AIRLIVE

L3POE-XGS4804-400 - Network switch AIRLIVE - Free user manual and instructions

Find the device manual for free L3POE-XGS4804-400 AIRLIVE in PDF.

📄 190 pages English EN Download 💬 AI Question
Notice AIRLIVE L3POE-XGS4804-400 - page 10
Pick your language and provide your email: we'll send you a specifically translated version.

User questions about L3POE-XGS4804-400 AIRLIVE

0 question about this device. Answer the ones you know or ask your own.

Ask a new question about this device

The email remains private: it is only used to notify you if someone responds to your question.

No questions yet. Be the first to ask one.

Download the instructions for your Network switch in PDF format for free! Find your manual L3POE-XGS4804-400 - AIRLIVE and take your electronic device back in hand. On this page are published all the documents necessary for the use of your device. L3POE-XGS4804-400 by AIRLIVE.

USER MANUAL L3POE-XGS4804-400 AIRLIVE

24-Gigabit PoE Port + 4-10G SFP+ Port

L3-XGS2404

24-Gigabit Port + 4-10G SFP+ Port

L3POE-XGS4804

48-Gigabit PoE Port + 4-10G SFP+ Port

L3-XGS4804

48-Gigabit Port + 4-10G SFP+ Port

L3-XGF28

24-Gigabit Port SFP + 8-Gigabit Port RJ-45 (Combo) + 4-10G SFP+ Port

L3-10XGF12

12-10Gigabit Port SFP +

Web Manual

AIRLIVE L3POE-XGS4804-400 - Web Manual - 1

natural_image Abstract blue line drawing resembling a stylized letter 'a' with a dot above, no text or symbols present.

airlive®

Ver. 1.2

Revision history

DateVersionDescription
Jul. 08, 2021V 1.0The first edition
Dec. 20, 2021V 1.1Revision
May 10, 2022V 1.2Revision

Contents

L3POE-XGS2404....1

24-Gigabit PoE Port + 4-10G SFP+ Port 1

L3-XGS2404 1

24-Gigabit Port + 4-10G SFP+ Port 1

L3POE-XGS4804....1

48-Gigabit PoE Port + 4-10G SFP+ Port 1

L3-XGS4804 1

48-Gigabit Port + 4-10G SFP+ Port 1

L3-XGF28 1

24-Gigabit Port SFP + 8-Gigabit Port RJ-45 (Combo) + 4-10G SFP+ Port.....1

L3-10XGF12....1

12-10Gigabit Port SFP + 1

Web Manual 1

Ver. 1.2....1

Contents 3

1 Foreword....10

1.1 Target Audience....10

1.2 Manual Convention....10

2 Web Page Login....11

2.1 Log in the Network Management Client....11

2.2 Constitution of Client Interface 12

2.3 Navigation Bar on Web Interface....12

3 Status....18

3.1 System Information....18

3.2 Statistics....19

3.3 MAC Address Table....20

3.4 Reboot....21

3.5 Management IP Address....21

4 Network....22

4.1 DNS 22

4.2 System Time 23

5 Port....25

5.1 Port Setting 25

5.2 Error Disabled....26

5.3 Link Aggregation....27

5.3.1 Group....28

5.3.2 Port Setting 30

5.3.3 LACP 30

5.4 EEE 33

5.5 Jumbo Frame....34

5.6 Port Security ...... 34

5.7 Protected Port 35

5.8 Storm Control....36

5.9 Mirroring....38

6 POE Setting....40

6.1 PoE Port Setting 40

6.2 POE Port Timer Setting 41

6.3 POE Port Timer Reboot Setting....41

7 VLAN 43

7.1 VLAN....44

7.1.1 Create VLAN 44

7.1.2 VLAN Configuration....45

7.1.3 Membership....46

7.1.4 Port Setting....47

7.2 Voice VLAN 49

7.3 Protocol VLAN 54

7.4 MAC VLAN 58

7.5 Surveillance VLAN....61

7.6 GVRP 63

7.6.1 Property....64

7.6.2 Membership....65

7.6.3 Statistics 66

8 MAC Address Table....66

8.1 Dynamic Address....67
8.2 Static Address....68
8.3 Filtering Address 69
8.4 Port Security Address....70

9 Spanning Tree....71

9.1 Property 71
9.2 Port Setting....73
9.3 MST Instance....74
9.4 MST Port Setting....76
9.5 Statistics 80

10 Discovery....80

10.1 LLDP 81
10.2 Port Setting....82
10.3 MED Network Policy....84
10.4 MED Port Setting 85
10.5 Packet View 87
10.6 Local Information....87
10.7 Neighbor....88
10.8 Statistics....88

11 DHCP 89

11.1 Property....92
11.2 IP Pool Setting....93
11.3 VLAN IF Address Group Setting 94
11.4 Client List....94
11.5 Client Static Binding Table....95

12 Multicast....95

12.1 General....95
12.1.1 Property....95
12.1.2 Group Address 96
12.1.3 Router Port 97
12.1.4 Forward All....98

12.1.5 Throttling....98

12.1.6 Filtering Profile 99

12.2 IGMP Snooping....100

12.2.1 Property....100

12.2.2 Querier....102

12.2.3 Statistics....102

12.3 MLD Snooping .... 103

12.3.1 Property....104

12.3.2 Statistics....106

12.4 MVR....106

12.4.1 Property....107

12.4.2 Port Setting....108

12.4.3 Group Address....109

13 Routing....110

13.1 IPv4 Management and Interfaces....110

13.1.1 IPv4 Interface 110

13.1.2 IPv4 Routes....111

13.1.3 ARP....112

13.2 IPv6 Management and Interfaces ....113

13.2.1 IPv6 Interface 113

13.2.2 IPv6 Address....115

13.2.3 IPv6 Routes....115

13.2.4 Neighbors....116

13.3 Rip Routes Management ....117

13.4 Ospf Routes Management ....119

14 Security....121

14.1 RADIUS....121

14.2 TACACS+....122

14.3 AAA....124

14.3.1 Method List....124

14.3.2 Login Authentication....125

14.4 Management Access....125

14.4.1 Management Service....125

14.4.2 Management ACL....127

14.5 Authentication Manager....130

14.5.1 Property....130

14.5.2 Port Setting....132

14.5.3 MAC-Based Local Account 133

14.5.4 WEB-Based Local Account....133

14.5.5 Sessions....134

14.6 DoS....134

14.6.1 Property....134

14.6.2 Port Setting....135

14.7 Dynamic ARP Inspection....136

14.7.1 Property....136

14.7.2 Statistics....137

14.8 DHCP Snooping....137

14.8.1 Property 138

14.8.2 Statistics....140

14.8.3 Option82 Property 140

14.9 IP Source Guard....146

14.9.1 Port Setting....146

14.9.2 IMPV Binding 147

15 ACL....149

15.1 MAC ACL....150

15.2 IPv4 ACL....152

15.3 IPv6 ACL....154

15.4 ACL Binding....157

16 QoS 158

16.1 General....160

16.1.1 Property....160

16.1.2 Queue Scheduling....161

16.1.3 CoS Mapping....162

17.4 Copper Test....171

17.5 Fiber Module....171

17.6 UDLD 171

17.6.1 Property....172

17.6.2 Neighbor....173

18 Management....174

18.1 User Account....174

18.2 Firmware....174

18.3 Configuration....175

18.3.1 Upgrade....175

18.3.2 Save Configuration....176

18.4 SNMP....177

18.4.1 View....178

18.4.2 Group....179

18.4.3 Community....180

18.4.4 User....181

18.4.5 Engine ID 182

18.4.6 Trap Event....183

18.4.7 Notification....183

18.5 RMON 184

18.5.1 Statistics....185

18.5.2 History....186

18.5.3 Event....187

18.5.4 Alarm....189

1 Foreword

1.1 Target Audience

This manual is prepared for the installers and system administrators who are responsible for network installation, configuration and maintenance. It assumes that the user has understood all network communication and management protocols, as well as the technical terms, theoretical principles, practical skills, and expertise of devices, protocols and interfaces related to networking. Work experience in Graphical User Interface (GUI), Command-line Interface, Simple Network Management Protocol (SNMP) and Web Explorer is also required.

**This manual has been made with the images and layout of the L3POE-XGS2404 Switch. Note that the models L3-XGS2404, L3-XGS4804, L3-XGF28 and L3-10XGF12 do not have PoE. For these models chapter 6 and all other PoE functions are irrelevant.**

**Note model L3POE-XGS4804 Supports 802.3bt Max 90W PoE++ on ports 1\~8.**

1.2 Manual Convention

The following approaches should prevail.

GUI ConventionDescription
InterpretationDescribe operations and add necessary information.
AIRLIVE L3POE-XGS4804-400 - Manual Convention - 1CautionRemind the user of cautions as improper operations will result in data loss or equipment damage.

2 Web Page Login

2.1 Log in the Network Management Client

Type in the default switch address: http://192.168.2.1 and press "Enter".

Description:
Browser standards: superior to IE 9.0, Chrome 23.0 and Firefox 20.0

Keep the IP network segment of PC consistent with that of switch but differentiate the IP address as you log in. Set PC's IP address of 192.168.2.x and the subnet mask of 255.255.255.0 for the first login (1 < x ≤ 254).

A login window appears as follows. Type in the default username of "admin" and the password of "admin". Click the "Log in" to see the switch system.

AIRLIVE L3POE-XGS4804-400 - Log in the Network Management Client - 1

text_image Login Username: Password: LOGIN

2.2 Constitution of Client Interface

The typical operation interface of Web network management system is as follows.

AIRLIVE L3POE-XGS4804-400 - Constitution of Client Interface - 1

text_image Airlive® Save | Logout | reboot | Debug Status >> System Information Port status area System menu area Status System Information Logging Message Port Link Aggregation MAC Address Table Network Port POE Stating VLAN MAC Address Table Spanning Tree Discovery DHCP Multicast Routing Security ACL QoS Diagnostics Management System Information Edit Model L3POE-XG52404 System Name L3POE-XG52404 System Location default System Contact Alive Serial Number 0123456789 MAC Address 00.4F 4C 00.05 A0 IPv4 Address 192.168.2.1 IPv6 Address t=90 : t=2a a=3f t=00.342484 System OID 1.2-8.5-6.4-372023-6-3 System Uptime 0 day, 0 hr, 6 min and 16 sec Information show area

2.3 Navigation Bar on Web Interface

Menu items such as State, Network, Port, PoE Setting, VLAN, MAC Address Table, Spanning Tree, Discovery, DHCP, Multicast, Routing, Security, ACL, QoS, Diagnostics and Management are available on the web network management client. Each item contains submenus. Navigation bar is detailed as follows:

Menu ItemsSubmenusSecondary SubmenusDescription
StatusSystem InformationDisplay the port state and product info
Logging MessageDisplay the device running and operation logs
PortStatisticsDisplay the detailed port statistics
Error DisabledDisplay the faults occurring to ports
Bandwidth UtilizationDisplay the bandwidth utilization per unit time of all ports
Link AggregationDisplay the aggregation group state and members
MAC Address TableDisplay the MAC address table of the current device
NetworkIP AddressConfigure and view the management IP address
DNSConfigure and view the DNS and server setting
HostsConfigure and view the DNS Server and dynamic host mapping table
System TimeConfigure and view the current system time
PortPort SettingConfigure and view all ports
Error DisabledConfigure and view the port error disable protection
Link AggregationGroupConfigure and view the port & strategy balancing algorithms contained in LAG
Port SettingConfigure and view the LAG
LACPCheck LACP system priority and port configuration
EEEConfigure and view the EEE state and information
Jumbo FrameConfigure and view the length of the max message forwarded by system
Port SecurityConfigure and view the rate limiting of port security, as well as port state
Protected PortConfigure and view the port isolation
Storm ControlConfigure and view the port storm policing
MirroringConfigure and view the port mirroring
POE SettingPoE Port SettingConfigure and view the PoE port
PoE Port Timer SettingConfigure and view the timing switch of PoE port
PoE Port Timer Reboot SettingConfigure and view Poe port scheduled restart
VLANVLANCreate VLANConfigure and view the VLAN info of the device
VLAN ConfigurationConfigure and view the VLAN configuration of all ports
MembershipConfigure and view the port info of VLANs
Port SettingConfigure and view the PVID and VLAN attributes of ports
Voice VLANPropertyConfigure and view Voice-VLAN function and port status information
Voice OUIConfigure and view Voice-VLAN OUI information
Protocol VLANProtocol GroupConfigure and view the protocol VLAN group
Group BindingConfigure and view the protocol VLAN port and group binding.
MAC VLAMAC GroupConfigure and view the MAC VLAN group
Group BindingConfigure and view the MAC VLAN
port and group binding
Surveillance VLANPropertyConfigure and view Surveillance-VLAN function and port status information
Surveillance OUIConfigure and view Surveillance-VLAN OUI information
GVRPPropertyConfigure and view the functional global and port state
MembershipConfigure and view the VLANs learned and the port members
StatisticsConfigure and view the message statistics related to ports
MAC Address TableDynamic AddressConfigure and view the dynamic MAC addresses and aging time of the device
Static AddressConfigure and view the static MAC address tables of the device
Filtering AddressConfigure and view the MAC address tables to be filtered
Port Security AddressConfigure and view the MAC address table learned by port security
Spanning TreePropertyConfigure and view the STP state and attributes
Port SettingConfigure and view the port attributions of STP
MST InstanceConfigure and view the instance attributes of STPs
MST Port SettingConfigure and view the instances (incl. port info) of STPs
StatisticsConfigure and view the STP message statistics of each port
DiscoveryLLDPPropertyConfigure and view the attributes related to LLDP
Port SettingConfigure and view the transmitting & receiving state of LLDP at each port
MED Network PolicyConfigure and view the MED network strategy table entry
MED Port SettingConfigure and view the MED state at each port
Packet ViewConfigure and view the detailed LLDP messages at each port
Local InformationConfigure and view the LLDP and LLDP-MED state
NeighborConfigure and view the LLDP neighbor info
StatisticsConfigure and view the transmitting & receiving state of LLDP message
at each port
DHCPPropertyConfigure and view DHCP service switches and port switches
IP Pool SettingConfigure and view DHCP server IP address pool
VLAN IF Address Group SettingConfigure and view VLANIF and DHCP server group binding relationship
Client ListView the list of DHCP clients
Client Static Binding TableConfigure and view DHCP client static binding table entries
MulticastGeneralPropertyConfigure and view the function configuration
Group AddressConfigure and view the relevant static multicast info
Router PortConfigure and view the multicast routed port info
Forwarding AllConfigure and view the multicast forwarding port info
ThrottlingConfigure and view the multicast limit at each port
Filtering ProfileConfigure and view the multicast addresses filtered
Filtering BindingConfigure and view the binding info related to filtering rule and ports
IGMP SnoopingPropertyConfigure and view the switch, version, etc.
QuerierConfigure and view the querier state
StatisticsConfigure and view the protocol messages
MLD SnoopingPropertyConfigure and view the protocol, switch, etc.
StatisticsConfigure and view the protocol messages
MVRPropertyConfigure and view the attribute info such as switch
Port SettingConfigure and view the state at each port
Group AddressConfigure and view the function, VLAN and group address
RoutingIPv4 Management and InterfacesIPv4 InterfaceConfigure and view VLANIF IPv4 address information
IPv4 RoutesConfigure and view IPv4 static routes
ARPConfigure and view ARP table
IPv6IPv6 InterfaceConfigure and view VLANIF IPv6 interface information
Management and InterfacesIPv6 AddressConfigure and view VLANIF IPv6 address information
IPv6 RoutesConfigure and view IPv6 static routes
IPv6 NeighborsConfigure and view IPv6 neighbors table
Rip Routes ManagementRip Routes SettingConfigure and view RIP routes
Ospf Routes ManagementOspf Routes SettingConfigure and view OSPF routes
SecurityRADIUSConfigure to view RADIUS server related information
TACACS+Configure to view TACACS+ server related information
AAAMethod ListConfigure and view the login authentication method
Login AuthenticationConfigure and view the authentication methods of terminals
Management AccessManagement VLANConfigure and view management VLAN
Management ServiceConfigure and view the service management mode and relevant attributes
Management ACLConfigure and view the ACL aiming at management channels
Management ACEConfigure and view the ACE configuration of management channels
Authentication ManagementPropertyConfigure and view the authentication attributes
Port SettingConfigure and view the authentication info at each port
MAC Local AccountConfigure and view the list of MAC local accounts
Web Local AccountConfigure and view the list of Web local accounts
SessionsConfigure and view the info related to session authentication
DoSPropertyConfigure and view the switch option
Port SettingConfigure and view the switch option at ports
Dynamic ARP InspectionPropertyConfigure and view the dynamic ARP inspection
StatisticsConfigure and view the messages statistics in APR inspection state at each port
DHCP SnoopingPropertyConfigure and view the switch and state
StatisticsConfigure and view the DHCP message statistics received by each port
Option82 PropertyConfigure and view the attributes related to Option 82
Option82 Circuit IDConfigure and view the Circuit ID of Option 82
IP Source GuardPort SettingConfigure and view the state at ports
IMPV BindingConfigure and view the binding tables of IP, MAC, Port and VLAN
Save DatabaseConfigure and view the storage and info of the binding table entry
ACLMAC ACLConfigure and view the MAC ACL rules
MAC ACEConfigure and view the MAC ACE table entries
IPv4 ACLConfigure and view the IPv4 ACL rules
IPv4 ACEConfigure and view the IPv4 ACE table entries
IPv6 ACLConfigure and view the IPv6 ACL rules
IPv6 ACEConfigure and view the IPv6 ACE table entries
ACL BindingConfigure and view the ACL rules and the port binding application
QoSGeneralPropertyConfigure and view the QoS switch and state
Queue SchedulingConfigure and view the algorithm of queue scheduling
CoS MappingConfigure and view the priority and local queue mapping table
DSCP MappingConfigure and view the priority and local queue mapping table
IP Precedence MappingConfigure and view the priority and local queue mapping table
Rate LimitIngress/Egress PortConfigure and view the configuration of port rate limiting
Egress QueueConfigure and view the rate limiting configuration based on egress queue
DiagnosticsLoggingPropertyConfigure and view the switch and state
Remote ServerConfigure and view the address of remote servers
PingNetwork diagnostics by Ping
TracerouteNetwork diagnostics by traceroute
Copper TestElectrical interface link diagnostics by VCT
Fiber ModuleCheck the SFP module at optical interfaces
UDLDPropertyConfigure and view the switch and state
NeighborConfigure and view the neighbor state
ManagementUser AccountConfigure and view the user info
FirmwareUpgradeUpdate software
ConfigurationUpgradeUpdate configuration files
Save ConfigurationSave the configuration files supporting device running
SNMPViewConfigure and view the SNMP function view table entry
GroupConfigure and view the SNMP group
CommunityConfigure and view the SNMP Community
UserConfigure and view the SNMP user attributes
Engine IDConfigure and view the SNMP and remote Engine IDs
Trap EventConfigure and view the SNMP Trap switch and state
NotificationConfigure and view the SNMP Notification server state
RMONStatisticsConfigure and view the message statistics history of all ports
HistoryConfigure and view the history record state
EventConfigure and view the event state
AlarmConfigure and view the alarm state

3 Status

3.1 System Information

According to the switch connected, web network management panel directly displays the port and product info, incl.: number of ports, port states, product info, device states, function on-off states, etc.

Instructions:

  1. Click the "Status > System Information" in the navigation bar as follows:

AIRLIVE L3POE-XGS4804-400 - System Information - 1

text_image 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28

AIRLIVE L3POE-XGS4804-400 - System Information - 2

text_image System Information Edit Model L3POE-XGS2404 System Name L3POE-XGS2404 System Location Protein System Contact Airlive Serial Number 0123456789 MAC Address 00:4F:4C:00:05:A0 IPv4 Address 192.168.2.1 IPv6 Address fe80::1e2a.a3ff:fe00:3424/64 System OID 1.3.6.1.4.1.27282.1.3 System Uptime 0 day, 0 hr, 6 min and 16 sec Current Time 2021-01-01 08:06:01 UTC+8 Loader Version 1.0.0.2 Loader Date Jul 06 2021 - 14:01:53 Firmware Version 1.1.1.4 Firmware Date Jul 06 2021 - 14:08:43 Telnet Disabled SSH Disabled HTTP Enabled HTTPS Disabled SNMP Disabled

AIRLIVE L3POE-XGS4804-400 - System Information - 3

line | Time | CPU | | -------- | ---- | | 08:02:00 | 20% | | 08:03:00 | 10% | | 08:04:00 | 20% | | 08:05:00 | 15% |

AIRLIVE L3POE-XGS4804-400 - System Information - 4

area | Time | MEM | | -------- | ---- | | 08:02:00 | 65% | | 08:03:00 | 65% | | 08:04:00 | 65% | | 08:05:00 | 70% |

Description:

Mouseover a port to check the port No., type, rate and state. "Edit" the "System Name", "Location" and "Contact" in the product info. "Apply" and finish.

3.2 Statistics

Introduce the detailed flow statistics at a port and the info to be refreshed or cleared manually by users.

