines how many bridges a root bridge can distribute its BPDU information to. The range of valid values is 4 to 30 seconds, and MaxAge must be <= (FwdDelay-1)*2.
Transmit Hold CountThe number of BPDUs a bridge port can send per second. When exceeded, transmission of the next BPDU will be delayed. The range of valid values is 1 to 10 BPDUs per second.
SaveClick to save changes.
ResetClick to undo any changes made locally and revert to previously saved values.

4.4.2 MSTP

Since the recovery time of STP and RSTP takes seconds, which are unacceptable in some industrial applications, MSTP was developed. The technology supports multiple spanning trees within a network by grouping and mapping multiple VLANs into different spanning-tree instances, known as MSTIs, to form individual MST regions. Each switch is assigned to an MST region. Hence, each MST region consists of one or more MSTP switches with the same VLANs, at least one MST instance, and the same MST region name. Therefore, switches can use different paths in the network to effectively balance loads.

Port Settings

This page allows you to examine and change the configurations of current MSTI ports. A MSTI port is a virtual port, which is instantiated separately for each active CIST (physical) port for each MSTI instance configured and applicable for the port. The MSTI instance must be selected before MSTI port configuration options are displayed.

This page contains MSTI port settings for physical and aggregated ports. The aggregation settings are stack global.

Black Box LE2711C - Port Settings - 1

text_image MSTI Port Configuration Select MSTI MST1 Get MST1 MST2 MST3 MST4 MST5 MST6 MST7

Black Box LE2711C - Port Settings - 2

text_image MSTI Normal Ports Configuration Port Path Cost Priority 1 Auto 128 2 Auto 128 3 Auto 128 4 Auto 128 5 Auto 128 6 Auto 128

Figure 4-6. MSTI Port Configuration screens.

Table 4-8. MSTI Port Configuration screen options.
Label Description
Port The switch port number of the corresponding STP CIST (and MSTI) port.
Path CostConfigures the path cost incurred by the port. Auto will set the path cost according to the physical link speed by using the 802.1D-recommended values. Specific allows you to enter a user-defined value. The path cost is used when establishing an active topology for the network. Lower path cost ports are chosen as forwarding ports in favor of higher path cost ports. The range of valid values is 1 to 200000000.
Priority Configures the priority for ports having identical port costs. (See above).
Save Click to save changes.
Reset Click to undo any changes made locally and revert to previously saved values.

Mapping

This page allows you to examine and change the configurations of current STP MSTI bridge instance.

Black Box LE2711C - Mapping - 1

text_image MSTI Configuration Add VLANs separated by spaces or comma. Unmapped VLANs are mapped to the CIST. (The default bridge instance). Configuration Identification Configuration Name 00-1e-94-ff-ff-ff Configuration Revision 0 MSTI Mapping MSTI VLANs Mapped MST1 MST2 MST3 MST4 MST5 MST6 MST7 Save Reset

Figure 4-7. MSTI Configuration screen.

Table 4-9. MSTI Configuration screen options.
Label Description
Configuration NameThe name which identifies the VLAN to MSTI mapping. Bridges must share the name and revision (see below), as well as the VLAN-to-MSTI mapping configurations in order to share spanning trees for MSTIs (intra-region). The name should not exceed 32 characters.
Configuration RevisionRevision of the MSTI configuration named above. This must be an integer between 0 and 65535.
MSTIThe bridge instance. The CIST is not available for explicit mapping, as it will receive the VLANs not explicitly mapped.
VLANS MappedThe list of VLANs mapped to the MSTI. The VLANs must be separated with commas and/or space. A VLAN can only be mapped to one MSTI. An unused MSTI will be left empty (ex. without any mapped VLANs).
Save Click to save changes.
Reset Click to undo any changes made locally and revert to previously saved values.

Priority

This page allows you to examine and change the configurations of current STP MSTI bridge instance priority.

Black Box LE2711C - Priority - 1

text_image MSTI Configuration MSTI Priority Configuration MSTI Priority CIST 128 MST1 128 MST2 128 MST3 128 MST4 128 MST5 128 MST6 128 MST7 128 Save Reset

Figure 4-8. MSTI configuration screen.

Table 4-10. MSTI configuration screen options.
Label Description
MSTI The bridge instance. CIST is the default instance, which is always active.
PriorityIndicates bridge priority. The lower the value, the higher the priority. The bridge priority, MSTI instance number, and the 6-byte MAC address of the switch forms a bridge identifier.
Save Click to save changes.
Reset Click to undo any changes made locally and revert to previously saved values.

4.4.3 CIST

With the ability to cross regional boundaries, CIST is used by MSTP to communicate with other MSTP regions and with any RSTP and STP single-instance spanning trees in the network. Any boundary port, that is, if it is connected to another region, will automatically belongs solely to CIST, even if it is assigned to an MSTI. All VLANs that are not members of particular MSTIs are members of the CIST.

Port Settings

Black Box LE2711C - Port Settings - 1

text_image STP CIST Ports Configuration CIST Aggregated Ports Configuration Port STP Enabled Path Cost Priority Admin Edge Auto Edge Restricted Role TCN BPDU Guard Point-to- point - □ Auto 128 Edge ✓ □ □ □ Forced True CIST Normal Ports Configuration Port STP Enabled Path Cost Priority Admin Edge Auto Edge Restricted Role TCN BPDU Guard Point-to- point 1 □ Auto 128 Edge ✓ □ □ □ Auto 2 □ Auto 128 Edge ✓ □ □ □ Auto 3 □ Auto 128 Edge ✓ □ □ □ Auto 4 □ Auto 128 Edge ✓ □ □ □ Auto 5 □ Auto 128 Edge ✓ □ □ □ Auto 6 □ Auto 128 Edge ✓ □ □ □ Auto

Figure 4-9. Port settings screen.

Table 4-11. Port Settings screen options.
Label Description
Port The switch port number to which the following settings will be applied.
STP Enabled Check to enable STP for the port.
Path CostConfigures the path cost incurred by the port. Auto will set the path cost according to the physical link speed by using the 802.1D-recommended values. Specific allows you to enter a user-defined value. The path cost is used when establishing an active topology for the network. Lower path cost ports are chosen as forwarding ports in favor of higher path cost ports. The range of valid values is 1 to 200000000.
Priority Configures the priority for ports having identical port costs. (See above).
OpenEdge (setate flag)A flag indicating whether the port is connected directly to edge devices or not (no bridges attached). Transiting to the forwarding state is faster for edge ports (operEdge set to true) than other ports.
AdminEdgeConfigures the operEdge flag to start as set or cleared.(the initial operEdge state when a port is initialized).
AutoEdgeCheck to enable the bridge to detect edges at the bridge port automatically. This allows operEdge to be derived from whether BPDUs are received on the port or not.
Restricted RoleWhen enabled, the port will not be selected as root port for CIST or any MSTI, even if it has the best spanning tree priority vector. Such a port will be selected as an alternate port after the root port has been selected. If set, spanning trees will lose connectivity. It can be set by a network administrator to prevent bridges outside a core region of the network from influencing the active spanning tree topology because those bridges are not under the full control of the administrator. This feature is also known as Root Guard.
Table 4-11 (continued). Port Settings screen options.
Label Description
Restricted TCNWhen enabled, the port will not propagate received topology change notifications and topology changes to other ports. If set, it will cause temporary disconnection after changes in an active spanning trees topology as a result of persistent incorrectly learned station location information. It is set by a network administrator to prevent bridges outside a core region of the network from causing address flushing in that region because those bridges are not under the full control of the administrator or is the physical link state for the attached LANs transitions frequently.
Point2PointConfigures whether the port connects to a point-to-point LAN rather than a shared medium. This can be configured automatically or set to true or false manually. Transiting to forwarding state is faster for point-to-point LANs than for shared media.
Save Click to save changes.
Reset Click to undo any changes made locally and revert to previously saved values.

4.5 Fast Recovery

Fast recovery mode can be set to connect multiple ports to one or more switches. IGPS-9084GP with fast recovery mode will provide redundant links. Fast recovery mode supports 12 priorities. Only the first priority will be the active port, and the other ports with different priorities will be backup ports.

Fast Recovery Mode
Black Box LE2711C - Fast Recovery - 1

text_image Active Port.01 Not included Port.02 Not included Port.03 Not included Port.04 Not included Port.05 Not included Apply

Figure 4-10. Fast Recovery screen.

Table 4-12. Fast Recovery screen options.
Label Description
Active Activates fast recovery mode.
portPorts can be set to 12 priorities. Only the port with the highest priority will be the active port. 1st Priority is the highest.
Apply Click to activate the configurations.

5. Management

The switch can be controlled via a built-in Web server that supports Internet Explorer (Internet Explorer 5.0 or above versions) and other Web browsers such as Chrome. Therefore, you can manage and configure the switch easily and remotely. You can also upgrade firmware via a Web browser. The Web management function not only reduces network bandwidth consumption, but also enhances access speed and provides a user-friendly viewing screen.

NOTE: By default, IE5.0 or later version do not allow Java applets to open sockets. You need to modify the browser setting separately in order to enable Java applets for network ports.

Preparing for Web Management

You can access the management page of the switch via the following default values:

IP Address: 192.168.10.1

Subnet Mask: 255.255.255.0

Default Gateway: 192.168.10.254

User Name: admin

Password: admin

System Login

  1. Launch Internet Explorer.

  2. Type http:// and the IP address of the switch. Press Enter.

Black Box LE2711C - System Login - 1

text_image 192.368.30.1 Google You Search Images Maps Play YouTube News Gmail Documents Calendar More -

Figure 5-1. System login.

  1. A login screen appears.

  2. Type in the username and password. The default username and password is admin.

  3. Click Enter or OK button, the management Web page appears.

Black Box LE2711C - System Login - 2

text_image Windows Security Enter Network Password Enter your password to connect to: PC-SWRD19 admin ***** Domain: blackbox Remember my credentials Logon failure: unknown user name or bad password. OK Cancel

Figure 5-2. Login screen.

After logging in, you can see the information of the switch as shown in the next screen.

Black Box LE2711C - System Login - 3

text_image System Name LE2700A Industrial 20-port managed Gigabit Ethernet switch with Description 8x10/100/1000Base-T(X) ports and 12x100/1000Base-X, SFP socket Location Contact OID 1.3.6.1.4.1.25972.100.0.0.113 Hardware MAC Address 00-1e-94-12-45-78 Time System Date 1970-01-01T05:53:34+00:00 System Uptime 0d 05:53:34 Software Kernel Version v9.00 Software Version v1.00 Software Date 2013-05-30T15:36:26+08:00 Auto-refresh □ Refresh Enable Location Alert

Figure 5-3. System information.

On the right-hand side of the management interface shows links to various settings. You can click on the links to access the configuration pages of different functions.

5.1 Basic Settings

Basic Settings allow you to configure the basic functions of the switch.

5.1.1 System Information

This page shows the general information of the switch.

Black Box LE2711C - System Information - 1

text_image System Information Configuration System Name IGS-9812GP System Description Industrial 20-port managed Gi System Location System Contact System Timezone Offset (minutes) 0 Save Reset

Figure 5-4. System information configuration.

Table 5-1. System information configuration screen options.
Label Description
System NameAn administratively assigned name for the managed node. By convention, this is the node's fully-qualified domain name. A domain name is a text string consisting of alphabets (A-Z, a-z), digits (0-9), and minus sign (-). Space is not allowed to be part of the name. The first character must be an alpha character. And the first or last character must not be a minus sign. The allowed string length is 0 to 255.
System DescriptionDescription of the device.
System LocationThe physical location of the node (e.g., telephone closet, 3rd floor). The allowed string length is 0 to 255, and only ASCII characters from 32 to 126 are allowed.
Table 5-1 (continued). System information configuration screen options.
Label Description
System ContactThe textual identification of the contact person for this managed node, together with information on how to contact this person. The allowed string length is 0 to 255, and only ASCII characters from 32 to 126 are allowed.
System Timezone offset (minutes)Provides the time-zone offset from UTC/GMT.The offset is given in minutes east of GMT. The valid range is from -720 to 720 minutes.
Save Click to save changes.
Reset Click to undoany changes made locally and revert to previously saved values.

5.1.2 Admin & Password

This page allows you to configure the system password required to access the web pages or log in from CLI.

Black Box LE2711C - Admin &amp; Password - 1

text_image System Password Username admin Old Password New Password Confirm New Password Save

Figure 5-5. System Password screen.

Table 5-2. System Password screen options.
Label Description
Old Password The existing password. If this is incorrect, you cannot set the new password.
New PasswordThe new system password. The allowed string length is 0 to 31, and only ASCII characters from 32 to 126 are allowed.
Confirm New PasswordRe-type the new password.
Save Click to save changes.

5.1.3 Authentication

This page allows you to configure how a user is authenticated when he/she logs into the switch via one of the management interfaces.

Authentication Method Configuration
Black Box LE2711C - Authentication - 1

text_image Client Authentication Method Fallback console local telnet local ssh local web local Save Reset

Figure 5-6. Authentication Method Configuration screen.

Table 5-3. Authentication Method Configuration screen options.
Label Description
Client The management client for which the configuration below applies.
Authentication MethodAuthentication Method can be set to one of the following values: None: authentication is disabled and login is not possible. Local: local user database on the switch is used for authentication. Radius: a remote RADIUS server is used for authentication.
Fallback Check to enable fallback to local authentication. If none of the configured authentication servers are active, the local user database is used for authentication. This is only possible if Authentication Method is set to a value other than none or local.
Save Click to save changes.
Reset Click to undo any changes made locally and revert to previously saved values.

5.1.4 IP Settings

You can configure IP information of the switch in this page.

Black Box LE2711C - IP Settings - 1

text_image IP Configuration DHCP Client IP Address 192.168.10.1 192.168.10.1 IP Mask 255.255.255.0 255.255.255.0 IP Router 0.0.0.0 0.0.0.0 VLAN ID 1 1 DNS Server 0.0.0.0 0.0.0.0

Figure 5-7. IP Configuration screen.

Table 5-4. IP Configuration screen options.
Label Description
DHCP ClientEnable the DHCP client by checking this box. If DHCP fails or the configured IP address is zero, DHCP will retry. If DHCP retry fails, DHCP will stop trying and the configured IP settings will be used.
IP AddressAssigns the IP address of the network in use. If DHCP client function is enabled, you do not need to assign the IP address. The network DHCP server will assign the IP address to the switch and it will be displayed in this column. The default IP is 192.168.10.1.
IP Mask Assigns the subnet mask of the IP address. If DHCP client function is enabled, you do not need to assign the subnet mask.
IP RouterAssigns the network gateway for the switch. The default gateway is 192.168.10.254.
VLAN ID Provides the managed VLAN ID. The allowed range is 1 through 4095.
DNS Server Provides the IP address of the DNS server in dotted decimal notation.
Save Click to save changes.
Reset Click to undo any changes made locally and revert to previously saved values.

5.1.5 IPv6 Settings

You can configure IPv6 information of the switch on the following page.

Black Box LE2711C - IPv6 Settings - 1

text_image IPv6 Configuration Auto Configuration Address ::192.0.2.1 Prefix 96 Router :: Current Renew ::192.0.2.1 Link-Local Address: fe80::21e:94ff:fe01:6735 96 ::

Figure 5-8. IPv6 Configuration screen.

Table 5-5. IPv6 Configuration screen options.
Label Description
Auto ConfigurationCheck to enable IPv6 auto-configuration. If the system cannot obtain the stateless address in time, the configured IPv6 settings will be used. The router may delay responding to a router solicitation for a few seconds; therefore, the total time needed to complete auto-configuration may be much longer.
AddressProvides the IPv6 address of the switch. IPv6 address consists of 128 bits represented as eight groups of four hexadecimal digits with a colon separating each field (:). For example, in 'fe80::215:c5ff:fe03:4dc7', the symbol '::' is a special syntax that can be used as a shorthand way of representing multiple 16-bit groups of contiguous zeros; but it can appear only once. It can also represent a legally valid IPv4 address. For example, "::192.1.2.34".
Prefix Provides the IPv6 prefix of the switch. The allowed range is 1 to 128.
RouterProvides the IPv6 address of the switch. IPv6 address consists of 128 bits represented as eight groups of four hexadecimal digits with a colon separating each field (:). For example, in 'fe80::215:c5ff:fe03:4dc7', the symbol '::' is a special syntax that can be used as a shorthand way of representing multiple 16-bit groups of contiguous zeros; but it can appear only once. It canalso represent a legally valid IPv4 address. For example, "::192.1.2.34".
Save Click to save changes.
Reset Click to undo any changes made locally and revert to previously saved values.

5.1.6 HTTPS

You can configure the HTTPS mode in the following page.

Black Box LE2711C - HTTPS - 1

text_image HTTPS Configuration Mode Disabled Save Reset

Figure 5-9. HTTPS Configuration screen.

Table 5-6. HTTPS Configuration options.
Label Description
ModeIndicates the selected HTTPS mode. When the current connection is HTTPS, disabling HTTPS will automatically redirect web browser to an HTTP connection. The modes include:Enabled: enable HTTPS.Disabled: disable HTTPS.
Save Click to save changes.
Reset Click to undo any changes made locally and revert to previously saved values.

5.1.7 SSH

You can configure the SSH mode in the following page.

Black Box LE2711C - SSH - 1

text_image HTTPS Configuration Mode Disabled Save Reset

Figure 5-10. SSH Configuration screen.

Table 5-7. SSH Configuration screen options.
Label Description
Mode Indicates the selected SSH mode. The modes include:Enabled: enable SSH.Disabled: disable SSH.
Save Click to save changes.
Reset Click to undo any changes made locally and revert to previously saved values.

5.1.8 LLDP

LLDP Configurations

This page allows you to examine and configure current LLDP port settings.

Black Box LE2711C - LLDP - 1

text_image LLDP Configuration LLDP Parameters Tx Interval 30 seconds Port Mode 1 Disabled ✓ 2 Disabled ✓ 3 Disabled ✓ 4 Disabled ✓

Figure 5-11. LLDP Configurations.

Table 5-8. LLDP Configuration screen options.
Label Description
Port The switch port number to which the following settings will be applied.
Mode Indicates the selected LLDP mode.
Rx only: the switch will not send out LLDP information, but LLDP information from its neighbors will be analyzed.Tx only: the switch will drop LLDP information received from its neighbors, but will send out LLDP information.Disabled: the switch will not send out LLDP information, and will drop LLDP information received from its neighbors.Enabled: the switch will send out LLDP information, and will analyze LLDP information received from its neighbors.

LLDP Neighbor Information

This page provides a status overview for all LLDP neighbors. The following table contains information for each port on which an LLDP neighbor is detected. The columns include the following information:

Local PortChassis IDRemote Port IDSystem NamePort DescriptionSystem CapabilitiesManagement Address
Port 800-1E-94-12-45-787IGS-9812GPPort #7Bridge(+)192.168.10.14 (IPv4)

Figure 5-12. LLDP Neighbor Information screen.

Table 5-9. LLDP Neighbor Information screen options.
Label Description
Local Port The port that you use to transmits and receives LLDP frames.
Chassis ID The identification number of the neighbor sending out the LLDP frames.
Remote Port ID The identification of the neighbor port.
System Name The name advertised by the neighbor.
Port Description The description of the port advertised by the neighbor.
System CapabilitiesDescription of the neighbor's capabilities. The capabilities include:1. Other2. Repeater3. Bridge4. WLAN Access Point5. Router6. Telephone7. DOCSIS Cable Device8. Station Only9. ReservedWhen a capability is enabled, a (+) will be displayed. If the capability is disabled, a (-) will be displayed.
Management AddressThe neighbor's address that can be used to help network management. This may contain the neighbor's IP address.
Refresh Click to refresh the page immediately.
Auto-Refresh Check to enable an automatic refresh of the page at regular intervals.

Port Statistics

This page provides an overview of all LLDP traffic. Two types of counters are shown. Global counters will apply settings to the whole switch stack, while local counters will apply settings to specified switches.

Black Box LE2711C - Port Statistics - 1

text_image Auto-refresh ☐ Refresh Clear Global Counters Neighbor entries were last changed at 1970-01-01 04:03:03 +0000 (26 sec. ago) Total Neighbors Entries Added 1 Total Neighbors Entries Deleted 0 Total Neighbors Entries Dropped 0 Total Neighbors Entries Aged Out 0

LLDP Statistics

Local Counters
Local PortTx FramesRx FramesRx ErrorsFrames DiscardedTLVs DiscardedTLVs UnrecognizedOrg. DiscardedAge-Outs
110000000
200000000
340000000
400000000
521000000
600000000
700000000
810000000
900000000
1000000000
1100000D

Figure 5-13. Port Statistics screen.

Global Counters

Table 5-10. Global Counters options.
Label Description
Neighbor entries were last changed at Shows the time when the last entry was deleted or added.
Total Neighbors Entries Added Shows the number of new entries added since switch reboot.
Total Neighbors Entries Deleted Shows the number of new entries deleted since switch reboot.
Total Neighbors Entries Dropped Shows the number of LLDP frames dropped due to full entry table.
Total Neighbors Entries Aged Out Shows the number of entries deleted due to expired time-to-live.
Table 5-11. Local Counters options.
Label Description
Local Port The port that receives or transmits LLDP frames.
Tx Frames The number of LLDP frames transmitted on the port.
Rx Frames The number of LLDP frames received on the port.
Rx Errors The number of received LLDP frames containing errors.
Frames DiscardedIf a port receives an LLDP frame, and the switch's internal table is full, the LLDP frame will be counted and discarded. This situation is known as "too many neighbors" in the LLDP standard. LLDP frames require a new entry in the table if Chassis ID or Remote Port ID is not included in the table. Entries are removed from the table when a given port links down, an LLDP shutdown frame is received, or when the entry ages out.
TLVs DiscardedEach LLDP frame can contain multiple pieces of information, known as TLVs (Type Length Value). If a TLV is malformed, it will be counted and discarded.
TLVs UnrecognizedThe number of well-formed TLVs, but with an unknown type value.
Org. DiscardedThe number of organizationally TLVs received.
Table 5-11 (continued). Local Counters options.
Label Description
Age-OutsEach LLDP frame contains information about how long the LLDP information is valid (age-out time). If no new LLDP frame is received during the age-out time, the LLDP information will be removed, and the value of the age-out counter will be incremented.
Refresh Click to refresh the page immediately.
ClearClick to clear the local counters. All counters (including global counters) are cleared upon reboot.
Auto-refresh Check to enable an automatic refresh of the page at regular intervals.

5.1.9 Modbus TCP

This page shows Modbus TCP support of the switch. (For more information regarding Modbus, please visit http://www.modbus.org/)

Black Box LE2711C - Modbus TCP - 1

text_image MODBUS Configuration Mode Enabled Save Reset

Figure 5-14. Modbus configuration screen.

Table 5-12. Modbus TCP support.
Label Description
Mode Shows the existing status of theModbus TCP function.

5.1.10 Backup/Restore Configurations

You can save/view or load switch configurations. The configuration file is in XML format.

Black Box LE2711C - Backup/Restore Configurations - 1

text_image Configuration Save Save configuration

Black Box LE2711C - Backup/Restore Configurations - 2

text_image Configuration Upload Browse Upload

Figure 5-15.

5.1.11 Firmware Update

This page allows you to update the firmware of the switch.

Black Box LE2711C - Firmware Update - 1

text_image Firmware Update Browse Upload

Figure 5-16. Firmware Update screen.

5.2 DHCP Server

The switch provides DHCP server functions. By enabling DHCP, the switch will become a DHCP server and dynamically assigns IP addresses and related IP information to network clients.

5.2.1 Basic Settings

This page allows you to set up DHCP settings for the switch. You can check the Enabled checkbox to activate the function. Once the box is checked, you will be able to input information in each column.

Black Box LE2711C - Basic Settings - 1

text_image DHCP Server Configuration Enabled Start IP Address 192.168.10.100 End IP Address 192.168.10.200 Subnet Mask 255.255.255.0 Router 192.168.10.254 DNS 192.168.10.254 Lease Time (sec.) 86400 TFTP Server 0.0.0.0 Boot File Name Save Reset

Figure 5-17. DHCP Server Configuration screen.

5.2.2 Dynamic Client List

When DHCP server functions are activated, the switch will collect DHCP client information and display in the following table.

Black Box LE2711C - Dynamic Client List - 1

text_image DHCP Dynamic Client List No. Select Type MAC Address IP Address Surplus Lease Select/Clear All Add to static Table

Figure 5-18. DHCP Dynamic Client List.

5.2.3 Client List

You can assign a specific IP address within the dynamic IP range to a specific port. When a device is connected to the port and requests for dynamic IP assigning, the switch will assign the IP address that has previously been assigned to the connected device.