  1. Click the "Status > Port > Statistics" in the navigation bar as follows:

AIRLIVE L3POE-XGS4804-400 - Statistics - 1

text_image Port GE3 ▼ MIB Counter All Interface Etherlike RMON Refresh Rate None 5 sec 10 sec 30 sec

AIRLIVE L3POE-XGS4804-400 - Statistics - 2

Interface
ifInOctets60938
ifInUcastPkts210
ifInNUcastPkts318
ifInDiscards0
ifOutOctets185965
ifOutUcastPkts212
ifOutNUcastPkts1422
ifOutDiscards0
ifInMulticastPkts160
ifInBroadcastPkts158
ifOutMulticastPkts770
ifOutBroadcastPkts652

Description:

"Clear" the flow statistics at the current port and refresh the page.

3.3 MAC Address Table

View MAC address table information

Instructions:

  1. Click the "Status > MAC Address Table" in the navigation bar as follows:

MAC Address Table
AIRLIVE L3POE-XGS4804-400 - MAC Address Table - 1

text_image Showing All entries Showing 1 to 2 of 2 entries VLAN MAC Address Type Port 1 00:4F:4C:00:05:A0 Management CPU 1 00:E0:4C:2E:2C:DD Dynamic GE1 Clear Refresh First Previous 1 Next Last

Interface data are as follows.

Query ItemsDescription
MACDestination MAC Address
VLANVLAN ID belonging to MAC address
PortMessage egress corresponding to MAC address
TypeDynamic MAC Address refers to the entry which will age with the set aging time. Switches can add entries based on the learning mechanism of MAC address or manual creation.Static MAC address refers to the specified table which is manually configured and won't age.Management MAC address refers to the address at the management port.

3.4 Reboot

  1. Click the "Reboot" on the upper right as guided as follows.

AIRLIVE L3POE-XGS4804-400 - Reboot - 1

text_image Save | Logout | Reboot | Debug Reboot the system and unsaved changes in the configuration will be lost. Do you want to continue? OK Cancel

3.5 Management IP Address

Change the management IP address on web interface. Instructions:

  1. Click the "Routing > IPv4 Management and Interfaces > IPv4 Interface" in the navigation bar to discover IPv4 address of 192.168.2.1/24 by default as follows:

IPv4 Interface Table
AIRLIVE L3POE-XGS4804-400 - Management IP Address - 1

text_image Interface IP Address Type IP Address Mask Status VLAN 1 Static 192.168.2.1 255.255.255.0 Valid Add Delete

4 Network

4.1 DNS

DNS is short for Domain Name System to name computers and network services from units to domain hierarchies. A domain name consists of the dots separated by a series of words or abbreviations, each corresponding to a unique IP address. DNS is the server on the Internet that resolves domain names. Applicable to Internet and other TCP/IP networks, DNS name retrieves computers and services through user-friendly names. As one of the core Internet services, DNS is a distributed database that maps domain names and IP addresses mutually.

Instructions:

  1. Click on the "Network > DNS" in the navigation bar as follows.

DNS Configuration
AIRLIVE L3POE-XGS4804-400 - DNS - 1

text_image DNS Status Disable Enable DNS Default Name (1 to 255 alphanumeric characters) Apply

DNS Server Configuration
AIRLIVE L3POE-XGS4804-400 - DNS - 2

text_image Preference DNS Server 0 results found. Add Delete

Interface data are as follows.

Configuration ItemsDescription
DNS StateDNS switch
DNS Default NameEnter the DNS default name
  1. "Add" to configure DNS server.

Add DNS Server

AIRLIVE L3POE-XGS4804-400 - DNS - 3

text_image IPv4/IPv6 Address 114.114.114.114 Apply Close
  1. "Apply" and finish as follows.

DNS Server Configuration
AIRLIVE L3POE-XGS4804-400 - DNS - 4

text_image Preference DNS Server 1 114.114.114.114 Add Delete

4.2 System Time

It is mainly used to configure the system time, and select the time source, daylight-saving time, etc.

Instructions

  1. Click on the "Network > System Time" in the navigation bar as follows.

AIRLIVE L3POE-XGS4804-400 - System Time - 1

text_image Source Time Zone SNTP From Computer Manual Time UTC +8:00 SNTP Address Type Hostname IPv4 Server Address Server Port 123 (1 - 65535, default 123) Manual Time Date 2021-01-01 YYYY-MM-DD Time 08:14:12 HH:MM:SS Daylight Saving Time Type None Recurring Non-recurring USA European Offset 60 Min (1 - 1440, default 60) Recurring From: Day Sun Week First Month Jan Time To: Day Sun Week First Month Jan Time Non-recurring From: YYYY-MM-DD HH:MM To: YYYY-MM-DD HH:MM Operational Status Current Time 2021-01-01 08:14:12 UTC+8

Apply

Interface data are as follows.

Configuration ItemsDescription
Time SourceSelect the time source in SNTP, PC or manual modes
Time ZoneSet the time zone
Address TypeHost name or IPv4 address (with time source set by SNTP)
Server AddressServer Address (with time source set by SNTP)
Server Port No.Server Port No. (with time source set by SNTP)
DateDate info: DD/MM/YYYY (with time source set in manual mode)
TimeTime info: SS/MM/HH (with time source set in manual mode)
TypeDaylight-saving time types are divided into None, cyclic, non-cyclic, United States and Europe.
Reimbursed TimeReimbursed Time of daylight-saving time
Cyclic ModeConfigure the cyclic mode of daylight-saving time
Non-cyclic ModeConfigure the non-cyclic mode of daylight-saving time

5 Port

5.1 Port Setting

Interfaces should be identified so that users can inquire and configure Ethernet interfaces as they want.

Instructions:

  1. Click the "Port > Port Setting" in the navigation bar:

Port Setting Table

EntryPortTypeDescriptionStateLink StatusSpeedDuplexFlow Control
1GE11000M CopperEnabledDownAutoAutoDisabled
2GE21000M CopperEnabledDownAutoAutoDisabled
3GE31000M CopperEnabledDownAutoAutoDisabled
4GE41000M CopperEnabledDownAutoAutoDisabled
5GE51000M CopperEnabledDownAutoAutoDisabled
6GE61000M CopperEnabledDownAutoAutoDisabled
7GE71000M CopperEnabledDownAutoAutoDisabled
  1. Select the port(s) to be configured, and "Edit" as follows:

Edit Port Setting

PortGE1-GE3
Description
StateEnable
SpeedAuto 10M Auto - 10M 100M Auto - 100M 1000M Auto - 1000M 10G Auto - 10M/100M
DuplexAuto Full Half
Flow ControlAuto Enable Disable

Interface data are as follows

ConfigurationDescription
Items
PortPort list
DescriptionPort alias
StateEnable or disable port
SpeedConfigurable auto negotiation with mandatory 10 Mb, 100 Mb and 1,000 Mb states. Interface rates including 10 Mbit/s, 10 Mbit/s and 1,000 Mbit/s are available to Ethernet electrical interfaces and are optional as required.
DuplexConfigurable auto negotiation with full or half duplexes.
Flow ControlAfter it is enabled on both local network and opposite network devices, the local one will notify the other to stop transmitting messages in the presence of network congestion. The opposite one will execute the command temporarily to ensure zero message loss.Disable-Disabled reception and transmission of PAUSE frame; Enable-Enabled reception and transmission of PAUSE frame; Auto negotiation-Negotiate PAUSE frame with opposite network devices automatically.

5.2 Error Disabled

In general, if the software of the switch detects some errors in the port, the port will be closed immediately. In other words, when the operating system of the switch detects some error events on the switch port, the switch will automatically close the port Instructions:

  1. Click the "Port > Error Disabled" in the navigation bar to enable or disable configuration as follows:

AIRLIVE L3POE-XGS4804-400 - Error Disabled - 1

text_image Recovery Interval 300 Sec (30 - 86400) BPDU Guard Enable UDLD Enable Self Loop Enable Broadcast Flood Enable Unknown Multicast Flood Enable Unicast Flood Enable ACL Enable Port Security Enable DHCP Rate Limit Enable ARP Rate Limit Enable

Apply

Link Aggregation broadens bandwidth and reliability by bundling a group of physical interfaces into a single logical interface.

LAG (Link Aggregation Group) is a logical link bundled by multiple Ethernet links (Eth-Trunk).

Ceaselessly expanding network size increases users' demands of link bandwidth and reliability. Traditionally, high-speed interface board or the compatible equipment is usually replaced to optimize bandwidth, which is expensive and inflexible.

Link Aggregation Technology bundles multiple physical interfaces into a single logical interface without upgrading hardware. Its backup mechanism not only improves reliability, but also shares the flow load on different physical links.

As shown below, Switch A is linked with Switch B through three Ethernet links which are bundled into an Eth-Trunk logical link. Its bandwidth equals to that of the three links in total, thus broadening the bandwidth. Meanwhile, these three links back up mutually to be more reliable.

AIRLIVE L3POE-XGS4804-400 - Link Aggregation - 1

flowchart
graph TD
    A["VLAN10"] -->|ge1/4| B["SwitchA"]
    B -->|ge1/1| C["SwitchB"]
    C -->|ge1/1| A
    B -->|ge1/2| C
    B -->|ge1/3| C
    D["VLAN20"] -->|ge1/5| B
    E["VLAN10"] -->|ge1/4| C
    F["VLAN20"] -->|ge1/5| C
    G["Eth-Trunk"] -->|ge1/2| C
    G -->|ge1/3| B

Link Aggregation can meet the following demands:

● Insufficient bandwidth of two switches connected with one link.

● Insufficient reliability of two switches connected with one link.

Link Aggregation can be divided into Manual Mode and LACP Mode in accordance with Link Aggregation Control Protocol (LACP) state.

In the first mode, Eth-Trunk establishment, member interface access should be added manually without LACP. It is also called the Load-sharing Mode because all links are involved in data forwarding and load sharing. In case any active link fails, LAG will average load with the remaining ones. This mode is preferred under the circumstance

that two directly connected devices require a larger link bandwidth but has no access to LACP.

5.3.1 Group

Instructions for adding a Static Link Aggregation:

  1. Click the "Port > Link Aggregation > Group", select a load-balancing algorithm with a radio button. "Apply" and finish as follows:

AIRLIVE L3POE-XGS4804-400 - Group - 1

text_image Load Balance Algorithm ● MAC Address ○ IP-MAC Address

Apply

LAGNameTypeLink StatusActive MemberInactive Member
OgLAG 1--
OgLAG 2--
OgLAG 3--
OgLAG 4--
OgLAG 5--
OgLAG 6--
OgLAG 7--
OgLAG 8--

Edit

  1. Select one of 8 LAGs available, "Edit" the configuration page as follows:

AIRLIVE L3POE-XGS4804-400 - Edit Link Aggregation Group - 1

text_image LAG 1 Name Type Static LACP Member Available Port GE1 GE2 GE3 GE4 GE5 GE6 GE7 GE8 Selected Port

Apply

Close

Interface data are as follows

Configuration ItemsDescription
LAGThere are 8 LAGs numbering from 1 to 8.
NameDescription of LAG, which can be modified as needed.
TypeSelect from the manual mode and the LACP mode.
MemberUp to 8 member ports are available in LAG.

Illustration:

As shown below, Switch A and Switch B connect VLAN 10 and 20 via Ethernet respectively, with large data flow between them.

Both Switch A and B are expected to provide superior link bandwidth for VLAN communication. Meanwhile, there should be the redundancy for reliable data transmission and links.

Networking diagram LAG in manual mode

AIRLIVE L3POE-XGS4804-400 - Edit Link Aggregation Group - 2

flowchart
graph TD
    A["VLAN10"] -->|ge1/4| B["SwitchA"]
    B -->|ge1/1| C["SwitchB"]
    C -->|ge1/1| A
    B -->|ge1/2| C
    B -->|ge1/3| C
    D["VLAN20"] -->|ge1/5| B
    E["VLAN10"] -->|ge1/4| C
    F["VLAN20"] -->|ge1/5| C
    G["Eth-Trunk"] -->|ge1/2| C
    G -->|ge1/3| B

Instructions:

  1. Create the ETH trunk interface in SwitchA and add a member interface to increase the link bandwidth. The configuration of SwitchB is like that of SwitchA. Click the "Port > Link Aggregation > Group", choose "LAG 1" and port GE1, 2 and 3 and move them to the selected ports on the right. "Apply" and finish as follows.

AIRLIVE L3POE-XGS4804-400 - Link Aggregation Table - 1

LAGNameTypeLink StatusActive MemberInactive Member
LAG 1StaticUpGE3GE1-GE2
LAG 2------
LAG 3------
LAG 4------

5.3.2 Port Setting

Attribute configuration of aggregation group member port

  1. Click the "Port > Link Aggregation > Port Setting", to enter the attribute configuration interface of aggregation group member port as follows:

Port Setting Table

AIRLIVE L3POE-XGS4804-400 - Port Setting Table - 1

LAGTypeDescriptionStateLink StatusSpeedDuplexFlow Control
LAG 1EnabledDownAutoAutoDisabled
LAG 2EnabledDownAutoAutoDisabled
LAG 3EnabledDownAutoAutoDisabled
LAG 4EnabledDownAutoAutoDisabled
LAG 5EnabledDownAutoAutoDisabled
LAG 6EnabledDownAutoAutoDisabled
LAG 7EnabledDownAutoAutoDisabled
LAG 8EnabledDownAutoAutoDisabled

Edit

5.3.3 LACP

LACP (Link Aggregation Control Protocol), based on IEEE 802.3ad Standard, dynamically aggregates and disaggregates links. It exchanges info with the opposite network devices through LACPDU (Link Aggregation Control Protocol Data Unit). After a port uses LACP, it will inform the opposite network device of system priority, system MAC, port priority and No., and operation Key by transmitting a LACPDU. The opposite device will compare such info with that saved by other ports after receiving it, thus reaching an agreement on port participation in or quitting from a dynamic aggregation.

Dynamic LACP aggregation is automatically created or deleted by system, that is, internal ports can be added or removed by themselves. Only the ports connected to a same device with the same rate, duplex, and basic configuration can be aggregated. Instructions for adding a dynamic link aggregation:

  1. Click the "Port > Link Aggregation > Group" in the navigation bar, select the LAG ID and LACP mode, "Edit" them as follows:

AIRLIVE L3POE-XGS4804-400 - Edit Link Aggregation Group - 1

text_image LAG Name Type Static LACP Member Available Port GE1 GE2 GE3 GE7 GE8 GE9 GE10 GE11 Selected Port GE4 GE5 GE6 Apply Close
  1. Click the "Port >Link Aggregation > LACP" in the navigation bar to configure the LACP attributes such as system priority, port priority and timeout method as follows:

AIRLIVE L3POE-XGS4804-400 - Edit Link Aggregation Group - 2

text_image System Priority 32768 (1 - 65535, default 32768) Apply

LACP Port Setting Table

EntryPortPort PriorityTimeout
1GE11Long
2GE21Long
3GE31Long
4GE41Long
5GE51Long
6GE61Long
7GE71Long
8GE81Long

Interface data are as follows

Configuration ItemsDescription
System PriorityLACP determines the active and passive modes between two devices subject to priority standard.
PortPort list
Port PriorityLACP determines the dynamic LAG member mode subject to the port priority with a superior system.
TimeoutIt decides the transmission frequency of LACP messages.

Description:

Please make sure there is no member interface accessing the Eth-Trunk before changing its work pattern, otherwise it fails.

Work pattern of the local network devices should be consistent with that of the opposite network devices.

Illustration

Ethernet Switch A aggregates 3 ports from GE1 to GE3 to Switch B, in order to share the load by each member port.

The following configurations are exampled by means of dynamic aggregation.

AIRLIVE L3POE-XGS4804-400 - Illustration - 1

flowchart
graph TD
    A["Switch A"] -->|Link aggregation| B["Switch B"]
    style A fill:#f9f,stroke:#333
    style B fill:#bbf,stroke:#333

Description:

The following is the configuration of Switch A only, which should stay the same with that of Switch B for port aggregation.

Instructions:

  1. Click the "Port > Link Aggregation > Group" in the navigation bar, "Edit" with LAG 2, select GE1-GE3 in LACP mode. "Apply" and finish as follows:

AIRLIVE L3POE-XGS4804-400 - Edit Link Aggregation Group - 1

text_image LAG Name Type Static LACP Member Available Port GE4 GE5 GE6 GE7 GE8 GE9 GE10 GE11 Selected Port GE1 GE2 GE3 Apply Close

5.4 EEE

Port power will be turned down in case of zero or less flow Instructions:

  1. Click the "Port > EEE" in the navigation bar, select the port and "Edit" to enter the configuration interface as follows:

EEE Setting Table

EntryPortState
1GE1Disabled
2GE2Disabled
3GE3Disabled
4GE4Disabled
5GE5Disabled
6GE6Disabled
7GE7Disabled

Edit EEE Setting

AIRLIVE L3POE-XGS4804-400 - Edit EEE Setting - 1

text_image Port GE1-GE2 State Enable Apply Close
  1. Set the port enable tag and "Apply" to complete the configuration as follows:

EEE Setting Table

EntryPortState
1GE1Enabled
2GE2Enabled
3GE3Disabled
4GE4Disabled

5.5 Jumbo Frame

Set the MTU (Maximum Transmission Unit) of the port

Instructions:

  1. Click the "Port > Jumbo Frame" in the navigation bar, enter Jumbo Frame configuration interface as follows:

AIRLIVE L3POE-XGS4804-400 - Jumbo Frame - 1

text_image Jumbo Frame Enable 10000 Byte (1518 - 10000, default 1522) Apply

5.6 Port Security

The port security feature records the Ethernet MAC address connected to the switch port through the MAC address table, and only one MAC address can communicate through this port. When packets sent by other MAC addresses pass through this port, port security features prevent it. Using port security features can prevent unauthorized devices from accessing the network and enhance security. In addition, port security features can also be used to prevent MAC address table from filling up due to MAC address flooding

Instructions:

  1. Click the "Port > Port Security" in the navigation bar, enter port security configuration interface as follows:

AIRLIVE L3POE-XGS4804-400 - Port Security - 1

text_image State Enable Rate Limit 100 Packet / Sec (1 - 600, default 100) Apply
  1. Click the "Port > Port Security" in the navigation bar, select the port and "Edit" to enter the port level configuration interface as follows:

Port Security Table

EntryPortStateAddress LimitTotalConfiguredViolate NumberViolate ActionSticky
1GE1Disabled1000ProtectDisabled
2GE2Disabled1000ProtectDisabled
3GE3Disabled1000ProtectDisabled
4GE4Disabled1000ProtectDisabled
5GE5Disabled1000ProtectDisabled
6GE6Disabled1000ProtectDisabled
7GE7Disabled1000ProtectDisabled

Edit Port Security

AIRLIVE L3POE-XGS4804-400 - Edit Port Security - 1

text_image Port GE1-GE2 State Enable Address Limit 1 (1 - 256, default 1) Violate Action Protect Restrict Shutdown Sticky Enable Apply Close

5.7 Protected Port

Messages of broadcast, multicast, etc. will flood at each port even though the flow needs no mutual communication sometimes. Under this circumstance, port isolation can separate the messages between two ports.

Instructions:

  1. Click the "Port > Protected Port" in the navigation bar, check the port(s) to be isolated, "Edit" to switch this function as follows:

Protected Port Table

AIRLIVE L3POE-XGS4804-400 - Protected Port Table - 1

EntryPortState
1GE1Unprotected
2GE2Unprotected
3GE3Unprotected
4GE4Unprotected
5GE5Unprotected
6GE6Unprotected
7GE7Unprotected

Edit Protected Port

AIRLIVE L3POE-XGS4804-400 - Edit Protected Port - 1

text_image Port GE1-GE4 State ✓ Protected

AIRLIVE L3POE-XGS4804-400 - Edit Protected Port - 2

Instructions for achieve port isolation:

  1. Click the "Port > Protected Port" in the navigation bar, check and "Edit" the GE1, 2 and 3 to be isolated. "Apply" and finish as follows:

Protected Port Table

AIRLIVE L3POE-XGS4804-400 - Protected Port Table - 1

EntryPortState
1GE1Protected
2GE2Protected
3GE3Protected
4GE4Unprotected
5GE5Unprotected
  1. GE1, 2 and 3 fail to communicate mutually like other non-isolated ports.

5.8 Storm Control

Storms generated via broadcast, unknown multicast and unicast messages are prevented as follows. These messages will be suppressed subject to packet rates respectively. The average rate of the messages received by monitoring interfaces will be compared with the max threshold configured during an inspection interval. Configured storm policing will be performed at this interface if the average rate exceeds the max

threshold.

When a L2 Ethernet interface receives the broadcast, unknown multicast or unicast messages, the device will forward them to other L2 interfaces in a same VLAN (Virtual Local Area Network) if the egress interface cannot be recognized according to destination MAC addresses. As a result, broadcast storm may occur to degrade device operation performance.

Three kinds of message flow can be controlled by storm policing characteristics to stay away from broadcast storms.