Black Box LE2711C - Client List - 1

text_image DHCP Client List MAC Address IP Address Add as Static No. Select Type MAC Address IP Address Surplus Lease Delete Select/Clear All

Figure 5-19. DHCP Client Lists screen.

5.2.4 Relay Agent

DHCP relay is used to forward and transfer DHCP messages between the clients and the server when they are not in the same subnet domain. You can configure the function in this page.

Black Box LE2711C - Relay Agent - 1

text_image DHCP Relay Configuration Relay Mode Disabled Relay Server 0.0.0.0 Relay Information Mode Enabled Relay Information Policy Replace Save Reset

Figure 5-20. DHCP Relay Configuration screen.

Table 5-13. DHCP Relay Configuration screen options.
Label Description
Relay ModeIndicates the existing DHCP relay mode. The modes include:Enabled: activate DHCP relay. When DHCP relay is enabled, the agent forwards and transfers DHCP messages between the clients and the server when they are not in the same subnet domain to prevent the DHCP broadcast message from flooding for security considerations.Disabled: disable DHCP relay
Relay ServerIndicates the DHCP relay server IP address. A DHCP relay agent is used to forward and transfer DHCP messages between the clients and the server when they are not in the same subnet domain.
Relay Information ModeIndicates the existing DHCP relay information mode. The format of DHCP option 82 circuit ID format is "[vlan_id][module_id][port_no}". The first four characters represent the VLAN ID, and the fifth and sixth characters are the module ID. In stand-alone devices, the module ID always equals to 0; in stacked devices, it means switch ID. The last two characters are the port number. For example, "00030108" means the DHCP message received form VLAN ID 3, switch ID 1, and port No. 8. The option 82 remote ID value equals to the switch MAC address.The modes include: Enabled: activate DHCP relay information. When DHCP relay information is enabled, the agent inserts specific information (option 82) into a DHCP message when forwarding to a DHCP server and removes it from a DHCP message when transferring to a DHCP client. It only works when DHCP relay mode is enabled.Disabled: disable DHCP relay information
Table 5-13 (continued). DHCP Relay Configuration screen options.
Label Description
Relay Information PolicyIndicates the policies to be enforced when receiving DHCP relay information. When DHCP relay information mode is enabled, if the agent receives a DHCP message that already contains relay agent information, it will enforce the policy. The Replace option is invalid when relay information mode is disabled. The policies includes:Replace: replace the original relay information when a DHCP message containing the information is received.Keep: keep the original relay information when a DHCP message containing the information is received.Drop: drop the package when a DHCP message containing the information is received.

The relay statistics show the information of relayed packets of the switch.

Black Box LE2711C - Relay Agent - 2

text_image Auto-refresh □ Refresh Clear DHCP Relay Statistics Server Statistics Transmit to Server 0 Transmit Error Receive from Server Receive Missing Agent Option Receive Missing Circuit ID Receive Missing Remote ID Receive Bad Circuit ID Receive Bad Remote ID 0 0 0 0 0 0 0 0

Figure 5-21. DHCP Relay Statistics.

Table 5-14. DHCP Relay Statistics screen options.
Label Description
Transmit to Server The number of packets relayed from the client to the server.
Transmit Error The number of packets with errors when being sent to clients.
Receive from Server The number of packets received from the server.
Receive Missing Agent Option The number of packets received without agent information.
Receive Missing Circuit ID The number of packets received with Circuit ID.
Receive Missing Remote ID The number of packets received with the Remote ID option missing.
Receive Bad Circuit ID The number of packets whose Circuit ID do not match the known circuit ID.
Receive Bad Remote ID The number of packets whose Remote ID do not match the known Remote ID.
Transmit to ClientTransmit ErrorReceive from ClientReceive Agent OptionReplace Agent OptionKeep Agent OptionDrop Agent Option
0000000

Figure 5-22. Client Statistics screen.

Table 5-15. Client Statistics screen options.
Label Description
Transmit to Client The number of packets relayed from the server to the client.
Transmit Error The number of packets with errors when being sent to servers.
Receive from Client The number of packets received from the server.
Receive Agent Option The number of received packets containing relay agent information.
Replace Agent OptionThe number of packets replaced when received messages contain relay agent information.
Keep Agent Option The number of packets whose relay agent information is retained.
Drop Agent OptionThe number of packets dropped when received messages contain relay agent information.

5.3 Port Setting

Port Setting allows you to manage individual ports of the switch, including traffic, power, and trunks.

5.3.1 Port Control

This page shows current port configurations. Ports can also be configured here.

PortLinkSpeedFlow ControlMaximum Frame SizePower Control
CurrentConfiguredCurrent RxCurrent TxConfigured
<>✓ 9600<>✓
1DownAuto 9600Disabled✓
2DownAuto 9600Disabled✓
3DownAuto 9600Disabled✓
4DownAuto 9600Disabled✓
5DownAuto 9600Disabled✓
6DownAuto 9600Disabled✓
71GfdxAuto 9600Disabled✓
8DownAuto 9600Disabled✓
9DownAuto 9600
10DownAuto 9600
11DownAuto 9600
12DownAuto 9600
13DownAuto 9600

Figure 5-23. Port Configuration screen.

Table 5-16. Port Configuration screen options.
Label Description
Port The switch port number to which the following settings will be applied.
LinkThe current link state is shown by different colors. Green indicates the link is up and red means the link is down.
Current Link Speed Indicates the current link speed of the port.
Configured Link SpeedThe drop-down list provides available link speed options for a given switch port. Auto selects the highest speed supported by the link partner. Disabled disables switch port configuration. <> configures all ports.
Table 5-16 (continued). Port Configuration screen options.
Label Description
Flow ControlWhen Auto is selected for the speed, the flow control will be negotiated to the capacity advertised by the link partner.When a fixed-speed setting is selected, that is what is used. Current Rx indicates whether pause frames on the port are obeyed, and Current Tx indicates whether pause frames on the port are transmitted. The Rx and Tx settings are determined by the result of the last auto-negotiation.You can check the Configured column to use flow control. This setting is related to the setting of Configured Link Speed.
Maximum Frame Youcan enter the maximum frame size allowed for the switch port in this column, including FCS. The allowed range is 1518 bytes to 9600 bytes.
Power ControlShows the current power consumption of each port in percentage. The Configured column allows you to change power saving parameters for each port.Disabled: all power savings functions are disabled.ActiPHY: link down and power savings enabledPerfectReach: link up and power savings enabled.Enabled: both link up and link down power savings enabled.
Total Power Usage Total power consumption of the board, measured in percentage.
Save Click to save changes.
Reset Click to undo any changes made locally and revert to previously saved values.
Refresh Click to refresh the page. Any changes made locally will be undone.

5.3.2 Port Trunk

This page allows you to configure the aggregation hash mode and the aggregation group.

Aggregation Mode Configuration

Black Box LE2711C - Aggregation Mode Configuration - 1

text_image Hash Code Contributors Source MAC Address ✓ Destination MAC Address ✓ IP Address ✓ TCP/UDP Port Number ✓

Figure 5-24. Aggregation Mode Configuration screen.

Table 5-17. Aggregation Mode Configuration screen options.
Label Description
Source MAC AddressCalculates the destination port of the frame. You can check this box to enable the source MAC address, or uncheck to disable. By default, Source MAC Address is enabled.
Destination MAC Address Calculates the destination port of the frame. You can check this box to enable the destination MAC address, or uncheck to disable. By default, Destination MAC Address is disabled.
IP AddressCalculates the destination port of the frame. You can check this box to enable the IP address, or uncheck to disable. By default, IP Address is enabled.
TCP/UDP Port NumberCalculates the destination port of the frame. You can check this box to enable the TCP/UDP port number, or uncheck to disable. By default, TCP/UDP Port Number is enabled.

Aggregation Group Configuration
Black Box LE2711C - Aggregation Mode Configuration - 2

other Port Members Group ID1234567891011121314151617181920 Normal 1 2 3 4 5 6 7 8 9 10

Figure 5-25. Aggregation Group Configuration screen.

Table 5-18. Aggregation Group Configuration screen options.
Label Description
Group IDIndicates the ID of each aggregation group. Normal means no aggregation. Only one group ID is valid per port.
Port MembersLists each switch port for each group ID. Select a radio button to include a port in an aggregation, or clear the radio button to remove the port from the aggregation. By default, no ports belong to any aggregation group. Only full duplex ports can join an aggregation and the ports must be in the same speed in each group.

5.3.3 LACP

This page allows you to enable LACP functions to group ports together to form single virtual links, thereby increasing the bandwidth between the switch and other LACP-compatible devices. LACP trunks are similar to static port trunks, but they are more flexible because LACP is compliant with the IEEE 802.3ad standard. Hence, it is interoperable with equipment from other vendors that also comply with the standard. You can change LACP port settings in this page.

LACP Port Configuration
Black Box LE2711C - LACP - 1

text_image Open in new window Port LACP Enabled Key Role 1 □ Auto ✓ Active 2 □ Auto ✓ Active 3 □ Auto ✓ Active 4 □ Auto ✓ Active 5 □ Auto ✓ Active

Figure 5-26. LACP Port Configuration screen.

Table 5-19. LACP Port Configuration screen options.
Label Description
PortIndicates the ID of each aggregation group. Normal indicates there is no aggregation. Only one group ID is valid per port.
LACP Enabled Listseach switch port for each group ID. Check to include a port in an aggregation, or clear the box to remove the port from the aggregation. By default, no ports belong to any aggregation group. Only full duplex ports can join an aggregation and the ports must be in the same speed in each group.
KeyThe Key value varies with the port, ranging from 1 to 65535. Auto will set the key according to the physical link speed (10Mb = 1, 100Mb = 2, 1Gb = 3). Specific allows you to enter a user-defined value. Ports with the same key value can join in the same aggregation group, while ports with different keys cannot.
RoleIndicates LACP activity status. Active will transmit LACP packets every second, while Passive will wait for a LACP packet from a partner (speak if spoken to).
Save Click to save changes.
Reset Click to undoany changes made locally and revert to previously saved values.

LACP System Status

This page provides a status overview for all LACP instances.

Black Box LE2711C - LACP System Status - 1

text_image LACP System Status Auto-refresh □ Refresh Open in new window Aggr ID Partner System ID Partner Key Last Changed Local Ports No ports enabled or no existing partners

Figure 5-27. LACP System Status screen.

Table 5-20. LACP System Status screen options.
Label Description
Aggr IDThe aggregation ID is associated with the aggregation instance. For LLAG, the ID is shown as 'isid:aggr-id' and for GLAGs as "aggr-id."
Partner System ID System ID (MAC address) of the aggregation partner
Partner Key The key assigned by the partner to the aggregation ID
Last Changed The time since this aggregation changed.
Local PortsIndicates which ports belong to the aggregation of the switch/stack. The format is: "Switch ID:Port."
RefreshClick to refresh the page immediately
Auto-refreshCheck to enable an automatic refresh of the page at regular intervals

LACP Status

This page provides an overview of the LACP status for all ports.

Black Box LE2711C - LACP Status - 1

text_image LACP Status Auto-refresh ☐ Refresh Open in new window Port LACP Key Aggr ID Partner System ID Partner Port 1 No - - - - 2 No - - - - 3 No - - - - 4 No - - - - 5 No - - - -

Figure 5-28. LACP Status screen.

Table 5-21. LACP Status screen options.
Label Description
Port Switch port number
LACPYes means LACP is enabled and the port link is up. No means LACP is not enabled or the port link is down. Backup means the port cannot join in the aggregation group unless other ports are removed. The LACP status is disabled.
Key The key assigned to the port. Only ports with the same key can be aggregated.
Aggr ID The aggregation ID assigned to the aggregation group.
Partner System ID The partner's system ID (MAC address).
Partner Port The partner's port number associated with the port.
Refresh Click to refresh the page immediately.
Auto-refresh Check to enable an automatic refresh of the page at regular intervals.

LACP Statistics

This page provides an overview of the LACP statistics for all ports.

Black Box LE2711C - LACP Statistics - 1

text_image LACP Statistics Auto-refresh □ Refresh Clear Port LACP Transmitted LACP Received Discarded Unknown Illegal 1 0 0 0 0 2 0 0 0 0 3 0 0 0 0 4 0 0 0 0 5 0 0 0 0 6 0 0 0 0 7 0 0 0 0 8 0 0 0 0 9 0 0 0 0 10 0 0 0 0 11 0 0 0 0 12 0 0 0 0

Figure 5-29. LACP Statistics screen.

Table 5-22. LACP Statistics screen options.
Label Description
Port Switch port number
LACP Transmitted The number of LACP frames sent from each port.
LACP Received The number of LACP frames received at each port.
Discarded The number of unknown or illegal LACP frames discarded at each port.
Refresh Click to refresh the page immediately.
Auto-refresh Check to enable an automatic refresh of the page at regular intervals.
Clear Click to clear the counters for all ports.

5.3.4 Loop Gourd

This feature prevents loop attack. When receiving loop packets, the port will be disabled automatically, preventing the loop attack from affecting other network devices.

Black Box LE2711C - Loop Gourd - 1

text_image General Settings Global Configuration Enable Loop Protection Disable Transmission Time 5 seconds Shutdown Time 180 seconds

Figure 5-30. Loop Gourd screen.

Table 5-23. Loop Gourd screen options.
Label Description
Enable Loop ProtectionActivate loop protection functions (as a whole)
Transmission TimeThe interval between each loop protection PDU sent on each port. The valid value is 1 to 10 seconds.
Shutdown TimeThe period (in seconds) for which a port will be kept disabled when a loop is detected (shutting down the port). The valid value is 0 to 604800 seconds (7 days). A value of zero will keep a port disabled permanently (until the device is restarted).

Black Box LE2711C - Loop Gourd - 2

text_image Port Configuration Port Enable Action Tx Mode * <> <> 1 Shutdown Port Enable 2 Shutdown Port Enable 3 Shutdown Port Enable 4 Shutdown Port Enable 5 Shutdown Port Enable 6 Shutdown Port Enable

Figure 5-31. Port Configuration screen.

Table 5-24. Port Configuration screen options.
Label Description
Port Switch port number
Enable Activateloop protection functions (as a whole)
ActionConfigures the action to take when a loop is detected. Valid values include Shutdown Port, Shutdown Port, and Log or Log Only.
Tx ModeControls whether the port is actively generating loop protection PDUs or only passively look for looped PDUs.

5.4 VLAN

5.4.1 VLAN Membership

You can view and change VLAN membership configurations for a selected switch stack in this page. Up to 64 VLANs are supported. This page allows for adding and deleting VLANs as well as adding and deleting port members of each VLAN.

Black Box LE2711C - VLAN Membership - 1

text_image VLAN Membership Configuration Refresh |<< >> Start from VLAN 1 with 20 entries per page. Delete VLAN ID VLAN Name Port Members 1 2 3 4 5 6 7 8 9 10 11 12 □ 1 default ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ Add New VLAN Save Reset

Figure 5-32. VLAN Membership Configuration screen.

Table 5-25. VLAN Membership Configuration screen options.
Label Description
Delete Check to delete the entry. It will be deleted during the next save.
VLAN ID The VLAN ID for the entry.
MAC Address The MAC address for the entry.
Port MembersCheckmarks indicate which ports are members of the entry. Check or uncheck as needed to modify the entry.
Add New VLANClick to add a new VLAN ID. An empty row is added to the table, and the VLAN can be configured as needed. Valid values for a VLAN ID are 1 through 4095.After clicking Save, the new VLAN will be enabled on the selected switch stack but contains no port members.A VLAN without any port members on any stack will be deleted when you click Save.Click Delete to undo the addition of new VLANs.

5.4.2 Port Configurations

This page allows you to set up VLAN ports individually.

Black Box LE2711C - Port Configurations - 1

text_image Auto-refresh □ Refresh Ethertype for Custom S-ports 0x88A8 VLAN Port Configuration Port Port Type Ingress Filtering Frame Type Port VLAN Tx Tag Mode ID * <> << << 1 << 1 Unaware All Specific 1 Untag_pvid 2 Unaware All Specific 1 Untag_pvid 3 Unaware All Specific 1 Untag_pvid 4 Unaware All Specific 1 Untag_pvid 5 Unaware All Specific 1 Untag_pvid 6 Unaware All Specific 1 Untag_pvid 7 Unaware All Specific 1 Untag_pvid 8 Unaware All Specific 1 Untag_pvid 9 Unaware All Specific 1 Untag_pvid 10 Unaware All Specific 1 Untag_pvid 11 Unaware All Specific 1 Untag_pvid 12 Unaware All Specific 1 Untag_pvid Save Reset

Figure 5-33. VLAN Port Configuration screen.

Table 5-26. VLAN Port Configuration screen options.
Label Description
Ethertype for customer S-PortsThis field specifies the Ether type used for custom S-ports. This is a global setting for all custom S-ports.
Port The switch port number to which the following settings will be applied.
Port typePort can be one of the following types: Unaware, Customer (C-port), Service (S-port), Custom Service (S-custom-port). If port type is Unaware, all frames are classified to the port VLAN ID and tags are not removed.
Ingress FilteringEnable ingress filtering on a port by checking the box. This parameter affects VLAN ingress processing. If ingress filtering is enabled and the ingress port is not a member of the classified VLAN of the frame, the frame will be discarded. By default, ingress filtering is disabled (no check mark).
Frame TypeDetermines whether the port accepts all frames or only tagged/untagged frames. This parameter affects VLAN ingress processing. If the port only accepts tagged frames, untagged frames received on the port will be discarded. By default, the field is set to All.
Port VLAN ModeThe allowed values are None or Specific. This parameter affects VLAN ingress and egress processing. If None is selected, a VLAN tag with the classified VLAN ID is inserted in frames transmitted on the port. This mode is normally used for ports connected to VLAN-aware switches. Tx tag should be set to Untag_pvid when this mode is used.If Specific (the default value) is selected, a port VLAN ID can be configured (see below). Untagged frames received on the port are classified to the port VLAN ID. If VLAN awareness is disabled, all frames received on the port are classified to the port VLAN ID. If the classified VLAN ID of a frame transmitted on the port is different from the port VLAN ID, a VLAN tag with the classified VLAN ID will be inserted in the frame.
Port VLAN ID Configuresthe VLAN identifier for the port. The allowed range of the values is 1 through 4095. The default value is 1. The port must be a member of the same VLAN as the port VLAN ID.
Tx Tag Determines egress tagging of a port. Untag_pvid: all VLANs except the configured PVID will be tagged. Tag_all: all VLANs are tagged. Untag_all: all VLANs are untagged.

Introduction of Port Types

Below is a detailed description of each port type, including Unaware, C-port, S-port, and S-custom-port.

Table 5-27. Port types.
Ingress Action Egress Action
UnawareThe function of Unaware can be used for 802.1QinQ (double tag).When the port receives untagged frames, an untagged frame obtains a tag (based on PVID) and is forwarded.When the port receives tagged frames:If the tagged frame contains a TPID of 0x8100, it will become a double-tag frame and will be forwarded.If the TPID of tagged frame is not 0x8100 (ex. 0x88A8), it will be discarded.The TPID of a frame transmitted by Unaware port will be set to 0x8100.The final status of the frame after egressing will also be affected by the Egress Rule.
C-port When the port receives untagged frames, an untagged frame obtains a tag (based on PVID) and is forwarded.When the port receives tagged frames:If the tagged frame contains a TPID of 0x8100, it will be forwarded.If the TPID of tagged frame is not 0x8100 (ex. 0x88A8), it will be discarded.The TPID of a frame transmitted by C-port will be set to 0x8100.
S-port When the port receives untagged frames, an untagged frame obtains a tag (based on PVID) and is forwarded.When the port receives tagged frames:If the tagged frame contains a TPID of 0x8100, it will be forwarded.If the TPID of tagged frame is not 0x88A8 (ex. 0x8100), it will be discarded.The TPID of a frame transmitted by S-port will be set to 0x88A8.
S-custom-port When the port receives untagged frames, an untagged frame obtains a tag (based on PVID) and is forwarded.When the port receives tagged frames:If the tagged frame contains a TPID of 0x8100, it will be forwarded.If the TPID of tagged frame is not 0x88A8 (ex. 0x8100), it will be discarded.The TPID of a frame transmitted by S-custom-port will be set to a self-customized value, which can be set by the user via Ethertype for Custom S-ports.

Examples of VLAN Settings

Switch A,

Port 7 is VLAN Access mode = Untagged 20

Port 8 is VLAN Access mode = Untagged 10

Below are the switch settings.

Black Box LE2711C - Introduction of Port Types - 1

text_image VLAN Membership Configuration Refresh |<< >> Start from VLAN 1 with 20 entries per page. Delete VLAN ID default vlan10 vlan20 Port Members 1 2 3 4 5 6 7 8 9 10 11 12 1 10 20 Add New VLAN for port 1 VLAN trunk setting Save Reset for port 7 & port 8 VLAN Access

Figure 5-34.

Black Box LE2711C - Introduction of Port Types - 2

text_image VLAN VLAN Membership Ports Private VLAN SNMP Traffic Prioritization Multicast Security Warning Monitor and Diag Synchronization PoE Factory Default System Reboot Port Type > Ingress/Linking Profile Type Mode ID Link Tag <><><><><> 1 C-port 2 Unaware 3 Unaware 4 Unaware 5 Unaware 6 Unaware 7 Unaware 8 Unaware 9 Unaware 10 Unaware 11 Unaware <><><><> 1 Tag_all None 1 Untag_pvid Specific 1 Untag_pvid Specific 1 Untag_pvid Specific 1 Untag_pvid Specific 20 Untag_pvid Specific 30 Untag_pvid Specific 1 Untag_pvid Specific 1 Untag_pvid

Figure 5-35.

VLAN 1Q Trunk Mode:

Switch B,

Port 1 = VLAN 1Qtrunk mode = tagged 10, 20

Port 2 = VLAN 1Qtrunk mode = tagged 10, 20

Below are the switch settings.

Black Box LE2711C - Introduction of Port Types - 3

text_image VLAN Membership Configuration Refresh |<< >> Start from VLAN 1 with 20 entries per page. Port Members Delete VLAN ID VLAN Name 1 2 3 4 5 6 7 8 9 10 11 12 □ 1 default ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ □ 200 QinQ ✓ ✓ □ □ □ □ □ □ □ Add New VLAN Save Reset

Figure 5-36.

Black Box LE2711C - Introduction of Port Types - 4

text_image Open all System Information Front Panel Basic Setting DHCP Server/Relay Port Setting Redundancy VLAN VLAN Membership Ports Private VLAN SNMP Traffic Prioritization Multicast Security Warning Auto-refresh Refresh Ethertype for Custom S-ports 0x 88A8 VLAN Port Configuration Port Port Type Ingress Filtering Frame Type Port VLAN Tx Tag Mode ID 1 1 1 Unaware All Specific 200 Untag_all C-port Tagged None 1 Tag_all Unaware All Specific 1 Untag_pvid Unaware All Specific 1 Untag_pvid Unaware All Specific 1 Untag_pvid Unaware All Specific 1 Untag_pvid

Figure 5-37.

VLAN Hybrid Mode:

Port 1 VLAN Hybrid mode = untagged 10

Tagged 10, 20

Below are the switch settings.

Black Box LE2711C - Introduction of Port Types - 5

text_image VLAN Membership Configuration Refresh |<< >> Start from VLAN 1 with 20 entries per page. VLAN VLAN Membership Ports Private VLAN SNMP Traffic Prioritization Multicast Security Port Members Delete VLAN ID VLAN Name 1 2 3 4 5 6 7 8 9 10 11 12 1 default ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ 200 QinQ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓√ Add New VLAN Save Reset

Figure 5-38.

Black Box LE2711C - Introduction of Port Types - 6

text_image Open all System Information Front Panel Basic Setting DHCP Server/Relay Port Setting Redundancy VLAN VLAN Membership Ports Private VLAN SNMP Traffic Prioritization Multicast Security Warning Auto-refresh Refresh Ethertype for Custom S-ports 0x 88A8 VLAN Port Configuration Port Port Type Ingress Filtering Frame Type Port VLAN Tx Tag Mode ID 1 Unaware All Specific 200 Untag_all 2 C-port Tagged None Tag_all 3 Unaware All Specific 1 Untag_pvid 4 Unaware All Specific 1 Untag_pvid 5 Unaware All Specific 1 Untag_pvid 6 Unaware All Specific 1 Untag_pvid

Figure 5-39.

VLAN QinQ Mode:

VLAN QinQ mode is usually adopted when there are unknown VLANs, as shown in the figure below.