Instructions:

  1. Click the "Port > Storm Control" in the navigation bar to configure the attributes related to storm policing such as mode as follows:

AIRLIVE L3POE-XGS4804-400 - Storm Control - 1

text_image Mode Packet / Sec Kbits / Sec IFG Exclude Include Apply
  1. Select the appropriate port and "Edit" it by configuring the policing rates of broadcast, unknown multicast and unicast storms at each port.

Port Setting Table

EntryPortStateBroadcastUnknown MulticastUnknown UnicastAction
StateRate (Kbps)StateRate (Kbps)StateRate (Kbps)
1GE1DisabledDisabled10000Disabled10000Disabled10000Drop
2GE2DisabledDisabled10000Disabled10000Disabled10000Drop
3GE3DisabledDisabled10000Disabled10000Disabled10000Drop
4GE4DisabledDisabled10000Disabled10000Disabled10000Drop
5GE5DisabledDisabled10000Disabled10000Disabled10000Drop
6GE6DisabledDisabled10000Disabled10000Disabled10000Drop
7GE7DisabledDisabled10000Disabled10000Disabled10000Drop
8GE8DisabledDisabled10000Disabled10000Disabled10000Drop
  1. Configure info such as storm switch and rate, "Apply" and finish as follows:

Edit Port Setting

AIRLIVE L3POE-XGS4804-400 - Edit Port Setting - 1

text_image Port GE1-GE3 State Enable Broadcast Enable 10000 Kbps (16 - 1000000, default 10000) Unknown Multicast Enable 10000 Kbps (16 - 1000000, default 10000) Unknown Unicast Enable 10000 Kbps (16 - 1000000, default 10000) Action Drop Shutdown Apply Close

5.9 Mirroring

Port Mirroring copies the message of a specified switch port to the destination port. The copied port is the Source Port, and the copying port is the Destination Port. Destination Port accesses to data inspection devices so that users can analyze the messages received to monitor network and troubleshoot as follows:

AIRLIVE L3POE-XGS4804-400 - Mirroring - 1

flowchart
graph TD
    A["Network"] --> B["Mirror Source Port"]
    B --> C["PC"]
    B --> D["Mirroring Destination Port"]
    D --> E["Data Monitoring Device"]

Instance

PC1 and PC2 access Switch A through interface GE1 and GE2 respectively.

Users intend to monitor the messages transmitted from PC2 to PC1.

Instructions:

  1. Click the "Port > Mirroring" in the navigation bar. 4 sets of flow mirroring rules can be configured as follows:

Mirroring Table

AIRLIVE L3POE-XGS4804-400 - Mirroring Table - 1

Session IDStateMonitor PortIngress PortEgress Port
1Disabled---------
2Disabled---------
3Disabled---------
4Disabled---------

Edit

“*” Allow the monitor port to send or receive normal packets

  1. Select one session and "Edit" it in the mirroring group configuration interface:

Edit Mirroring

AIRLIVE L3POE-XGS4804-400 - Edit Mirroring - 1

text_image Session ID 1 State ✓ Enable Monitor Port GE1 ✓ ✓ Send or Receive Normal Packet Ingress Port Available Port GE1 GE5 GE6 GE7 GE8 GE9 GE10 GE11 Selected Port GE2 GE3 GE4 Egress Port Available Port GE1 GE5 GE6 GE7 GE8 GE9 GE10 GE11 Selected Port GE2 GE3 GE4

Apply

Close

Interface data are as follows

Configuration ItemsDescription
Session IDThe switch has 4 session IDs by default.
StateThe mirroring group can be enabled or not.
Monitor PortOnly one ordinary physical port can be selected, excluding lin aggregation port and source port.
Ingress PortAny message received will be mirrored to the destination port.
Egress PortAny message transmitted will be mirrored to the destination port.

6 POE Setting

PoE (Power over Ethernet) transmits data signal for the terminals based on IP (e.g. IP phone, WAP, and IP camera) and supplies the devices with direct current, without changing the existing Cat-5 network cabling status. It ensures safe structured cabling and normal network operation to minimize the cost.

6.1 PoE Port Setting

Instructions:

  1. Click the "POE Setting > POE Port Setting" in the navigation bar as follows:

System info

AIRLIVE L3POE-XGS4804-400 - System info - 1

text_image System Power(mW) 0 System Temperature(C) 62 Refresh Rate None 5 sec 10 sec 30 sec

Port Setting Table

EntryPortPortEnableStatusTypeLevelActual Power(mW)Voltage(V)Current(mA)WatchDog
1GE1EnabledOffAF(U)0N/AN/AN/ADisabled
2GE2EnabledOffAF(U)0N/AN/AN/ADisabled
3GE3EnabledOffAF(U)0N/AN/AN/ADisabled
4GE4EnabledOffAF(U)0N/AN/AN/ADisabled
5GE5EnabledOffAF(U)0N/AN/AN/ADisabled
6GE6EnabledOffAF(U)0N/AN/AN/ADisabled
7GE7EnabledOffAF(U)0N/AN/AN/ADisabled
8GE8EnabledOffAF(U)0N/AN/AN/ADisabled
  1. Select the ports to be configured, and "Edit" as follows:

Edit Port Setting

AIRLIVE L3POE-XGS4804-400 - Edit Port Setting - 1

text_image Port GE1-GE2 PortEnable Enable WatchDog Enable Apply Close

Interface data are as follows

Configuration ItemsDescription
PortEnableEnable/Disable Poe port power
WatchDogEnable/Disable Poe port watchdog function; After enabling the watchdog function, when the POE port is continuously powered but there is no traffic, the POE watchdog will be triggered. After 2 minutes of detection, the power supply will be stopped and then powered on. The total detection cycle is 5 times

6.2 POE Port Timer Setting

Instructions:

  1. Click the "POE Setting > POE Port Timer Setting", select the power supply time of Poe schedule. "Apply" and finish as follows

AIRLIVE L3POE-XGS4804-400 - Instructions: - 1

text_image Port GE1 00 01 02 03 04 05 06 07 08 09 10 11 12 13 14 15 16 17 18 19 20 21 22 23 Mon ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓✓√ Tue ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ Wed ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ /V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/V/A Thu /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V / V Fri /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V/ V Sat /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /V /VSun V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V V

6.3 POE Port Timer Reboot Setting

By setting, the power supply can be restarted periodically based on the port.

Instructions:

  1. Click the "POE Setting > POE Port Timer Reboot Setting" in the navigation bar as

follows:

Port Setting Table

Q

EntryPortRebootTimerDelayTimer
1GE100:00:0000:00:00
2GE200:00:0000:00:00
3GE300:00:0000:00:00
4GE400:00:0000:00:00
5GE500:00:0000:00:00
6GE600:00:0000:00:00
7GE700:00:0000:00:00
8GE800:00:0000:00:00
  1. Select the port and "Edit" to enter the configuration interface

Reboot Timer Edit Port Setting

AIRLIVE L3POE-XGS4804-400 - Reboot Timer Edit Port Setting - 1

text_image Port GE1-GE2 RebootTimer Hour 00 ▼ Minute 00 ▼ Second 00 ▼ DelayTimer Hour 00 ▼ Minute 00 ▼ Second 00 ▼ Apply Close

Interface data are as follows

Configuration ItemsDescription
PortPort list
RebootTimerSet the time synchronization time when PoE port turns off PoE power supply. It only supports setting to minutes
DelayTimerAfter the PoE power supply is turned off at the restart time, the delay time to restart and turn on the power supply can only be set to minutes

Note:

● To use this function, you need to set the system time synchronization
● The minimum granularity time of Poe port restart is minutes
- When the restart time is set, the delay time needs to be set
- When the delay time is 00:00:00, it means that the port is no longer powered on

7 VLAN

VLAN is formulated not restricted to physical locations, which means the hosts in a same VLAN can be placed at will. As shown below, each VLAN, as a broadcast domain, divides a physical LAN into logical LANs. Hosts can exchange messages by means of traditional communication. For the hosts in different VLANs, the device such as router or L3 switch is a must.

AIRLIVE L3POE-XGS4804-400 - VLAN - 1

flowchart
graph TD
    A["Router"] --> B["Switch"]
    A --> C["Switch"]
    B --> D["VLAN A"]
    B --> E["VLANB"]
    C --> F["VLAN A"]
    C --> G["VLANB"]
    D <--> H["VLAN A"]
    E <--> I["VLAN B"]
    F <--> J["VLAN B"]
    G <--> K["VLAN B"]

VLAN is superior to the traditional Ethernet in terms of:

- Broadcast domain coverage: the broadcast message in a LAN is limited in a VLAN to save the bandwidth and handle the network-related issues more efficiently.

● LAN security: VLAN hosts fail to communicate with each other since the messages are separated by the broadcast domain in the data link layer. They need a router on a Layer 3 switch for Layer 3 forwarding.

- Flexibility of creating a virtual working team: VLAN can create a virtual working team beyond the control of physical network. Users have access to the network without changing the configuration if their physical locations are moving within the scope. This management switch is compatible with VLAN types based on 802.1Q, protocols, MAC, and ports. For default configuration, 802.1Q VLAN mode should be adopted. Port VLAN is divided subject to a switch's interface No. Network administrator gives each switch interface a different PVID, namely a port default VLAN. If a data frame without a VLAN tag flows into a switch interface with a PVID, it will be marked with the same PVID, or it will get rid of an additional tag even though the interface has a PVID.

- The solution to a VLAN frame depends on the interface type, which eases member definition but re-configures VLAN in case of member mobility.

7.1 VLAN

7.1.1 Create VLAN

Instructions for creating a new VLAN:

  1. Click the "VLAN > VLAN > Create VLAN" to select a name in the valid VLAN box, move it to the VLAN creating box on the right (up to 256 VLANs can be created). "Apply" and finish as follows:

AIRLIVE L3POE-XGS4804-400 - Create VLAN - 1

text_image VLAN Available VLAN VLAN 2 VLAN 3 VLAN 4 VLAN 5 VLAN 6 VLAN 7 VLAN 8 VLAN 9 Created VLAN VLAN 1 Apply

VLAN Table
AIRLIVE L3POE-XGS4804-400 - Create VLAN - 2

text_image Showing All entries Showing 1 to 1 of 1 entries VLAN Name Type VLAN Interface State 1 default Default Disabled First Previous 1 Next Last Edit Delete
  1. The VLAN created will be displayed in the VLAN Table. Users can "Edit" the VLAN as follows:

Edit VLAN Name
AIRLIVE L3POE-XGS4804-400 - Create VLAN - 3

text_image Name VLAN0002 Apply Close

Interface data are as follows.

Configuration ItemsDescription
VLAN IDIt is required to select an ID ranging from 1 to 4,094. F example, 1-3,5,7 and 9. LAN 1 is the default, which won't berepeated in another new VLAN.
NameIt is optional to modify the VLAN description as required.

7.1.2 VLAN Configuration

There are two methods. One is to add multiple ports under a single VLAN. The other is to add a port to multiple VLANs. They are configured according to different purposes.

Instructions for the first method to add the current port to a specified VLAN

  1. Click the "VLAN > VLAN > VLAN Configuration" in the navigation bar, select the VLAN ID on the upper left, and then click the port info as follows:

VLAN Configuration Table

VLAN default ▼

AIRLIVE L3POE-XGS4804-400 - VLAN Configuration Table - 1

EntryPortModeMembershipPVIDForbidden
1GE1Trunk○ Excluded○ Tagged● Untagged
2GE2Trunk○ Excluded○ Tagged● Untagged
3GE3Trunk○ Excluded○ Tagged● Untagged
4GE4Trunk○ Excluded○ Tagged● Untagged
5GE5Trunk○ Excluded○ Tagged● Untagged
6GE6Trunk○ Excluded○ Tagged● Untagged
7GE7Trunk○ Excluded○ Tagged● Untagged
8GE8Trunk○ Excluded○ Tagged● Untagged

Interface data are as follows.

Configuration ItemsDescription
VLANVLAN ID to be configured
PortPort list
ModeVLAN mode of port
MembershipMember roles at the VLAN port: Excluded: the port is out of this VLAN Tagged: the port is a tagged member of this VLAN Untagged: the port is an untagged member of this VLAN
PVIDWhether this VLAN is the port PVID
ForbiddenWhether the VLAN message is forbidden to be forwarded at this port

7.1.3 Membership

Instructions for the second method to add the current port to a specified VLAN

  1. Click the "VLAN > VLAN > Membership" in the navigation bar, select the port to be configured and "Edit" to configure its attributes:

Membership Table

EntryPortModeAdministrative VLANOperational VLAN
![]('img_url')1GE1Trunk1UP1UP
![]('img_url')2GE2Trunk1UP1UP
![]('img_url')3GE3Trunk1UP1UP
![]('img_url')4GE4Trunk1UP1UP
![]('img_url')5GE5Trunk1UP1UP
![]('img_url')6GE6Trunk1UP1UP
![]('img_url')7GE7Trunk1UP1UP

Edit Port Setting

AIRLIVE L3POE-XGS4804-400 - Membership - 1

text_image Port GE2 Mode Trunk Membership 10 1UP 2T 3T 4T 5T 6T 7T 8T Forbidden Excluded Tagged Untagged PVID

AIRLIVE L3POE-XGS4804-400 - Membership - 2

Interface data are as follows.

Configuration ItemsDescription
PortPort list
ModeVLAN mode of port
MembershipThe port is the attribute of VLAN ID and VLAN: Forbidden: do not forward the VLAN message Excluded: the port out of the VLAN Tagged: The Tagged member of the VLAN Untagged: The Untagged member of the VLANPVID: whether the VLAN is the port PVLAN

7.1.4 Port Setting

Trunk configuration. Connected with other switches, Trunk interfaces mainly connect trunk links to allow the VLAN frames to flow through. IEEE 802.1q is the encapsulation protocol of Trunk link and considers the formal standard for Virtual Bridged Local Area Networks. It changes the frame format of Ethernet by adding a 4-bit 802.1q Tag between the source MAC address field and the protocol field.

802.1q frame format

AIRLIVE L3POE-XGS4804-400 - Port Setting - 1

text_image 6bytes 6bytes 4bytes 2bytes 46-1500bytes 4bytes Destination address Source address 802.1Q Tag Length/ Type Data FCS TPID PRI CFI VID 2bytes 3bits 1bit 12bits

Meanings of 802.1q tag fields

FieldLengthNameAnalysis
TPID2 bytesTag Protocol Identifier to describe the frame typeIt refers to the 802.1q Tag frame when the value is 0x8,100, which will be discarded if relevant equipment fails to receive it.
PRI3 bitsFrame PriorityIt ranges from 0 to 7, with the higher priority represented by larger number. Data frame with higher priority will be sent preferentially in case of switch congestion.
CFI1 bitCanonical Format Indicator to reveal whether the MAC address is classical or not.MAC address is classical when CFI is 0 and non-classical when CFI is 1. It promotes the compatibility between Ethernet and token ring. CFI will be 0 in the Ethernet.
VID12 bitsVLAN ID indicates the VLAN to which the frame belongs.It ranges from 0 to 4,095, with 1 to 4,094 valid since 0 and 4,095 are the protocol retention values.

Packets sent by each switch supporting 802.1q protocol contain a VLAN ID to indicate the VLAN to which the switch belongs. Therefore, Ethernet frames are divided into two types as follows in a VLAN switching network:

  • Tagged frame: it refers to the frame adding a 4-bit 802.1q Tag.
  • Untagged frame: it refers to the original frame without a 4-bit 802.1q Tag.

Connected with other switches, Trunk interfaces mainly connect trunk links to allow the VLAN frames to flow through.

Instructions for trunk interface configuration:

  1. Click the "VLAN > VLAN > Port Setting" in the navigation bar, select the port and "Edit" it to configure the attributes:

Port Setting Table

EntryPortModePVIDAccept Frame TypeIngress FilteringUplinkTPID
1GE1Trunk1AllEnabledDisabled0x8100
2GE2Trunk1AllEnabledDisabled0x8100
3GE3Trunk1AllEnabledDisabled0x8100
4GE4Trunk1AllEnabledDisabled0x8100
5GE5Trunk1AllEnabledDisabled0x8100
6GE6Trunk1AllEnabledDisabled0x8100
7GE7Trunk1AllEnabledDisabled0x8100
8GE8Trunk1AllEnabledDisabled0x8100

Edit Port Setting

AIRLIVE L3POE-XGS4804-400 - Edit Port Setting - 1

text_image Port GE4-GE8 Mode ● Hybrid ○ Access ○ Trunk ○ Tunnel PVID 1 (1 - 4094) Accept Frame Type ● All ○ Tag Only ○ Untag Only Ingress Filtering ✓ Enable Uplink □ Enable TPID Apply Close

Interface data are as follows.

Configuration ItemsDescription
PortPort No. to be configured
ModeVLAN mode of portHybrid: port in this mode serves as the member of Tagged and Untagged ports of VLANsAccess: port in this mode serves as the only member of VLANTrunk: port in this mode serves as the only Untagge member of PVID and the Tagged member of VLANsTunnel: Port Q-in-Q VLAN
PVIDPort native VLAN
Accept Frame TypeMessage types received by portsAll: all messagesTag Only: only Tagged messages will be receivedUntag Only: only Untagged messages will be received
Ingress FilteringA switch to decide to filter VLAN messages excluded at the port
UplinkWhether in uplink mode or not
TPIDIdentification No. of VLAN Tag

7.2 Voice VLAN

Traditionally, ACL (Access Control List) will be applied to distinguish Voice Data and QoS (Quality of Service) will be used to ensure transmission quality, thus enhancing the priority. In order to simplify user configuration and facilitate voice flow management, Voice VLAN emerges. Enabled interface judges whether it is Voice Data flow or not according to the source MAC address field accessing the interface data flow. The message in the source MAC address is the Voice Data flow, which confirms to the OUI (Organizationally Unique Identifier) of the voice devices that are configured by the system. The interfaces receiving Voice Data flow will automatically transmit to Voice VLAN, thus simplifying user configuration and Voice Data management.

OUI of Voice VLAN

OUI represents a MAC address field. Its address can be calculated based on the 48-bit MAC address and the corresponding bit of mask. The number of bits of ingress MAC address and matching OUI is determined by the length of the all "1"-bit in the mask. For example, if the MAC address is 1-1-1 and the mask is FFFF-FF00-0000, the result of execution and calculation of MAC address and corresponding mask, namely OUI, will be 0001-0000-0000.

If the first 24 bits of the ingress MAC address are matched with those of OUI, the enabled Voice VLAN interface identifies the data flow and the ingress device as the Voice Data flow and voice device respectively.

Voice VLAN is divided for user Voice Data flow. Voice VLANs are created to connect the interfaces linked with voice devices to transmit the Voice Data inside in a centralized way.

Voice Data and non-Voice Data often exist in the same network. Voice Data needs a higher priority than other business data during transmission to reduce the possible delay and packet loss.

  1. Click the "VLAN > Voice VLAN > Property" in the navigation bar as follows.

AIRLIVE L3POE-XGS4804-400 - OUI of Voice VLAN - 1

text_image State Enable VLAN None CoS / 802.1p Remarking Enable 6 Aging Time 1440 Min (30 - 65536, default 1440)

Apply

Interface data are as follows.

Configuration ItemsDescription
StateCheck and enable the Voice VLAN
VLANSpecify the VLAN ID added ranging from 1 to 4,094, e.g. 1-3, 5, 7 and 9, with VLAN 1 by default. Other VLANs must be added in an untagged way to the port needing links.
CoS / 802.1p RemarkingWhether to redefine the Voice VLAN message priority or not
Aging TimeTable aging time

Port Setting Table

Q

EntryPortStateModeQoS Policy
1GE1DisabledAutoVoice Packet
2GE2DisabledAutoVoice Packet
3GE3DisabledAutoVoice Packet
4GE4DisabledAutoVoice Packet
5GE5DisabledAutoVoice Packet
6GE6DisabledAutoVoice Packet
7GE7DisabledAutoVoice Packet

Edit Port Setting

AIRLIVE L3POE-XGS4804-400 - Edit Port Setting - 1

text_image Port GE1 State Enable Mode Auto Manual QoS Policy Voice Packet All

Apply

Close

Interface data are as follows.

Configuration ItemsDescription
PortEnabled Voice VLAN port
StateCheck and enable the Voice VLAN
ModeVoice VLAN port can be operated in auto mode and manual mode.
QoS PolicySelect the message to be affected by QoS
  1. Click the "VLAN > Voice VLAN > Voice OUI" in the navigation bar to configure the address segment of OUI of Voice VLAN as follows:

Voice OUI Table

AIRLIVE L3POE-XGS4804-400 - Voice OUI Table - 1

text_image Showing All entries Showing 1 to 8 of 8 entries OUI Description 00:E0:BB 3COM 00:03:6B Cisco 00:E0.75 Veritel 00:D0:1E Pingtel 00:01:E3 Siemens 00:60:B9 NEC/Phillips 00:0F:E2 H3C 00:09:6E Avaya Add Edit Delete First Previous 1 Next Last

Add Voice OUI

AIRLIVE L3POE-XGS4804-400 - Add Voice OUI - 1

text_image OUI Description Apply Close
  1. Fill in corresponding configuration items.
  2. "Apply" and finish as follows.