VLAN "X" = Unknown VLAN

Black Box LE2711C - VLAN QinQ Mode: - 1

flowchart
graph LR
    A["VLAN &quot;X&quot;"] --> B["P1"]
    B --> C["P2"]
    C --> D["VLAN TRUNK 200"]
    D --> E[" "]
    E --> F["VLAN TRUNK 200"]
    F --> G["P1"]
    G --> H["VLAN &quot;X&quot;"]
    I["tagged X + tagged"] --> B
    J["tagged 200"] --> C
    K["tagged X Packet"] --> B
    L["Setting VLAN QinQ 200"] --> G

Figure 5-40. VLAN QinQ mode.

Port 1 VLAN Settings:

Black Box LE2711C - Port 1 VLAN Settings: - 1

text_image VLAN Membership Configuration Refresh |<< >> Start from VLAN 1 with 20 entries per page. Delete VLAN ID default 200 Port Members 1 2 3 4 5 6 7 8 9 10 11 12 Add New VLAN Save Reset

Figure 5-41. VLAN Settings screen.

Black Box LE2711C - Port 1 VLAN Settings: - 2

text_image Open all System Information Front Panel Basic Setting DHCP ServerRelay Port Setting Redundancy VLAN VLAN Membership Ports Private VLAN SNMP Traffic Prioritization Multicast Security Warning Auto-refresh Refresh Ethertype for Custom S-ports 0x 88A8 VLAN Port Configuration Port Port Type Ingress Filtering Frame Type Port VLAN Tx Tag Mode ID 1 << << << 1 1 Unaware All Specific 200 Untag_all 2 C-port Tagged None Tag_all 3 Unaware All Specific 1 Untag_pvid 4 Unaware All Specific 1 Untag_pvid 5 Unaware All Specific 1 Untag_pvid 6 Unaware All Specific 1 Untag_pvid

Figure 5-42. VLAN settings screen.

VLAN ID Settings

When setting the management VLAN, only the same VLAN ID port can be used to control the switch.

VLAN Settings:

Black Box LE2711C - VLAN ID Settings - 1

text_image Open all System Information Front Panel Basic Setting Basic Setting Admin Password Auth Method IP Setting IPv6 Setting HTTPS SSH LLDP Modbus TCP Backup Restore Upgrade Firmware IP Configuration Configured Current DHCP Client Renew IP Address 192.168.10.2 192.168.10.2 IP Mask 255.255.255.0 255.255.255.0 IP Router 0.0.0.0 0.0.0.0 VLAN ID 1 1 SNTP Server Save Reset

Figure 5-43.

5.4.3 Private VLAN

The private VLAN membership configuration for the switch can be monitored and modified here. Private VLANs can be added or deleted here. Port members of each private VLAN can be added or removed here. Private VLANs are based on the source port mask, and there are no connections to VLANs. This means that VLAN IDs and private VLAN IDs can be identical.

A port must be a member of both a VLAN and a private VLAN to be able to forward packets. By default, all ports are VLAN unaware and members of VLAN 1 and private VLAN 1.

A VLAN-unaware port can only be a member of one VLAN, but it can be a member of multiple private VLANs.

Black Box LE2711C - Private VLAN - 1

text_image Private VLAN Membership Configuration Open in new window Port Members Delete PVLAN ID 1 2 3 4 5 6 7 8 9 10 11 12 1 Add new Private VLAN Save Reset

Figure 5-44. Private VLAN Membership Configuration screen.

Table 5-28. Private VLAN Membership Configuration screen options.
Label Description
Delete Check to delete the entry. It will be deleted duringthe next save.
Private VLAN ID Indicates the ID of this particular privateVLAN.
MAC Address The MAC address for the entry.
Port Members A row of check boxes for each port is displayed for each privateVLAN ID. You can check the box to include a port in a private VLAN. To remove or exclude the port from the private VLAN, make sure the box is unchecked. By default, no ports are members, and all boxes are unchecked.
Adding a New Static Entry Click Add new Private LAN to add a new private VLAN ID. An empty row is added to the table, and the private VLAN can be configured as needed. The allowed range for a private VLAN ID is the same as the switch port number range. Any values outside this range are not accepted, and a warning message appears. Click OK to discard the incorrect entry, or click Cancel to return to the editing and make a correction.The private VLAN is enabled when you click Save.The Delete button can be used to undo the addition of new private VLANs.

Black Box LE2711C - Private VLAN - 2

text_image Port Isolation Configuration Open in new window Port Number 1 2 3 4 5 6 7 8 9 10 11 12 Save Reset

Figure 5-45. Port Isolation Configuration screen.

Table 5-29. Port Isolation Configuration screen options.
Label Description
Port MembersA check box is provided for each port of a private VLAN.When checked, port isolation is enabled for that port.When unchecked, port isolation is disabled for that port.By default, port isolation is disabled for all ports.

5.5 SNMP

5.5.1 SNMP System Configurations

Black Box LE2711C - SNMP System Configurations - 1

text_image SNMP System Configuration Mode Enabled Version SNMP v2c Read Community public Write Community private Engine ID 800007e5017f000001

Figure 5-46. SNMP system configuration screen.

Table 5-30. SNMP System Configuration screen options.
Label Description
Mode Indicates existing SNMP mode. Possible modes include:Enabled: enable SNMP modeDisabled: disable SNMP mode
VersionIndicates the supported SNMP version. Possible versions include:SNMP v1: supports SNMP version 1.SNMP v2c: supports SNMP version 2c.SNMP v3: supports SNMP version 3.
Read CommunityIndicates the read community string to permit access to SNMP agent. The allowed string length is 0 to 255, and only ASCII characters from 33 to 126 are allowed.The field only suits to SNMPv1 and SNMPv2c. SNMPv3 uses USM for authentication and privacy and the community string will be associated with SNMPv3 community table.
Write CommunityIndicates the write community string to permit access to SNMP agent. The allowed string length is 0 to 255, and only ASCII characters from 33 to 126 are allowed.The field only suits to SNMPv1 and SNMPv2c. SNMPv3 uses USM for authentication and privacy and the community string will be associated with SNMPv3 community table.
Engine IDIndicates the SNMPv3 engine ID. The string must contain an even number between 10 and 64 hexa-decimal digits, but all-zeros and all-'F's are not allowed. Change of the Engine ID will clear all original local users.

SNMP Trap Configuration
Black Box LE2711C - SNMP System Configurations - 2

text_image Trap Mode Trap Version Trap Community Trap Destination Address Trap Destination IPv6 Address Trap Authentication Failure Trap Link-up and Link-down Trap Inform Mode Trap Inform Timeout (seconds) Trap Inform Retry Times Disabled SNMP v1 public :: Enabled Enabled Enabled 1 5 Save Reset

Figure 5-47. SNMP Trap Configuration screen.

Table 5-31. SNMP Trap Configuration screen options.
Label Description
Trap ModeIndicates existing SNMP trap mode. Possible modes include:Enabled: enable SNMP trap modeDisabled: disable SNMP trap mode
Trap VersionIndicates the supported SNMP trap version. Possible versions include:SNMP v1: supports SNMP trap version 1SNMP v2c: supports SNMP trap version 2cSNMP v3: supports SNMP trap version 3
Trap Community Indicates the community access string when sending SNMP trap packets. The allowed string length is 0 to 255, and only ASCII characters from 33 to 126 are allowed.
Trap Destination AddressIndicates the SNMP trap destination address.
Trap Destination IPv6 AddressProvides the trap destination IPv6 address of this switch. IPv6 address consists of 128 bits represented as eight groups of four hexadecimal digits with a colon separating each field (:.). For example, in 'fe80::215:c5ff:fe03:4dc7', the symbol '::' is a special syntax that can be used as a shorthand way of representing multiple 16-bit groups of contiguous zeros; but it can only appear once. It also uses a following legally IPv4 address. For example, "::192.1.2.34"
Trap Authentication FailureIndicates the SNMP entity is permitted to generate authentication failure traps. Possible modes include:Enabled: enable SNMP trap authentication failureDisabled: disable SNMP trap authentication failure
Trap Link-up and Link-downIndicates the SNMP trap link-up and link-down mode. Possible modes include:Enabled: enable SNMP trap link-up and link-down modeDisabled: disable SNMP trap link-up and link-down mode
Trap Inform ModeIndicates the SNMP trap inform mode. Possible modes include:Enabled: enable SNMP trap inform modeDisabled: disable SNMP trap inform mode
Table 5-31 (continued). SNMP Trap Configuration screen options.
Label Description
Trap Inform Timeout(seconds)Configures the SNMP trap inform timeout. The allowed range is 0 to 2147.
Trap Inform Retry TimesConfigures the retry times for SNMP trap inform. The allowed range is 0 to 255.

5.5.2 SNMP Community Configurations

This page allows you to configure SNMPv3 community table. The entry index key is Community.

Black Box LE2711C - SNMP Community Configurations - 1

text_image SNMPv3 Communities Configuration Delete Community Source IP Source Mask □ public 0.0.0.0 0.0.0.0 □ private 0.0.0.0 0.0.0.0 Add new community Save Reset

Figure 5-48. SNMPv3 Communities Configuration screen.

Table 5-32. SNMPv3 Communities Configuration screen options.
Label Description
Delete Check to delete the entry. It will be deleted during the next save.
CommunityIndicates the community access string to permit access to SNMPv3 agent. The allowed string length is 1 to 32, and only ASCII characters from 33 to 126 are allowed.
Source IP Indicates the SNMP source address.
Source Mask Indicates the SNMP source address mask.

5.5.3 SNMP User Configurations

This page allows you to configure SNMPv3 user table. The entry index keys are Engine ID and User Name.

Black Box LE2711C - SNMP User Configurations - 1

text_image SNMPv3 Users Configuration Delete Engine ID User Security Authentication Authentication Privacy Privacy Name Level Protocol Password Protocol Password □ 800007e5017f000001 default_user NoAuth, NoPriv None None None None Add new user Save Reset

Figure 5-49. SNMP Users Configuration screen.

Table 5-33. SNMPv3 Users Configuration screen options.
Label Description
Delete Check to delete the entry. It will be deleted during the next save.
Engine IDAn octet string identifying the engine ID that this entry should belong to. The string must contain an even number between 10 and 64 hexadecimal digits, but all-zeros and all-'F's are not allowed. The SNMPv3 architecture uses User-based Security Model (USM) for message security and View-based Access Control Model (VACM) for access control. For the USM entry, the usmUserEngineID and usmUserName are the entry keys. In a simple agent, usmUserEngineID is always that agent's own snmpEngineID value. The value can also take the value of the snmpEngineID of a remote SNMP engine with which this user can communicate. In other words, if user engine ID is the same as system engine ID, then it is local user; otherwise it's remote user.
User NameA string identifying the user name that this entry should belong to. The allowed string length is 1 to 32, and only ASCII characters from 33 to 126 are allowed.
Security LevelIndicates the security model that this entry should belong to. Possible security models include: NoAuth, NoPriv: no authentication and none privacyAuth, NoPriv: Authentication and no privacyAuth, Priv: Authentication and privacyThe value of security level cannot be modified if the entry already exists, which means the value must be set correctly at the time of entry creation.
Authentication ProtocolIndicates the authentication protocol that this entry should belong to. Possible authentication protocols include: None: no authentication protocolMD5: an optional flag to indicate that this user is using MD5 authentication protocolSHA: an optional flag to indicate that this user is using SHA authentication protocolThe value of security level cannot be modified if the entry already exists, which means the value must be set correctly at the time of entry creation.
Authentication PasswordA string identifying the authentication pass phrase. For MD5 authentication protocol, the allowed string length is 8 to 32. For SHA authentication protocol, the allowed string length is 8 to 40. Only ASCII characters from 33 to 126 are allowed.
Privacy ProtocolIndicates the privacy protocol that this entry should belong to. Possible privacy protocols include: None: no privacy protocolDES: an optional flag to indicate that this user is using DES authentication protocol
Privacy PasswordA string identifying the privacy pass phrase. The allowed string length is 8 to 32, and only ASCII characters from 33 to 126 are allowed.

5.5.4 SNMP Groups Configuration

This page allows you to configure SNMPv3 group table. The entry index keys are Security Model and Security Name.

SNMPv3 Groups Configuration

DeleteSecurity ModelSecurity NameGroup Name
v1publicdefault_ro_group
v1privatedefault_rw_group
v2cpublicdefault_ro_group
v2cprivatedefault_rw_group
usmdefault_userdefault_rw_group

Figure 5-50. SNMPv3 Groups Configuration screen.

Table 5-34. SNMPv3 Groups Configuration screen options.
Label Description
Delete Check to delete the entry. It will be deleted during the next save.
Security ModelIndicates the security model that this entry should belong to. Possible security models included:v1: Reserved for SNMPv1.v2c: Reserved for SNMPv2c.usm: User-based Security Model (USM).
Security NameA string identifying the security name that this entry should belong to. The allowed string length is 1 to 32, and only ASCII characters from 33 to 126 are allowed.
Group NameA string identifying the group name that this entry should belong to. The allowed string length is 1 to 32, and only ASCII characters from 33 to 126 are allowed.

5.5.5 SNMP View Configurations

This page allows you to configure SNMPv3 view table. The entry index keys are View Name and OID Subtree.

Black Box LE2711C - SNMP View Configurations - 1

text_image SNMPv3 Views Configuration Delete View Name View Type OID Subtree default_view included .1 Add new view Save Reset

Figure 5-51. SNMPv3 Views Configuration screen.

Table 5-35. SNMPv3 Views Configuration screen options.
Label Description
Delete Check to delete the entry. It will be deleted during the next save.
View NameA string identifying the view name that this entry should belong to. The allowed string length is 1 to 32, and only ASCII characters from 33 to 126 are allowed.
View TypeIndicates the view type that this entry should belong to. Possible view types include: Included: an optional flag to indicate that this view subtree should be included.Excluded: An optional flag to indicate that this view subtree should be excluded.Generally, if an entry's view type is Excluded, it should exist another entry whose view type is Included, and its OID subtree oversteps the Excluded entry.
OID SubtreeThe OID defining the root of the subtree to add to the named view. The allowed OID length is 1 to 128. The allowed string content is digital number or asterisk (*).

5.5.6 SNMP Access Configurations

This page allows you to configure SNMPv3 access table. The entry index keys are Group Name, Security Model, and Security Level.

SNMPv3 Accesses Configuration
Black Box LE2711C - SNMP Access Configurations - 1

text_image Delete default_ro_group default_rw_group Security Model any any Security Level NoAuth, NoPriv NoAuth, NoPriv Read View Name default_view default_view None default_view Add new access Save Reset

Figure 5-52. SNMPv3 Access Configuration screen.

Table 5-36. SNMPv3 Access Configuration screen options.
Label Description
Delete Check to delete the entry. It will be deleted during the next save.
Group NameA string identifying the group name that this entry should belong to. The allowed string length is 1 to 32, and only ASCII characters from 33 to 126 are allowed.
Security ModelIndicates the security model that this entry should belong to. Possible security models include:any: Accepted any security model (v1|v2c|usm).v1: Reserved for SNMPv1.v2c: Reserved for SNMPv2c.usm: User-based Security Model (USM).
Security LevelIndicates the security model that this entry should belong to. Possible security models include:NoAuth, NoPriv: no authentication and no privacyAuth, NoPriv: Authentication and no privacyAuth, Priv: Authentication and privacy
Read View Name The name of the MIB view defining the MIB objects for which this request may request the current values. The allowed string length is 1 to 32, and only ASCII characters from 33 to 126 are allowed.
Write View Name The name of the MIB view defining the MIB objects for which this request may potentially SET new values. The allowed string length is 1 to 32, and only ASCII characters from 33 to 126 are allowed.

5.6 Traffic Prioritization

5.6.1 Storm Control

There is a unicast storm rate control, multicast storm rate control, and a broadcast storm rate control. These only affect flooded frames, i.e. frames with a (VLAN ID, DMAC) pair not present on the MAC Address table.

The rate is 2^n, where n is equal to or less than 15, or "No Limit". The unit of the rate can be either pps (packets per second) or kpps (kilopackets per second). The configuration indicates the permitted packet rate for unicast, multicast, or broadcast traffic across the switch.

NOTE: Frames sent to the CPU of the switch are always limited to approximately 4 kpps. For example, broadcasts in the management VLAN are limited to this rate. The management VLAN is configured on the IP setup page.

Black Box LE2711C - Storm Control - 1

text_image Storm Control Configuration Frame Type Status Rate (pps) Unicast 1K Multicast 1K Broadcast 1K Save Reset

Figure 5-53. Storm Control Configuration screen.

Table 5-37. Storm Control Configuration screen options.
Label Description
Frame TypeThe settings in a particular row apply to the frame type listed here: unicast, multicast, or broadcast.
Status Enable or disable the storm control status for the given frame type.
RateThe rate unit is packet per second (pps), configure the rate as 1K, 2K, 4K, 8K, 16K, 32K, 64K, 128K, 256K, 512K, or 1024K. The 1 kpps is actually 1002.1 pps.

5.6.2 Port Classification

QoS is an acronym for Quality of Service. It is a method to achieve efficient bandwidth utilization between individual applications or protocols.

PortQoS classDP levelPCPDEITag Class.DSCP Based
"<>✓<>✓<>✓<>✓
10✓0✓0✓0✓Disabled
20✓0✓0✓0✓Disabled
30✓0✓0✓0✓Disabled
40✓0✓0✓0✓Disabled
50✓0✓0✓0✓Disabled
60✓0✓0✓0✓Disabled
70✓0✓0✓0✓Disabled
80✓0✓0✓0✓Disabled
90✓0✓0✓0✓Disabled
100✓0✓0✓0✓Disabled
110✓0✓0✓0✓Disabled
120✓0✓0✓0✓Disabled
130✓0✓0✓0✓Disabled

Figure 5-54. QoS Ingres Port Classification screen.

Table 5-38. QoS Ingres Port Classification screen options.
Label Description
Port The port number for which the configuration below applies.
QoS Class Controls the default QoS class.All frames are classified to a QoS class. There is a one to one mapping between QoS class, queue, and priority. A QoS class of 0 (zero) has the lowest priority.If the port is VLAN aware and the frame is tagged, then the frame is classified to a QoS class that is based on the PCP value in the tag as shown below. Otherwise the frame is classified to the default QoS class.PCP value: 0 1 2 3 4 5 6 7QoS class: 1 0 2 3 4 5 6 7If the port is VLAN aware, the frame is tagged, and Tag Class is enabled, then the frame is classified to a QoS class that is mapped from the PCP and DEI value in the tag. Otherwise the frame is classified to the default QoS class.The classified QoS class can be overruled by a QCL entry.NOTE: If the default QoS class has been dynamically changed, then the actual default QoS class is shown in parentheses after the configured default QoS class.
DP level Controls the default Drop Precedence Level.All frames are classified to a DP level.If the port is VLAN aware and the frame is tagged, then the frame is classified to a DP level that is equal to the DEI value in the tag. Otherwise the frame is classified to the default DP level.If the port is VLAN aware, the frame is tagged, and Tag Class is enabled, then the frame is classified to a DP level that is mapped from the PCP and DEI value in the tag. Otherwise the frame is classified to the default DP level.The classified DP level can be overruled by a QCL entry.
Table 5-38 (continued). QoS Ingres Port Classification screen options.
Label Description
PCP Controls the default PCP value.All frames are classified to a PCP value.If the port is VLAN aware and the frame is tagged, then the frame is classified to the PCP value in the tag. Otherwise the frame is classified to the default PCP value.
DEI Controls the default DEI value.All frames are classified to a DEI value.If the port is VLAN aware and the frame is tagged, then the frame is classified to the DEI value in the tag. Otherwise the frame is classified to the default DEI value.
Tag ClassShows the classification mode for tagged frames on this port.Disabled: Use default QoS class and DP level for tagged frames.Enabled: Use mapped versions of PCP and DEI for tagged frames.Click on the mode to configure the mode and/or mapping.NOTE: This setting has no effect if the port is VLAN unaware. Tagged frames received on VLAN-unaware ports are always classified to the default QoS class and DP level.
DSCP Based Click to enable DSCP Based QoS Ingress Port Classification.

5.6.3 Port Tag Remaking

This page provides an overview of QoS Egress Port Tag Remarking for all switch ports.

PortMode
1Classified
2Classified
3Classified
4Classified
5Classified
6Classified
7Classified
8Classified
9Classified
10Classified
11Classified
12Classified
13Classified
14Classified
15Classified
16Classified
17Classified
18Classified
19Classified
20Classified

Figure 5-55. QoS Egress Port Tag Remarking.

Table 5-39. QoS Egress Port Tag Remarking screen options.
Label Description
PortThe switch port number to which the following settings will be applied. Click on the port number to configure tag remarking.
ModeEnable or disable the storm control status for the given frame type.Shows the tag remarking mode for this port.Classified: use classified PCP/DEI valuesDefault: use default PCP/DEI valuesMapped: use mapped versions of QoS class and DP level
RateThe rate unit is packet per second (pps), configure the rate as 1K, 2K, 4K, 8K, 16K, 32K, 64K, 128K, 256K, 512K, or 1024K. The 1 kpps is actually 1002.1 pps.

5.6.4 Port DSCP

This page allows you to configure basic QoS Port DSCP settings for all switch ports.

QoS Port DSCP Configuration

PortIngressEgress
TranslateClassifyRewrite
*<><>
1DisableDisable
2DisableDisable
3DisableDisable
4DisableDisable
5DisableDisable
6DisableDisable
7DisableDisable
8DisableDisable
9DisableDisable
10DisableDisable
11DisableDisable
12DisableDisable
13DisableDisable
14DisableDisable
15DisableDisable

Figure 5-56. QoS Egress Port DSCP Configuration screen.

Table 5-40. QoS Egress Port DSCP Configuration screen options.
Label Description
Port Shows the list of ports for which you can configure DSCP Ingress and Egress settings.
IngressIn Ingress settings, you can change ingress translation and classification settings for individual ports.There are two configuration parameters available in Ingress:1. Translate2. Classify
1. Translate Check to enable ingress translation.
2. Classify Classification has 4 different values.Disable: no Ingress DSCP classificationDSCP=0: classify if incoming (or translated if enabled) DSCP is 0.Selected: classify only selected DSCP whose classification is enabled as specified in DSCP Translation window for the specific DSCP.All: classify all DSCP
Table 5-40 (continued). QoS Egress Port DSCP Configuration screen options.
Label Description
EgressPort egress rewriting can be one of the following options:Disable: no Egress rewriteEnable: rewrite enabled without remappingRemap DP Unaware: DSCP from the analyzer is remapped and the frame is remarked with a remapped DSCP value. The remapped DSCP value is always taken from the “DSCP Translation->Egress Remap DP0” table.Remap DP Aware: DSCP from the analyzer is remapped and the frame is remarked with a remapped DSCP value.Depending on the DP level of the frame, the remapped DSCP value is either taken from the 'DSCP Translation->Egress Remap DP0' table or from the “DSCP Translation->Egress Remap DP1” table.

5.6.5 Port Policing

This page allows you to configure Policer settings for all switch ports.

QoS Ingress Port Policers

PortEnabledRateUnitFlow Control
* 500
1 500kbps
2 500kbps
3 500kbps
4 500kbps
5 500kbps
6 500kbps
7 500kbps
8 500kbps
9 500kbps
10 500kbps
11 500kbps
12 500kbps
13 500kbps
14 500kbps

Figure 5-57. QoS Ingress Port Policers screen.

Table 5-41. QoS Ingress Port Policers screen options.
Label Description
Port The port number for which the configuration below applies.
Enable Check to enable the policer for individual switch ports.
RateConfigures the rate of each policer. The default value is 500. This value is restricted to 100 to 1000000 when the Unit is kbps or fps, and is restricted to 1 to 3300 when the Unit is Mbps or kfps.
UnitConfigures the unit of measurement for each policer rate as kbps, Mbps, fps, or kfps. The default value is kbps.
Flow ControlIf Flow Control is enabled and the port is in Flow Control mode, then pause frames are sent instead of being discarded.

5.6.6 Queue Policing

This page allows you to configure Queue Policer settings for all switch ports.

PortQueue 0Queue 1 EnableQueue 2 EnableQueue 3 EnableQueue 4 EnableQueue 5 EnableQueue 6 EnableQueue 7 Enable
ERateUnit
*500<>✓
1500kbps✓
2500kbps✓
3500kbps✓
4500kbps✓
5500kbps✓

Figure 5-58. QoS Ingress Queue Policers screen.

Table 5-42. QoS Ingress Queue Policers screen options.
Label Description
Port The port number for which the configuration below applies.
Enable(E) Check to enable queue policer for individual switch ports.
RateConfigures the rate of each queue policer. The default value is 500. This value is restricted to 100 to 1000000 when the Unit is kbps, and is restricted to 1 to 3300 when the Unit is Mbps.This field is only shown if at least one of the queue policers is enabled.
UnitConfigures the unit of measurement for each queue policer rate as kbps or Mbps. The default value is kbps.This field is only shown if at least one of the queue policers is enabled.

5.6.7 QoS Egress Port Scheduler and Shapers

This page allows you to configure Scheduler and Shapers for a specific port.

Strict Priority

Black Box LE2711C - QoS Egress Port Scheduler and Shapers - 1

flowchart
graph TD
    A["Queue Shaper"] --> B["Enable Rate Unit Excess"]
    C["Port Shaper"] --> D["Enable Rate Unit"]
    B --> E["500 kbps"]
    D --> F["500 kbps"]
    E --> G["STRICT"]
    F --> G
    G --> H["500 kbps"]

Figure 5-59. Strict Priority screen.

Table 5-43. Strict Priority screen options.
Label Description
Scheduler ModeControls whether the scheduler mode is Strict Priority or Weighted on this switch port.
Queue Shaper Enable Check to enable queue shaper for individual switch ports.
Queue Shaper RateConfigures the rate of each queue shaper. The default value is 500. This value is restricted to 100 to 1000000 when the Unit is kbps, and it is restricted to 1 to 3300 when the Unit is Mbps.
Queues Shaper UnitConfigures the rate for each queue shaper. The default value is 500. This value is restricted to 100 to 1000000 when the Unit is kbps, and it is restricted to 1 to 3300 when the Unit is Mbps.
Queue Shaper Excess Allows the queue to use excess bandwidth.
Port Shaper Enable Check to enable port shaper for individual switch ports.
Port Shaper Rate Configures the rate of each port shaper. The default value is 500 This value is restricted to 100 to 1000000 when the Unit is kbps, and it is restricted to 1 to 3300 when the Unit is Mbps.
Port Shaper Unit Configures the unit of measurement for each port shaper rate as kbps or Mbps. The default value is kbps.

Weighted

Black Box LE2711C - Weighted - 1

flowchart
graph TD
    A["Scheduler Mode Weighted"] --> B["Queue Shaper"]
    B --> C["Enable Rate Unit Excess"]
    B --> D["Queue Scheduler Weight Percent"]
    D --> E["DWRR"]
    E --> F["STRICT"]
    F --> G["S 500 kbps"]
    style A fill:#f9f,stroke:#333
    style G fill:#bbf,stroke:#333

Figure 5-60. QoS Egress Port Scheduler and Shapers Port 1.

Table 5-44. QoS Egress Port Scheduler and Shapers Port 1 screen options.
Label Description
Scheduler ModeControls whether the scheduler mode is Strict Priority or Weighted on this switch port.
Queue Shaper Enable Check to enable queue shaper for individual switch ports.
Queue Shaper RateConfigures the rate of each queue shaper. The default value is 500. This value is restricted to 100 to 1000000 when the Unit is kbps, and it is restricted to 1 to 3300 when the Unit is Mbps.
Queues Shaper UnitConfigures the rate of each queue shaper. The default value is 500. This value is restricted to 100 to 1000000 when the Unit is kbps, and it is restricted to 1 to 3300 when the Unit is Mbps.
Queue Shaper Excess Allows the queue to use excess bandwidth.
Queue Scheduler WeightConfigures the weight of each queue. The default value is 17. This value is restricted to 1 to 100. This parameter is only shown if Scheduler Mode is set to Weighted.
Queue Scheduler PercentShows the weight of the queue in percentage. This parameter is only shown if Scheduler Mode is set to Weighted.
Port Shaper Enable Check to enable port shaper for individual switch ports.
Table 5-44 (continued). QoS Egress Port Scheduler and Shapers Port 1 screen options.
Label Description
Port Shaper RateConfigures the rate of each port shaper. The default value is 500. This value is restricted to 100 to 1000000 when the Unit is kbps, and it is restricted to 1 to 3300 when the Unit is Mbps.
Port Shaper UnitConfigures the unit of measurement for each port shaper rate as kbps or Mbps. The default value is kbps.

5.6.8 Port Scheduled

This page provides an overview of QoS Egress Port Schedulers for all switch ports.

QoS Egress Port Schedulers

PortModeWeight
Q0Q1Q2Q3Q4Q5
1Strict Priority------
2Strict Priority------
3Strict Priority------
4Strict Priority------
5Strict Priority------
6Strict Priority------

Figure 5-61. QoS Egress Port Schedulers screen.

Table 5-45. QoS Egress Port Schedulers screen options.
Label Description
PortThe switch port number to which the following settings will be applied.Click on the port number to configure the schedulers.
Mode Shows the scheduling mode for this port.
Qn Shows the weight for this queue and port.

5.6.9 Port Shaping

This page provides an overview of QoS Egress Port Shapers for all switch ports.

QoS Egress Port Shapers

PortShapers
Q0Q1Q2Q3Q4Q5Q6Q7Port
1disableddisableddisableddisableddisableddisableddisableddisableddisabled
2disableddisableddisableddisableddisableddisableddisableddisableddisabled
3disableddisableddisableddisableddisableddisableddisableddisableddisabled
4disableddisableddisableddisableddisableddisableddisableddisableddisabled
5disableddisableddisableddisableddisableddisableddisableddisableddisabled
6disableddisableddisableddisableddisableddisableddisableddisableddisabled

Figure 5-62. QoS Egress Port Shapers screen.

Table 5-46. QoS Egress Port Shapers screen options.
Label Description
PortThe switch port number to which the following settings will be applied. Click on the port number to configure the shapers.
Mode Shows disabled or actual queue shaper rate - e.g. “800 Mbps.”
Qn Shows disabled or actual port shaper rate - e.g. “800 Mbps.”

5.6.10 DSCP Based QoS

This page allows you to configure basic QoS DSCP-based QoS Ingress Classification settings for all switches.

Black Box LE2711C - DSCP Based QoS - 1

text_image DSCP-Based QoS Ingress Classification DSCP Trust QoS Class DPL * <> <> ✓ 0 (BE) 0 0 ✓ 1 0 0 ✓ 2 0 0 ✓ 3 0 0 ✓ 4 0 0 ✓ 5 0 0 ✓

Figure 5-63. DSCP-Based QoS Ingress Classification screen.

Table 5-47. DSCP-Based QoS Ingress Classification screen options.
Label Description
DSCP Maximum number of supported DSCP values is 64.
TrustCheck to trust a specific DSCP value. Only frames with trusted DSCP values are mapped to a specific QoS class and drop precedence level. Frames with untrusted DSCP values are treated as a non-IP frame.
QoS Class QoS class value can be any number from 0–7.
DPL Drop Precedence Level (0–1)

5.6.11 DSCP Translation

This page allows you to configure basic QoS DSCP translation settings for all switches. DSCP translation can be done in Ingress or Egress.

DSCPIngressEgress
TranslateClassifyRemap DPORemap DP1
×<><><>
0 (BE)0 (BE)0 (BE)0 (BE)
1111
2222
3333
4444
5555
6666
7777
8 (CS1)8 (CS1)8 (CS1)8 (CS1)
9999

Figure 5-64. DSCP Translation screen.

Table 5-48. DSCP Translation screen options.
Label Description
DSCPMaximum number of supported DSCP values is 64 and valid DSCP value ranges from 0 to 63.
IngressIngress DSCP can be first translated to new DSCP before using the DSCP for QoS class and DPL map.There are two configuration parameters for DSCP Translation -1. Translate: DSCP can be translated to any of (0-63) DSCP values.2. Classify: check to enable ingress classification.
Egress Configurable egress parameters include;Remap DP0: controls the remapping for frames with DP level 0. You can select the DSCP value from a selected menu to which you want to remap. DSCP value ranges form 0 to 63.Remap DP1: controls the remapping for frames with DP level 1. You can select the DSCP value from a selected menu to which you want to remap. DSCP value ranges form 0 to 63.

5.6.12 DSCP Classification

This page allows you to configure the mapping of QoS class and Drop Precedence Level to DSCP value.

Black Box LE2711C - DSCP Classification - 1

text_image DSCP Classification QoS Class DPL DSCP * * <> ✓ 0 0 0 (BE) ✓ 0 1 8 (CS1) ✓ 1 0 14 (AF13) ✓ 1 1 0 (BE) ✓ 2 0 0 (BE) ✓

Figure 5-65. DSCP Classification screen.

Table 5-49. DSCP Classification screen options.
Label Description
QoS Class Actual QoS class
DPL Actual Drop Precedence Level
DSCP Select the classified DSCP value (0–63)

5.6.13 QoS Control List

This page allows you to edit or insert a single QoS control entry at a time. A QCE consists of several parameters. These parameters vary with the frame type you select.

Black Box LE2711C - QoS Control List - 1

text_image QCE Configuration Port Members 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓√ Key Parameters Tag Tag VID Specific Value: PCP 2 DEI 0 SMAC Specific 0x 00-00-00 DMAC Type UC Frame Type Ethernet Action Parameters Class 3 DPL 1 DSCP 28 (AF32) MAC Parameters Ether Type Specific Value: 0x FFFF Save Reset Cancel

Figure 5-66. QCE Configuration screen.

Table 5-50. QCE Configuration screen options.
Label Description
Port MembersCheck to include the port in the QCL entry. By default, all ports are included.
Key ParametersKey configurations include:Tag: value of tag, can be Any, Untag or Tag.VID: valid value of VLAN ID, can be any value from 1 to 4095 Any: user can enter either a specific value or a range of VIDs.PCP: Priority Code Point, can be specific numbers (0, 1, 2, 3, 4, 5, 6, 7), a range (0-1, 2-3, 4-5, 6-7, 0-3, 4-7) or AnyDEI: Drop Eligible Indicator, can be any of values between 0 and 1 or AnySMAC: Source MAC Address, can be 24 MS bits (OUI) or AnyDMAC Type: Destination MAC type, can be unicast (UC), multicast (MC), broadcast (BC) or AnyFrame Type can be the following values:AnyEthernetLLCSNAPIPv4IPv6NOTE: All frame types are explained below.
Any Allow all types of frames.
EthernetValid Ethernet values can range from 0x600 to 0xFFFF or Any' but excluding 0x800(IPv4) and 0x86DD(IPv6).The default value is Any.
LLCSSAP Address: valid SSAP (Source Service Access Point) values can range from 0x00 to 0xFF or Any. The default value is Any.DSAP Address: valid DSAP (Destination Service Access Point) values can range from 0x00 to 0xFF or Any. The default value is Any.Control Valid Control: valid values can range from 0x00 to 0xFF or Any. The default value is Any.
SNAPPID: valid PID (a.k.a ethernet type) values can range from 0x00 to 0xFFFF or Any. The default value is Any.
IPv4 Protocol IPProtocol Number: (0-255, TCP or UDP) or Any.Source IP: specific Source IP address in value/mask format or Any. IP and mask are in the format of x.y.z.w where x, y, z, and w are decimal numbers between 0 and 255. When the mask is converted to a 32-bit binary string and read from left to right, all bits following the first zero must also be zero.DSCP (Differentiated Code Point): can be a specific value, a range, or Any. DSCP values are in the range 0-63 including BE, CS1-CS7, EF or AF11-AF43.IP Fragment: IPv4 frame fragmented options include 'yes', 'no', and 'any'.Sport Source TCP/UDP Port: (0-65535) or Any, specific value or port range applicable for IP protocol UDP/TCPDport Destination TCP/UDP Port: (0-65535) or Any, specific value or port range applicable for IP protocol UDP/TCP
IPv6 Protocol IPprotocol number: (0-255, TCP or UDP) or Any.Source IP IPv6 source address: (a.b.c.d) or Any, 32 LS bits.DSCP (Differentiated Code Point): can be a specific value, a range, or Any. DSCP values are in the range 0-63 including BE, CS1-CS7, EF or AF11-AF43.Sport Source TCP/UDP port: (0-65535) or Any, specific value or port range applicable for IP protocol UDP/TCPDport Destination TCP/UDP port: (0-65535) or Any, specific value or port range applicable for IP protocol UDP/TCP
Table 5-50 (continued). QCE Configuration screen options.
Label Description
Action Parameters Class QoS class: (0–7) or DefaultValid Drop Precedence Level value can be (0–1) or Default.Valid DSCP value can be (0–63, BE, CS1–CS7, EF or AF11–AF43) or Default.Default means that the default classified value is not modified by this QCE.

5.6.14 QoS Counters

This page provides the statistics of individual queues for all switch ports.

PortQ0Q1Q2Q3Q4Q5Q6Q7
RxTxRxTxRxTxRxTxRxTxRxTxRxTxRxTx
10000000000000000
20000000000000000
30000000000000000
40000000000000000
50000000000000000
60000000000000000
758600000000000000493
8 1307

Figure 5-67. Queuing Counters screen.

Table 5-51. Queuing Counters screen options.
Label Description
Port The switch port number to which the following settings will be applied.
Qn There are 8 QoS queues per port. Q0 is the lowest priority.
Rx/Tx The number of received and transmitted packets per queue.

5.6.15 QCL Status

This page shows the QCL status by different QCL users. Each row describes the QCE that is defined. It is a conflict if a specific QCE is not applied to the hardware due to hardware limitations. The maximum number of QCEs is 256 on each switch.

Black Box LE2711C - QCL Status - 1

text_image Combined Auto-refresh Resolve Conflict Refresh QoS Control List Status User QCE# Frame Type Port Action Conflict Class DPL DSCP No entries

Figure 5-68. QoS Control List Status screen.

Table 5-52. QoS Control List Status screen options.
Label Description
User Indicates the QCL user
QCE# Indicates the index of QCE
Frame TypeIndicates the type of frame to look for incoming frames. Possible frame types are:Any: the QCE will match all frame type.Ethernet: Only Ethernet frames (with Ether Type 0x600-0xFFFF) are allowed.LLC: Only (LLC) frames are allowed.SNAP: Only (SNAP) frames are allowed.IPv4: the QCE will match only IPV4 frames.IPv6: the QCE will match only IPV6 frames.
Port Indicates the list of ports configured with the QCE.
ActionIndicates the classification action taken on ingress frame if parameters configured are matched with the frame's content.There are three action fields: Class, DPL, and DSCP.Class: Classified QoS; if a frame matches the QCE, it will be put in the queue.DPL: Drop Precedence Level; if a frame matches the QCE, then DP level will set to a value displayed under DPL column.DSCP: if a frame matches the QCE, then DSCP will be classified with the value displayed under DSCP column.
ConflictDisplays the conflict status of QCL entries. As hardware resources are shared by multiple applications, resources required to add a QCE may not be available. In that case, it shows conflict status as Yes, otherwise it is always No.NOTE: Conflict can be resolved by releasing the hardware resources required to add the QCL entry by pressing Resolve Conflict button.

5.7 Multicast

5.7.1 IGMP Snooping

This page provides IGMP Snooping related configurations.

Black Box LE2711C - IGMP Snooping - 1

text_image IGMP Snooping Configuration Global Configuration Snooping Enabled Unregistered IPMCv4 Flooding Enabled Port Related Configuration Port Router Port Fast Leave " □ □ 1 □ □ 2 □ □ 3 □ □ 4 □ □ 5 □ □ 6 □ □

Figure 5-69. IGMP Snooping Configuration screen.

Table 5-53. IGMP Snooping Configuration screen options.
Label Description
Snooping Enabled Check to enable global IGMP snooping.
Unregistered IPMCv4Flooding enabledCheck to enable unregistered IPMC traffic flooding.
Router PortSpecifies which ports act as router ports. A router port is a port on the Ethernet switch that leads towards the Layer 3 multicast device or IGMP querier.If an aggregation member port is selected as a router port, the whole aggregation will act as a router port.
Fast Leave Check to enable fast leave on the port.

5.7.2 VLAN Configurations of IGMP Snooping

Each page shows up to 99 entries from the VLAN table, with a default value of 20, selected by the Entries Per Page input field. When first visited, the web page will show the first 20 entries from the beginning of the VLAN Table. The first displayed will be the one with the lowest VLAN ID found in the VLAN Table.

The VLAN input field allows the user to select the starting point in the VLAN Table. Clicking the Refresh button will update the displayed table starting from that or the next closest VLAN Table match.

The >> will use the last entry of the currently displayed entry as a basis for the next lookup. When the end is reached, the text No more entries is shown in the displayed table. Use the |<< button to start over.

Black Box LE2711C - VLAN Configurations of IGMP Snooping - 1

text_image IGMP Snooping VLAN Configuration Refresh |<< >> Start from VLAN 1 with 20 entries per page. Delete VLAN ID Snooping Enabled IGMP Querier 1 Add New IGMP VLAN Save Reset

Figure 5-70. IGMP Snooping VLAN Configuration screen.

Table 5-54. IGMP Snooping VLAN Configuration screen options.
Label Description
DeleteCheck to delete the entry. The designated entry will be deleted during the next save.
VLAN ID The VLAN ID of the entry.
IGMP Snooping Enable Check to enable IGMP snooping for individual VLAN. Up to 32 VLANs can be selected.
IGMP Querier Check to enable the IGMP Querier in the VLAN.

5.7.3 IGMP Snooping Status

This page provides IGMP snooping status.

Black Box LE2711C - IGMP Snooping Status - 1

text_image Auto-refresh □ Refresh Clear IGMP Snooping Status Statistics VLAN ID Querier Version Host Version Querier Status Queries Transmitted Queries Received V1 Reports Received V2 Reports Received V3 Reports Received V2 Leaves Received 1 v3 v3 DISABLE 0 0 0 0 0 0 Router Port Port Status 1 - 2 - 3 - 4 - 5 - 6 -

Figure 5-71. IGMP Snooping Status screen.

Table 5-55. IGMP Snooping Status screen options.
Label Description
VLAN ID The VLAN ID of the entry.
Querier Version Active Querier version
Host Version Active Host version
Querier Status Shows the Querier status as ACTIVE or IDLE
Querier Receive The number of transmitted Querier
V1 Reports Receive The number of received V1 reports
V2 Reports Receive The number of received V2 reports
V3 Reports Receive The number of received V3 reports
V2 Leave Receive The number of received V2 leave packets
RefreshClick to refresh the page immediately
ClearClear all statistics counters
Auto-refreshCheck to enable an automatic refresh of the page at regular intervals
PortSwitch port number
StatusIndicates whether a specific port is a router port or not

5.7.4 Groups Information of IGMP Snooping

Entries in the IGMP Group Table are shown on this page. The IGMP Group Table is sorted first by VLAN ID, and then by group.

Black Box LE2711C - Groups Information of IGMP Snooping - 1

text_image IGMP Snooping Group Information Auto-refresh □ Refresh |<< >> Start from VLAN 1 and group address 224.0.0.0 with 20 entries per page. Port Members VLAN ID Groups 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 No more entries

Figure 5-72. IGMP Snooping Group Information screen.

Table 5-56. IGMP Snooping Group Information screen options.
Label Description
VLAN ID The VLAN ID ofthe group
Groups The group address of the group displayed
Port Members Ports under this group

5.8 Security

5.8.1 Remote Control Security Configurations

Remote Control Security allows you to limit the remote access to the management interface. When enabled, requests of the client which is not in the allow list will be rejected.

Black Box LE2711C - Remote Control Security Configurations - 1

text_image Remote Control Security Configuration Mode Enable Delete Port IP Web Telnet SNMP Delete Any 0.0.0.0 Add new entry Save Reset

Figure 5-73. Remote Control Security Configuration screen.

Table 5-57. Remote Control Security Configuration screen options.
Label Description
Port Port number of the remote client
IP Address IP address of the remote client. 0.0.0.0 means “any IP.”
Web Check to enable management via a Web interface
Telnet Check to enable management via a Telnet interface
SNMP Check to enable management via a SNMP interface
Delete Check to delete entries

5.8.2 Device Binding

This page provides device binding configurations. Device binding is a powerful way to monitor devices and network security.

Black Box LE2711C - Device Binding - 1

text_image Device Binding Function State Enable Port Mode Alive Check Stream Check DDOS Prevention Device Active Status Active Status Active Status IP Address MAC Address 1 Scan --- --- 0.0.0.0 00-00-00-00- 2 Binding --- --- 0.0.0.0 00-00-00-00- 3 Shutdown --- --- 0.0.0.0 00-00-00-00- 4 ----- --- --- 0.0.0.0 00-00-00-00- 5 ----- --- --- 0.0.0.0 00-00-00-00-

Figure 5-74. Device Binding screen.

Table 5-58. Device Binding screen options.
Label Description
ModeIndicates the device binding operation for each port. Possible modes are:---: disableScan: scans IP/MAC automatically, but no binding functionBinding: enables binding. Under this mode, any IP/MAC that does not match the entry will not be allowed to access the network.Shutdown: shuts down the port (No Link)
Alive Check Active Check to enable alive check. When enabled, switch will ping the device continually.
Alive Check Status Indicates alive check status. Possible statuses are:---: disableGot Reply: receive ping reply from device, meaning the device is still aliveLost Reply: not receiving ping reply from device, meaning the device might have been dead.
Stream Check Active Check to enable stream check. When enabled, the switch will detect the stream change (getting low) from the device.
Stream Check Status Indicates stream check status. Possible statuses are:---: disableNormal: the stream is normal.Low: the stream is getting low.
DDoS Prevention ActionCheck to enable DDOS prevention. When enabled, the switch will monitor the device against DDOS attacks.
Table 5-58 (continued). Device Binding screen options.
Label Description
DDoS Prevention StatusIndicates DDOS prevention status. Possible statuses are:----: disableAnalyzing: analyzes packet throughput for initializationRunning: analysis completes and ready for next moveAttacked: DDOS attacks occur
Device IP Address SpecifiesIP address of the device
Device MAC Address SpecifiesMAC address of the device

Advanced Configurations

Alias IP Address

This page provides Alias IP Address configuration. Some devices might have more than one IP addresses. You could specify the other IP address here.

Alias IP Address

PortAlias IP Address
10.0.0.0
20.0.0.0
30.0.0.0
40.0.0.0
50.0.0.0
60.0.0.0
70.0.0.0

Figure 5-75. Alias IP Address screen.

Table 5-59. Aiias IP Address screen options.
Label Description
Alias IP AddressSpecifies alias IP address. Keep 0.0.0.0 if the device does not have an alias IP address.

Alive Check

You can use ping commands to check port link status. If port link fails, you can set actions from the drop-down list.

Black Box LE2711C - Alive Check - 1

text_image Alive Check Port Mode Action Status 1 --- 2 --- 3 Link Change --- 4 Only Log it --- 5 Shunt Down the Port --- 6 Reboot Device --- 7 --- 8 --- 9 --- 10 --- 11 --- 12 ---

Figure 5-76. Alive Check screen.

Table 5-60. Alive Check screen options.
Label Description
Link Change Disables or enables the port
Only log it Simply sends logs to the log server
Shut Down the Port Disables the port
Reboot Device Disables or enables PoE power

DDoS Prevention

This page provides DDOS Prevention configurations. The switch can monitor ingress packets, and perform actions when DDOS attack occurred on this port. You can configure the setting to achieve maximum protection.

DDOS Prevention

PortModeSensibilityPacket TypeSocket NumberFilterActionStatus
LowHigh
1EnabledNormalTCP8080Destination---Running...
2---NormalTCP8080Destination---Blocking 1 minuteBlocking 10 minuteBlockingShunt Down the Port---
3---NormalTCP8080Destination---
4---NormalTCP8080Destination---
5---NormalTCP8080DestinationOnly Log itReboot Device---
6---NormalTCP8080Destination---
7---NormalTCP8080Destination------
8---NormalTCP8080Destination------
9---NormalTCP8080Destination------
10---NormalTCP8080Destination------
11---NormalTCP8080Destination------

Figure 5-77. DDOS Prevention screen.

Table 5-61. DDOS Prevention screen options.
Label Description
Mode Enables or disablesDDOS prevention of the port
SensibilityIndicates the level of DDOS detection. Possible levels are:Low: low sensibilityNormal: normal sensibilityMedium: medium sensibilityHigh: high sensibility
Packet Type Indicates the types of DDoS attack packets to be monitored. Possible types are:RX Total: all ingress packetsRX Unicast: unicast ingress packetsRX Multicast: multicast ingress packetsRX Broadcast: broadcast ingress packetsTCP: TCP ingress packetsUDP: UDP ingress packets
Socket Number If packet type is UDP (or TCP), please specify the socket number here.The socket number can be a range, from low to high. If the socket number is only one, please fill the same number in the low and high fields.
Table 5-61 (continued). DDOS Prevention screen options.
Label Description
FilterIf packet type is UDP (or TCP), please choose the socket direction (Destination/Source).
ActionIndicates the action to take when DDOS attacks occur. Possible actions are:---: no actionBlocking 1 minute: blocks the forwarding for 1 minute and log the eventBlocking 10 minute: blocks the forwarding for 10 minutes and log the eventBlocking: blocks and logs the eventShunt Down the Port: shuts down the port (No Link) and logs the eventOnly Log it: simply logs the eventReboot Device: if PoE is supported, the device can be rebooted. The event will be logged.
StatusIndicates the DDOS prevention status. Possible statuses are:---: disables DDOS preventionAnalyzing: analyzes packet throughput for initializationRunning: analysis completes and ready for next moveAttacked: DDOS attacks occur

Device Description

This page allows you to configure device description settings.