Voice OUI Table

AIRLIVE L3POE-XGS4804-400 - Voice OUI Table - 1

text_image Showing All entries Showing 1 to 9 of 9 entries OUI Description 00:E0:BB 3COM 00:03:6B Cisco 00:E0:75 Veritel 00:D0:1E Pingtel 00:01:E3 Siemens 00:60:B9 NEC/Philips 00:0F:E2 H3C 00:09:6E Avaya 98:00:36 H7650 First Previous 1 Next Last Add Edit Delete

For example, configure the Voice VLAN in manual mode so that the ports accessing IP telephony can ingress/egress the Voice VLAN and transmit voice flow within it. Create VLAN2 to operate Voice VLAN securely, which allows only Voice Data to flow through. IP telephony transmits Untagged voice flow to GE1, the ingress Trunk port. Users must customize an OUI (0011-2231-05e1) and configure the Voice VLAN networking diagram in automatic mode.

AIRLIVE L3POE-XGS4804-400 - Voice OUI Table - 2

flowchart
graph TD
    A["Device A"] -->|VLAN2| B["Internet"]
    C["010-1001\nOUI:0011-2200-0000\nMask:ffff-ff00-0000"] --> A
    D["Device B"] --> E["Internet"]
    E --> F["Device B"]

Instructions:

  1. Create a VLAN to recognize the VLANs where employees belong. Click the "VLAN > VLAN > Create VLAN" in the navigation bar to add VLAN 2 to the VLAN list on the right. "Apply" and finish:

AIRLIVE L3POE-XGS4804-400 - Instructions: - 1

text_image VLAN Available VLAN VLAN 3 VLAN 4 VLAN 5 VLAN 6 VLAN 7 VLAN 8 VLAN 9 VLAN 10 Created VLAN VLAN 1 VLAN 2 Apply

VLAN Table
AIRLIVE L3POE-XGS4804-400 - Instructions: - 2

text_image Showing All entries Showing 1 to 2 of 2 entries VLAN Name Type VLAN Interface State ○ 1 default Default Disabled ○ 2 VLAN0002 Static Disabled First Previous 1 Next Last Edit Delete
  1. Configure the Ethernet interface GE1 of Switch A in Hybrid mode. Click the "VLAN > VLAN > Port Setting" in the navigation bar, "Edit" GE1 in Hybrid mode:

Port Setting Table

EntryPortModePVIDAccept Frame TypeIngress FilteringUplinkTPID
1GE1Hybrid1AllEnabledDisabled0x8100
  1. Click the "VLAN > Voice VLAN > Voice OUI" in the navigation bar to configure and add the range of OUI MAC address, and enter the first 24 bits of MAC address of voice device: 00:11:22. "Apply" and finish as follows:

Voice OUI Table
AIRLIVE L3POE-XGS4804-400 - Instructions: - 3

text_image Showing All entries Showing 1 to 1 of 1 entries OUI Description 00:11:22 aaa Add Edit Delete First Previous 1 Next Last
  1. Enable the Voice VLAN of port GE1. Click the "VLAN > Voice VLAN > Property" in the navigation bar to enable the global configuration, select VLAN2. Select port GE1 in the configuration list, "Edit" and enable the auto mode. "Apply" and finish as follows:

AIRLIVE L3POE-XGS4804-400 - Instructions: - 4

text_image State Enable VLAN VLAN0002 CoS / 802.1p Remarking Enable 6 Aging Time 1440 Min (30 - 65536, default 1440) Apply

Port Setting Table

EntryPortStateModeQoS Policy
1GE1EnabledAutoVoice Packet
2GE2DisabledAutoVoice Packet

Note:

- With the auto mode enabled, ports will forward Voice VLAN messages even though there is no port in VLAN2.

7.3 Protocol VLAN

Protocol VLAN distributes different VLAN IDs according to the protocol (family) type and encapsulation format of the messages received by the interfaces.

Administrators should prepare the mapping scheme between the protocol domain of Ethernet frame and VLAN ID which will be added if untagged frames are received. Strength: Such division method will enhance the management and maintenance by binding the network services and VLANs. Shortcomings: Initial configuration of the mapping relation scheme is necessary. Address formats of protocols should be analyzed and converted, thus leading to a lower speed due to many resources consumed. Instructions:

  1. Click the "VLAN > Protocol VLAN > Protocol Group" in the navigation bar as follows:

Protocol Group Table

AIRLIVE L3POE-XGS4804-400 - Protocol Group Table - 1

text_image Showing All entries Showing 1 to 1 of 1 entries Group ID Frame Type Protocol Value 1 Ethernet_II 0x8888 Add Edit Delete First Previous 1 Next Last

Add Protocol Group

AIRLIVE L3POE-XGS4804-400 - Add Protocol Group - 1

text_image Group ID 2 Frame Type Ethernet_II Protocol Value 0x (0x600 ~ 0xFFFE) Apply Close

Interface data are as follows.

Configuration ItemsDescription
Group IDProtocol VLAN Group
Frame TypeFrame types: Ether2, LLC, RFC 1042
Protocol ValueIt ranges from 0x600 to 0xFFFE
  1. Fill in corresponding configuration items.
  2. "Apply" and finish.

Protocol Group Table

AIRLIVE L3POE-XGS4804-400 - Protocol Group Table - 1

text_image Showing All entries Showing 1 to 2 of 2 entries Group ID Frame Type Protocol Value 1 Ethernet_II 0x8888 2 RFC_1042 0x8889 Add Edit Delete First Previous 1 Next Last
  1. Click the "VLAN > Protocol VLAN > Group Binding" in the navigation bar to bind the protocol No., port No. and VLAN ID, to bring the configuration into effect as follows:

Group Binding Table

AIRLIVE L3POE-XGS4804-400 - Group Binding Table - 1

text_image Showing All entries Showing 1 to 1 of 1 entries Port Group ID VLAN GE1 1 10 Add Edit Delete First Previous 1 Next Last

Description:

Configure the matching protocols IPv4 and IPv6, as well as the ARP protocol.

For example, PC1 and 3 can access mutually, with IPv4 communication protocol binding with VLAN10. PC2 and 4 can access mutually, with IPv6 communication protocol binding with VLAN20.

Networking diagram of protocol VLAN division

AIRLIVE L3POE-XGS4804-400 - Description: - 1

flowchart
graph TD
    PC3["PC3\nIPV4\nVLAN10"] -->|ge1/2| SwitchB["SwitchB"]
    SwitchB -->|ge1/3| PC4["PC4\nIPV6\nVLAN20"]
    SwitchB -->|ge1/1| PC1["PC1\nIPV4\nVLAN10"]
    SwitchB -->|ge1/1| SwitchA["SwitchA"]
    SwitchA -->|ge1/3| PC2["PC2\nIPV6\nVLAN20"]

Instructions:

  1. Create a VLAN to recognize the VLANs where employees belong. Click the "VLAN > VLAN > Create VLAN", add the VLAN10 and 20 to the VLAN Creating List on the right, "Apply" and finish:

AIRLIVE L3POE-XGS4804-400 - Instructions: - 1

text_image VLAN Available VLAN VLAN 2 VLAN 3 VLAN 4 VLAN 5 VLAN 6 VLAN 7 VLAN 8 VLAN 9 Created VLAN VLAN 1 VLAN 10 VLAN 20

Apply

VLAN Table

VLANNameTypeVLAN Interface State
1defaultDefaultDisabled
10VLAN0010StaticDisabled
20VLAN0020StaticDisabled
  1. Configure GE2 and GE3 interfaces of Switch A in Hybrid mode. Click the "VLAN > VLAN > Port Setting", "Edit" the interfaces in Hybrid mode:

Port Setting Table

EntryPortModePVIDAccept Frame TypeIngress FilteringUplinkTPID
1GE1Trunk1AllEnabledDisabled0x8100
2GE2Hybrid1AllEnabledDisabled0x8100
3GE3Hybrid1AllEnabledDisabled0x8100
4GE4Trunk1AllEnabledDisabled0x8100
5GE5Trunk1AllEnabledDisabled0x8100
  1. Add the Untagged GE2 and GE3 to VLAN10 and VLAN20 respectively. Click the "VLAN > VLAN > VLAN Configuration", drop down the list to choose VLAN10 and the Untagged GE2 port. Following the same steps, add the untagged GE3 to VLAN20 as follows:

VLAN Configuration Table

VLAN VLAN0010

AIRLIVE L3POE-XGS4804-400 - VLAN Configuration Table - 1

EntryPortModeMembershipPVIDForbidden
1GE1Trunk● Excluded○ Tagged○ Untagged
2GE2Hybrid○ Excluded○ Tagged● Untagged
3GE3Hybrid● Excluded○ Tagged○ Untagged

VLAN Configuration Table

VLAN VLAN0020

AIRLIVE L3POE-XGS4804-400 - VLAN Configuration Table - 1

EntryPortModeMembershipPVIDForbidden
1GE1Trunk● Excluded○ Tagged○ Untagged
2GE2Hybrid● Excluded○ Tagged○ Untagged
3GE3Hybrid○ Excluded○ Tagged● Untagged
4GE4Trunk● Excluded○ Tagged○ Untagged
  1. Add the Untagged GE2 and GE3 interfaces of Switch B to VLAN whose ports need links. Steps are like step 2 and 3.
  2. Add the Tagged GE1 interface of Switch A to VLAN10 and 20. Click the "VLAN > VLAN > VLAN Configuration", drop down the list to select VLAN10 and the Tagged member of GE1. Configure VLAN20 similarly.

VLAN Configuration Table

VLAN VLAN0010

AIRLIVE L3POE-XGS4804-400 - VLAN Configuration Table - 1

EntryPortModeMembershipPVIDForbidden
1GE1Trunk○ Excluded● Tagged○ Untagged

VLAN Configuration Table

VLAN VLAN0020

AIRLIVE L3POE-XGS4804-400 - VLAN Configuration Table - 1

EntryPortModeMembershipPVIDForbidden
1GE1Trunk○ Excluded● Tagged○ Untagged
  1. Related protocol and VLAN. VLAN IDs are assigned according to the protocol (family) type and encapsulation format of the messages received by interfaces. Click the "VLAN > Protocol VLAN > Protocol Group" in the navigation bar to add 2 rules for

protocol groups:

Protocol Group Table

AIRLIVE L3POE-XGS4804-400 - Protocol Group Table - 1

text_image Showing All entries Showing 1 to 2 of 2 entries Group ID Frame Type Protocol Value 1 Ethernet_II 0x0800 2 Ethernet_II 0x86DD Add Edit Delete First Previous 1 Next Last
  1. Port, protocol group, and VLAN binding. Click the "VLAN > Protocol Group > Group Binding", "Add" to bind GE2 and binding group ID1 with VLAN10, and to bind GE3 and binding group ID2 with VLAN20:

Group Binding Table

AIRLIVE L3POE-XGS4804-400 - Group Binding Table - 1

text_image Showing All entries Showing 1 to 2 of 2 entries Port Group ID VLAN GE2 1 10 GE3 2 20 Add Edit Delete First Previous 1 Next Last

7.4 MAC VLAN

MAC-based VLANs are divided subject to the MAC addresses in the network card. Administrators will prepare the mapping scheme between MAC address and VLAN ID which will be added if the switch receives untagged frames.

Strength: There is no need to re-configure VLAN when the physical location of a terminal user changes, which ensures user security and access flexibility. Shortcoming: It applies to the scene where network card and simple network environment are infrequently replaced, with members defined in advance.

Instructions:

  1. Click the "VLAN > MAC VLAN > MAC Group" in the navigation bar, and "Add" a new MAC group as follows:

MAC Group Table

AIRLIVE L3POE-XGS4804-400 - MAC Group Table - 1

text_image Showing All entries Showing 1 to 1 of 1 entries Group ID MAC Address Mask 1 00:0A:5A:00:00:00 24 Add Edit Delete First Previous 1 Next Last

AIRLIVE L3POE-XGS4804-400 - MAC Group Table - 2

text_image Group ID 2 (1 - 2147483647) MAC Address 00:22:00:22:00:22 Mask 48 × (9 - 48)

AIRLIVE L3POE-XGS4804-400 - MAC Group Table - 3

Interface data are as follows.

Configuration ItemsDescription
Group IDMAC VLAN Group ID
MAC AddressThe MAC address to be bound with VLAN
MaskIt indicates the MAC address port. Enter 48 if it is an exa match. Others should be consistent with the masks of IP addresses.

For example, a company with high info security requirements allows its PCs only to access the internal network. As is shown, switch GE1 connects the uplink ports of Switch A while its downstream ports connect PC1, 2 and 3. As a result, PC1, 2 and 3 can access the internal network through Switch A and Switch, while other PCs can't.

Configuration logic: following steps are used to divide the VLAN based on MAC address.

  1. Create a relevant VLAN.
  2. Add Ethernet interfaces to the VLAN in a correct way.
  3. Connect the VLAN with the MAC addresses of PC1, 2 and 3.

Data preparation: following data should be prepared for the configuration instance:

  • Set GE1 PVID of 100 on the switch.
  • Set GE1 to access VLAN10 in the Untagged way on the switch.
  • Set GE2 to access VLAN10 in the Tagged way on the switch.
  • Set the Switch A interface by default, namely all interfaces will be added to VLAN1 in an Untagged way.
  • Connect the MAC addresses of PC1, 2 and 3 with VLAN10.

Draw a networking diagram for VLAN division based on MAC addresses: Instructions:

  1. Create a VLAN to recognize the VLANs where employees belong. Click the "VLAN > VLAN > Create VLAN" in the navigation bar, add VLAN10 to the VLAN Creating List on the right, "Apply" and finish as follows:

VLAN Table

Showing All ▼ entries

Showing 1 to 3 of 3 entries

AIRLIVE L3POE-XGS4804-400 - VLAN Table - 1

VLANNameTypeVLAN Interface State
1defaultDefaultDisabled
10VLAN0010StaticDisabled
100VLAN0100StaticDisabled
  1. Configure Switch's GE1 in Hybrid mode with PVID of 100 to serve as an Untagged member of VLAN10. Configure GE2 in Trunk mode to serve as a Tagged member of VLAN10.

Port Setting Table

EntryPortModePVIDAccept Frame TypeIngress FilteringUplinkTPID
1GE1Hybrid100AllEnabledDisabled0x8100
2GE2Trunk1AllEnabledDisabled0x8100

Membership Table

EntryPortModeAdministrative VLANOperational VLAN
Og1GE1Hybrid1U, 10U, 100P1U, 10U, 100P
Og2GE2Trunk1UP, 10T1UP, 10T
Og3GE3Trunk1UP1UP
  1. Configure the Switch A's interfaces by default, namely all interfaces access VLAN1 in an Untagged way. Connect the MAC addresses of PC1, 2 and 3 with VLAN10. Click the "VLAN > MAC VLAN > MAC Group" in the navigation bar, enter the MAC addresses of PC1 (0022-0022-0022), PC2 (0033-0033-0033) and PC3 (0044-0044-0044), with the mask of 48-bit exact match as follows:

MAC Group Table

AIRLIVE L3POE-XGS4804-400 - MAC Group Table - 1

text_image Showing All entries Showing 1 to 3 of 3 entries Group ID MAC Address Mask 1 00:22:00:22:00:22 48 2 00:33:00:33:00:33 48 3 00:44:00:44:00:44 48 Add Edit Delete First Previous 1 Next Last
  1. Click the "VLAN > MAC VLAN > Group Binding" in the navigation bar, "Add" to select the Hybrid port only, MAC group ID to be bound, and specified VLAN ID. "Apply" and finish:

MAC Group Table
AIRLIVE L3POE-XGS4804-400 - MAC Group Table - 2

text_image Showing All entries Showing 1 to 3 of 3 entries Group ID MAC Address Mask 1 00:22:00:22:00:22 48 2 00:33:00:33:00:33 48 3 00:44:00:44:00:44 48 Add Edit Delete First Previous 1 Next Last

5. Configuration verification

Only PC1, 2 and 3 have access to the internal network.

7.5 Surveillance VLAN

Surveillance VLAN is mainly used for video stream packets. In order to ensure the priority of such packets in the transmission process, it is higher than ordinary packets. Instructions:

  1. Click the "VLAN > Surveillance VLAN > Property" in the navigation bar as follows.

AIRLIVE L3POE-XGS4804-400 - Surveillance VLAN - 1

text_image State Enable VLAN None CoS / 802.1p Remarking Enable 6 Aging Time 1440 Min (30 - 65536, default 1440)

Apply

Configuration ItemsDescription
StateCheck and enable the Surveillance VLAN
VLANSpecify the VLAN ID added ranging from 1 to 4,094, e.g. 1-3, 5, 7 and 9, with VLAN 1 by default. Other VLANs must be added in an untagged way to the port needing links.
CoS / 802.1p RemarkingWhether to redefine the Voice VLAN message priority or not
Aging TimeTable aging time

Port Setting Table

AIRLIVE L3POE-XGS4804-400 - Port Setting Table - 1

EntryPortStateModeQoS Policy
1GE1DisabledAutoVideo Packet
2GE2DisabledAutoVideo Packet
3GE3DisabledAutoVideo Packet
4GE4DisabledAutoVideo Packet
5GE5DisabledAutoVideo Packet
6GE6DisabledAutoVideo Packet
7GE7DisabledAutoVideo Packet

Edit Port Setting

AIRLIVE L3POE-XGS4804-400 - Edit Port Setting - 1

text_image Port GE1-GE2 State Enable Mode Auto Manual QoS Policy Video Packet All

AIRLIVE L3POE-XGS4804-400 - Edit Port Setting - 2

Interface data are as follows.

Configuration ItemsDescription
PortEnabled Voice VLAN port
StateCheck and enable the Surveillance VLAN
ModeSurveillance VLAN port can be operated in auto mode and manual mode.
QoS PolicySelect the message to be affected by QoS
  1. Click the "VLAN > Surveillance VLAN > Surveillance OUI" in the navigation bar to configure the address segment of OUI of Surveillance VLAN as follows:

Surveillance OUI Table

AIRLIVE L3POE-XGS4804-400 - Surveillance OUI Table - 1

text_image Showing All entries Showing 0 to 0 of 0 entries OUI Description 0 results found. Add Edit Delete First Previous 1 Next Last

Add Voice OUI

AIRLIVE L3POE-XGS4804-400 - Add Voice OUI - 1

text_image OUI Description Apply Close
  1. Fill in corresponding configuration items.
  2. "Apply" and finish as follows.

Surveillance OUI Table

AIRLIVE L3POE-XGS4804-400 - Surveillance OUI Table - 1

text_image Showing All entries Showing 1 to 1 of 1 entries OUI Description 98:00:36 H7650 Add Edit Delete First Previous 1 Next Last

7.6 GVRP

GVRP VLAN registration protocol is an application of general attribute registration protocol, which provides 802.1Q compatible VLAN pruning function and dynamic VLAN establishment on 802.1Q trunk port trunk port.

GVRP switches can exchange VLAN configuration information with each other, cut unnecessary broadcast and unknown unicast traffic, and create and manage VLAN dynamically on switches connected through 802.1Q trunk.

GID and GIP are used in GVRP, which provide the general state mechanism description and information dissemination mechanism for GARP based applications respectively. GVRP only runs on 802.1Q trunk links. GVRP cuts off the trunk link so that only the active VLAN is transmitted on the trunk connection. Before GVRP adds a VLAN to the trunk line, it first receives the join information from the switch. GVRP update information and timer can be changed. The GVRP ports have a variety of operating modes to control how they tailor VLANs. GVRP can dynamically add and manage VLAN for VLAN database

GVRP supports the propagation of VLAN information between devices. In GVRP, the VLAN information of a switch can be configured manually, and all other switches in the network can dynamically understand the VLANs. The terminal node can access any switch and connect to the required VLAN. In order to use GVRP, a GVRP compatible network interface card (NIC) should be installed. GVRP compatible NIC can be configured to join the required VLAN, and then access to a GVRP enabled switch. The

communication connection between NIC and switch is established, and VLAN connectivity is realized between NIC and switch.

7.6.1 Property

Global and port configuration

Instructions:

  1. Click the "VLAN > GVRP > Property" in the navigation bar as follows.

AIRLIVE L3POE-XGS4804-400 - Property - 1

text_image State Enable Operational Timeout Join 20 cs (2 - 16375, default 20) Leave 60 cs (45 - 32760, default 60) LeaveAll 1000 cs (65 - 32765, default 1000)

AIRLIVE L3POE-XGS4804-400 - Property - 2

Interface data are as follows.

Configuration ItemsDescription
StateThe GVRP feature is globally enabled by setting
JoinA value in the range of 2-16375cs, i.e. in units of one hundredth of a second. The default value is 20cs.
leavea value in the range of 45-32760cs, i.e. in units of one hundredth of a second. The default is 60cs.
LeaveAlla value in the range of 65-32765cs, i.e. in units of one hundredth of a second. The default is 1000cs.
  1. Click the "VLAN > GVRP > Property" in the navigation bar, select the port and "Edit" to enter the configuration interface as follows.