Black Box LE2711C - Device Description - 1

text_image Device Description Port Device Type Location Address Description 1 IP Camera ✓ 2 IP Phone ✓ 3 Access Point ✓ 4 PC ✓ 5 PLC ✓ 6 Network Video Recorder ✓ 7 --- ✓ 8 --- ✓ 9 --- ✓ 10 --- ✓ 11 --- ✓ 12 --- ✓

Figure 5-78. Device Description screen.

Table 5-62. Device Description screen options.
Label Description
Device TypeIndicates device types. Possible types are: --- (no specification), IP Camera, IP Phone, Access Point, PC, PLC, and Network Video Recorder
Location AddressIndicates location information of the device. The information can be used for Google Mapping.
Description Device descriptions

Stream Check

This page allows you to configure stream check settings.

Black Box LE2711C - Stream Check - 1

text_image Stream Check Port Mode Action Status 1 Enabled Log it Normal 2 --- --- --- 3 --- --- --- 4 --- --- --- 5 --- --- --- 6 --- --- --- 7 --- --- --- 8 --- --- --- 9 --- --- --- 10 --- --- --- 11 --- --- --- 12 --- --- ---

Figure 5-79. Stream Check screen.

Table 5-63. Stream Check screen options.
Label Description
Mode Enables or disablesstream monitoring of the port.
ActionIndicates the action to take when the stream gets low. Possible actions are:---: no actionLog it: simply logs the event

5.8.3 ACL Ports

This page allows you to configure the ACL parameters (ACE) of each switch port. These parameters will affect frames received on a port unless the frame matches a specific ACE.

PortPolicy IDActionRate Limiter IDPort CopyLoggingShutdownCounter
11✓Permit✓Disabled✓Disabled✓Disabled✓Disabled✓108498
21✓Permit✓Disabled✓Disabled✓Disabled✓Disabled✓0
31✓Permit✓Disabled✓Disabled✓Disabled✓Disabled✓68732984
41✓Permit✓Disabled✓Disabled✓Disabled✓Disabled✓0
51✓Permit✓Disabled✓Disabled✓Disabled✓Disabled✓0
61✓Permit✓Disabled✓Disabled✓Disabled✓Disabled✓68732984
71✓Permit✓Disabled✓Disabled✓Disabled✓Disabled✓0
81✓Permit✓Disabled✓Disabled✓Disabled✓Disabled✓0

Figure 5-80. ACL Ports Configuration screen.

Table 5-64. ACL Ports Configuration screen options.
Label Description
Port The switch port number to which the following settings will be applied.
Policy IDSelect to apply a policy to the port. The allowed values are 1 to 8. The default value is 1.
Action Select to Permit to permit or Deny to deny forwarding. The default value is Permit.
Rate Limiter IDSelect a rate limiter for the port. The allowed values are Disabled or numbers from 1 to 15. The default value is Disabled.
Port CopySelect which port frames are copied to. The allowed values are Disabled or a specific port number. The default value is Disabled.
LoggingSpecifies the logging operation of the port. The allowed values are:Enabled: frames received on the port are stored in the system logDisabled: frames received on the port are not loggedThe default value is Disabled.NOTE: System log memory capacity and logging rate is limited.
ShutdownSpecifies the shutdown operation of this port. The allowed values are:Enabled: if a frame is received on the port, the port will be disabled.Disabled: port shut down is disabled.The default value is Disabled.
Counter Counts the number of frames that match this ACE.

Rate Limiters

This page allows you to configure the rate limiter for the ACL of the switch.

Rate Limiter IDRate (pps)
11
21
31
41
51
61
71
81
91
101
111
121

Figure 5-81. ACL Rate Limiter Configuration screen.

Table 5-65. ACL Rate Limiter Configuration screen options.
Label Description
Rate Limiter ID The rate limiter ID for the settings contained in the same row.
RateThe rate unit is packet per second (pps), which can be configured as 1, 2, 4, 8, 16, 32, 64, 128, 256, 512, 1K, 2K, 4K, 8K, 16K, 32K, 64K, 128K, 256K, 512K, or 1024K.The 1 kpps is actually 1002.1 pps.

ACL Control List

This page allows you to configure ACE (Access Control Entry).

An ACE consists of several parameters. These parameters vary with the frame type you have selected. First select the ingress port for the ACE, and then the frame type. Different parameter options are displayed according to the frame type you have selected.

A frame matching the ACE can be configured here.

Black Box LE2711C - ACL Control List - 1

text_image ACE Configuration Ingress Port Port 1 Frame Type IPv4

Black Box LE2711C - ACL Control List - 2

text_image Action Rate Limiter Port Copy Logging Shutdown Counter Permit Disabled Disabled Disabled Disabled 5197

Figure 5-82. ACE Configuration screen.

Table 5-66. ACE Configuration screen.
Label Description
Ingress PortIndicates the ingress port to which the ACE will apply.Any: the ACE applies to any portPort n: the ACE applies to this port number, where n is the number of the switch port.Policy n: the ACE applies to this policy number, where n can range from 1 to 8.
Frame TypeIndicates the frame type of the ACE. These frame types are mutually exclusive.Any: any frame can match the ACE.Ethernet Type: only Ethernet type frames can match the ACE. The IEEE 802.3 descripts the value of length/types should be greater than or equal to 1536 decimal (equal to 0600 hexadecimal).ARP: only ARP frames can match the ACE. Notice the ARP frames will not match the ACE with Ethernet type.IPv4: only IPv4 frames can match the ACE. Notice the IPv4 frames will not match the ACE with Ethernet type.
ActionSpecifies the action to take when a frame matches the ACE Permit: takes action when the frame matches the ACE.Deny: drops the frame matching the ACE.
Table 5-66 (continued). ACE Configuration screen.
Label Description
Rate LimiterSpecifies the rate limiter in number of base units. The allowed range is 1 to 15. Disabled means the rate limiter operation is disabled.
Port CopyFrames matching the ACE are copied to the port number specified here. The allowed range is the same as the switch port number range. Disabled means the port copy operation is disabled.
LoggingSpecifies the logging operation of the ACE. The allowed values are:Enabled: frames matching the ACE are stored in the system log.Disabled: frames matching the ACE are not logged.NOTE: System log memory capacity and logging rate is limited.
ShutdownSpecifies the shutdown operation of the ACE. The allowed values are:Enabled: if a frame matches the ACE, the ingress port will be disabled.Disabled: port shutdown is disabled for the ACE.
Counter Indicates the number of times the ACE matched by a frame.

MAC Parameters

Black Box LE2711C - MAC Parameters - 1

text_image SMAC Filter SMAC Value DMAC Filter DMAC Value Specific 00-00-00-00-00-0 Specific 00-00-00-00-00-0:

Figure 5-83. MAC Parameters screen.

Table 5-67. MAC Parameters screen options.
Label Description
SMAC Filter(Only displayed when the frame type is Ethernet Type or ARP.)Specifies the source MAC filter for the ACE.Any: no SMAC filter is specified (SMAC filter status is “don't-care”).Specific: if you want to filter a specific source MAC address with the ACE, choose this value. A field for entering an SMAC value appears.
SMAC ValueWhen Specific is selected for the SMAC filter, you can enter a specific source MAC address. The legal format is "xx-xx-xx-xx-xx-xx". Frames matching the ACE will use this SMAC value.
DMAC FilterSpecifies the destination MAC filter for this ACE.Any: no DMAC filter is specified (DMAC filter status is “don't-care”).MC: frame must be multicast.BC: frame must be broadcast.UC: frame must be unicast.Specific: If you want to filter a specific destination MAC address with the ACE, choose this value.A field for entering a DMAC value appears.
Table 5-67 (continued). MAC Parameters screen options.
Label Description
DMAC ValueWhen Specific is selected for the DMAC filter, you can enter a specific destination MAC address. The legal format is “xx-xx-xx-xx-xx-xx.” Frames matching the ACE will use this DMAC value.

VLAN Parameters

Black Box LE2711C - VLAN Parameters - 1

text_image VLAN ID Filter VLAN ID Tag Priority Specific 1 6

Figure 5-84. VLAN Parameters screen.

Table 5-68. VLAN Parameters screen menu.
Label Description
VLAN ID Filter Specifies the VLAN ID filter for the ACEAny: no VLAN ID filter is specified (VLAN ID filter status is "don't-care").Specific: if you want to filter a specific VLAN ID with the ACE, choose this value. A field for entering a VLAN ID number appears.
VLAN ID When Specific is selected for the VLAN ID filter, you can enter a specific VLAN ID number. The allowed range is 1 to 4095. Frames matching the ACE will use this VLAN ID value.
Tag Priority Specifies the tag priority for the ACE. A frame matching the ACE will use this tag priority. The allowed number range is 0 to 7. Any means that no tag priority is specified (tag priority is "don't-care").

IP Parameters

Black Box LE2711C - IP Parameters - 1

text_image IP Protocol Filter IP Protocol Value IP TTL IP Fragment IP Option SIP Filter SIP Address SIP Mask DIP Filter DIP Address DIP Mask Other 6 Non-zero Yes Yes Network 0.0.0.0 0.0.0.0 Network 0.0.0.0 0.0.0.0

Figure 5-85. IP Parameters screen.

Chapter 5: Management

Table 5-69. IP Parameters screen options.
Label Description
IP Protocol FilterSpecifies the IP protocol filter for the ACEAny: no IP protocol filter is specified ("don't-care").Specific: if you want to filter a specific IP protocol filter with the ACE, choose this value. A field for entering an IP protocol filter appears.ICMP: selects ICMP to filter IPv4 ICMP protocol frames. Extra fields for defining ICMP parameters will appear. For more details of these fields, please refer to the help file.UDP: selects UDP to filter IPv4 UDP protocol frames. Extra fields for defining UDP parameters will appear. For more details of these fields, please refer to the help file.TCP: selects TCP to filter IPv4 TCP protocol frames. Extra fields for defining TCP parameters will appear. For more details of these fields, please refer to the help file.
IP Protocol ValueSpecific allows you to enter a specific value. The allowed range is 0 to 255. Frames matching the ACE will use this IP protocol value.
IP TTL Specifies thetime-to-live settings for the ACEZero: IPv4 frames with a time-to-live value greater than zero must not be able to match this entry.Non-zero: IPv4 frames with a time-to-live field greater than zero must be able to match this entry.Any: any value is allowed ("don't-care").
IP FragmentSpecifies the fragment offset settings for the ACE. This includes settings of More Fragments (MF) bit and Fragment Offset (FRAG OFFSET) for an IPv4 frame.No: IPv4 frames whose MF bit is set or the FRAG OFFSET field is greater than zero must not be able to match this entry.Yes: IPv4 frames whose MF bit is set or the FRAG OFFSET field is greater than zero must be able to match this entry.Any: any value is allowed ("don't-care").
IP Option Specifiesthe options flag settings for the ACENo: IPv4 frames whose options flag is set must not be able to match this entry.Yes: IPv4 frames whose options flag is set must be able to match this entry.Any: any value is allowed ("don't-care").
SIP Filter Specifiesthe source IP filter for this ACEAny: no source IP filter is specified (Source IP filter is "don't-care").Host: source IP filter is set to Host. Specify the source IP address in the SIP Address field that appears.Network: source IP filter is set to Network. Specify the source IP address and source IP mask in the SIP Address and SIP Mask fields that appear.
SIP AddressWhen Host or Network is selected for the source IP filter, you can enter a specific SIP address in dotted decimal notation.
SIP MaskWhen Network is selected for the source IP filter, you can enter a specific SIP mask in dotted decimal notation.
DIP Filter Specifiesthe destination IP filter for the ACEAny: no destination IP filter is specified (destination IP filter is "don't-care").Host: destination IP filter is set to Host. Specify the destination IP address in the DIP Address field that appears.Network: destination IP filter is set to Network. Specify the destination IP address and destination IP mask in the DIP Address and DIP Mask fields that appear.
DIP AddressWhen Host or Network is selected for the destination IP filter, you can enter a specific DIP address in dotted decimal notation.
DIP MaskWhen Network is selected for the destination IP filter, you can enter a specific DIP mask in dotted decimal notation.

ARP Parameters
Black Box LE2711C - IP Parameters - 2

text_image ARP/RARP Request/Reply Sender IP Filter Sender IP Address Sender IP Mask Target IP Filter Target IP Address Target IP Mask Other Request Network 192.168.1.1 255.255.255.0 Network 192.168.1.254 255.255.255.0

Black Box LE2711C - IP Parameters - 3

text_image ARP SMAC Match 1 RARP SMAC Match 1 IP/Ethernet Length Any IP 0 Ethernet 1

Figure 5-86. ARP Parameters screen.

Table 5-70. ARP Parameters screen options.
Label Description
ARP/RARPSpecifies the available ARP/RARP opcode (OP) flag for the ACEAny: no ARP/RARP OP flag is specified (OP is "don't-care").ARP: frame must have ARP/RARP opcode set to ARPRARP: frame must have ARP/RARP opcode set to RARP.Other: frame has unknown ARP/RARP Opcode flag.
Request/ReplySpecifies the available ARP/RARP opcode (OP) flag for the ACEAny: no ARP/RARP OP flag is specified (OP is "don't-care").Request: frame must have ARP Request or RARP Request OP flag set.Reply: frame must have ARP Reply or RARP Reply OP flag.
Sender IP Filter Specifies the sender IP filter for the ACEAny: no sender IP filter is specified (sender IP filter is "don't-care").Host: sender IP filter is set to Host. Specify the sender IP address in the SIP Address field that appears.Network: sender IP filter is set to Network. Specify the sender IP address and sender IP mask in the SIP Address and SIP Mask fields that appear.
Sender IP AddressWhen Host or Network is selected for the sender IP filter, you can enter a specific sender IP address in dotted decimal notation.
Sender IP MaskWhen Network is selected for the sender IP filter, you can enter a specific sender IP mask in dotted decimal notation.
Target IP FilterSpecifies the target IP filter for the specific ACEAny: no target IP filter is specified (target IP filter is "don't-care").Host: target IP filter is set to Host. Specify the target IP address in the Target IP Address field that appears.Network: target IP filter is set to Network. Specify the target IP address and target IP mask in the Target IP Address and Target IP Mask fields that appear.
Target IP AddressWhen Host or Network is selected for the target IP filter, you can enter a specific target IP address in dotted decimal notation.
Target IP MaskWhen Network is selected for the target IP filter, you can enter a specific target IP mask in dotted decimal notation.
Table 5-70 (continued). ARP Parameters screen options.
Label Description
ARP SMAC MatchSpecifies whether frames will meet the action according to their sender hardware address field (SHA) settings.0: ARP frames where SHA is not equal to the SMAC address1: ARP frames where SHA is equal to the SMAC addressAny: any value is allowed ("don't-care").
RARP SMAC MatchSpecifies whether frames will meet the action according to their target hardware address field (THA) settings.0: RARP frames where THA is not equal to the SMAC address1: RARP frames where THA is equal to the SMAC addressAny: any value is allowed ("don't-care")
IP/Ethernet LengthSpecifies whether frames will meet the action according to their ARP/RARP hardware address length (HLN) and protocol address length (PLN) settings.0: ARP/RARP frames where the HLN is equal to Ethernet (0x06) and the (PLN) is equal to IPv4 (0x04) must not match this entry.1: ARP/RARP frames where the HLN is equal to Ethernet (0x06) and the (PLN) is equal to IPv4 (0x04) must match this entry.Any: any value is allowed ("don't-care").
IPSpecifies whether frames will meet the action according to their ARP/RARP hardware address space (HRD) settings.0: ARP/RARP frames where the HLD is equal to Ethernet (1) must not match this entry.1: ARP/RARP frames where the HLD is equal to Ethernet (1) must match this entry.Any: any value is allowed ("don't-care").
EthernetSpecifies whether frames will meet the action according to their ARP/RARP protocol address space (PRO) settings.0: ARP/RARP frames where the PRO is equal to IP (0x800) must not match this entry.1: ARP/RARP frames where the PRO is equal to IP (0x800) must match this entry.Any: any value is allowed ("don't-care").

ICMP Parameters

Black Box LE2711C - ICMP Parameters - 1

text_image ICMP Type Filter ICMP Type Value ICMP Code Filter ICMP Code Value Specific 255 Specific 255

Figure 5-87. ICMP Parameters screen.

Table 5-71. ICMP Parameters screen options.
Label Description
ICMP Type Filter SSpecifies the ICMP filter for the ACEAny: no ICMP filter is specified (ICMP filter status is "don't-care").Specific: if you want to filter a specific ICMP filter with the ACE, you can enter a specific ICMP value. A field for entering an ICMP value appears.
ICMP Type ValueWhen Specific is selected for the ICMP filter, you can enter a specific ICMP value. The allowed range is 0 to 255. A frame matching the ACE will use this ICMP value.
ICMP Code Filter SSpecifies the ICMP code filter for the ACEAny: no ICMP code filter is specified (ICMP code filter status is "don't-care").Specific: if you want to filter a specific ICMP code filter with the ACE, you can enter a specific ICMP code value. A field for entering an ICMP code value appears.
ICMP Code ValueWhen Specific is selected for the ICMP code filter, you can enter a specific ICMP code value. The allowed range is 0 to 255. A frame matching the ACE will use this ICMP code value.

TCP Parameters

Black Box LE2711C - TCP Parameters - 1

text_image Source Port Filter Source Port No. Dest. Port Filter Dest. Port No. TCP FIN TCP SYN TCP RST TCP PSH TCP ACK TCP URG Specific 0 Specific 80 Any Any Any Any Any Any

UDP Parameters

Black Box LE2711C - UDP Parameters - 1

text_image Source Port Filter Specific Source Port No. 0 Dest. Port Filter Range Dest. Port Range 80 -65535

Figure 5-88. TCP Parameters and UDP Parameters screens.

Table 5-72. TCP Parameters and UDP Parameters screens options.
Label Description
TCP/UDP Source FilterSpecifies the TCP/UDP source filter for the ACEAny: no TCP/UDP source filter is specified (TCP/UDP source filter status is "don't-care").Specific: if you want to filter a specific TCP/UDP source filter with the ACE, you can enter a specific TCP/UDP source value. A field for entering a TCP/UDP source value appears.Range: if you want to filter a specific TCP/UDP source range filter with the ACE, you can enter a specific TCP/UDP source range. A field for entering a TCP/UDP source value appears.
TCP/UDP Source No.When Specific is selected for the TCP/UDP source filter, you can enter a specific TCP/UDP source value. The allowed range is 0 to 65535. A frame matching the ACE will use this TCP/UDP source value.
TCP/UDP Source RangeWhen Range is selected for the TCP/UDP source filter, you can enter a specific TCP/UDP source range value.The allowed range is 0 to 65535. A frame matching the ACE will use this TCP/UDP source value.
Table 5-72 (continued). TCP Parameters and UDP Parameters screens options.
Label Description
TCP/UDP Destination FilterSpecifies the TCP/UDP destination filter for the ACEAny: no TCP/UDP destination filter is specified (TCP/UDP destination filter status is "don't-care").Specific: if you want to filter a specific TCP/UDP destination filter with the ACE, you can enter a specific TCP/UDP destination value. A field for entering a TCP/UDP destination value appears.Range: if you want to filter a specific range TCP/UDP destination filter with the ACE, you can enter a specific TCP/UDP destination range. A field for entering a TCP/UDP destination value appears.
TCP/UDP Destination NumberWhen Specific is selected for the TCP/UDP destination filter, you can enter a specific TCP/UDP destination value. The allowed range is 0 to 65535. A frame matching the ACE will use this TCP/UDP destination value.
TCP/UDP Destination RangeWhen Range is selected for the TCP/UDP destination filter, you can enter a specific TCP/UDP destination range value. The allowed range is 0 to 65535. A frame matching the ACE will use this TCP/UDP destination value.
TCP FINSpecifies the TCP FIN ("no more data from sender") value for the ACE.0: TCP frames where the FIN field is set must not be able to match this entry.1: TCP frames where the FIN field is set must be able to match this entry.Any: any value is allowed ("don't-care").
TCP SYNSpecifies the TCP SYN ("synchronize sequence numbers") value for the ACE0: TCP frames where the SYN field is set must not be able to match this entry.1: TCP frames where the SYN field is set must be able to match this entry.Any: any value is allowed ("don't-care").
TCP PSHSpecifies the TCP PSH ("push function") value for the ACE0: TCP frames where the PSH field is set must not be able to match this entry.1: TCP frames where the PSH field is set must be able to match this entry.Any: any value is allowed ("don't-care").
TCP ACKSpecifies the TCP ACK ("acknowledgment field significant") value for the ACE0: TCP frames where the ACK field is set must not be able to match this entry.1: TCP frames where the ACK field is set must be able to match this entry.Any: any value is allowed ("don't-care").
TCP URGSpecifies the TCP URG ("urgent pointer field significant") value for the ACE0: TCP frames where the URG field is set must not be able to match this entry.1: TCP frames where the URG field is set must be able to match this entry.Any: any value is allowed ("don't-care").

5.8.4 AAA

Common Server Configurations

This page allows you to configure authentication servers.

Authentication Server Configuration

Common Server Configuration

Black Box LE2711C - Authentication Server Configuration - 1
Figure 5-89. Authentication Server Configuration screen.

Table 5-73. Authentication Server Configuration screen options.
Label Description
TimeoutThe timeout, which can be set to a number between 3 and 3600 seconds, is the maximum time to wait for a reply from a server.If the server does not reply within this time frame, we will consider it to be dead and continue with the next enabled server (if any).RADIUS servers are using the UDP protocol, which is unreliable by design. In order to cope with lost frames, the timeout interval is divided into 3 subintervals of equal length. If a reply is not received within the subinterval, the request is transmitted again. This algorithm causes the RADIUS server to be queried up to 3 times before it is considered to be dead.
Dead TimeThe dead time, which can be set to a number between 0 and 3600 seconds, is the period during which the switch will not send new requests to a server that has failed to respond to a previous request. This will stop the switch from continually trying to contact a server that it has already determined as dead.Setting the dead time to a value greater than 0 (zero) will enable this feature, but only if more than one server has been configured.

5.8.5 RADIUS

Authentication and Accounting Server Configurations

The table has one row for each RADIUS authentication server and a number of columns, which are:

RADIUS Authentication Server Configuration

#EnabledIP AddressPortSecret
1 1812
2 1812
3 1812
4 1812
5 1812

Figure 5-90. RADIUS Authentication and Accounting Server Configurations screen.

Table 5-74. RADIUS Authentication and Accounting Server Configurations screen options.
Label Description
# The RADIUS authentication server number for which the configuration below applies.
Enabled Check to enable the RADIUS authentication server.
IP AddressThe IP address or hostname of the RADIUS authentication server. IP address is expressed in dotted decimal notation.
PortThe UDP port to use on the RADIUS authentication server. If the port is set to 0 (zero), the default port (1812) is used on the RADIUS authentication server.
SecretThe secret—up to 29 characters long—shared between the RADIUS authentication server and the switch stack.

RADIUS Accounting Server Configuration

#EnabledIP AddressPortSecret
1 1813
2 1813
3 1813
4 1813
5 1813
SaveReset

Figure 5-91. RADIUS Accounting Server Configuration screen.

Figure 5-75. RADIUS Accounting Server Configuration screen options.
Label Description
# The RADIUS accounting server number for which the configuration below applies.
Enabled Check to enable the RADIUS accounting server.
IP AddressThe IP address or hostname of the RADIUS accounting server. IP address is expressed in dotted decimal notation.
PortThe UDP port to use on the RADIUS accounting server. If the port is set to 0 (zero), the default port (1813) is used on the RADIUS accounting server.
SecretThe secret—up to 29 characters long—shared between the RADIUS accounting server and the switch stack.

Authentication and Accounting Server Status Overview

This page provides an overview of the status of the RADIUS servers configurable on the authentication configuration page.

RADIUS Authentication Server Status Overview

#IP AddressStatus
10.0.0.0:1812Disabled
20.0.0.0:1812Disabled
30.0.0.0:1812Disabled
40.0.0.0:1812Disabled
50.0.0.0:1812Disabled

Figure 5-92. RADIUS Authentication Server Status Overview screen.

Table 5-76. RADIUS Authentication Server Status Overview screen options.
Label Description
# The RADIUS server number. Click to navigate to detailed statistics of the server.
IP AddressThe IP address and UDP port number (in: notation) of the server.
Table 5-76 (continued). RADIUS Authentication Server Status Overview screen options.
Label Description
StatusThe current status of the server. This field has one of the following values:Disabled: the server is disabled.Not Ready: the server is enabled, but IP communication is not yet up and running.Ready: the server is enabled, IP communications are built, and the RADIUS module is ready to accept access attempts.Dead (X seconds left): access attempts are made to this server, but it does not reply within the configured timeout. The server has temporarily been disabled, but will be re-enabled when the dead-time expires. The number of seconds left before this occurs is displayed in parentheses. This state is only reachable when more than one server is enabled.

RADIUS Accounting Server Status Overview

#IP AddressStatus
10.0.0.0:1813Disabled
20.0.0.0:1813Disabled
30.0.0.0:1813Disabled
40.0.0.0:1813Disabled
50.0.0.0:1813Disabled

Figure 5-93. RADIUS Accounting Server Status Overview screen.

Table 5-77. RADIUS Accounting Server Status Overview screen options.
Label Description
# The RADIUS server number. Click to navigate to detailed statistics of the server.
IP AddressThe IP address and UDP port number (in: notation) of the server.
StatusThe current status of the server. This field has one of the following values:Disabled: the server is disabled.Not Ready: the server is enabled, but IP communication is not yet up and running.Ready: the server is enabled, IP communication is up and running, and the RADIUS module is ready to accept accounting attempts.Dead (X seconds left): accounting attempts are made to this server, but it does not reply within the configured timeout. The server has temporarily been disabled, but will be re-enabled when the dead-time expires. The number of seconds left before this occurs is displayed in parentheses. This state is only reachable when more than one server is enabled.

Authentication and Accounting Server Statistics

The statistics map closely to those specified in RFC4668 - RADIUS Authentication Client MIB.

Use the server drop-down list to switch between the backend servers to show related details.

RADIUS Authentication Statistics for Server #1

Server #1 Auto-refresh Refresh Clear
Receive PacketsTransmit Packets
Access Accepts0Access Requests0
Access Rejects0Access Retransmissions0
Access Challenges0Pending Requests0
Malformed Access Responses0Timeouts0
Bad Authenticators0
Unknown Types0
Packets Dropped0
Other Info
IP Address 0.0.0.0:1812State DisabledRound-Trip Time 0 ms

Figure 5-94. RADIUS Authentication Statistics for Server #1 screen.

Table 5-78. RADIUS Authentication Statistics for Server #1 screen options.
Label Description
Packet CountersRADIUS authentication server packet counters. There are seven “receive” and “transmit” counters.
DirectionNameRFC4668 NameDescription
RxAccess AcceptsradiusAuthClientExtAccessAcceptsThe number of RADIUS Access-Accept packets (valid or invalid) received from the server.
RxAccess RejectsradiusAuthClientExtAccessRejectsThe number of RADIUS Access-Reject packets (valid or invalid) received from the server.
RxAccess ChallengesradiusAuthClientExtAccessChallengesThe number of RADIUS Access-Challenge packets (valid or invalid) received from the server.
RxMalformed Access ResponsesradiusAuthClientExtMalformedAccessResponsesThe number of malformed RADIUS Access-Response packets received from the server. Malformed packets include packets with an invalid length. Bad authenticators or Message Authenticator attributes or unknown types are not included as malformed access responses.
RxBad AuthenticatorsradiusAuthClientExtBadAuthenticatorsThe number of RADIUS Access-Response packets containing invalid authenticators or Message Authenticator attributes received from the server.
RxUnknown TypesradiusAuthClientExtUnknownTypesThe number of RADIUS packets that were received from the server on the authentication port and dropped for some other reason.
RxPackets DroppedradiusAuthClientExtPacketsDroppedThe number of RADIUS packets that were received from the server on the authentication port and dropped for some other reason.
TxAccess RequestsradiusAuthClientExtAccessRequestsThe number of RADIUS Access-Request packets sent to the server. This does not include retransmissions.
TxAccess RetransmissionsradiusAuthClientExtAccessRetransmissionsThe number of RADIUS Access-Request packets retransmitted to the RADIUS authentication server.
TxPending RequestsradiusAuthClientExtPendingRequestsThe number of RADIUS Access-Request packets destined for the server that have not yet timed out or received a response. This variable is incremented when an Access-Request is sent and decremented due to receipt of an Access-Accept, Access-Reject, Access-Challenge, timeout, or retransmission.
TxTimeoutsradiusAuthClientExtTimeoutsThe number of authentication timeouts to the server. After a timeout, the client may retry to the same server, send to a different server, or give up. A retry to the same server is counted as a retransmit as well as a timeout. A send to a different server is counted as a Request as well as a timeout.

Table 5-78 (continued). RADIUS Authentication Statistics for Server #1 screen options.
Label Description
Other Info This section contains information about the state of the server and the latest round-trip time.

NameRFC4668 NameDescription
State-Shows the state of the server. It takes one of the following values:Disabled: The selected server is disabled.Not Ready: The server is enabled, but IP communication is not yet up and running.Ready: The server is enabled, IP communication is up and running, and the RADIUS module is ready to accept access attempts.Dead (X seconds left): Access attempts were made to this server, but it did not reply within the configured timeout. The server has temporarily been disabled, but will get re-enabled when the dead-time expires. The number of seconds left before this occurs is displayed in parentheses. This state is only reachable when more than one server is enabled.
Round-Trip TimeradiusAuthClientExtRoundTripTimeThe time interval (measured in milliseconds) between the most recent Access-Reply/Access-Challenge and the Access-Request that matched it from the RADIUS authentication server. The granularity of this measurement is 100 ms. A value of 0 ms indicates that there hasn't been round-trip communication with the server yet.

RADIUS Accounting Statistics for Server #1

Receive PacketsTransmit Packets
Responses0Requests0
Malformed Responses0Retransmissions0
Bad Authenticators0Pending Requests0
Unknown Types0Timeouts0
Packets Dropped0
Other Info
IP Address0.0.0.0:1813
StateDisabled
Round-Trip Time0 ms

Figure 5-95. RADIUS Accounting Statistics for Server #1 screen.

Table 5-79. RADIUS Accounting Statistics for Server #1 screen options.
Label Description
Packet CountersRADIUS authentication server packet counters. There are five “receive” and four “transmit” counters.
DirectionNameRFC4670 Name
RxResponsesradiusAccClientExtResponses
RxMalformedradiusAccClientExtMalformedResponses with an invalid length. Bad authenticators or or
DirectionNameRFC4670 NameDescription
RxResponsesradiusAccClientExtResponsesThe number of RADIUS packets (valid or invalid) received from the server.
RxMalformed ResponsesradiusAccClientExtMalformedResponses with an invalid length. Bad authenticators or or unknown types are not included as malformed access responses.The number of malformed RADIUS packets received from the server. Malformed packets include packets
RxBad AuthenticatorsradiusAccClientExtBadAuthenticatorsThe number of RADIUS packets containing invalid authenticators received from the server.
RxUnknown TypesradiusAccClientExtUnknownTypesThe number of RADIUS packets of unknown types that were received from the server on the accounting port.
RxPackets DroppedradiusAccClientExtPacketsDroppedThe number of RADIUS packets that were received from the server on the accounting port and dropped for some other reason.
TxRequestsradiusAccClientExtRequestsThe number of RADIUS packets sent to the server. This does not include retransmissions.
TxRetransmissionsradiusAccClientExtRetransmissionsThe number of RADIUS packets retransmitted to the RADIUS accounting server.
TxPending RequestsradiusAccClientExtPendingRequestsThe number of RADIUS packets destined for the server that have not yet timed out or received a response. This variable is incremented when a Request is sent and decremented due to receipt of a Response, timeout, or retransmission.
TxTimeoutsradiusAccClientExtTimeoutsThe number of accounting timeouts to the server. After a timeout, the client may retry to the same server, send to a different server, or give up. A retry to the same server is counted as a retransmit as well as a timeout. A send to a different server is counted as a Request as well as a timeout.

Table 5-79 (continued). RADIUS Accounting Statistics for Server #1 screen options.

Label Description
Other info This section contains information about the state of the server and the latest round-trip time.
NameRFC4670 NameDescription
State-Shows the state of the server. It takes one of the following values:Disabled: The selected server is disabled.Not Ready: The server is enabled, but IP communication is not yet up and running.Ready: The server is enabled, IP communication is up and running, and the RADIUS module is ready to accept accounting attempts.Dead (X seconds left): Accounting attempts were made to this server, but it did not reply within the configured timeout. The server has temporarily been disabled, but will get re-enabled when the dead-time expires. The number of seconds left before this occurs is displayed in parentheses. This state is only reachable when more than one server is enabled.
Round-Trip TimeradiusAccClientExtRoundTripTimeThe time interval (measured in milliseconds) between the most recent Response and the Request that matched it from the RADIUS accounting server. The granularity of this measurement is 100 ms. A value of 0 ms indicates that there hasn't been round-trip communication with the server yet.

5.8.6 NAS (802.1x)

This page allows you to configure the IEEE 802.1X and MAC-based authentication system and port settings.

The IEEE 802.1X standard defines a port-based access control procedure that prevents unauthorized access to a network by requiring users to first submit credentials for authentication. One or more central servers (the backend servers) determine whether the user is allowed access to the network. These backend (RADIUS) servers are configured on the authentication configuration page.

MAC-based authentication allows for authentication of more than one user on the same port, and does not require the users to have special 802.1X software installed on their system. The switch uses the users' MAC addresses to authenticate against the backend server. As intruders can create counterfeit MAC addresses, MAC-based authentication is less secure than 802.1X authentication.

Overview of 802.1X (Port-Based) Authentication

In an 802.1X network environment, the user is called the supplicant, the switch is the authenticator, and the RADIUS server is the authentication server. The switch acts as the man-in-the-middle, forwarding requests and responses between the supplicant and the authentication server. Frames sent between the supplicant and the switch are special 802.1X frames, known as EAPOL (EAP Over LANs) frames which encapsulate EAP PDUs (RFC3748). Frames sent between the switch and the RADIUS server are RADIUS packets. RADIUS packets also encapsulate EAP PDUs together with other attributes like the switch's IP address, name, and the supplicant's port number on the switch. EAP is very flexible as it allows for different authentication methods, like MD5-Challenge, PEAP, and TLS. The important thing is that the authenticator (the switch) does not need to know which authentication method the supplicant and the authentication server are using, or how many information exchange frames are needed for a particular method. The switch simply encapsulates the EAP part of the frame into the relevant type (EAPOL or RADIUS) and forwards it.

When authentication is complete, the RADIUS server sends a special packet containing a success or failure indication. Besides forwarding the result to the supplicant, the switch uses it to open up or block traffic on the switch port connected to the supplicant.

NOTE: In an environment where two backend servers are enabled, the server timeout is configured to X seconds (using the authentication configuration page), and the first server in the list is currently down (but not considered dead), if the supplicant retransmits EAPOL Start frames at a rate faster than X seconds, it will never be authenticated because the switch will cancel on-going backend authentication server requests whenever it receives a new EAPOL Start frame from the supplicant. Since the server has not failed (because the X seconds have not expired), the same server will be contacted when the next backend authentication server requests from the switch. This scenario will loop forever. Therefore, the server timeout should be smaller than the supplicant's EAPOL Start frame retransmission rate.

Overview of MAC-Based Authentication

Unlike 802.1X, MAC-based authentication is not a standard, but merely a best-practices method adopted by the industry. In MAC-based authentication, users are called clients, and the switch acts as the supplicant on behalf of clients. The initial frame (any kind of frame) sent by a client is snooped by the switch, which in turn uses the client's MAC address as both username and password in the subsequent EAP exchange with the RADIUS server. The 6-byte MAC address is converted to a string in the following form "xx-xx-xx-xx-xx-xx", that is, a dash (-) is used as separator between the lower-cased hexadecimal digits. The switch only supports the MD5-Challenge authentication method, so the RADIUS server must be configured accordingly.

When authentication is complete, the RADIUS server sends a success or failure indication, which in turn causes the switch to open up or block traffic for that particular client, using static entries into the MAC Table. Only then will frames from the client be forwarded on the switch. There are no EAPOL frames involved in this authentication, and therefore, MAC-based authentication has nothing to do with the 802.1X standard.

The advantage of MAC-based authentication over 802.1X is that several clients can be connected to the same port (e.g. through a 3rd party switch or a hub) and still require individual authentication, and that the clients do not need special supplicant software to authenticate. The disadvantage is that MAC addresses can be spoofed by malicious users, equipment whose MAC address is a valid RADIUS user can be used by anyone, and only the MD5-Challenge method is supported.

802.1X and MAC-Based authentication configurations consist of two sections: system- and port-wide.

Black Box LE2711C - Overview of MAC-Based Authentication - 1

text_image Refresh Network Access Server Configuration System Configuration Mode Disabled Reauthentication Enabled Reauthentication Period 3600 seconds EAPOL Timeout 30 seconds Aging Period 300 seconds Hold Time 10 seconds Port Configuration Port Admin State Port State Restart * <> / 1 Force Authorized Globally Disabled Reauthenticate Reinitialize 2 Force Unauthorized Globally Disabled Reauthenticate Reinitialize 3 802.1X Globally Disabled Reauthenticate Reinitialize 4 MAC-based Auth. Globally Disabled Reauthenticate Reinitialize 5 Force Authorized Globally Disabled Reauthenticate Reinitialize

Figure 5-96. Network Access Server Configuration screen.

Table 5-80. Network Access Server Configuration screen options.
Label Description
ModeIndicates if 802.1X and MAC-based authentication is globally enabled or disabled on the switch. If globally disabled, all ports are allowed to forward frames.
Reauthentication EnabledIf checked, clients are reauthenticated after the interval specified by the Reauthentication Period.Reauthentication for 802.1X-enabled ports can be used to detect if a new device is plugged into a switch port.For MAC-based ports, reauthentication is only useful if the RADIUS server configuration has changed. It does not involve communication between the switch and the client, and therefore does not imply that a client is still present on a port (see Age Period below).
Reauthentication PeriodDetermines the period, in seconds, after which a connected client must be re-authenticated. This is only active if the Reauthentication Enabled checkbox is checked. Valid range of the value is 1 to 3600 seconds.
EAPOL TimeoutDetermines the time for retransmission of Request Identity EAPOL frames.Valid range of the value is 1 to 65535 seconds. This has no effect for MAC-based ports.
Age Period This setting applies to the following modes, i.e. modes using the Port Security functionality to secure MAC addresses:MAC-Based Auth.:When the NAS module uses the Port Security module to secure MAC addresses, the Port Security module needs to check for activity on the MAC address in question at regular intervals and free resources if no activity is seen within a given period of time. This parameter controls exactly this period and can be set to a number between 10 and 1000000 seconds.For ports in MAC-based Auth. mode, reauthentication does not cause direct communications between the switch and the client, so this will not detect whether the client is still attached or not, and the only way to free any resources is to age the entry.
Hold TimeThis setting applies to the following modes, i.e. modes using the Port Security functionality to secure MAC addresses:MAC-Based Auth.:If a client is denied access - either because the RADIUS server denies the client access or because the RADIUS server request times out (according to the timeout specified on the "Configuration Security AAA" page) - the client is put on hold in Unauthorized state. The hold timer does not count during an on-going authentication.The switch will ignore new frames coming from the client during the hold time.The hold time can be set to a number between 10 and 1000000 seconds.
Port The port number for which the configuration below applies.
Admin StateIf NAS is globally enabled, this selection controls the port's authentication mode. The following modes are available:Force AuthorizedIn this mode, the switch will send one EAPOL Success frame when the port link is up, and any client on the port will be allowed network access without authentication.Force UnauthorizedIn this mode, the switch will send one EAPOL Failure frame when the port link is up, and any client on the port will be disallowed network access.
Table 5-80 (continued). Network Access Server Configuration screen options.
Label Description
Admin State (continued)Port-based 802.1XIn an 802.1X network environment, the user is called the supplicant, the switch is the authenticator, and the RADIUS server is the authentication server. The authenticator acts as the man-in-the-middle, forwarding requests and responses between the supplicant and the authentication server. Frames sent between the supplicant and the switch are special 802.1X frames, known as EAPOL (EAP Over LANs) frames which encapsulate EAP PDUs (RFC3748). Frames sent between the switch and the RADIUS server is RADIUS packets. RADIUS packets also encapsulate EAP PDUs together with other attributes like the switch's IP address, name, and the supplicant's port number on the switch. EAP is very flexible as it allows for different authentication methods, like MD5-Challenge, PEAP, and TLS. The important thing is that the authenticator (the switch) does not need to know which authentication method the supplicant and the authentication server are using, or how many information exchange frames are needed for a particular method. The switch simply encapsulates the EAP part of the frame into the relevant type (EAPOL or RADIUS) and forwards it.When authentication is complete, the RADIUS server sends a special packet containing a success or failure indication. Besides forwarding the result to the supplicant, the switch uses it to open up or block traffic on the switch port connected to the supplicant.NOTE: In an environment where two backend servers are enabled, the server timeout is configured to X seconds (using the authentication configuration page), and the first server in the list is currently down (but not considered dead), if the supplicant retransmits EAPOL Start frames at a rate faster than X seconds, it will never be authenticated because the switch will cancel on-going backend authentication server requests whenever it receives a new EAPOL Start frame from the supplicant. Since the server has not failed (because the X seconds have not expired), the same server will be contacted when the next backend authentication server request from the switch This scenario will loop forever. Therefore, the server timeout should be smaller than the supplicant's EAPOL Start frame retransmission rate.a. Single 802.1XIn port-based 802.1X authentication, once a supplicant is successfully authenticated on a port, the whole port is opened for network traffic. This allows other clients connected to the port (for instance through a hub) to piggy-back on the successfully authenticated client and get network access even though they are not authenticated individually. To overcome this security breach, use the Single 802.1X variant.Single 802.1X is not yet an IEEE standard, but features many of the same characteristics as port-based 802.1X. In Single 802.1X, at most one supplicant can get authenticated on the port at a time. Normal EAPOL frames are used in the communications between the supplicant and the switch. If more than one supplicant are connected to a port, the one that comes first when the port's link is connected will be the first one considered. If that supplicant does not provide valid credentials within a certain amount of time, the chance will be given to another supplicant. Once a supplicant is successfully authenticated, only that supplicant will be allowed access. This is the most secure of all the supported modes. In this mode, the Port Security module is used to secure a supplicant's MAC address once successfully authenticated.b. Multi 802.1XIn port-based 802.1X authentication, once a supplicant is successfully authenticated on a port, the whole port is opened for network traffic. This allows other clients connected to the port (for instance through a hub) to piggy-back on the successfully authenticated client and get network access even though they are not authenticated individually. To overcome this security breach, use the Multi 802.1X variant.
Admin State(continued)In Multi 802.1X, it is not possible to use the multicast BPDU MAC address as the destination MAC address for EAPOL frames sent from the switch to the supplicant, since that would cause all supplicants attached to the port to reply to requests sent from the switch. Instead, the switch uses the supplicant's MAC address, which is obtained from the first EAPOL Start or EAPOL Response Identity frame sent by the supplicant. An exception to this is when no supplicants are attached. In this case, the switch sends EAPOL Request Identity frames using the BPDU multicast MAC address as destination—to wake up any supplicants that might be on the port.The maximum number of supplicants that can be attached to a port can be limited using the Port Security Limit Control functionality.The maximum number of supplicants that can be attached to a port can be limited using the Port Security Limit Control functionality.MAC-based Auth.Unlike port-based 802.1X, MAC-based authentication is not a standard, but merely a best-practices method adopted by the industry. In MAC-based authentication, users are called clients, and the switch acts as the supplicant on behalf of clients. The initial frame (any kind of frame) sent by a client is snooped by the switch, which in turn uses the client's MAC address as both username and password in the subsequent EAP exchange with the RADIUS server. The 6-byte MAC address is converted to a string in the following form "xx-xx-xx-xx-xx-xx", that is, a dash (-) is used as separator between the lower-cased hexadecimal digits. The switch only supports the MD5-Challenge authentication method, so the RADIUS server must be configured accordingly.When authentication is complete, the RADIUS server sends a success or failure indication, which in turn causes the switch to open up or block traffic for that particular client, using the Port Security module. Only then will frames from the client be forwarded on the switch. There are no EAPOL frames involved in this authentication, and therefore, MAC-based authentication has nothing to do with the 802.1X standard.The advantage of MAC-based authentication over port-based 802.1X is that several clients can be connected to the same port (e.g. through a 3rd party switch or a hub) and still require individual authentication, and that the clients don't need special supplicant software to authenticate. The advantage of MAC-based authentication over 802.1X-based authentication is that the clients do not need special supplicant software to authenticate. The disadvantage is that MAC addresses can be spoofed by malicious users - equipment whose MAC address is a valid RADIUS user can be used by anyone. Also, only the MD5-Challenge method is supported. The maximum number of clients that can be attached to a port can be limited using the Port Security Limit Control functionality.
Port StateThe current state of the port. It can undertake one of the following values: Globally Disabled: NAS is globally disabled. Link Down: NAS is globally enabled, but there is no link on the port. Authorized: the port is in Force Authorized or a single-supplicant mode and the supplicant is authorized. Unauthorized: the port is in Force Unauthorized or a single-supplicant mode and the supplicant is not successfully authorized by the RADIUS server. X Auth/Y Unauth: the port is in a multi-supplicant mode. Currently X clients are authorized and Y are unauthorized.
RestartTwo buttons are available for each row. The buttons are only enabled when authentication is globally enabled and the port's Admin State is in an EAPOL-based or MAC-based mode. Clicking these buttons will not cause settings changed on the page to take effect. Reauthenticate: schedules a reauthentication whenever the quiet-period of the port runs out (EAPOL-based authentication). For MAC-based authentication, reauthentication will be attempted immediately. The button only has effect on successfully authenticated clients on the port and will not cause the clients to be temporarily unauthorized. Reinitialize: forces a reinitialization of the clients on the port and hence a reauthentication immediately. The clients will transfer to the unauthorized state while the reauthentication is in progress.

NAS Status

This page provides an overview of the current NAS port states.

Black Box LE2711C - NAS Status - 1

text_image Network Access Server Switch Status Auto-refresh □ Refresh Port Admin State Port State Last Source Last ID 1 Force Authorized Globally Disabled 2 Force Authorized Globally Disabled 3 Force Authorized Globally Disabled 4 Force Authorized Globally Disabled 5 Force Authorized Globally Disabled 6 Force Authorized Globally Disabled

Figure 5-97. Network Access Server Switch Status screen.

Table 5-81. Network Access Server Switch Status screen options.
Label Description
Port The switch port number. Click to navigate to detailed 802.1X statistics of each port.
Admin StateThe port's current administrative state. Refer to NAS Admin State for more details regarding each value.
Port StateThe current state of the port. Refer to NAS Port State for more details regarding each value.
Last SourceThe source MAC address carried in the most recently received EAPOL frame for EAPOL-based authentication, and the most recently received frame from a new client for MAC-based authentication.
Last IDThe user name (supplicant identity) carried in the most recently received Response Identity EAPOL frame for EAPOL-based authentication, and the source MAC address from the most recently received frame from a new client for MAC-based authentication.

This page provides detailed IEEE 802.1X statistics for a specific switch port using port-based authentication. For MAC-based ports, only selected backend server (RADIUS Authentication Server) statistics is showed. Use the port drop-down list to select which port details to be displayed.

Black Box LE2711C - NAS Status - 2

text_image NAS Statistics Port 2 Port 2 Auto-refresh Refresh Port State Admin State Force Authorized Port State Globally Disabled

Figure 5-98. NAS Statistics Port 2 screen.

Table 5-82. NAS Statistics Port 2 screen options.
Label Description
Admin StateThe port's current administrative state. Refer to NAS Admin State for more details regarding each value.
Port StateThe current state of the port. Refer to NAS Port State for more details regarding each value.
EAPOL CountersThese supplicant frame counters are available for the following administrative states:Force AuthorizedForce Unauthorized802.1XBlack Box LE2711C - NAS Status - 3
Table 5-82 (continued). NAS Statistics Port 2 screen options.
Label Description
Backend Server CountersThese backend (RADIUS) frame counters are available for the following administrative states:802.1XMAC-based Auth.Black Box LE2711C - NAS Status - 4
Last Supplicant/Client InfoInformation about the last supplicant/client that attempts to authenticate. This information is available for the following administrative states:802.1XMAC-based Auth.Black Box LE2711C - NAS Status - 5

5.9 Alerts

5.9.1 Fault Alarm

When any selected fault event happens, the Fault LED on the switch panel will light up and the electric relay will signal at the same time.