Port Setting Table

AIRLIVE L3POE-XGS4804-400 - Port Setting Table - 1

EntryPortStateVLAN CreationRegistration
1GE1DisabledEnabledNormal
2GE2DisabledEnabledNormal
3GE3DisabledEnabledNormal
4GE4DisabledEnabledNormal
5GE5DisabledEnabledNormal
6GE6DisabledEnabledNormal
7GE7DisabledEnabledNormal
8GE8DisabledEnabledNormal

Edit Port Setting

AIRLIVE L3POE-XGS4804-400 - Edit Port Setting - 1

text_image Port GE1-GE2 State Enable VLAN Creation Enable Registration Normal Fixed Forbidden

AIRLIVE L3POE-XGS4804-400 - Edit Port Setting - 2

Interface data are as follows.

Configuration ItemsDescription
PortPort list
StateEnable or disable the GVRP function of the port
VLAN CreationEnable or disable to create VLAN automatically
RegistrationThree registration modes of GVRPNormal: Allow dynamic VLAN to register on the port, and send declaration messages of static VLAN and dynamic VLAN at the same timeFixed: Dynamic VLAN is not allowed to register on the port, only static VLAN declaration messages are sentForbidden: Dynamic VLAN is not allowed to register on the port. At the same time, all VLANs except vlan1 on the port are deleted, and only vlan1 declaration message is sent

7.6.2 Membership

View GVRP dynamic member information Instructions:

  1. Click the "VLAN > GVRP > Membership" in the navigation bar as follows.

Membership Table
AIRLIVE L3POE-XGS4804-400 - Membership - 1

text_image Showing All entries Showing 0 to 0 of 0 entries VLAN Member Dynamic Member Type 0 results found. First Previous 1 Next Last

7.6.3 Statistics

View port GVRP message statistics Instructions:

  1. Click the "VLAN > GVRP > Statistics" in the navigation bar as follows.

AIRLIVE L3POE-XGS4804-400 - Statistics - 1

text_image Port GE1 Statistics All Receive Transmit Error Refresh Rate None 5 sec 10 sec 30 sec Clear
Receive
Join empty0
Empty0
Leave Empty0
Join In0
Leave In0
Leave All0

8 MAC Address Table

Ethernet switches are mainly innovated to forward according to the purposes in the

data link layer. That is, MAC address will transmit the messages to corresponding ports according to the purposes. MAC address forwarding table is a L2 table illustrating MAC addresses and forwarding ports, which is the basis of fast forwarding of L2 messages.

MAC address forwarding table contains following data:

  • Destination MAC Address
    ● VLAN ID belonging to port
  • Forwarding ingress No. of this device

There are two message forwarding types according to MAC address table info:

  • Unicast mode: the switch directly transmits the messages from the table's egress when MAC address forwarding table contains corresponding entries with the destination MAC address.
  • Broadcast mode: When the switch receives the messages with the destination address full of F-bits, or there is no entry corresponding to the MAC destination address in the forwarding table, the switch will forward the messages to all ports excluding the receiving port in this way.

8.1 Dynamic Address

Aging time and table info of MAC addresses can be configured and checked on this page.

MAC address table needs constant updates to cater to network changes. It automatically generates entries that are limited by their lifetime (i.e. aging time). Those entries not refreshed after expiration will be deleted. The aging time of an entry will be recalculated if its record is refreshed before expiration.

Proper aging time helps to achieve the aging target of MAC address. Shortage of aging time may lead many switches broadcast to discover the packets of destination MAC addresses, thus influencing the switch performance.

Aging too long can cause the switch to save outdated MAC address entries, thus exhausting the forwarding resources and failing to update the forwarding table based on network changes.

The switch may remove valid MAC address table entries due to too short aging time, thus reducing forwarding efficiency. In general, the aging time recommended is 300 seconds by default.

Instructions for aging time setting:

  1. Click the "MAC Address Table > Dynamic Address" in the navigation bar to the configuration and view interface:

AIRLIVE L3POE-XGS4804-400 - Dynamic Address - 1

text_image Aging Time 300 Sec (10 - 630, default 300)

AIRLIVE L3POE-XGS4804-400 - Dynamic Address - 2

Dynamic Address Table

VLANMAC AddressPort
100:0B:0E:0F:00:EDGE3
100:CF:E0:52:B0:4FGE3
100:CF:E0:52:B0:8BGE3
100:E0:4C:00:53:35GE3
100:E0:4C:2E:2C:B3GE3
100:E0:4C:2E:2C:DDGE7
100:E0:4C:2E:2D:4CGE3
100:E0:4C:93:C3:00GE3
100:E0:4D:36:99:E4GE3
100:E0:66:70:A6:CBGE3

AIRLIVE L3POE-XGS4804-400 - Dynamic Address - 3

text_image Refresh Add Static Address First Previous 1 2 3 4 5 Next Last

Interface data are as follows

Configuration ItemsDescription
MAC Aging TimeEnter the aging time of MAC address
  1. Fill in corresponding configuration items.
  2. "Apply" and finish.

MAC Table stores the MAC address, VLAN No., Ingress/Egress info, etc. that are learned by switches. When forwarding data, it will fast locate the device egress in accordance with the destination MAC address and VLAN No. query table of Ethernet frames.

To check the MAC address table, see Section 3.3 of Chapter 3

8.2 Static Address

Static table is manually configured by users and distributed to each interface board, which won't age.

Instructions:

  1. Click the "MAC Address Table > Static Address" as follows:

Static Address Table
AIRLIVE L3POE-XGS4804-400 - Static Address - 1

text_image Showing All entries Showing 1 to 1 of 1 entries VLAN MAC Address Port 1 00:00:11:11:22:22 GE3 Add Edit Delete First Previous 1 Next Last

Add Static Address

AIRLIVE L3POE-XGS4804-400 - Static Address - 2

text_image MAC Address 00:00:11:11:22:22 VLAN 10 × (1 - 4094) Port GE1 ✓ Apply Close

Interface data are as follows.

Configuration ItemsDescription
MACRequired. Enter the new MAC address e.g.: HH:HH:HH:HH:HH:HH
VLANRequired. Specify the VLAN ID
PortRequired. Select the interface type and enter the interface name Description: it must be the member port of the configured VLANs.
  1. Fill in corresponding configuration items.
  2. "Apply" and finish.

8.3 Filtering Address

The switch discards the matched data frame by configuration Instructions:

  1. Click the "MAC Address Table > Filtering Address" as follows:

Filtering Address Table
AIRLIVE L3POE-XGS4804-400 - Filtering Address - 1

text_image Showing All entries Showing 0 to 0 of 0 entries VLAN MAC Address 0 results found. Add Edit Delete First Previous 1 Next Last

Add Filtering Address

AIRLIVE L3POE-XGS4804-400 - Add Filtering Address - 1

text_image MAC Address VLAN (1 - 4094) Apply Close

Interface data are as follows.

Configuration ItemsDescription
MAC AddressMAC address to be filtered
VLANVLAN of MAC address

8.4 Port Security Address

If the MAC address is set to secure Mac, the port only allows the data frames of the secure Mac to pass through forever, and the others will be discarded Instructions:

  1. Click the "MAC Address Table > Port Security Address" as follows:

Port Security Address Table

AIRLIVE L3POE-XGS4804-400 - Port Security Address Table - 1

text_image Showing All entries Showing 0 to 0 of 0 entries VLAN MAC Address Type Port 0 results found. Add Edit Delete First Previous 1 Next Last

Add Port Security Address

AIRLIVE L3POE-XGS4804-400 - Add Port Security Address - 1

text_image MAC Address VLAN (1 - 4094) Port GE1 ▼ Apply Close

Interface data are as follows.

Configuration ItemsDescription
MAC AddressMAC address for security
VLANVLAN of MAC address
PortPort ID that enables port security

9 Spanning Tree

Redundant links are often used for link backup and network reliability in the Ethernet switching network. However, such links will generate loops on the switching network, leading to broadcast storm, unstable MAC address list and other faults, thus worsening users' communication quality, or even interrupting the communication. As a result, STP (Spanning Tree Protocol) appears.

Same with the development of other protocols, from the original STP defined in IEEE 802.1D, to RSTP (Rapid Spanning Tree Protocol) defined in IEEE 802.1W and to MSTP (Multiple Spanning Tree Protocol) defined in IEEE 802.1S, STP keeps upgrading.

MSTP is compatible with RSTP and STP while RSTP is compatible with STP. The contrast among these 3 protocols is shown in the table.

The contrast among 3 protocols

STPCharacteristicApplication
STPA tree rid of loops as the solution to broadcast storms and redundant backups. It converges slowly.All VLANs can be shared without discrimination in user or business flow.
RSTPA tree rid of loops as the solution to broadcast storms and redundant backups. It converges rapidly.
MSTPA tree rid of loops as the solution to broadcast storms and redundant backups. It converges rapidly. Spanning trees balance the load among VLANs. Flow of different VLANs will be forwarded subject to paths.Distinguish the user and business flow for load sharing. Different VLANs forward the flow through separate spanning trees.

After STP is deployed, the following objectives can be achieved by calculating the loops with topology:

  • Loop elimination: eliminate possible communication loops by blocking redundant links.
  • Link backups: activate redundant links to restore network connectivity if the active path fails.

9.1 Property

Configure STP global parameters. In specific network environment, STP parameters of some devices must be adjusted to achieve the best performance.

Instructions:

  1. Click the "Spanning Tree > Property" in the navigation bar as follows:

AIRLIVE L3POE-XGS4804-400 - Property - 1

text_image State Operation Mode Path Cost BPDU Handling Enable STP RSTP MSTP Long Short Filtering Flooding Priority Hello Time Max Age Forward Delay Tx Hold Count 32768 Sec (1 - 10, default 2) 20 Sec (6 - 40, default 20) 15 Sec (4 - 30, default 15) 6 (1 - 10, default 6) Region Name Revision Max Hop 1C:2A:A3:00:34:24 0 (0 - 65535, default 0) 20 (1 - 40, default 20)

Interface data are as follows.

Configuration ItemsDescription
StateIt is checked by default to enable the spanning tree on behalf of switches.
Operation Mode3 modes are available, namely STP, RSTP and MSTP.
Path CostIn Long mode and Short mode
BPDU HandlingThe method to handle the BPDU messages received by the device
PriorityPort priority
Hello TimeIntervals between Hello messages
Max AgeMax aging time
Forward DelayForward delay time
Tx Hold CountSpecify the Tx-hold-count used to limit the maximum numbers of packets transmission per second
Region NameMST domain name. Switch master board sets the MAC address by default.Together with the VLAN mapping table of MST domain and the revision level of MSTP, switch domain name will jointly determine the domain to which it belongs.
RevisionThe MSTP revision number
Max HopSpecify the number of hops in an MSTP region before the BPDU is discarded
  1. Fill in corresponding configuration items.
  2. "Apply" and finish.

9.2 Port Setting

In specific network environment, STP parameters of some devices need to be adjusted for the best performance.

  1. Click the "Spanning Tree > Port Setting" in the navigation bar, select the port and "Edit" to configure its attributes:

Port Setting Table

EntryPortStatePath CostPriorityBPOU FilterBPOU GuardOperational EdgeOperational Point to-PointPort RolePort StateDesignated BridgeDesignated Port IDDesignated Cost
1GE1Enabled20000128DisabledDisabledDisabledDisabledDisabledDisabled0-00.00.00.00.00.00126-120000
2GE2Enabled20000128DisabledDisabledDisabledDisabledDisabledDisabled0-00.00.00.00.00.00126-220000
3GE3Enabled200000128DisabledDisabledDisabledDisabledDisabledForwarding0-00.00.00.00.00.00126-3200000
4GE4Enabled20000128DisabledDisabledDisabledDisabledDisabledDisabled0-00.00.00.00.00.00126-420000
5GE5Enabled20000128DisabledDisabledDisabledDisabledDisabledDisabled0-00.00.00.00.00.00126-520000
6GE6Enabled20000128DisabledDisabledDisabledDisabledDisabledDisabled0-00.00.00.00.00.00126-620000
7GE7Enabled200000128DisabledDisabledDisabledDisabledDisabledForwarding0-00.00.00.00.00.00126-7200000
8GE8Enabled20000128DisabledDisabledDisabledDisabledDisabledDisabled0-00.00.00.00.00.00126-820000

Edit Port Setting

AIRLIVE L3POE-XGS4804-400 - Port Setting - 1

text_image Port GE1 State Enable Path Cost 0 (0 - 200000000) (0 = Auto) Priority 128 Edge Port Enable BPDU Filter Enable BPDU Guard Enable Point-to-Point Auto Enable Disable Port State Disabled Designated Bridge 0-00:00:00:00:00:00 Designated Port ID 128-1 Designated Cost 20000 Operational Edge False Operational Point-to-Point False

Apply

Close

Interface data are as follows.

ConfigurationDescription
Items
PortThe port No. to configure attributes
StateEnable STP or not
Path CostEnter the path cost value of the interface Use IEEE 802.1t Standard with the value ranging from 0 to 200,000,000
PrioritySelect the port priority with smaller value representing higher priority.Interface priority affects the role of the interface on the specific MSTI. On different MSTI, users can configure the priorities for a same interface. As a result, flow of different VLANs can be forwarded along physical links to achieve VLAN load sharing.Description: MSTP will recalculate the interface role and migrate its state when its priority changes.
Edge PortRather than another switch or network segment, the edge port should be connected directly to user terminals. It can quickly transit to the forward state since topology changes create no loops. A edge port under configuration can be quickly transitioned to forward state by STP. To achieve this, it is recommended that Ethernet ports connected directly to user terminals should be configured as edge ports.
BPDU FilterEnable BPDU Filter or not
BPDU GuardEnable BPDU Guard or not. Unchecked by default. If BPDU Guard is enabled, the device will shut down the interfaces receiving BPD and notify the NMS. Such interfaces can only be restored manually by network administrators.
Point-to-PointSelect enabled, shutdown, and auto modes.Auto mode: it indicates the connect state between the default auto inspection and point-to-point links.Enabled mode: it indicates the specific port is connected to the point-to-point links.Shutdown mode: it indicates the specific port fails to connect the point-to-point links.
  1. Fill in corresponding configuration items.
  2. "Apply" and finish.

9.3 MST Instance

A switching network is divided into multiple domains by MSTP, with independent spanning trees formed within each domain. Each Spanning Tree is called a MSTI (Multiple Spanning Tree Instance), and each domain is called a MST Region: Multiple Spanning Tree Region).

Description:

An instance is a group of VLANs that reduces communication cost and resource utilization rate. Each instance, independently calculated with topology, can balance the load. VLANs with the same topology can be mapped to a same instance, and they are forwarded according to the port state in corresponding MSTP instances.

In simple terms, mapped to the specified MST instance, one or more VLANs are distributed to a spanning tree at a time.

Instructions:

  1. Click the "Spanning Tree > MST Instance" in the navigation bar, "Edit" the selected spanning tree instances to be configured as follows:

MST Instance Table

MSTIPriorityBridge IdentifierDesignated Root BridgeRoot PortRoot Path CostRemaining HopVLAN
003276832768-00:4F:4C:00:05:A00-00:00:00:00:00:00N/A001-4094
113276832768-00:4F:4C:00:05:A00-00:00:00:00:00:00N/A00
223276832768-00:4F:4C:00:05:A00-00:00:00:00:00:00N/A00
333276832768-00:4F:4C:00:05:A00-00:00:00:00:00:00N/A00
443276832768-00:4F:4C:00:05:A00-00:00:00:00:00:00N/A00
553276832768-00:4F:4C:00:05:A00-00:00:00:00:00:00N/A00

Edit MST Instance Setting

MSTI0
Priority32768 (0 - 61440, default 32768)
Bridge Identifier32768-00:4F:4C:00:05:A0
Designated Root Bridge0-00:00:00:00:00:00
Root Port
Root Path Cost0
Remaining Hop0

AIRLIVE L3POE-XGS4804-400 - MST Instance - 1

Interface data are as follows.

Configuration ItemsDescription
MSTIInstance No. of spanning trees ranges from 0 to 15
VLANVLAN No. mapped from instances
PrioritySet the priority of a multiple of 4,096 for the specified instance ranging from 0 to 65,535 with 32,768 as default.
  1. Fill in corresponding configuration items.
  2. "Apply" and finish as follows.

9.4 MST Port Setting

Instructions:

  1. Click the "Spanning Tree > MST Port Setting" in the navigation bar, check the port to be modified from the list of all ports of the device, "Edit" to enter the detailed configuration interface as follows:

MST Port Setting Table

EntryPortPath CostPriorityPort RolePort StateModeTypeDesignated BridgeDesignated Port IDDesignated CostRemaining Hop
1GE120000128DisabledDisabledRSTPBoundary0-00 00:00 00:00 00128-1020
2GE220000128DisabledDisabledRSTPBoundary0-00 00:00 00:00 00128-2020
3GE320000128DisabledDisabledRSTPBoundary0-00 00:00 00:00 00128-3020
4GE420000128DisabledDisabledRSTPBoundary0-00 00:00 00:00 00128-4020
5GE520000128DisabledDisabledRSTPBoundary0-00 00:00 00:00 00128-5020
6GE620000128DisabledDisabledRSTPBoundary0-00 00:00 00:00 00128-6020
7GE720000128DisabledDisabledRSTPBoundary0-00 00:00 00:00 00128-7020
8GE820000128DisabledForwardingRSTPBoundary0-00 00:00 00:00 00128-8020
9GE920000128DisabledDisabledRSTPBoundary0-00 00:00 00:00 00128-9020

Edit MST Port Setting

AIRLIVE L3POE-XGS4804-400 - Instructions: - 1

text_image MSTI 0 Port GE1-GE2 Path Cost 0 (0 - 200000000) (0 = Auto) Priority 128 Port Role Disabled Port State Disabled Mode RSTP Type Boundary Designated Bridge 0-00:00:00:00:00:00 Designated Port ID 128-1 Designated Cost 20000 Remaining Hop 20

Apply

Close

Interface data are as follows.

Configuration ItemsDescription
MSTISelect the instance for configuration through the drop-down box in the upper left.
PortSelect the port to be configured by users
Path CostEnter the path cost value of the interface Use IEEE 802.1t Standard with the value ranging from 0 to 200,000,000
PrioritySelect the port priority with smaller value representing higher priority.Interface priority affects the role of the interface on the specified MSTI. On different MSTI, users can configure the priorities for asame interface. As a result, flow of different VLANs can be forwarded along physical links to achieve VLAN load sharing.Description: MSTP will recalculate the interface role and migrate its state when its priority changes.
Port Role3 types of root ports, namely specified port, backup port and disabled port.
Port StateIncluding 3 states, namely Discarding, Forwarding and Disabled
ModeCurrent STP mode
TypeThe port types in the instance contain boundary and internal ports
  1. Fill in corresponding configuration items.

  2. "Apply" and finish.

Example of MSTP function configuration:

Switch A, B, C and D all run MSTP which introduces instances to share the load of VLAN10 and 20. MSTP can set up the VLAN mapping table to associate VLANs with spanning tree instances, and to map VLAN10 from instance 1 and VLAN20 from instance 2.

AIRLIVE L3POE-XGS4804-400 - Example of MSTP function configuration: - 1

flowchart
graph TD
    subgraph PSTI1:vlan10
        A["Switch A"] -->|gel/1| B["Switch B"]
        B -->|gel/1| C["Switch C"]
        C -->|gel/1| D["Switch D"]
        D -->|gel/1| E["PC1"]
        D -->|gel/1| F["PC2"]
        G["Root Switch:SwitchA"] --> H["Blocked port"]
    end
    I["Root Switch:SwitchB"] --> J["Blocked port"]
    style A fill:#99ccff,stroke:#333
    style B fill:#99ccff,stroke:#333
    style C fill:#99ccff,stroke:#333
    style D fill:#99ccff,stroke:#333
    style E fill:#99ccff,stroke:#333
    style F fill:#99ccff,stroke:#333

Instructions:

  1. Switch A, B, C and D create VLAN10 and 20 to configure the L2 forwarding function of the devices on the Ring. Click the "VLAN > VLAN > Create VLAN" in the navigation bar, fill in the corresponding configurations. "Apply" and finish as follows.