Black Box LE2711C - Fault Alarm - 1

text_image Port Link Down/Broken Port Active 1 □ 2 □ 3 □ 4 □ 5 □ 6 □ 7 □ 8 □ 9 □ 10 □ 11 □ 12 □ Apply Fault Alarm Power Failure □PWR 1 □PWR 2

Figure 5-99. Port Link Down/Broken and Fault Alarm screens.

5.9.2 System Warning

SYSLOG Setting

The SYSLOG is a protocol that transmits event notifications across networks. For more details, please refer to RFC 3164 - The BSD SYSLOG Protocol.

Black Box LE2711C - SYSLOG Setting - 1

text_image System Log Configuration Server Mode Disabled Server Address Save Reset

Figure 5-100. System Log Configuration screen.

Table 5-83. System Log Configuration screen options.
Label Description
Server ModeIndicates existing server mode. When the mode operation is enabled, the syslog message will be sent to syslog server. The syslog protocol is based on UDP communications and received on UDP port 514 and the syslog server will not send acknowledgments back to the sender since UDP is a connectionless protocol and it does not provide acknowledgments. The syslog packet will always be sent even if the syslog server does not exist. Possible modes are:Enabled: enable server modeDisabled: disable server mode
SYSLOG Server IP AddressIndicates the IPv4 host address of syslog server. If the switch provides DNS functions, it also can be a host name.

SMTP Setting

SMTP (Simple Mail Transfer Protocol) is a protocol for transmitting e-mails across the Internet. For more information, refer to RFC 821—Simple Mail Transfer Protocol.

Black Box LE2711C - SMTP Setting - 1

text_image SMTP Setting E-mail Alert : Disable SMTP Server Address 0.0.0.0 Sender E-mail Address administrator Mail Subject Automated Email Alert Authentication Recipient E-mail Address 1 Recipient E-mail Address 2 Recipient E-mail Address 3 Recipient E-mail Address 4 Recipient E-mail Address 5 Recipient E-mail Address 6 Save

Figure 5-101. SMTP Setting screen.

Table 5-84. SMTP Setting screen options.
Label Description
E-mail Alarm Enables or disables transmission of system warnings by e-mail.
Sender E-mail AddressSMTP server IP address
Mail Subject Subject of the mail
Authentication • Username: the authentication username• Password: the authentication password• Confirm Password: re-enter password
Recipient E-mail AddressThe recipient's e-mail address. A mail allows for 6 recipients.
Apply Click to activate the configurations
Help Shows help file

Event Selection

SYSLOG and SMTP are two warning methods supported by the system. Check the corresponding box to enable the system event warning method you want. Please note that the checkbox cannot be checked when SYSLOG or SMTP is disabled.

System Warning - Event Selection

System EventsSYSLOGSMTP
System Start
Power Status
SNMP Authentication Failure
Redundant Ring Topology Change
PortSYSLOGSMTP
1DisabledLink Up and Link Down
2DisabledLink Up
3DisabledLink Down
4DisabledDisabled
5DisabledDisabled
6DisabledDisabled
7DisabledDisabled
8DisabledDisabled
9DisabledDisabled
10DisabledDisabled
11DisabledDisabled
12DisabledDisabled

Black Box LE2711C - Event Selection - 1
Figure 5-102. System Warning—Event Selection screen.

Table 5-85. System Warning—Event Selection screen options.
Label Description
System Cold Start Sends out alerts when the system is restarted.
Power Status Sends out alerts when power is up or down.
SNMP Authentication Failure Sends out alert when SNMP authentication fails.
B-Ring Topology Change Sends out alerts when B-Ring topology changes.
Port EventSYSLOG/SMTP eventDisableLink UpLink DownLink Up & Link Down
Apply Click to activate the configurations.
Help Shows help file

5.10 Monitor and Diag

5.10.1 MAC Table

The MAC address table can be configured on this page. You can set timeouts for entries in the dynamic MAC table and configure the static MAC table here.

Black Box LE2711C - MAC Table - 1

Figure 5-103. MAC Address Table Configuration and Static Mac Table Configuration screens.

Aging Configuration

By default, dynamic entries are removed from the MAC after 300 seconds. This removal is called aging. You can configure aging time by entering a value in the box of Age Time. The allowed range is 10 to 1000000 seconds. You can also disable the automatic aging of dynamic entries by checking Disable Automatic Aging.

MAC Table Learning

If the learning mode for a given port is grayed out, it means another module is in control of the mode, and thus the user cannot change the configurations. An example of such a module is MAC-Based authentication under 802.1X.

You can configure the port to dynamically learn the MAC address based upon the following settings:

Black Box LE2711C - MAC Table Learning - 1

Figure 5-104. MAC Table Learning screen.

Table 5-86. MAC Table Learning screen options.
Label Description
Auto Learning is done automatically as soon as a frame with unknown SMAC is received.
Disable No learning is done.
Secure Only static MAC entries are learned, all other frames are dropped.NOTE: Make sure the link used for managing the switch is added to the static Mac table before changing to secure learning mode; otherwise, the management link will be lost and can only be restored by using another non-secure port or by connecting to the switch via the serial interface.

Static MAC Table Configurations

The static entries in the MAC table are shown in this table. The static MAC table can contain up to 64 entries. The entries are for the whole stack, not for individual switches. The MAC table is sorted first by VLAN ID and then by MAC address.

Black Box LE2711C - Static MAC Table Configurations - 1

text_image Static MAC Table Configuration Delete VLAN ID MAC Address Port Members 1 2 3 4 5 6 7 8 9 10 11 12 □ 1 00-1E-94-98-89-89 ✓ □ □ □ □ □ □ □ □ □ □ Delete 1 00-00-00-00-00-00 □ □ □ □ □ □ □ □ □ □ Delete 1 00-00-00-00-00-00 □ □ □ □ □ □ □ □ □ □ Add new static entry

Figure 5-105. Static MAC Table Configuration screen.

Table 5-87. Static MAC Table Configuration screen options.
Label Description
Delete Check to delete an entry. It will be deleted during the next save.
VLAN ID The VLAN ID for the entry.
MAC Address The MAC address for the entry.
Port MembersCheckmarks indicate which ports are members of the entry. Check or uncheck to modify the entry.
Adding New Static EntryClick to add a new entry to the static MAC table. You can specify the VLAN ID, MAC address, and port members for the new entry. Click Save to save the changes.

MAC Table

Each page shows up to 999 entries from the MAC table, with a default value of 20, selected by the Entries Per Page input field. When first visited, the web page will show the first 20 entries from the beginning of the MAC Table. The first displayed will be the one with the lowest VLAN ID and the lowest MAC address found in the MAC Table.

Each page shows up to 999 entries from the MAC table, with a default value of 20, selected by the Entries Per Page input field. When first visited, the web page will show the first 20 entries from the beginning of the MAC Table. The first displayed will be the one with the lowest VLAN ID and the lowest MAC address found in the MAC Table.

The Start from MAC address and VLAN fields allow the user to select the starting point in the MAC table. Clicking the Refresh button will update the displayed table starting from that or the closest next MAC table match. In addition, the two input fields will—upon clicking Refresh—assume the value of the first displayed entry, allows for continuous refresh with the same start address.

The >> will use the last entry of the currently displayed VLAN/MAC address pairs as a basis for the next lookup. When it reaches the end, the text "no more entries" is shown in the displayed table. Use the |<< button to start over.

Black Box LE2711C - MAC Table - 1

text_image MAC Address Table Auto-refresh □ Refresh Clear |<< >> Start from VLAN 1 and MAC address 00-00-00-00-00-0 with 20 entries per page. Port Members Type VLAN MAC Address CPU 1 2 3 4 5 6 7 8 9 10 11 12 Static 1 00-1E-94-98-89-89 ✓ Static 1 00-1E-94-FF-FF-FF ✓ Static 1 01-80-C2-4A-44-06 ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ Static 1 33-33-FF-A8-0A-01 ✓ Static 1 33-33-FF-FF-FF-FF ✓ Static 1 FF-FF-FF-FF-FF-FF ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓

Figure 5-106. MAC Address Table screen.

Table 5-88. MAC Address Table screen options.
Label Description
Type Indicates whether the entry is a static or dynamic entry.
MAC address The MAC address of the entry.
VLAN The VLAN ID of the entry.
Port members The ports that are members of the entry.

5.10.2 Port Statistics

Traffic Overview

This page provides an overview of general traffic statistics for all switch ports.

PortPacketsBytesErrorsDropsFiltered
ReceiveTransmitReceiveTransmitReceiveTransmitReceiveTransmitReceive
117980869461259117790625991808830000
000000000
687329846873298749574777144957477932000024710409
000000000
000000000
687329856873298749574778834957477932100025204638
000000000
000000000
000000000
000000000
000000000
00000000

Figure 5-107. Port Statistics Overview screen.

Table 5-89. Port Statistics Overview screen options.
Label Description
Port The switch port number to which the following settings will be applied.
Packets The number of received and transmitted packets per port.
Bytes The number of received and transmitted bytes per port.
ErrorsThe number of frames received in error and the number of incomplete transmissions per port.
Drops The number of frames discarded due to ingress or egress congestion.
Filtered The number of received frames filtered by the forwarding process.
Auto-refresh Check to enable an automatic refresh of the page at regular intervals.
Refresh Updates the counter entries, starting from the current entry ID.
Clear Flushes all counters entries

Detailed Statistics

This page provides detailed traffic statistics for a specific switch port. Use the port drop-down list to decide the details of which switch port to be displayed.

The displayed counters include the total number for receive and transmit, the size for receive and transmit, and the errors for receive and transmit.

Detailed Statistics—Total Receive & Transmit

Receive TotalTransmit Total
Rx Packets0Tx Packets0
Rx Octets0Tx Octets0
Rx Unicast0Tx Unicast0
Rx Multicast0Tx Multicast0
Rx Broadcast0Tx Broadcast0
Rx Pause0Tx Pause0
Receive Size CountersTransmit Size Counters
Rx 64 Bytes0Tx 64 Bytes0
Rx 65-127 Bytes0Tx 65-127 Bytes0
Rx 128-255 Bytes0Tx 128-255 Bytes0
Rx 256-511 Bytes0Tx 256-511 Bytes0
Rx 512-1023 Bytes0Tx 512-1023 Bytes0
Rx 1024-1526 Bytes0Tx 1024-1526 Bytes0
Rx 1527- Bytes0Tx 1527- Bytes0
Receive Queue CountersTransmit Queue Counters
Rx Q00Tx Q00
Rx Q10Tx Q10
Rx Q20Tx Q20
Rx Q30Tx Q30
Rx Q40Tx Q40
Rx Q50Tx Q50
Rx Q60Tx Q60
Rx Q70Tx Q70
Receive Error CountersTransmit Error Counters
Rx Drops0Tx Drops0
Rx CRC/Alignment0Tx Late/Exc. Coll.0
Rx Undersize0
Rx Oversize0
Rx Fragments0
Rx Jabber0
Rx Filtered0

Figure 5-108. Detailed Port Statistics Port 1 screen.

Table 5-90. Detailed Port Statistics Port 1 screen options.
Label Description
Rx and Tx Packets The number of received and transmitted (good and bad) packets.
Rx and Tx Octets The number of received and transmitted (good and bad) bytes, including FCS, except framing bits.
Rx and Tx Unicast The number of received and transmitted (good and bad) unicast packets.
Rx and Tx MulticastThe number of received and transmitted (good and bad) multicast packets.
Rx and Tx Broadcast The number of received and transmitted (good and bad) broadcast packets.
Rx and Tx PauseThe number of MAC Control frames received or transmitted on this port that have an opcode indicating a PAUSE operation.
Rx DropsThe number of frames dropped due to insufficient receive buffer or egress congestion.
Rx CRC/Alignment The number of frames received with CRC or alignment errors.
Rx Undersize The number of short1 frames received with a valid CRC.
Rx Oversize The number of long2 frames received with a valid CRC.
Rx Fragments The number of short1 frames received with an invalid CRC.
Rx JabberThe number of long2 frames received with an invalid CRC.
Rx FilteredThe number of received frames filtered by the forwarding process.
Tx DropsThe number of frames dropped due to output buffer congestion.
Tx Late/Exc.Coll.The number of frames dropped due to excessive or late collisions.
  1. Short frames are frames smaller than 64 bytes.

  2. Long frames are frames longer than the maximum frame length configured for this port.

5.10.3 Port Mirroring

You can configure port mirroring on this page.

To solve network problems, selected traffic can be copied, or mirrored, to a mirror port where a frame analyzer can be attached to analyze the frame flow.

The traffic to be copied to the mirror port is selected as follows:

All frames received on a given port (also known as ingress or source mirroring).

All frames transmitted on a given port (also known as egress or destination mirroring).

Port to mirror is also known as the mirror port. Frames from ports that have either source (rx) or destination (tx) mirroring enabled are mirrored to this port. Disabled option disables mirroring.

Black Box LE2711C - Port Mirroring - 1

text_image Mirror Configuration Port to mirror to Disabled Port Mode 1 Disabled ✓ 2 Disabled ✓ 3 Disabled ✓ 4 Disabled ✓ 5 Disabled ✓ 6 Disabled ✓ 7 Disabled ✓ 8 Disabled ✓ 9 Disabled ✓ 10 Disabled ✓ 11 Disabled ✓

Figure 5-109. Mlrror Configuration screen.

Table 5-91. Mlrror Configuration screen options.
Label Description
Port The switch port number to which the following settings will be applied.
Mode Drop-down list for selecting a mirror mode.Rx only: only frames received on this port are mirrored to the mirror port. Frames transmitted are not mirrored.Tx only: only frames transmitted from this port are mirrored to the mirror port. Frames received are not mirrored.Disabled: neither transmitted nor received frames are mirrored.Enabled: both received and transmitted frames are mirrored to the mirror port.NOTE: For a given port, a frame is only transmitted once. Therefore, you cannot mirror Tx frames to the mirror port. In this case, mode for the selected mirror port is limited to Disabled or Rx only.

5.10.4 System Log Information

This page provides switch system log information.

Black Box LE2711C - System Log Information - 1

text_image System Log Information Auto-refresh □ Refresh Clear |<< << >> >>| Open in new window Level All The total number of entries is 1 for the given level. Start from ID 1 with 20 entries per page. ID Level Time Message Info 1970-01-01 00:01:09 +0000 Port. 1 Device( 192.168.10.66): Alive Check got reply again.

Figure 5-110. System Log Information screen.

Table 5-92. System Log Information screen options.
Label Description
ID The ID (>= 1) of the system log entry.
Level The level of the system log entry. The following level types are supported:Info: provides general informationWarning: provides warning for abnormal operationError: provides error messageAll: enables all levels
Time The time of the system log entry.
Message The MAC address of the switch.
Auto-refreshCheck this box to enable an automatic refresh of the page at regular intervals.
Refresh Updates system log entries, starting from the current entry ID.
Clear Flushes all system log entries.
|<< Updates system log entries, starting from the first available entry ID
<< Updates system log entries, ending at the last entry currently displayed
>> Updates system log entries, starting from the last entry currently displayed.
>>| Updates system log entries, ending at the last available entry ID.

5.10.5 Cable Diagnostics

This page allows you to perform VeriPHY cable diagnostics.

Black Box LE2711C - Cable Diagnostics - 1

text_image VeriPHY Cable Diagnostics Port All Start Cable Status Port Pair A Length A Pair B Length B Pair C Length C Pair D Length D 1 -- -- -- -- -- -- -- 2 -- -- -- -- -- -- -- 3 -- -- -- -- -- -- -- 4 -- -- -- -- -- -- -- 5 -- -- -- -- -- -- -- 6 -- -- -- -- -- -- -- 7 -- -- -- -- -- -- -- 8 -- -- -- -- -- -- --

Figure 5-111. VeriPHY Cable Diagnostics screen.
Press Start to run the diagnostics. This will take approximately 5 seconds. If all ports are selected, this can take approximately 15 seconds. When completed, the page refreshes automatically, and you can view the cable diagnostics results in the cable status table. Note that VeriPHY diagnostics is only accurate for cables 7–140 meters long.

10 and 100 Mbps ports will be disconnected while running VeriPHY diagnostics. Therefore, running VeriPHY on a 10 or 100 Mbps management port will cause the switch to stop responding until VeriPHY is complete.

Table 5-93. SVeriPHY Cable Diagnostics screen options.
Label Description
Port The port for which VeriPHY Cable Diagnostics is requested.
Cable Status Port: port numberPair: the status of the cable pairLength: the length (in meters) of the cable pair

5.10.6 SFP Monitor

SFP modules with DDM (Digital Diagnostic Monitoring) function can measure the temperature of the apparatus, helping you monitor the status of connection and detect errors immediately. You can manage and set up event alarms through DDM Web interface.

Black Box LE2711C - SFP Monitor - 1

text_image SFP Monitor Auto-refresh □ Refresh Port No. Temperature (°C) Vcc (V) TX Bias(mA) TX Power(μW) RX Power(μW) 1 N/A N/A N/A N/A N/A 2 N/A N/A N/A N/A N/A 3 N/A N/A N/A N/A N/A 4 N/A N/A N/A N/A N/A 5 N/A N/A N/A N/A N/A 6 N/A N/A N/A N/A N/A 7 N/A N/A N/A N/A N/A 8 N/A N/A N/A N/A N/A 9 N/A N/A N/A N/A N/A 10 N/A N/A N/A N/A N/A 11 N/A N/A N/A N/A N/A 12 N/A N/A N/A N/A Warning Temperature : 85 °C(0~100) Event Alarm : □ Syslog Save

Figure 5-112. SFP Monitor screen.

5.10.7 Ping

This page allows you to issue ICMP PING packets to troubleshoot IP connectivity issues.

Black Box LE2711C - Ping - 1

text_image ICMP Ping IP Address 0.0.0.0 Ping Size 64 Start

Figure 5-113. ICMP Ping screen.

After you press Start, five ICMP packets will be transmitted, and the sequence number and roundtrip time will be displayed upon reception of a reply. The page refreshes automatically until responses to all packets are received, or until a timeout occurs.

PING6 ser ver ::10.10.132.20

64 bytes from ::10.10.132.20: icmp_seq=0, time=0ms

64 bytes from ::10.10.132.20: icmp_seq=1, time=0ms

64 bytes from ::10.10.132.20: icmp_seq=2, time=0ms

64 bytes from ::10.10.132.20: icmp_seq=3, time=0ms

64 bytes from ::10.10.132.20: icmp_seq=4, time=0ms

Sent 5 packets, received 5 OK, 0 bad

You can configure the following properties of the issued ICMP packets:

Table 5-94. ICMP Ping screen options.
Label Description
IP Address The destinationIP Address
Ping Size The payload sizeof the ICMP packet. Values range from 8 to 1400 bytes.

IPv6 Ping

Black Box LE2711C - Ping - 2

text_image IPv6 Ping IPv6 Address Ping Size 64 Start

Figure 5-114. IPv6 Ping screen.

PING6 ser ver ::192.168.10.1

sendto

sendto

sendto

sendto

sendto

Sent 5 packets, received 0 OK, 0 bad

5.11 Synchronization

MAC-based Authentication

This page allows you to configure and examine current PTP clock settings.

PTP External Clock Mode

PTP External Clock Mode
Black Box LE2711C - Synchronization - 1

text_image One_PPS_Mode Disable External Enable False VCXO Enable False Clock Frequency 1

Figure 5-115. PTP External Clock Mode screen.

Table 5-95. PTP External Clock Mode screen options.
Label Description
One_pps_modeThe box allows you to select One_pps_mode configurations.The following values are possible:Output: enable the 1 pps clock outputInput: enable the 1 pps clock inputDisable: disable the 1 pps clock in/out-put
External EnableThe box allows you to configure external clock output.The following values are possible:True: enable external clock outputFalse: disable external clock output
VCXO_EnableThe box allows you to configure the external VCXO rate adjustment.The following values are possible:True: enable external VCXO rate adjustmentFalse: disable external VCXO rate adjustment
Clock Frequency The boxallows you to set clock frequency.The range of values is 1–25000000 (1–25 MHz).

PTP Clock Configurations

PTP Clock Configuration
Black Box LE2711C - PTP Clock Configurations - 1

text_image Port List Delete Clock Instance Device Type 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 No Clock Instances Present Add New PTP Clock Save Reset

Figure 5-116. PTP Clock Configuration screen.

Table 5-96. PTP Clock Configuration screen options.
Label Description
Delete Check this box and click Save to delete the clock instance.
Clock InstanceIndicates the instance of a particular clock instance [0..3]Click on the clock instance number to edit the clock details
Device TypeIndicates the type of the clock instance. There are five device types.Ord-Bound: ordinary/boundary clockP2p Transp: peer-to-peer transparent clockE2e Transp: end-to-end transparent clockMaster Only: master onlySlave Only: slave only
Port List Set check mark for each port configured for this Clock Instance.
2 Step Flag Static member defined by the system; true if two-step Sync events and Pdelay_Resp events are used.
Clock Identity Shows a unique clock identifier.
One WayIf true, one-way measurements are used. This parameter applies only to a slave. In one-way mode no delay measurements are performed, i.e. this is applicable only if frequency synchronization is needed. The master always responds to delay requests.
Protocol Transport protocol used by the PTP protocol engineEthernet PTP over Ethernet multicastip4multi PTP over IPv4 multicastip4uni PTP over IPv4 unicastNOTE: IPv4 unicast protocol only works in Master Only and Slave Only clocks.For more information, please refer to Device Type.In a unicast Slave Only clock, you also need to configure which master clocks to request Announce and Sync messages from.For more information, please refer to Unicast Slave Configuration.
VLAN Tag Enable Enables VLAN tagging for PTP frames.NOTE: Packets are only tagged if the port is configured for vlan tagging. i.e:Port Type != Unaware and PortVLAN mode == None, and the port is member of the VLAN.
VID VLAN identifiers used for tagging the PTP frames
PCPPriority code point values used for PTP frames
Table 5-97. Power Over Ethernet Status screen options.
Label Description
Local Port The switch portnumber to which the following settings will be applied.
PD ClassEach power device is classified according to the class that defines the maximum power consumed by the PD.This setting includes five classes:Class 0: Max. power 15.4 WClass 1: Max. power 4.0 WClass 2: Max. power 7.0 WClass 3: Max. power 15.4 WClass 4: Max. power 30.0 W
Power Requested Showsthe amount of power requested by the powered device.
Power Allocated Showsthe amount of power the switch has allocated for the powered device.
Power Used Shows howmuch power the powered device currently is using.
Current Used Shows howmuch current the PD currently is using.
Priority Shows the port's priority configured by the user.
Port StatusShows the port's status. The status can be one of the following values:PoE not available: no PoE chip foundPoE turned OFF: PoE is disabled by user.PoE turned OFF: power budget exceeded. The total requested or used power by the powered devices exceeds the maximum power the power supply can deliver, and port(s) with the lowest priority will be powered down.No PD detected: no powered devices detected on the port.PoE turned OFF: powered devices overload. The powered devices have requested or used more power than the port can deliver, and the port is powered down.PoE turned OFF: the powered device is turned off.Invalid PD: the power device is detected, but is not working correctly.

5.12 Troubleshooting

5.12.1 Factory Defaults

You can reset the configuration of the stack switch on this page. Only the IP configuration is retained.

Factory Defaults

Are you sure you want to reset the configuration to Factory Defaults?

Black Box LE2711C - Factory Defaults - 1

Figure 5-117. Factory default prompt screen.

Table 5-98. Factory default prompt screen options.
Label Description
Yes Click to reset the configuration to factory defaults.
No Click to return to the Port State page without resetting.

5.12.2 System Reboot

You can reset the stack switch on this page. After reset, the system will boot normally as if you have powered on the devices.

Warm Reset

Are you sure you want to perform a Warm Restart?

Black Box LE2711C - System Reboot - 1

Figure 5-118. Warm Reset screen.

Table 5-99. Factory default prompt screen options.
Label Description
Yes Click to reboot device.
No Click to return to thePort State page without rebooting.

5.13 Command Line Interface Management

Besides Web-based management, the switch also supports CLI management. You can use console or telnet to manage the switch by CLI.

CLI Management by RS-232 Serial Console (115200, 8, none, 1, none)

Before configuring RS-232 serial console, connect the RS-232 port of the switch to your PC Com port using a RJ45 to DB9-F cable.

Follow the steps below to access the console via RS-232 serial cable.

Step 1: On Windows desktop, click on Start -> Programs -> Accessories -> Communications -> HyperTerminal.

Black Box LE2711C - Command Line Interface Management - 1

text_image Windows 2000 Professional Start Windows Update Programs Documents Settings Search Help Run... Shut Down... Accessories Network Associates Startup Internet Explorer Outlook Express Accessibility Communications HyperTerminal Network Time Protocol System Tools Acrobat Reader 5.0 Address Book Calculator Command Prompt NetTime Notepad Paint Windows Explorer WordPad

Figure 5-119. HyperTerminal screen.