AIRLIVE L3POE-XGS4804-400 - Instructions: - 1

text_image VLAN Available VLAN VLAN 2 VLAN 3 VLAN 4 VLAN 5 VLAN 6 VLAN 7 VLAN 8 VLAN 9 Created VLAN VLAN 1 VLAN 10 VLAN 20 Apply

VLAN Table
AIRLIVE L3POE-XGS4804-400 - Instructions: - 2

text_image Showing All entries Showing 1 to 3 of 3 entries VLAN Name Type VLAN Interface State ○ 1 default Default Disabled ○ 10 VLAN0010 Static Disabled ○ 20 VLAN0020 Static Disabled First Previous 1 Next Last Edit Delete
  1. VLANs are added to the switch ports ingress loops. Click the "VLAN > VLAN > Membership" in the navigation bar, select the ring port to be configured, move VLAN10 and 20 to the right box and mark them with "Tagged". "Apply" and finish:

Edit Port Setting
AIRLIVE L3POE-XGS4804-400 - Instructions: - 3

text_image Port GE1 Mode Trunk Membership 10 20 1UP Forbidden Excluded Tagged Untagged PVID Apply Close
  1. Click the "Spanning Tree > Property" in the navigation bar, and choose MSTP mode as follows:

AIRLIVE L3POE-XGS4804-400 - Instructions: - 4

text_image State Enable Operation Mode STP RSTP MSTP Path Cost Long Short BPDU Handling Filtering Flooding Priority 32768 (0 - 61440, default 32768) Hello Time 2 Sec (1 - 10, default 2) Max Age 20 Sec (6 - 40, default 20) Forward Delay 15 Sec (4 - 30, default 15) Tx Hold Count 6 (1 - 10, default 6) Region Name 00:4F:4C:00:05:A0 Revision 0 (0 - 65535, default 0) Max Hop 20 (1 - 40, default 20)
  1. Configure the VLAN mapping between instance MSTI1 and MSTI2. Click the "Spanning Tree > MST Instance" to fill in corresponding parameters, and "Add" them as follows:

MST Instance Table

MSTIPriorityBridge IdentifierDesignated Root BridgeRoot PortRoot Path CostRemaining HopVLAN
03276832768-00.4F.4C:00:05:A00-00:00:00:00:00:00N/A001-9,11-19,21-4094
13276832768-00.4F.4C:00:05:A00-00:00:00:00:00:00N/A0010
23276832768-00.4F.4C:00:05:A00-00:00:00:00:00:00N/A0020
33276832768-00.4F.4C:00:05:A00-00:00:00:00:00:00N/A00

Note:

  • Set the priority of MSTI1 to 0 and MSTI2 to 4,096 before configuring Switch A.
  • Set the priority of MSTI1 to 4,096 and MSTI2 to 0 before configuring Switch B.
    ● The priority must be a multiple of 4,096.

  • Switch B serves as the root bridge of MSTI2 and the backup root bridge of MSTI1 in the domain. Please refer to 5 for instructions.

  • The tree-shaped network will eliminate loops.

9.5 Statistics

Instructions:

  1. Click the "Spanning Tree > Statistics" in the navigation bar, entry port statistics as follows:

Statistics Table

EntryPortReceive BPDUTransmit BPDU
ConfigTCNMSTPConfigTCNMSTP
1GE1000000
2GE2000000
3GE3000000
4GE4000000
5GE5000000
6GE6000000
7GE7000000

10 Discovery

LLDP (Link Layer Discovery Protocol) is defined in IEEE 802.1ab. It is a standard L2 discovery method which integrates the info such as management addresses, device and interface identifications of local network devices and transmits to the neighbor devices. After receiving the info, they will save it in form of standard MIB (Management Information Base) for NMS query and link communication judgment.

It can also integrate the info and transmit to its own remote devices. The info received by the local network device will be kept in the form of MIB. The following shows how it works.

Block diagram of LLDP principles

AIRLIVE L3POE-XGS4804-400 - Discovery - 1

flowchart
graph TD
    A["Configure DHCP snooping to support Option 82 (Optional)"] <--> B["LLDP local system MIB"]
    C["Remote device customized LLDP extension MIB (Optional)"] <--> D["LLDP remote system MIB"]
    E["LLDP Agent"] --> F["Local Device Info"]
    F --> G["LLDP Frame"]
    G --> H["Remote Device Info"]
    I["Physical topology MIB (Optional)"] <--> J["Entity MIB (Optional)"]
    K["Interface MIB (Optional)"] <--> L["Other types MIB (Optional)"]
    B <--> G
    D <--> G
    F <--> G

LLDP is realized based on:

  • LLDP module updates its local system MIB, as well as the customized extension MIB, through the interaction between LLDP agent and MIBs of physical topology, entity, interface and other types.
  • Encapsulate the info of local network device into LLDP frames and transmit to the remote device.
  • Receive the LLDP frame sent by the remote device to update LLDP remote system MIB and customized extension MIB.
    ● Master the info of remote device such as connection interface and MAC address through the transmitting & receiving function of LLDP agent.
  • The local system MIB stores local device info, including device and interface IDs, system name and description, interface description, network management address, etc.
  • The remote system MIB stores local device info, including device and interface IDs, system name and description, interface description, network management address, etc.

Based on LLDP, LLDP-MED allows other units to expand. The info checked by network devices facilitates fault analysis and deepens the accurate understanding of network topology by management system.

10.1 LLDP

Instructions:

  1. Click the "Discovery > LLDP > Property" in the navigation bar as follows.

AIRLIVE L3POE-XGS4804-400 - LLDP - 1

text_image LLDP State Enable Filtering Bridging Flooding LLDP Handling TLV Advertise Interval 30 Sec (5 - 32767, default 30) Hold Multiplier 4 (2 - 10, default 4) Reinitializing Delay 2 Sec (1 - 10, default 2) Transmit Delay 2 Sec (1 - 8191, default 2) LLDP-MED Fast Start Repeat Count 3 (1 - 10, default 3)

AIRLIVE L3POE-XGS4804-400 - LLDP - 2

Interface data are as follows.

Configuration ItemsDescription
StateEnable or disable the LLDP
LLDP HandlingLLDP messages will be processed by means of “Filtering”, “Bridging” and “Flooding” when disabling the LLDP.
TLV Advertise Interval30s by default ranging from 5 to 32,768s.
Hold MultiplierTransmission period product with 4 by default ranges from 2 to 10. Transmission period * product should be no more than 65,535.
Reinitializing Delay2s by default ranging from:1 to 10s.
Transmit Delay2s by default ranging from:1 to 8,191s.
Fast Start Repeat Count3s by default of the LLDP-MED port ranging from 1 to 10s.

Ethernet message encapsulated with LLDPDU (LLDP Data Unit) are recognized as LLDP message. Each TLV is a unit of LLDPDU carried with specified info.

  1. Fill in corresponding configuration items
  2. "Apply" and finish.

10.2 Port Setting

Instructions

  1. Click the "Discovery > LLDP > Port Setting" in the navigation bar as follows.

AIRLIVE L3POE-XGS4804-400 - Port Setting - 1

EntryPortModeSelected TLV
1GE1Normal802.1 PVID
2GE2Normal802.1 PVID
3GE3Normal802.1 PVID
4GE4Normal802.1 PVID

Interface data are as follows.

Configuration ItemsDescription
PortPort list
ModeLLDP mode include: Transmit, Receive, Normal, Disable, the default is NormalTransmit: transmit LLDP messages only;Receive: receive LLDP messages only;Normal: transmit and receive LLDP messages;Disable: neither transmit nor receive LLDP messages.
Selected TLVInfo of selected TLV and VLAN

LLDP can work in 4 patterns: Transmit: transmit LLDP messages only; Receive: receive LLDP messages only; Normal: transmit and receive LLDP messages; Disable: neither transmit nor receive LLDP messages.

  1. Check corresponding port and "Edit" the port configuration. "Apply" and finish as follows.

AIRLIVE L3POE-XGS4804-400 - Port Setting - 2

text_image Port GE1 Mode ○ Transmit ○ Receive ● Normal ○ Disable Optional TLV Available TLV Selected TLV Port Description 802.1 PVID System Name System Description System Capabilities 802.3 MAC-PHY 802.1 VLAN Name Available VLAN Selected VLAN VLAN 1 Apply Close

Interface data are as follows.

Configuration ItemsDescription
PortPort list
ModeLLDP mode include: Transmit, Receive, Normal, Disable, the default is NormalTransmit: transmit LLDP messages only;Receive: receive LLDP messages only;Normal: transmit and receive LLDP messages;Disable: neither transmit nor receive LLDP messages.
Optional TLVSelect the info of TLV and VLAN
802.1 VLAN NameSelect the VLAN name

10.3 MED Network Policy

MED is based on IEEE 802.1ab. LLDP is the neighbor discovery protocol of IEEE, which can be extended by other organizations. Information identified from network devices, such as switches and wireless access points, can help with fault analysis and allow management systems to accurately understand the network topology.

Instructions

  1. Click the "Discovery > LLDP > MED Network Policy" in the navigation bar as follows.

MED Network Policy Table
AIRLIVE L3POE-XGS4804-400 - MED Network Policy - 1

text_image Showing All entries Showing 0 to 0 of 0 entries Policy ID Application VLAN VLAN Tag Priority DSCP 0 results found. Add Edit Delete First Previous 1 Next Last

Add MED Network Policy
AIRLIVE L3POE-XGS4804-400 - MED Network Policy - 2

text_image Policy ID 1 Application Voice VLAN Range (0 - 4095) VLAN Tag Tagged Untagged Priority 0 DSCP 0 Apply Close

Interface data are as follows.

Configuration ItemsDescription
Policy IDPolicy ID number
ApplicationConfigure and publish network policy TLV
VLANVLAN number
VLAN TagVLAN Mode, optional Tagged or Untagged
PriorityCoS for services
DSCPDSCP for services

10.4 MED Port Setting

Instructions

  1. Click the "Discovery > LLDP > MED Port Setting" in the navigation bar as follows.

MED Port Setting Table

AIRLIVE L3POE-XGS4804-400 - MED Port Setting Table - 1

EntryPortStateNetwork PolicyLocationInventory
ActiveApplication
1GE1EnabledYesNoNo
2GE2EnabledYesNoNo
3GE3EnabledYesNoNo
4GE4EnabledYesNoNo
5GE5EnabledYesNoNo
6GE6EnabledYesNoNo
7GE7EnabledYesNoNo

Edit MED Port Setting

AIRLIVE L3POE-XGS4804-400 - MED Port Setting Table - 2

text_image Port GE1-GE2 State Enable Optional TLV Available TLV Selected TLV Location > Network Policy Inventory Network policy Available Policy Selected Policy Available Policy > < < Location Coordinate (16 pairs of hexadecimal characters) Civic (6 - 160 pairs of hexadecimal characters) ECS ELIN (10 - 25 pairs of hexadecimal characters)

AIRLIVE L3POE-XGS4804-400 - MED Port Setting Table - 3

Interface data are as follows.

Configuration ItemsDescription
EntrySerial No. of MED port setting
PortPort list
StatePort enable status
Network PolicyConfigure and publish network policy TLV
LocationConfigure and publish location TLV
InventoryConfigure and publish inventory TLV

10.5 Packet View

Instructions

  1. Click the "Discovery > LLDP > Packet View" in the navigation bar as follows.

Packet View Table

EntryPortIn-Use (Bytes)Available (Bytes)Operational Status
1GE1381450Not Overloading
2GE2381450Not Overloading
3GE3381450Not Overloading
4GE4381450Not Overloading
5GE5381450Not Overloading
6GE6381450Not Overloading
7GE7381450Not Overloading
8GE8381450Not Overloading

10.6 Local Information

Instructions for device summary:

  1. Click the "Discovery > LLDP > Local Information" in the navigation bar as follows.

Device Summary

Chassis ID SubtypeMAC address
Chassis ID00:4F:4C:00:05:A0
System NameL3POE-XGS2404
System DescriptionL3POE-XGS2404
Supported CapabilitiesBridge, Router
Enabled CapabilitiesBridge, Router
Port ID SubtypeLocal

Instructions for port status table:

  1. Click the "Discovery > LLDP > Local Information" in the navigation bar as follows.

Port Status Table

AIRLIVE L3POE-XGS4804-400 - Port Status Table - 1

EntryPortLLDP StateLLDP-MED State
1GE1NormalEnabled
2GE2NormalEnabled
3GE3NormalEnabled
4GE4NormalEnabled
5GE5NormalEnabled
6GE6NormalEnabled

10.7 Neighbor

Instructions for LLDP neighbor displaying

  1. Click the "Discovery > LLDP > Neighbor" in the navigation bar as follows.

Neighbor Table
AIRLIVE L3POE-XGS4804-400 - Neighbor - 1

text_image Showing All entries Showing 1 to 1 of 1 entries Local Port Chassis ID Subtype Chassis ID Port ID Subtype Port ID System Name Time to Live GE9 MAC address 00:E0:41:00:00:02 Local gi13 118 Clear Refresh Detail First Previous 1 Next Last

10.8 Statistics

Instructions:

  1. Click the "Discovery > LLDP > Statistics" in the navigation bar as follows.

Global Statistics

AIRLIVE L3POE-XGS4804-400 - Global Statistics - 1

text_image Insertions 11 Deletions 7 Drops 0 AgeOuts 0 Clear Refresh

Statistics Table

EntryPortTransmit FrameReceive FrameReceive TLVNeighbor Timeout
TotalTotalDiscardErrorDiscardUnrecognized
1GE10000000
2GE20000000
3GE32782900000
4GE40000000
5GE50000000
6GE60000000

11 DHCP

DHCP Server brief introduction

With the expansion of network scale and the improvement of network complexity, network configuration is becoming more and more complex. Computer location changes (such as portable computer or wireless network) and the number of computers exceeds the IP address that can be allocated.

Dynamic Host Configuration Protocol (DHCP) is developed to meet these requirements. The DHCP protocol works in the client / server mode. The DHCP client requests the configuration information from the DHCP server dynamically, and the DHCP server returns the corresponding configuration information according to the policy.

In a typical application of DHCP, it generally includes a DHCP server and multiple clients (such as PC and laptop), as shown in Figure 1-1.

AIRLIVE L3POE-XGS4804-400 - DHCP Server brief introduction - 1

flowchart
graph TD
    A["DHCP Client"] --> B["LAN"]
    C["DHCP Client"] --> B
    D["DHCP Client"] --> B
    E["DHCP Client"] --> B
    F["DHCP Client"] --> B
    G["DHCP Client"] --> B
    H["DHCP Server"] --> I["X"]
    J["S"] --> K["Server"]

Figure 1-1. In a typical application of DHCP

IP address assignment of DHCP

IP address allocation strategy

According to the different needs of clients, DHCP provides three IP address allocation strategies

  • Manual address assignment: the administrator binds the fixed IP address for a few specific clients (such as WWW server). Send the configured fixed IP address to the client through DHCP.
    ● Automatic address assignment: DHCP assigns IP addresses with unlimited lease term to clients.
    ● Dynamic address assignment: DHCP assigns IP address with valid period to client, and client needs to re-apply for address after expiration of service life. Most clients get this dynamic address assignment.

Dynamic IP address acquisition process

The message interaction process between DHCP client and DHCP server is shown in Figure 2-1.

AIRLIVE L3POE-XGS4804-400 - Dynamic IP address acquisition process - 1

flowchart
graph TD
    A["DHCP Client"] -->|DHCP Discover| B["DHCP Server"]
    C["DHCP Client"] -->|DHCP Offer| D["DHCP Server"]
    E["DHCP Client"] -->|DHCP Request| F["DHCP Server"]
    G["DHCP Client"] -->|DHCP ACK| H["DHCP Server"]
    I["DHCP Client"] -->|DHCP Review| J["DHCP Server"]
    K["DHCP Client"] -->|DHCP ACK| L["DHCP Server"]

Figure 2-1. Interaction process

In order to obtain the legal dynamic IP address, the DHCP client interacts different information with the server at different stages. Generally, there are three modes as follows:

(1) DHCP client logs in to the network for the first time

When the DHCP client logs in to the network for the first time, it mainly establishes contact with the DHCP server through four stages

  • The discovery phase: the stage in which the DHCP client looks for the DHCP server. The client sends the DHCP discover message in broadcast mode, and only the DHCP server will respond.
  • The stage of providing IP address: that is, the stage when the DHCP server provides IP address. After receiving the DHCP discover message from the client, the DHCP server selects an unassigned IP address from the IP address pool and assigns it to the client, and sends the DHCP offer message containing the leased IP address and other settings to the client.
  • The selection stage: the stage in which the DHCP client selects the IP address. If more than one DHCP server sends a DHCP offer message to the client, the client only accepts the first received DHCP offer message, and then responds to the DHCP request message by broadcasting to each DHCP server. The information contains the content of requesting IP address from the selected DHCP server.
  • The confirmation stage: the stage in which the DHCP server confirms the IP address provided. When the DHCP server receives the DHCP request message answered by the DHCP client, it will send the dhcp-ack confirmation message containing the IP address and other settings provided by the client; otherwise, it will return the dhcp-nak message, indicating that the address cannot be assigned to the client. After receiving the dhcp-ack confirmation message returned by the server, the client will send ARP (the destination address is the address to which it is assigned) in broadcast mode for address detection. If no response is received within the specified time, the client will use this address.

(2) The DHCP client logs on to the network again

When the DHCP client logs in to the network again, it mainly establishes contact with the DHCP server through the following steps.

  • After the DHCP client logs in to the network correctly for the first time and then logs in to the network again, it only needs to broadcast the DHCP request message containing the IP address assigned last time, and it is not necessary to send the DHCP discover message again.
  • After receiving the DHCP request message, if the address requested by the client is not assigned, the dhcp-ack confirmation message will be returned to notify the DHCP client to continue using the original IP address.
  • If the IP address cannot be assigned to the DHCP client (for example, it has been assigned to other clients), the DHCP server will return a dhcp-nak

message. After receiving the message, the client sends the DHCP discover message again to request a new IP address.

(3) DHCP client extends lease validity of IP address

The dynamic IP address assigned by the DHCP server to the client usually has a certain lease term. After the expiration, the server will take back the IP address. If the DHCP client wants to continue using the address, the IP lease needs to be updated.

In practice, the DHCP client sends a DHCP request message to the DHCP server by default when the IP address lease term reaches half to complete the IP lease update. If the IP address is valid, the DHCP server will respond to the dhcp-ack message to inform the DHCP client that a new lease has been obtained.

11.1 Property

DHCP global and static binding configuration Instructions:

  1. Click the "DHCP > Property" in the navigation bar as follows.

AIRLIVE L3POE-XGS4804-400 - Property - 1

text_image State Static Binding First Enable Enable Apply

DHCP Port Setting Table

EntryPortState
1GE1Enabled
2GE2Disabled
3GE3Disabled
4GE4Disabled
5GE5Disabled
6GE6Disabled

Instructions for port DHCP configuration:

  1. Click the "DHCP > Property", and select the port and click "Edit" as follows.

Edit Port Setting
AIRLIVE L3POE-XGS4804-400 - Property - 2

text_image Port GE1-GE2 State Enable Apply Close

Note:

● Enable DHCP server or DHCP relay mode, port needs to enable this function

11.2 IP Pool Setting

DHCP IP pool configuration

Instructions:

  1. Click the "DHCP > IP Pool Setting", Click "Add" to add IP pool as follows.

IP Pool Table
AIRLIVE L3POE-XGS4804-400 - IP Pool Setting - 1

text_image Showing All entries Showing 0 to 0 of 0 entries Pool Section Gateway Mask DNS Primary Server DNS Second Server Lease time Section Start Address End Address 0 results found. Add Edit Delete First Previous Next Last

IP Pool Table
AIRLIVE L3POE-XGS4804-400 - IP Pool Setting - 2

text_image Pool Gateway Mask IP Address Section Section 1 Start Address End Address DNS Primary Server Enable DNS Second Server Enable Lease time 1 Day 00 Hour 00 Minute Apply Close (1 to 32 alphanumeric characters)

Note:

- The start address and end address cannot be configured or contain a gateway address

11.3 VLAN IF Address Group Setting

Server group configuration

Instructions:

  1. Click the "DHCP > VLAN IF Address Group Setting", enter the DHCP Server Group Table and click "Add" to configure the server group as follows.

DHCP Server Group Table
AIRLIVE L3POE-XGS4804-400 - VLAN IF Address Group Setting - 1

text_image Group ID Group IP Address Bind VLAN Interface 0 results found. Add Edit Delete

DHCP Server Group Table
AIRLIVE L3POE-XGS4804-400 - VLAN IF Address Group Setting - 2

text_image DHCP Server Group 1 Group IP Address Apply Close

VLAN interface and server group binding configuration Instructions:

  1. Click the "DHCP > VLAN IF Address Group Setting", enter the VLAN Interface Address Pool Table, select the interface and server group, and then click "Apply" as follows.

Vlan Interface Address Pool Table
AIRLIVE L3POE-XGS4804-400 - VLAN IF Address Group Setting - 3

text_image Interface MGMT VLAN DHCP Server Group Apply

11.4 Client List

Client list information

Instructions:

  1. Click the "DHCP > Client List", enter DHCP Client list as follows.

DHCP Client List
AIRLIVE L3POE-XGS4804-400 - Client List - 1

text_image Showing All entries Showing 0 to 0 of 0 entries MAC Address Table IPv4 Address VLAN Hostname 0 results found. Refresh First Previous 1 Next Last

11.5 Client Static Binding Table

Static IP address assignment configuration

Instructions:

  1. Click the "DHCP > Client Static Binding Table", enter Static Binding Table, and click "Add" as follows.

Static Binding Table
AIRLIVE L3POE-XGS4804-400 - Client Static Binding Table - 1

text_image Showing All entries Showing 0 to 0 of 0 entries MAC Address Table IPv4 Address VLAN User Name 0 results found. Add Delete First Previous 1 Next Last

Note:

- The IP configuration of static binding is required to be within the scope of IP address assignment.

12 Multicast

12.1 General

12.1.1 Property

Instructions:

  1. Click the "Multicast > General > Property" in the navigation bar as follows.

AIRLIVE L3POE-XGS4804-400 - Property - 1

text_image Unknown Multicast Action Flood Drop Forward to Router Port Multicast Forward Method IPv4 DMAC-VID DIP-VID IPv6 DMAC-VID DIP-VID

AIRLIVE L3POE-XGS4804-400 - Property - 2

12.1.2 Group Address

According to the previous request mode of multicast, the multicast router will copy and forward data to each VLAN containing receivers when users in different VLANs request the same multicast group, which wastes a great deal of bandwidth. IGMP Snooping configures multicast VLAN by connecting the different users of switch ports to a same multicast VLAN to receive multicast data. In this way, multicast flow can only be transmitted within a multicast VLAN, thus saving bandwidth. In addition, security and bandwidth are guaranteed because multicast VLANs are completely isolated from user VLANs.

Instructions

  1. Click the "Multicast > Group Address", "Add" a new static multicast item, and "Edit" the existing ones as follows:

Group Address Table

AIRLIVE L3POE-XGS4804-400 - Group Address Table - 1

text_image IP Version IPv4 Showing All entries Showing 0 to 0 of 0 entries VLAN Group Address Member Type Life (Sec) 0 results found. Add Edit Delete Refresh First Previous 1 Next Last

Add Group Address
AIRLIVE L3POE-XGS4804-400 - Group Address Table - 2

text_image VLAN IP Version IPv4 Group Address Member Available Port GE1 GE2 GE3 GE4 GE5 GE6 GE7 GE8 Selected Port Apply Close

Interface data are as follows.

Configuration ItemsDescription
VLANVLAN ID to which the multicast group belongs. Drop down to select an existing VLAN.
IP VersionWhether v4 or v6 is the version of multicast IP address
Multicast AddressEnter the multicast address
MemberAdd multicast member(s)
  1. Fill in corresponding configuration items.
  2. "Apply" and finish as follows.

Group Address Table
AIRLIVE L3POE-XGS4804-400 - Group Address Table - 3

text_image IP Version IPv4 Showing All entries Showing 1 to 1 of 1 entries VLAN Group Address Member Type Life (Sec) 1 224.1.1.111 GE1-GE8 Static Add Edit Delete Refresh First Previous 1 Next Last

12.1.3 Router Port

Configure and view multicast router port Instructions:

  1. Click the "Multicast > General > Router Port" in the navigation bar as follows.

Router Port Table

AIRLIVE L3POE-XGS4804-400 - Router Port Table - 1

text_image IP Version IPv4 Showing All entries Showing 0 to 0 of 0 entries VLAN Member Static Port Forbidden Port Life (Sec) 0 results found. Add Edit Refresh First Previous 1 Next Last

12.1.4 Forward All

Configure and view multicast forward port Instructions:

  1. Click the "Multicast > General > Forward All" in the navigation bar as follows.

Forward All Table

AIRLIVE L3POE-XGS4804-400 - Forward All Table - 1

text_image IP Version IPv4 Showing All entries Showing 0 to 0 of 0 entries VLAN Static Port Forbidden Port 0 results found. Add Edit Delete First Previous 1 Next Last

12.1.5 Throttling

Configure and view port multicast group restrictions Instructions:

  1. Click the "Multicast > General > Throttling" in the navigation bar as follows.

Throttling Table

IP Version IPv4 ▼

Q

EntryPortMax GroupExceed Action
1GE1256Deny
2GE2256Deny
3GE3256Deny
4GE4256Deny
5GE5256Deny
6GE6256Deny

12.1.6 Filtering Profile

Configure and view port multicast filtering profile Instructions:

  1. Click the "Multicast > General > Filtering Profile" in the navigation bar as follows.

Filtering Profile Table

AIRLIVE L3POE-XGS4804-400 - Filtering Profile Table - 1

text_image IP Version IPv4 Showing All entries Showing 0 to 0 of 0 entries Profile ID Start Address End Address Action 0 results found. Add Edit Delete First Previous 1 Next Last

Configure and view multicast filtering profile and port binding relationship

  1. Click the "Multicast > General > Filtering Binding" in the navigation bar as follows.

Filtering Binding Table

IP Version IPv4

Q

EntryPortProfile ID
1GE1
2GE2
3GE3
4GE4
5GE5
6GE6

12.2 IGMP Snooping

IGMP Snooping (Internet Group Management Protocol Snooping) is a constraint mechanism on L2 devices to manage and control multicast groups.

By analyzing the IGMP messages received, L2 devices establish a mapping between ports and MAC multicast addresses and forward the multicast data accordingly.

As shown below, multicast data are transmitted on L2 without IGMP snooping. When IGMP snooping runs, known multicast group data are transmitted to specified receivers while unknown multicast data are still on Layer 2.

AIRLIVE L3POE-XGS4804-400 - IGMP Snooping - 1

flowchart
graph TD
    subgraph "Multicast packet transmission without IGMP Snooping"
        A["Source"] --> B["Multicast router"]
        B --> C["Host A Receiver"]
        B --> D["Host B"]
        B --> E["Host C Receiver"]
        C --> F["Layer 2 switch"]
        D --> F
        E --> F
    end

    subgraph "Multicast packet transmission when IGMP Snooping runs"
        G["Source"] --> H["Multicast router"]
        H --> I["Host A Receiver"]
        H --> J["Host B"]
        H --> K["Host C Receiver"]
        I --> L["Layer 2 switch"]
        J --> L
        K --> L
    end

12.2.1 Property

IGMP Snooping is on the L2 switch between the multicast routers and the user hosts, applicable to deploy IPv4 networks. It is configured in a VLAN to snoop the IGMP/MLD messages transmitted between routers and hosts, and to establish a L2 forwarding table for multicast data, in order to manage and control the multicast data forwarding in L2 network.

Global IGMP Snooping function should be enabled since it is disabled by default. Instructions:

  1. Click the "Multicast > IGMP Snooping > Property", select the VLAN to be configured from the created VLAN info, and "Edit" the details as follows:

AIRLIVE L3POE-XGS4804-400 - Property - 1

text_image State □ Enable Version ● IGMPv2 ○ IGMPv3 Report Suppression ✓ Enable

AIRLIVE L3POE-XGS4804-400 - Property - 2
VLAN Setting Table

AIRLIVE L3POE-XGS4804-400 - Property - 3

VLANOperational StatusRouter Port Auto LearnQuery RobustnessQuery IntervalQuery Max Response IntervalLast Member Query CounterLast Member Query IntervalImmediate Leave
1DisabledEnabled21251021Disabled
10DisabledEnabled21251021Disabled
20DisabledEnabled21251021Disabled

Edit

Edit VLAN Setting
AIRLIVE L3POE-XGS4804-400 - Property - 4

text_image VLAN 20 State ☐ Enable Router Port Auto Learn ☑ Enable Immediate leave ☐ Enable Query Robustness 2 (1 - 7, default 2) Query Interval 125 Sec (30 - 18000, default 125) Query Max Response Interval 10 Sec (5 - 20, default 10) Last Member Query Counter 2 (1 - 7, default 2) Last Member Query Interval 1 Sec (1 - 25, default 1)
Operational Status
StatusDisabled
Query Robustness2
Query Interval125 (Sec)
Query Max Response Interval10 (Sec)
Last Member Query Counter2
Last Member Query Interval1 (Sec)

AIRLIVE L3POE-XGS4804-400 - Property - 5

Close

Interface data are as follows.

Configuration ItemsDescription
VLANVLAN ID to be configured
StateEnable or disable the IGMP Snooping in this VLAN
Router Port Auto LearnEnable or disable route port automatic learning
Immediate leaveMulticast members leave quickly
Query RobustnessThe Robustness Variable allows tuning for the expected packet loss on a network
Query IntervalThe interval between message queries
Query Max Response IntervalTimeout (over the max response time) of a query message
Last Member Query CounterMax number of queries for a specified group
Last Member Query IntervalThe interval between message queries for a specified group
  1. Fill in corresponding configuration items.
  2. "Apply" and finish.

12.2.2 Querier

Configure and view IGMP snooping Querier

Instructions:

  1. Click the "Multicast > IGMP Snooping > Querier" in the navigation bar as follows.

Querier Table

AIRLIVE L3POE-XGS4804-400 - Querier Table - 1

text_image VLAN State Operational Status Version Querier Address 1 Disabled Disabled Edit

Interface data are as follows.

Configuration ItemsDescription
VLANMulticast VLAN
StateEnable or disable IGMP snooping querier
Operational StatusIGMP snooping querier running status
VersionVersion for querier
Querier AddressMulticast address for querier

12.2.3 Statistics

Configure and view IGMP snooping statistics Instructions:

  1. Click the "Multicast > IGMP Snooping > statistics" in the navigation bar as follows.

AIRLIVE L3POE-XGS4804-400 - Statistics - 1

text_image Receive Packet Total 0 Valid 0 InValid 0 Other 0 Leave 0 Report 0 General Query 0 Special Group Query 0 Source-specific Group Query 0 Transmit Packet Leave 0 Report 0 General Query 0 Special Group Query 0 Source-specific Group Query 0 Clear Refresh

12.3 MLD Snooping

MLD snooping is the abbreviation of multicast Listener Discovery snooping. It is an IPv6 Multicast constraint mechanism running on layer 2 devices, which is used to manage and control IPv6 Multicast Groups.

The second layer device running MLD snooping establishes a mapping relationship between port and MAC multicast address by analyzing the received MLD message, and forwards IPv6 multicast data according to the mapping relationship

As shown in the figure below, when the layer 2 device does not run MLD snooping, the IPv6 multicast data packets are broadcast at layer 2; when the layer 2 device runs MLD snooping, the multicast data packets of known IPv6 Multicast groups will not be broadcast at layer 2, but will be multicast to the designated receivers at layer 2.

AIRLIVE L3POE-XGS4804-400 - MLD Snooping - 1

flowchart
graph TD
    A["Source"] --> B["Router"]
    B --> C["L2 Switch"]
    C --> D["Host A Receiver"]
    C --> E["Host B"]
    C --> F["Host C Receiver"]
    G["Source"] --> H["Router"]
    H --> I["L2 Switch"]
    I --> J["Host A Receiver"]
    I --> K["Host B"]
    I --> L["Host C Receiver"]
    M["Multicast Packets"] --> C
    M --> I

MLD snooping can only forward information to the receivers in need through layer 2 multicast, which can bring the following benefits:

  • Reduce the broadcast packets in the layer 2 network and save the network bandwidth;
    ● Enhance the security of IPv6 Multicast information;
  • It is convenient to charge each host separately.

12.3.1 Property

Global MLD Snooping function should be enabled since it is disabled by default. Instructions:

  1. Click the "Multicast > MLD Snooping > Property", select the VLAN to be configured from the created VLAN info, and "Edit" the details as follows:

AIRLIVE L3POE-XGS4804-400 - Property - 1

text_image State Version Report Suppression Enable MLDv1 MLDv2 Enable Apply

VLAN Setting Table

VLANOperational StatusRouter Port Auto LearnQuery RobustnessQuery IntervalQuery Max Response IntervalLast Member Query CounterLast Member Query IntervalImmediate Leave
1DisabledEnabled21251021Disabled

AIRLIVE L3POE-XGS4804-400 - Property - 2

text_image VLAN 1 State Enable Router Port Auto Learn Enable Immediate leave Enable Query Robustness 2 (1 - 7, default 2) Query Interval 125 Sec (30 - 18000, default 125) Query Max Response Interval 10 Sec (5 - 20, default 10) Last Member Query Counter 2 (1 - 7, default 2) Last Member Query Interval 1 Sec (1 - 25, default 1) Operational Status Status Disabled Query Robustness 2 Query Interval 125 (Sec) Query Max Response Interval 10 (Sec) Last Member Query Counter 2 Last Member Query Interval 1 (Sec)

AIRLIVE L3POE-XGS4804-400 - Property - 3

Interface data are as follows.

Configuration ItemsDescription
VLANVLAN ID to be configured
StateEnable or disable the IGMP Snooping in this VLAN
Router Port Auto LearnEnable or disable route port automatic learning
Immediate leaveMulticast members leave quickly
Query RobustnessThe Robustness Variable allows tuning for the expected packet loss on a network
Query IntervalThe interval between message queries
Query Max Response IntervalTimeout (over the max response time) of a query message
Last Member Query CounterMax number of queries for a specified group
Last Member Query IntervalThe interval between message queries for a specified group
  1. Fill in corresponding configuration items.

  2. "Apply" and finish.

12.3.2 Statistics

Configure and view MLD snooping statistics

Instructions:

  1. Click the "Multicast > MLD Snooping > statistics" in the navigation bar as follows.
Receive Packet
Total0
Valid0
InValid0
Other0
Leave0
Report0
General Query0
Special Group Query0
Source-specific Group Query0
Transmit Packet
Leave0
Report0
General Query0
Special Group Query0
Source-specific Group Query0

AIRLIVE L3POE-XGS4804-400 - Statistics - 1

12.4 MVR

In order to solve the problem of multicast traffic broadcast based on VLAN in layer 2 network, we use IGMP snooping protocol to control the receiver, that is, only the receiver can receive the multicast traffic normally.

However, IGMP snooping can only effectively control the traffic of the same multicast VLAN, but not the cross VLAN traffic. As a result, the efficiency of multiple replication of the same multicast in different VLANs still exists. In order to solve the flooding problem of cross VLAN, we adopt the dedicated multicast VLAN of multicast source traffic, as shown in the figure below

AIRLIVE L3POE-XGS4804-400 - MVR - 1

flowchart
graph TD
    A["Source"] --> B["Router"]
    B --> C["L2 Switch"]
    C --> D["Host A Receiver VLAN 10"]
    C --> E["Host B Receiver VLAN 20"]
    C --> F["Host C Receiver VLAN 30"]
    B --> G["VLAN 10, VLAN 20, VLAN 30"]
    H["Source"] --> I["Router"]
    I --> J["L2 Switch"]
    J --> K["Host A Receiver VLAN 10"]
    J --> L["Host B Receiver VLAN 20"]
    J --> M["Host C Receiver VLAN 30"]
    I --> N["VLAN 100"]
    N --> O["MVR"]
    style O fill:#f9f,stroke:#333
    note right of O Multicast Packets

12.4.1 Property

Global MVR function should be enabled since it is disabled by default.

Instructions:

  1. Click the "Multicast > MVR > Property", enter the MVR global configuration interface as follows:

AIRLIVE L3POE-XGS4804-400 - Property - 1

text_image State Enable VLAN 1 Mode Compatible Dynamic Group Start 0.0.0.0 Group Count 1 (1 - 128) Query Time 1 Sec (1 - 10) Operational Group Maximum 128 Current 0 Apply

Interface data are as follows.

Configuration ItemsDescription
StateEnable or disable MVR
VLANVLAN ID to be configured
ModeCompatible: The CPU of MVR switch normally forwards the query message of router and the join message of client form the multicast forwarding table of dynamic learning. However, the CPU will not forward the join message to the router port, so the upper router will not receive the following join message, resulting in the router data cannot be forwarded to the switch normally. In this mode, it is necessary to configure the router manually Multicast forwarding table forwards data to switchDynamic: The only difference between the dynamic mode and the compatible mode is that the CPU can forward the join message to the router port in the dynamic mode, so the upper layer router can learn the multicast forwarding table dynamically, and there is no need to manually configure the multicast forwarding table of the router to forward the data to the switch
Group StartThe starting address of the multicast group
Group CountNumber of multicast group addresses
Query TimeMulticast group query time
  1. Fill in corresponding configuration items.
  2. "Apply" and finish.

12.4.2 Port Setting

Instructions:

  1. Click the "Multicast > MVR > Port Setting", enter the MVR port setting interface as follows:

Port Setting Table

EntryPortRoleImmediate Leave
1GE1NoneDisabled
2GE2NoneDisabled
3GE3NoneDisabled
4GE4NoneDisabled
5GE5NoneDisabled
6GE6NoneDisabled

Edit Port Setting

AIRLIVE L3POE-XGS4804-400 - Edit Port Setting - 1

text_image Port GE1 Role None Receiver Source Immediate Leave Enable

AIRLIVE L3POE-XGS4804-400 - Edit Port Setting - 2

Interface data are as follows.

Configuration ItemsDescription
PortPort list
RolePort modeReceiver: Represents the port of the switch to which the multicast host is connected, which is used to receive the multicast streamSource: Source port refers to the source port of multicast flow of upper layer equipment, that is, multicast source access port
Immediate LeaveMulticast members leave quickly

12.4.3 Group Address

Instructions:

  1. Click the "Multicast > MVR > Group Address", view multicast group information as follows:

Group Address Table

AIRLIVE L3POE-XGS4804-400 - Group Address Table - 1

text_image Showing All entries Showing 0 to 0 of 0 entries VLAN Group Address Member Type Life (Sec) 0 results found. Add Edit Delete Refresh First Previous 1 Next Last

AIRLIVE L3POE-XGS4804-400 - Group Address Table - 2

text_image VLAN 1 Group Address (0.0.0.0 - 0.0.0.0) Member Available Port Selected Port Apply Close

Interface data are as follows.

Configuration ItemsDescription
VLANVLAN ID for multicast
Group AddressEnter the multicast address
MemberAdd multicast member(s)

13 Routing

The switch provides three layers of VLAN interface, which is used to communicate with network layer devices. VLANIF interface is a network layer interface, which can be configured with IP address. Before creating VLANIF interface, the corresponding VLAN should be created first. With the help of VLANIF interface, switches can communicate with other network layer devices.

13.1 IPv4 Management and Interfaces

13.1.1 IPv4 Interface

Instructions:

  1. Click the "Routing > IPv4 Management and Interfaces > IPv4 Interface", enter IPv4 layer 3 interface configuration as follows:

IPv4 Interface Table
AIRLIVE L3POE-XGS4804-400 - IPv4 Interface - 1

text_image Interface IP Address Type IP Address Mask Status VLAN 1 Static 192.168.2.1 255.255.255.0 Valid Add Delete

Add IPv4 Interface
AIRLIVE L3POE-XGS4804-400 - IPv4 Interface - 2

text_image Interface Address Type IP Address Mask VLAN Loopback Dynamic Static Network Mask Prefix Length (8 - 30) Apply Close

Interface data are as follows.

Configuration ItemsDescription
VLANVLAN ID to be configured
LoopbackLoopback interface
Address TypeDynamic: The IP address of the interface is obtained by DHCPStatic: The IP address of the interface is configured manually
IP AddressThe IP address of the interface
MaskThe IP address mask of the interface

13.1.2 IPv4 Routes

Instructions:

  1. Click the "Routing > IPv4 Management and Interfaces > IPv4 Routes", enter IPv4 static route interface configuration as follows:

IPv4 Routing Table
AIRLIVE L3POE-XGS4804-400 - Instructions: - 1

text_image Destination IP Prefix Prefix Length Route Type Next Hop Router IP Address Metric Administrative Distance Outgoing Interface 192.168.2.0 24 Directly Connected MGMT VLAN* Add Edit Delete

Add IPv4 Static Route
AIRLIVE L3POE-XGS4804-400 - Instructions: - 2

text_image IP Address Mask Network Mask Prefix Length (0 - 32) Next Hop Router IP Address Metric 1 (1 - 255, default 1) Apply Close

Interface data are as follows.

Configuration ItemsDescription
IP AddressDestination IP address segment
MaskDestination IP address mask
Next Hop Router IP AddressThe next hop IP address needs to be in the same netwc segment as the interface gateway
MetricNetwork hops

13.1.3 ARP

Instructions:

  1. Click the "Routing > IPv4 Management and Interfaces >ARP", configure and view ARP table entries as follows:

AIRLIVE L3POE-XGS4804-400 - Instructions: - 1

text_image ARP Entry Age Out 1200 Sec (15 - 21600, default 1200) Clear ARP Table Entries All Dynamic Static Normal Age Out Apply Cancel

ARP Table

InterfaceIP AddressMAC AddressStatus
VLAN 1192.168.0.2000:e0:4c:2e:2c:ddDynamic
VLAN 1192.168.1.1500:e0:4c:2e:2c:ddDynamic
VLAN 1192.168.1.7104:d4:c4:49:63:fbDynamic
VLAN 1192.168.1.80b0:6e:bf:c6:dc:1aDynamic

Add ARP
AIRLIVE L3POE-XGS4804-400 - Instructions: - 2

text_image Interface VLAN 1 ▼ Note: Only interfaces with an valid IPv4 address are available for selection IP Address MAC Address Apply Close

Interface data are as follows.