Step 2: Input a name for the new connection.

Black Box LE2711C - Command Line Interface Management - 2

text_image File Edit View Call Transfer Help Connection Description New Connection Enter a name and choose an icon for the connection: Name: Icon: OK Cancel Disconnected Auto detect Auto detect SCROLL CAPS NUM Capture Print echo

Figure 5-120. Connection Description screen.

Step 3: Select a COM port in the drop-down list.

Black Box LE2711C - Command Line Interface Management - 3

text_image Terminal - HyperTerminal File Edit View Call Transfer Help Connect To ? / terminal Enter details for the phone number that you want to dial Country/region: Taiwan (896) Area code: 2 Phone number: Connect using: COM1 OK Cancel Disconnected Auto detect Auto detect SCROLL CAPS NUM Capture Print echo

Figure 5-121. COM port screen.

Step 4: A pop-up window that indicates COM port properties appears, including bits per second, data bits, parity, stop bits, and flow control.

Black Box LE2711C - Command Line Interface Management - 4

text_image Terminal - Ubox Terminal COM1 Properties Port Settings Bits per second: 115200 Data bits: 8 Parity: None Stop bits: 1 Flow control: None Restore Defaults OK Cancel Apply Disconnected Auto detect Auto detect SCROLL CAPS NUM Capture Print echo

Figure 5-122. COM Properties screen.

Step 5: The console login screen will appear. Use the keyboard to enter the Username and Password (same as the password for Web browsers), then press Enter.

Black Box LE2711C - Command Line Interface Management - 5

text_image Command Line Interface Username : Password :

Figure 5-123. CLI screen.

CLI Management by Telnet

You can can use TELNETto configure the switch. The default values are:

IP Address: 192.168.10.1

Subnet Mask: 255.255.255.0

Default Gateway: 192.168.10.254

User Name: admin

Password: admin

Follow the steps below to access the console via Telnet.

Step 1: Telnet to the IP address of the switch from the Run window by inputting commands (or from the MS-DOS prompt) as below.

Black Box LE2711C - CLI Management by Telnet - 1

text_image Run Type the name of a program, folder, document, or Internet resource, and Windows will open it for you. Open: telnet 192.168.10.1 OK Cancel Browse...

Figure 5-124. Run screen.

Step 2: The Login screen will appear. Use the keyboard to enter the Username and Password (same as the password for Web browser), and then press Enter.

Black Box LE2711C - CLI Management by Telnet - 2

text_image Command Line Interface Username : Password :

Figure 5-125. Telnet screen.

Commander Groups

Command Groups:
System : System settings and reset options
IP : IP configuration and Ping
Port : Port management
MAC : MAC address table
ULAN : Virtual LAN
PULAN : Private VLAN
Security : Security management
STP : Spanning Tree Protocol
Aggr : Link Aggregation
LACP : Link Aggregation Control Protocol
LLDP : Link Layer Discovery Protocol
PoE : Power Over Ethernet
QoS : Quality of Service
Mirror : Port mirroring
Config : Load/Save of configuration via TFTP
Firmware : Download of firmware via TFTP
PTP : IEEE1588 Precision Time Protocol
Loop Protect : Loop Protection
IPMC : MLD/IGMP Snooping
Fault : Fault Alarm Configuration
Event : Event Selection
DHCPServer : DHCP Server Configuration
Ring : Ring Configuration
Chain : Chain Configuration
RCS : Remote Control Security
Fastrecovery : Fast-Recovery Configuration
SFP : SFP Monitor Configuration
DeviceBinding : Device Binding Configuration
MRP : MRP Configuration
Modbus : Modebus TCP Configuration 

Figure 5-126. Command Groups screen.

System
System>
Configuration [all] [<port_list>]
Reboot
Restore Default [keep_ip]
Contact [<contact>]
Name [<name>]
Location [<location>]
Description [<description>]
Password <password>
Username [<username>]
Timezone [<offset>]
Log [<log_id>] [all|info|warning|error] [clear] 

IP

IP> Configuration
DHCP [enable|disable]
Setup [<ip_addr>] [<ip_mask>] [<ip_router>] [<vid>]
Ping <ip_addr_string> [<ping_length>]
SNTP [<ip_addr_string>] 

Port

port> Configuration [<port_list>] [up|down]
Mode [<port_list>] [auto|10hdx|10fdx|100hdx|100fdx|1000fdx|sfp_auto_ams]
Flow Control [<port_list>] [enable|disable]
State [<port_list>] [enable|disable]
MaxFrame [<port_list>] [<max_frame>]
Power [<port_list>] [enable|disable|actiphy|dynamic]
Excessive [<port_list>] [discard|restart]
Statistics [<port_list>] [<command>] [up|down]
VeriPHY [<port_list>]
SFP [<port_list>] 

MAC

MAC> Configuration [<port_list>]
Add <mac_addr> <port_list> [<vid>]
Delete <mac_addr> [<vid>]
Lookup <mac_addr> [<vid>]
Agetime [<age_time>]
Learning [<port_list>] [auto|disable|secure]
Dump [<mac_max>] [<mac_addr>] [<vid>]
Statistics [<port_list>]
Flush 

VLAN

VLAN> Configuration [<port_list>]
PVID [<port_list>] [<vid>|none]
FrameType [<port_list>] [all|tagged|untagged]
IngressFilter [<port_list>] [enable|disable]
tx_tag [<port_list>] [untag_pvid|untag_all|tag_all]
PortType [<port_list>] [unaware|c-port|s-port|s-custom-port]
EtypeCustomSport [<etype>] 
Add <vid>|<name> [<ports_list>]
Forbidden Add <vid>|<name> [<port_list>]
Delete <vid>|<name>
Forbidden Delete <vid>|<name>
Forbidden Lookup [<vid>] [(name <name>)]
Lookup [<vid>] [(name <name>)] [combined|static|nas|all]
Name Add <name> <vid>
Name Delete <name>
Name Lookup [<name>]
Status [<port_list>] [combined|static|nas|mstp|all|conflicts] 

Private VLAN

PVLAN> Configuration [<port_list>]
Add <pvlan_id> [<port_list>]
Delete <pvlan_id>
Lookup [<pvlan_id>]
Isolate [<port_list>] [enable|disable] 

Security

Security > Switch    Switch security setting
Network    Network security setting
AAA    Authentication, Authorization and Accounting setting 

Security Switch

Security/switch> Password <password>
Auth Authentication
SSH Secure Shell
HTTPS Hypertext Transfer Protocol over RMON Remote Network Monitoring 

Security Switch Authentication

Security/switch/auth> Configuration
Method [console|telnet|ssh|web] [none|local|radius] [enable|disable] 

Security Switch SSH

Security/switch/ssh> Configuration
Mode [enable|disable] 

Security Switch HTTPS

Security/switch/ssh> Configuration
Mode [enable|disable] 

Security Switch RMON

Security/switch/rmon> Statistics Add <stats_id> <data_source>

Statistics Delete <stats_id>

Statistics Lookup [<stats_id>]

History Add <history_id> <data_source> [<interval>] [<buckets>]

History Delete <history_id>

History Lookup [<history_id>]

Alarm Add <alarm_id> <interval> <alarm_variable> [absolute|delta]<rising_threshold> <rising_event_index> <falling_threshold> <falling_event_index> [rising|falling|both]

Alarm Delete <alarm_id>

Alarm Lookup [<alarm_id>] 

Security Network

Security/Network> Psec Port Security Status
NAS Network Access Server (IEEE 802.1X)
ACL Access Control List
DHCP Dynamic Host Configuration Protocol 

Security Network Psec

Security/Network/Psec> Switch [<port_list>]
Port [<port_list>] 

Security Network NAS

Security/Network/NAS> Configuration [<port_list>]
Mode [enable|disable]
State [<port_list>] [auto|authorized|unauthorized|macbased]
Reauthentication [enable|disable]
ReauthPeriod [<reauth_period>]
EapolTimeout [<eapol_timeout>]
Agetime [<age_time>]
Holdtime [<hold_time>] 

Authenticate [] [now]

Statistics

[]

[clear|eapol|radius]

Security Network ACL

Security/Network/ACL> Configuration [<port_list>]

Action [<port_list>] [permit|deny] [<rate_limiter>][<port_redirect>] [<mirror>] [<logging>] [<shutdown>]

Policy [<port_list>] [<policy>]

Rate [<rate_limiter_list>] [<rate_unit>] [<rate>]

Add [<ace_id>] [<ace_id_next>][(port <port_list>)] [(policy <policy> <policy_bitmask>)] [<tagged>]
[<vid>] [<tag_prio>] [<dmac_type>][(etype <etype>] [<smac>] [<dmac>]) | (arp [<sip>] [<dip>] [<smac>] [<arp_opcode>] [<arp_flags>]) | (ip [<sip>] [<dip>] [<protocol>] [<ip_flags>]) | (icmp [<sip>] [<dip>] [<icmp_type>] [<icmp_code>] [<ip_flags>]) | (udp [<sip>] [<dip>] [<sport>] [<dport>] [<ip_flags>]) | (tcp [<sip>] [<dip>] [<sport>] [<dport>] [<ip_flags>] [<tcp_flags>]) | [permit|deny] [<rate_limiter>] [<port_redirect>] [<mirror>] [<logging>]
[<shutdown>]

Delete <ace_id>

Lookup [<ace_id>]

Clear

Status [combined|static|loop_protect|dhcp|ptp|ipmc|conflicts]

Port State [<port_list>] [enable|disable] 

Security Network DHCP

Security/Network/DHCP> Configuration
Mode [enable|disable]
Server [<ip_addr>]
Information Mode [enable|disable]
Information Policy [replace|keep|drop]
Statistics [clear] 

Security Network AAA

Security/Network/AAA> Configuration
Timeout [<timeout>]
Deadtime [<dead_time>]
    RADIUS [<server_index>] [enable|disable] [<ip_addr_string>] [<secret>] [<server_port>]
    ACCT_RADIUS [<server_index>] [enable|disable] [<ip_addr_string>] [<secret>] [<server_port>]
Statistics [<server_index>] 

STP

STP> Configuration
Version [<stp_version>]
Non-certified release, v
Txhold [<holdcount>]lt 15:15:15, Dec 6 2007
MaxAge [<max_age>]
FwdDelay [<delay>]
bpduFilter [enable|disable]
bpduGuard [enable|disable]
recovery [<timeout>]
CName [<config-name>] [<integer>]
Status [<msti>] [<port_list>]
Msti Priority [<msti>] [<priority>]
Msti Map [<msti>] [clear]
Msti Add <msti> <vid>
Port Configuration [<port_list>]
Port Mode [<port_list>] [enable|disable]
Port Edge [<port_list>] [enable|disable]
Port AutoEdge [<port_list>] [enable|disable]
Port P2P [<port_list>] [enable|disable|auto]
Port RestrictedRole [<port_list>] [enable|disable]
Port RestrictedTcn [<port_list>] [enable|disable]
Port bpduGuard [<port_list>] [enable|disable]
Port Statistics [<port_list>]
Port Mcheck [<port_list>]
Msti Port Configuration [<msti>] [<port_list>]
Msti Port Cost [<msti>] [<port_list>] [<path_cost>]
Msti Port Priority [<msti>] [<port_list>] [<priority>] 

Aggr

Aggr> Configuration
Add <port_list> [<aggr_id>]
Delete <aggr_id>
Lookup [<aggr_id>]
Mode [smac|dmac|ip|port] [enable|disable] 

LACP

LACP> Configuration [<port_list>]
Mode [<port_list>] [enable|disable]
Key [<port_list>] [<key>]
Role [<port_list>] [active|passive]
Status [<port_list>]
Statistics [<port_list>] [clear] 

LLDP

LLDP> Configuration [<port_list>]
Mode [<port_list>] [enable|disable]
Statistics [<port_list>] [clear]
Info [<port_list>] 

PoE

PoE> Configuration [<port_list>]

Mode [<port_list>] [disabled|poe|poe+]

Priority [<port_list>] [low|high|critical]

Mgmt_mode [class_con|class_res|al_con|al_res|lldp_res|lldp_con]

Maximum_Power [<port_list>] [<port_power>]

Status

Primary_Supply [<supply_power>] 

QoS

QoS> DSCP Map [<dscp_list>] [<class>] [<dpl>]

DSCP Translation [<dscp_list>] [<trans_dscp>]

DSCP Trust [<dscp_list>] [enable|disable]

DSCP Classification Mode [<dscp_list>] [enable|disable]

DSCP Classification Map [<class_list>] [<dpl_list>] [<dscp>]

DSCP EgressRemap [<dscp_list>] [<dpl_list>] [<dscp>]

Storm Unicast [enable|disable] [<packet_rate>]

Storm Multicast [enable|disable] [<packet_rate>]

Storm Broadcast [enable|disable] [<packet_rate>]

QCL Add [<qce_id>] [<qce_id_next>]

    [<port_list>]

    [<tag>] [<vid>] [<pcp>] [<dei>] [<smac>]

    [<dmac_type>]

    [(etype    [<etype>]) | (LLC [<DSAP>] [<SSAP>] [<control>]) | (SNAP    [<PID>]) | (ipv4 [<protocol>] [<sip>] [<dscp>] [<fragment>] [<sport>] [<dport>]) | (ipv6 [<protocol>] [<sip_v6>] [<dscp>] [<sport>]
    [<dport>])]

    [<class>]    [<dp>]    [<classified_dscp>]

QCL Delete <qce_id>

QCL Lookup [<qce_id>]

QCL Status [combined|static|conflicts]

QCL Refresh

Mirror

Mirror> Configuration [<port_list>]

Port [<port>|disable]

Mode [<port_list>] [enable|disable|rx|tx] 

Dot1x

Dot1x> Configuration [<port_list>]

Mode [enable|disable]

State [<port_list>] [macbased|auto|authorized|unauthorized]

Authenticate [<port_list>] [now]

Reauthentication [enable|disable]

Period [<reauth_period>]

Timeout [<eapol_timeout>]

Statistics [<port_list>] [clear|eapol|radius]

Clients [<port_list>] [all|<client_cnt>]

Agetime [<age_time>]

Holdtime [<hold_time>] 

IGMP

IGMP> Configuration [<port_list>]
Mode [enable|disable]
State [<vid>] [enable|disable]
Querier [<vid>] [enable|disable]
Fastleave [<port_list>] [enable|disable]
Router [<port_list>] [enable|disable]
Flooding [enable|disable]
Groups [<vid>]
Status [<vid>] 

ACL

ACL> Configuration [<port_list>]

Action [<port_list>] [permit[deny] [<rate_limiter>] [<port_copy>]

    [<logging>]    [<shutdown>]

Policy [<port_list>] [<policy>]

Rate [<rate_limiter_list>] [<packet_rate>]

Add [<ace_id>] [<ace_id_next>] [switch | (port <port>) | (policy <policy>)]
    [<vid>] [<tag_prio>] [<dmac_type>]

    [(etype [<etype>] [<smac>] [<dmac>]) | (arp [<sip>] [<dip>] [<smac>] [<arp_opcode>] [<arp_flags>]) | (ip [<sip>] [<dip>] [<protocol>] [<ip_flags>]) | (icmp [<sip>] [<dip>] [<icmp_type>] [<icmp_code>] [<ip_flags>]) | (udp [<sip>] [<dip>] [<sport>] [<dport>] [<ip_flags>]) | (tcp [<sip>] [<dip>] [<sport>] [<dport>] [<ip_flags>] [<tcp_flags>]) | [permit[deny] [<rate_limiter>] [<port_copy>] [<logging>] [<shutdown>]

Delete <ace_id>

Lookup [<ace_id>]

Clear 

Mirror

Mirror> Configuration [<port_list>]
Port [<port>|disable]
Mode [<port_list>] [enable|disable|rx|tx] 

Config

Config> Save <ip_server> <file_name>
Load <ip_server> <file_name> [check] 

Firmware

Firmware> Load <ip_addr_string> <file_name>

SNMP

SNMP> Trap Inform Retry Times [<retries>]

Trap Probe Security Engine ID [enable|disable]

Trap Security Engine ID [<engineid>]

Trap Security Name [<security_name>]

Engine ID [<engineid>]

Community Add <community> [<ip_addr>] [<ip_mask>]

Community Delete <index>

Community Lookup [<index>]

User Add <engineid> <user_name> [MD5|SHA] [<auth_password>] [DES] [<priv_password>]

User Delete <index>

User Changekey <engineid> <user_name> <auth_password> [<priv_password>]

User Lookup [<index>]

Group Add <security_model> <security_name> <group_name>

Group Delete <index>

Group Lookup [<index>]

View Add <view_name> [included|excluded] <oid_subtree>

View Delete <index>

View Lookup [<index>]

Access Add <group_name> <security_model> <security_level> [<read_view_name>] [<write_view_name>]

Access Delete <index>

Access Lookup [<index>] 

Firmware

Firmware> Load <ip_addr_string> <file_name>

PTP

PTP> Configuration [<clockinst]

PortState <clockinst> [<port_list>] [enable|disable|internal]
ClockCreate <clockinst> [<devtype>] [<twostep>] [<protocol>] [<oneway>] [<clockid>] [<tag_enable>] [<vid>] [<prio>]
ClockDelete <clockinst> [<devtype>]
DefaultDS <clockinst> [<priority1>] [<priority2>] [<domain>]
CurrentDS <clockinst>
ParentDS <clockinst>
Timingproperties <clockinst> [<utcoffset>] [<valid>] [<leap59>] [<leap61>] [<teaptrac>] [<freqtrac>] [<ptptimescale>]
[<timesource>]
PTP PortDataSet <clockinst> [<port_list>] [<announceintv>] [<announceto>] [<syncintv>] [<delaymech>] [<minpd layreqintv>] [<delayasymmetry>] [<ingressLatency>]
LocalClock <clockinst> [update|show|ratio] [<clockratio>]
Filter <clockinst> [<def_delay_filt>] [<period>] [<dist>]
Servo <clockinst> [<displaystates>] [<ap_enable>] [<ai_enable>] [<ad_enable>] [<ap>] [<ai>] [<ad>]
SlaveTableUnicast <clockinst>
UniConfig <clockinst> [<index>] [<duration>] [<ip_addr>]
ForeignMasters <clockinst> [<port_list>]
EgressLatency [show|clear]
MasterTableUnicast <clockinst>
ExtClockMode [<one_pps_mode>] [<ext_enable>] [<clockfreq>] [<vcxo_enable>]
OnePpsAction [<one_pps_clear>]
DebugMode <clockinst> [<debug_mode>]
Wireless mode <clockinst> [<port_list>] [enable|disable]
Wireless pre notification <clockinst> <port_list>
Wireless delay <clockinst> [<port_list>] [<base_delay>] [<incr_delay>] 

Loop Protect

Loop Protect> Configuration
Mode [enable|disable]
Transmit [<transmit-time>]
Shutdown [<shutdown-time>]
Port Configuration [<port_list>]
Port Mode [<port_list>] [enable|disable]
Port Action [<port_list>] [shutdown|\shut_log|log]
Port Transmit [<port_list>] [enable|disable]
Status [<port_list>] 

IPMC

IPMC> Configuration [igmp]
Mode [igmp] [enable|disable]
Flooding [igmp] [enable|disable]
VLAN Add [igmp] <vid>
VLAN Delete [igmp] <vid>
State [igmp] [<vid>] [enable|disable]
Querier [igmp] [<vid>] [enable|disable]
Fastleave [igmp] [<port_list>] [enable|disable]
Router [igmp] [<port_list>] [enable|disable]
Status [igmp] [<vid>]
Groups [igmp] [<vid>]
Version [igmp] [<vid>] 

Fault

Fault> Alarm PortLinkDown [<port_list>] [enable|disable]
Alarm PowerFailure [pwr1|pwr2|pwr3] [enable|disable] 

Event

Event> Configuration
Syslog SystemStart [enable|disable]
Syslog PowerStatus [enable|disable]
Syslog SnmpAuthenticationFailure [enable|disable]
Syslog RingTopologyChange [enable|disable]
Syslog Port [<port_list>] [disable|linkup|linkdown|both]
SMTP SystemStart [enable|disable]
SMTP PowerStatus [enable|disable]
SMTP SnmpAuthenticationFailure [enable|disable]
SMTP RingTopologyChange [enable|disable]
SMTP Port [<port_list>] [disable|linkup|linkdown|both] 

DHCPServer

DHCPServer> Mode [enable|disable]
Setup [<ip_start>] [<ip_end>] [<ip_mask>] [<ip_router>] [<ip_dns>] [<ip_tftp>] [<lease>] [<bootfile>] 

Ring

Ring> Mode [enable|disable]
Master [enable|disable]
1stRingPort [<port>]
2ndRingPort [<port>]
Couple Mode [enable|disable]
Couple Port [<port>]
Dualhoming Mode [enable|disable]
Dualhoming Port [<port>] 

Chain

Chain> Configuration
Mode [enable|disable]
1stUplinkPort [<port>]
2ndUplinkPort [<port>]
EdgePort [1st|2nd|none] 

RCS

RCS> Mode [enable|disable]
Add [<ip_addr>] [<port_list>] [web_on|web_off] [telnet_on|telnet_off] [snmp_on|snmp_off]
Del <index>
Configuration 

FastRecovery

FastRecovery> Mode [enable|disable]
Port [<port_list>] [<fr_priority>] 

SFP

SFP> syslog [enable|disable]
temp [<temperature>]
Info 

DeviceBinding

Devicebinding> Mode [enable|disable]
Port Mode [<port_list>] [disable|scan|binding|shutdown]
Port DDOS Mode [<port_list>] [enable|disable]
Port DDOS Sensibility [<port_list>] [low|normal|medium|high]
Port DDOS Packet [<port_list>] [rx_total|rx_unicast|rx_multicast|rx_broadcast|tcp|udp]
Port DDOS Low [<port_list>] [<socket_number>]
Port DDOS High [<port_list>] [<socket_number>] 
Port DDOS Filter [<port_list>] [source|destination]
    Port DDOS Action [<port_list>] [do_nothing|block_1_min|block_10_mins|block|shutdown|only_log|reboot_device]
Port DDOS Status [<port_list>]
Port Alive Mode [<port_list>] [enable|disable]
    Port Alive Action [<port_list>] [do_nothing|link_change|shutdown|only_log|reboot_device]
Port Alive Status [<port_list>]
Port Stream Mode [<port_list>] [enable|disable]
Port Stream Action [<port_list>] [do_nothing|only_log]
Port Stream Status [<port_list>]
Port Addr [<port_list>] [<ip_addr>] [<mac_addr>]
Port Alias [<port_list>] [<ip_addr>]
Port DeviceType [<port_list>] [unknown|ip_cam|ip_phone|ap|pc|plc|nvr]
Port Location [<port_list>] [<device_location>]
Port Description [<port_list>] [<device_description>] 

MRP

MRP> Configuration
Mode [enable|disable]
Manager [enable|disable]
React [enable|disable]
1stRingPort [<mrp_port>]
2ndRingPort [<mrp_port>]
Parameter MRP_TOPchgT [<value>]
Parameter MRP_TOPNRmax [<value>]
Parameter MRP_TSTshortT [<value>]
Parameter MRP_TSTdefaultT [<value>]
Parameter MRP_TSTNRmax [<value>]
Parameter MRP_LNKdownT [<value>]
Parameter MRP_LNKupT [<value>]
Parameter MRP_LNKNRmax [<value>] 

Modbus

Modbus> Status
Mode [enable|disable] 

Black Box Tech Support: FREE! Live. 24/7.

Tech support the way it should be.

Black Box LE2711C - Black Box Tech Support: FREE! Live. 24/7. - 1

natural_image Close-up portrait of a smiling man with short hair holding a small object, against a blue gradient background (no text or symbols visible)

Great tech support is just 60 seconds away at 724-746-5500 or blackbox.com.

Black Box LE2711C - Black Box Tech Support: FREE! Live. 24/7. - 2

BLACK BOX®

About Black Box

Black Box provides an extensive range of networking and infrastructure products. You'll find everything from cabinets and racks and power and surge protection products to media converters and Ethernet switches all supported by free, live 24/7 Tech support available in 60 seconds or less.

© Copyright 2016. Black Box Corporation. All rights reserved. Black Box ^® and the Double Diamond logo are registered trademarks of BB Technologies, Inc. Any third-party trademarks appearing in this manual are acknowledged to be the property of their respective owners.

LE2700A user manual, version 5

Table of contents Click a title to access it
Manual assistant
Powered by Anthropic
Waiting for your message
Product information

Brand : Black Box

Model : LE2711C

Category : Switch