Configuration ItemsDescription
InterfaceVLANIF interface
IP AddressIP address of the same network segment as the interface gateway
MAC AddressMAC address corresponding to IP address

13.2 IPv6 Management and Interfaces

13.2.1 IPv6 Interface

Instructions:

  1. Click the "Routing > IPv6 Management and Interfaces > IPv6 Interface", enter IPv6 layer 3 interface configuration as follows:

AIRLIVE L3POE-XGS4804-400 - Instructions: - 1

text_image IPv6 Unicast Routing Enable Apply Cancel

IPv6 Interface Table

AIRLIVE L3POE-XGS4804-400 - Instructions: - 2

text_image Interface DHCPv6 Client Stateless Information Refresh Time Minimum Information Refresh Time Auto Configuration DAD Attempts 0 results found. Add Edit Delete

Add IPv6 Interface

AIRLIVE L3POE-XGS4804-400 - Instructions: - 3

text_image Interface Auto Configuration DAD Attempts VLAN ▼ Loopback Enable 1 (0 - 600, default 1) DHCPv6 Client Stateless Information Refresh Time 86400 (86400 - 4294967294, default 86400) Minimum Information Refresh Time 600 (600 - 4294967294, default 600)

Apply

Close

Interface data are as follows.

Configuration ItemsDescription
VLANVLAN ID to be configured
LoopbackLoopback interface
Auto ConfigurationAuto configuration switch
DAD AttemptsConfigure the number of times neighbor request messages are sent for duplicate address detection
StatelessStateless auto configuration
Information Refresh TimeAuto configuration refresh Time
Minimum Information Refresh TimeMinimum refresh time for auto configuration

13.2.2 IPv6 Address

Instructions:

  1. Click the "Routing > IPv6 Management and Interfaces > IPv6 Address", enter the IPv6 address configuration interface as follows:

IPv6 Address Table

Interface

VLAN 1

AIRLIVE L3POE-XGS4804-400 - IPv6 Address Table - 1

IPv6 Address TypeIPv6 AddressIPv6 Prefix LengthDAD Status
Link Localfe80::1e2a:a3ff:fe00:342464Active
Multicastff02::1:ff00:3424
Multicastff02::1
Multicastff01::1

Add

Delete

Add IPv6 Interface

AIRLIVE L3POE-XGS4804-400 - Add IPv6 Interface - 1

text_image Interface IPv6 Address Type IPv6 Address Prefix Length EUI-64 VLAN 5 Global Link Local (3 - 128) Enable

Apply

Close

Interface data are as follows.

Configuration ItemsDescription
InterfaceVLANIF interface
IPv6 Address TypeGlobal: Global IPv6 addressLink Local: Local IPv6 address
IPv6 AddressIPv6 address
Prefix LengthPrefix of IPv6 address
EUI-64Enable or disable the address derived from the IEEE802 address

13.2.3 IPv6 Routes

Instructions:

  1. Click the "Routing > IPv6 Management and Interfaces > IPv6 Routes", enter IPv6 static route interface configuration as follows:

IPv6 Routing Table
AIRLIVE L3POE-XGS4804-400 - IPv6 Routes - 1

text_image Destination IP Prefix Prefix Length Route Type Next Hop Router IP Address Metric Administrative Distance Outgoing Interface 0 results found. Add Edit Delete

Add IPv6 Static Route
AIRLIVE L3POE-XGS4804-400 - IPv6 Routes - 2

text_image IPv6 Prefix IPv6 Prefix Length (0 - 128) Next Hop Router IP Address Metric 1 (1 - 255, default 1) Apply Close

Interface data are as follows.

Configuration ItemsDescription
IPv6 PrefixDestination IPv6 address segment
IPv6 Prefix LengthDestination IPv6 address prefix
Next Hop Router IP AddressThe next hop IPv6 address needs to be in the same network segment as the interface gateway
MetricNetwork hops

13.2.4 Neighbors

Instructions:

  1. Click the "Routing > IPv6 Management and Interfaces > Neighbors", configure and view IPv6 neighbor table entries as follows:

AIRLIVE L3POE-XGS4804-400 - Instructions: - 1

text_image Clear Neighbor Table All Dynamic Static N/A Apply Cancel

IPv6 Neighbor Table
AIRLIVE L3POE-XGS4804-400 - Instructions: - 2

text_image Interface IPv6 Address MAC Address Status Router 0 results found. Add Edit Delete

Add Neighbor
AIRLIVE L3POE-XGS4804-400 - Instructions: - 3

text_image Interface IP Address MAC Address VLAN 1 ▼ Apply Close

Interface data are as follows.

Configuration ItemsDescription
InterfaceVLANIF interface
IP AddressIPv6 address of the same network segment as the interface gateway
MAC AddressMAC address corresponding to IPv6 address

13.3 Rip Routes Management

The routing information protocol (RIP) is a relatively outdated but still widely used internal gateway protocol (IGP), which is mainly used in the smaller homogeneous networks. RIP is a classical distance vector routing protocol, which appears in RFC 1058, and presents an improved RIP-2 among RFC1388, and was revised in RFC 1723 and RFC 2453.

RIP uses Bellman-For algorithm currently RIP IPv4 has two versions, RIPv1 and RIPv2. RIP has the following main features:

RIP is a typical distance vector routing protocol.

RIP messages sent by the broadcast address 255.255.255.255, RIPv2 send messages

by using multicast address 224.0.0.9, both using the port 520 of UDP

RIP takes the minimum hop count to the destination network as the routing metric, rather than the bandwidth and delay of the link.

RIP is designed for small networks. The number of hops is limited to 15 hops, and the 16 hop is not reachable.

RIP-1 is a kind of class routing protocol, does not supporting discontinuous subnet design.

RIP-2 support CIDR and VLSM variable subnet mask, which make it supports the discontinuous subnet mask design

RIP periodic full routing updating, make the routing table broadcast to the neighbor router, broadcast cycle default 30 seconds.

RIP protocol management distance is 120.

For small networks, in terms of occupied bandwidth, RIP is small cost and easy to configure, manage, and implement, and RIP is still in use. But RIP also has obvious shortcomings. When there is more than one network will appear loop problem. In order to solve the loop problem, IETF proposed a split-Horizon method, the routing information received at this interface will no longer go out from the interface. The scope of the division solves the routing loop problem between two routers, but can't prevent the problem which is the loop mainly formed by delay factor because of large scale network. The trigger update requires the router to transmit its routing table immediately when the link changes. These speeds up the convergence of the network, but prone to broadcast flooding. In short, the solution of the loop problem needs to consume a certain amount of time and bandwidth. If the RIP protocol is adopted, the number of links in the network can't exceed 15, which makes the RIP protocol is not suitable for large networks.

RIP Working principle

RIP is a distributed type routing protocol based on distance vector, which is the standard protocol of the Internet. Its biggest advantage is simple. The RIP protocol requires that each router in the network maintain a distance record from itself to each other destination network. The RIP protocol defines “distance” as: the distance of a router directly connected network defines as 1.the distance of a router not directly connected network defines as pass each router plus 1. "Distance" is also called "hops". RIP allows one path contain up to 15 routers, so distance equal to 16 is unreachable. So RIP protocol only applies to small Internet.

RIP 2 comes from RIP and is a supplementary protocol for RIP. It is mainly used to increase the number of loaded useful information and increase its security performance. RIPv1 and RIPv2 are UDP-based protocols. Under RIP2, each host or router sends and receives packets from UDP port 520 through the routing select process. The default routing update period for RIP protocol is 30S.

Instructions

  1. Click on the "Routing > Rip Routes Management > Rip Routes Setting" in the

navigation tree as follows.

Rip Routes Info

AIRLIVE L3POE-XGS4804-400 - Rip Routes Info - 1

text_image Rip Routes status Enable Apply
  1. Network Setting table, click "Add" enter the configuration interface as follows.

Network Setting table

AIRLIVE L3POE-XGS4804-400 - Network Setting table - 1

text_image Showing All entries Showing 0 to 0 of 0 entries Network lpv4 Address Network Mask 0 results found. Add Delete First Previous 1 Next Last Network Setting table Network lpv4 Address Network Mask Apply Close

Notice:

Before configuring and publishing the network, please configure the interface IP and ensure that the IP protocol and physical state of the interface are up

13.4 Ospf Routes Management

OSPF (Open Shortest Path First) is an Interior Gateway Protocol (IGP) for routing decisions within a single autonomous system (AS). It is an implementation of the link state routing protocol, under the internal gateway protocol (IGP). It is operating within the autonomous system. The shortest path is calculated using the Dixdale algorithm.

OSPF is IGP routing protocols developed by IETF's OSPF workgroup OSPF designed for IP networks support IP subnet and external routing information marking, also allows authentication of message and supports IP multicast

OSPF routing protocol is a typical link state routing protocol, which is generally used in the same routing domain. Here, routing domain refers to an autonomous system (as), which refers to a group of networks that exchange routing information through a unified routing policy or routing protocol. In this as, all OSPF routers maintain

the same database describing the as structure, which stores the state information of the corresponding links in the routing domain. It is through this database that OSPF routers calculate their OSPF routing tables

As a link state routing protocol, OSPF transmits link state multicast data LSA (link state advertisement) to all routers in a certain area, which is different from distance vector routing protocol. The router running distance vector routing protocol passes part or all of the routing tables to its neighboring routers

As for the security of information exchange, OSPF stipulates that any information exchange between routers can be authenticated when necessary, so as to ensure that only trusted routers can transmit routing information. OSPF supports a variety of authentication mechanisms, and allows different authentication mechanisms to be used among different regions. OSPF optimizes the application of link state algorithm in broadcast network (such as Ethernet) in order to make full use of hardware broadcast ability to transmit link state messages. Usually, in the topology of link state algorithm, a node represents a router. If all k routers are connected to the Ethernet, when the link state is broadcast, the packets about these K routers will reach the square of K. Therefore, OSPF allows a node to represent a broadcast network in the topology diagram. All routers in each broadcast network send link status messages to report the link status of routers in the network

Instructions

  1. Click on the "Routing > Ospf Routes Management > Ospf Routes Setting" in the navigation tree as follows.

OSPF Routes Info

AIRLIVE L3POE-XGS4804-400 - OSPF Routes Info - 1

text_image OSPF Routes status Enable Apply
  1. Area Network Setting, click "Add" enter the configuration interface as follows.

Area Network Setting table

AIRLIVE L3POE-XGS4804-400 - Area Network Setting table - 1

text_image Showing All entries Showing 0 to 0 of 0 entries Area Id Network lpv4 Address Network Mask 0 results found. Add Delete First Previous 1 Next Last

Area Network Setting table

AIRLIVE L3POE-XGS4804-400 - Area Network Setting table - 1

text_image Area Id A.B.C.D Network IPv4 Address Network Mask Apply Close

Notice:

Before configuring and publishing the network, please configure the interface IP and ensure that the IP protocol and physical state of the interface are up

14 Security

14.1 RADIUS

Instructions:

  1. Click the "Security > RADIUS", enter RADIUS interface as follows:

AIRLIVE L3POE-XGS4804-400 - RADIUS - 1

text_image Use Default Parameter Retry 3 (1 - 10, default 3) Timeout 3 Sec (1 - 30, default 3) Key String Apply

RADIUS Table

AIRLIVE L3POE-XGS4804-400 - RADIUS Table - 1

text_image Showing All entries Showing 0 to 0 of 0 entries Server Address Server Port Priority Retry Timeout Usage 0 results found. Add Edit Delete First Previous 1 Next Last

AIRLIVE L3POE-XGS4804-400 - RADIUS Table - 2

text_image Address Type Hostname IPv4 IPv6 Server Address Server Port 1812 (0 - 65535, default 1812) Priority (0 - 65535) Key String Use Default Retry Use Default (1 - 10, default 3) Timeout Use Default Sec (1 - 30, default 3) Usage Login 802.1X All

AIRLIVE L3POE-XGS4804-400 - RADIUS Table - 3

Interface data are as follows.

Configuration ItemsDescription
Address TypeDepending on the type, you can choose Hostname, IPv4, IPv6
Server AddressServer's IP address
Server PortService's port
PriorityService's priority
Key StringThe secret key, shared between the RADIUS server and the switch
RetryRetransmit is the number of times
Timeoutto wait for a reply from a RADIUS server before retransmitting the request
UsageUsage scenarios

14.2 TACACS+

Instructions:

  1. Click the "Security > TACACS+", enter TACACS+ interface as follows:

AIRLIVE L3POE-XGS4804-400 - TACACS+ - 1

text_image Use Default Parameter Timeout 5 Sec (1 - 30, default 5) Key String Apply

TACACS+ Table
AIRLIVE L3POE-XGS4804-400 - TACACS+ - 2

text_image Showing All entries Showing 0 to 0 of 0 entries Server Address Server Port Priority Timeout 0 results found. Add Edit Delete First Previous 1 Next Last

Add TACACS+ Server
AIRLIVE L3POE-XGS4804-400 - TACACS+ - 3

text_image Address Type Hostname IPv4 IPv6 Server Address Server Port 49 (0 - 65535, default 49) Priority (0 - 65535) Key String ✓ Use Default Timeout ✓ Use Default 5 Sec (1 - 30, default 5) Apply Close

Interface data are as follows.

Configuration ItemsDescription
Address TypeDepending on the type, you can choose Hostname, IPv4, IPv6
Server AddressServer's IP address
Server PortService's port
PriorityService's priority
Key StringThe secret key, shared between the RADIUS server and th switch
RetryRetransmit is the number of times
Timeoutto wait for a reply from a RADIUS server before retransmitting the request

14.3 AAA

14.3.1 Method List

Instructions:

  1. Click the "Security > AAA > Method List", enter method list interface as follows:

Method List Table
AIRLIVE L3POE-XGS4804-400 - Method List - 1

text_image Showing All entries Showing 1 to 1 of 1 entries Name Sequence default (1) Local Add Edit Delete First Previous 1 Next Last

Add Method List

AIRLIVE L3POE-XGS4804-400 - Method List - 2

text_image Name Method 1 Empty None Local Enable RADIUS TACACS+ Method 2 Empty None Local Enable RADIUS TACACS+ Method 3 Empty None Local Enable RADIUS TACACS+ Method 4 Empty None Local Enable RADIUS TACACS+ Apply Close

Interface data are as follows.

Configuration ItemsDescription
NameMethod name
Method 1-4Empty: Method is disableNone: Do nothing and just make user to be authenticatedLocal: Use local user account database to authenticateEnable: Use local enable password database to authenticateRADIUS: Use remote Radius server to authenticateTACACS+: Use remote TACACS+ server to authenticate

14.3.2 Login Authentication

Instructions:

  1. Click the "Security > AAA > Login Authentication", enter login authentication interface as follows:

AIRLIVE L3POE-XGS4804-400 - Login Authentication - 1

text_image Console default ▼ (1) Local Telnet default ▼ (1) Local SSH default ▼ (1) Local HTTP default ▼ (1) Local HTTPS default ▼ (1) Local

AIRLIVE L3POE-XGS4804-400 - Login Authentication - 2

14.4 Management Access

14.4.1 Management Service

Instructions for Telnet:

  1. Click the "Security > Management Access > Management Service", enter management service interface as follows:

AIRLIVE L3POE-XGS4804-400 - Management Service - 1

text_image Management Service Telnet ✓ Enable SSH □ Enable HTTP ✓ Enable HTTPS □ Enable SNMP □ Enable Session Timeout Console 10 Min (0 - 65535, default 10) Telnet 10 Min (0 - 65535, default 10) SSH 10 Min (0 - 65535, default 10) HTTP 10 Min (0 - 65535, default 10) HTTPS 10 Min (0 - 65535, default 10)

Instructions for SSH:

  1. Click the "Security > Management Access > Management Service", enter management service interface as follows:

AIRLIVE L3POE-XGS4804-400 - Management Service - 2

text_image Management Service Telnet Enable SSH Enable HTTP Enable HTTPS Enable SNMP Enable Session Timeout Console 10 Min (0 - 65535, default 10) Telnet 10 Min (0 - 65535, default 10) SSH 10 Min (0 - 65535, default 10)

Instructions for HTTPS:

  1. Click the "Security > Management Access > Management Service", enter management service interface as follows:

AIRLIVE L3POE-XGS4804-400 - Management Service - 3

text_image Management Service Telnet Enable SSH Enable HTTP Enable HTTPS Enable SNMP Enable Session Timeout Console 10 Min (0 - 65535, default 10) Telnet 10 Min (0 - 65535, default 10) SSH 10 Min (0 - 65535, default 10) HTTP 10 Min (0 - 65535, default 10) HTTPS 10 Min (0 - 65535, default 10)

Instructions for SNMP:

  1. Click the "Security > Management Access > Management Service", enter management service interface as follows:

AIRLIVE L3POE-XGS4804-400 - Management Service - 4

text_image Management Service Telnet Enable SSH Enable HTTP Enable HTTPS Enable SNMP Enable

14.4.2 Management ACL

ACLS applied to management

Instructions:

  1. Click the "Security > Management Access > Management ACL", enter management ALC interface as follows:

AIRLIVE L3POE-XGS4804-400 - Management ACL - 1

text_image ACL Name Apply

Management ACL Table
AIRLIVE L3POE-XGS4804-400 - Management ACL - 2

text_image Showing All entries Showing 0 to 0 of 0 entries ACL Name State Rule 0 results found. First Previous 1 Next Last Active Deactive Delete
  1. Click the "Security > Management Access > Management ACE", enter management ACE interface as follows:

Management ACE Table
AIRLIVE L3POE-XGS4804-400 - Management ACL - 3

text_image ACL Name None Showing All entries Showing 0 to 0 of 0 entries Priority Action Service Port Address / Mask 0 results found. First Previous 1 Next Last

AIRLIVE L3POE-XGS4804-400 - Management ACL - 4

text_image ACL Name Priority 1 (1 - 65535) Service All Http Https Snmp SSH Telnet Action Permit Deny Available Port Selected Port GE1 GE2 GE3 GE4 GE5 GE6 GE7 GE8 IP Version All IPv4 IPv6 IPv4 / 255.255.255.255 IPv6 / 128 (1 - 128)

AIRLIVE L3POE-XGS4804-400 - Management ACL - 5

Interface data are as follows.

Configuration ItemsDescription
ACL NameACL name
PriorityACL Priority
ServiceType of service used
ActionMatch action
PortThe port on which this ACL is applied
IP VersionManage the version of the IP address
IPv4IPv4 address
IPv6IPv6 address

14.5 Authentication Manager

14.5.1 Property

Enable the global setting of 802.1x/MAC/WEB authentication network access control

Instructions:

  1. Click the "Security > Management Manager > Property", enter global interface as follows:

AIRLIVE L3POE-XGS4804-400 - Property - 1

text_image Authentication Type 802.1x MAC-Based WEB-Based Enable Guest VLAN MAC-Based User ID Format XXXXXXXXXXXXX

Apply

Port Mode Table

EntryPortAuthentication TypeHost ModeOrderMethodGuest VLANVLAN Assign Mode
802.1xMAC-BasedWEB-Based
1GE1EnabledDisabledDisabledMultiple Authentication802.1xRADIUSDisabledStatic
2GE2DisabledDisabledDisabledMultiple Authentication802.1xRADIUSDisabledStatic
3GE3DisabledDisabledDisabledMultiple Authentication802.1xRADIUSDisabledStatic
4GE4DisabledDisabledDisabledMultiple Authentication802.1xRADIUSDisabledStatic
5GE5DisabledDisabledDisabledMultiple Authentication802.1xRADIUSDisabledStatic
6GE6DisabledDisabledDisabledMultiple Authentication802.1xRADIUSDisabledStatic
7GE7DisabledDisabledDisabledMultiple Authentication802.1xRADIUSDisabledStatic

AIRLIVE L3POE-XGS4804-400 - Property - 2

text_image Port Authentication Type Host Mode Order Method Guest VLAN VLAN Assign Mode GE1 802.1x MAC-Based WEB-Based Multiple Authentication Multiple Hosts Single Host Available Type MAC-Based WEB-Based Select Type 802.1x Available Method Local Enable Disable Reject Static Select Method RADIUS

AIRLIVE L3POE-XGS4804-400 - Property - 3

Interface data are as follows.

Configuration ItemsDescription
PortPort list
Authentication TypePort authentication type
Host ModeMultiple Authentication: In this mode, every client needs to pass authenticate procedure individually.Multiple Hosts: In this mode, only one client need to be authenticated and other clients will get the same access accessibility.Single Host: In this mode, only one host can be authenticated. It is the same as multi-auth mode with ma hosts number configure to be 1
OrderMatch action
MethodPort authentication method order
Guest VLANGuest VLAN
VLAN Assign ModePort RADIUS VLAN assign modeReject: If get VLAN authorized information, just use it.However, if there is no VLAN authorized information, rejectthe host and make it unauthorizedStatic: If get VLAN authorized information, just use it. If there is no VLAN authorized information, keep original VLAN o host.

14.5.2 Port Setting

Instructions:

  1. Click the "Security > Management Manager > Port Setting", enter port setting interface as follows:

Port Setting Table

EntryPortPort ControlReauthenticationMax HostsCommon Timer802.1x ParametersWeb-Based Parameters
ReauthenticationInactiveQuietTX PeriodSupplicant TimeoutServer TimeoutMax RequestMax Login
1GE1DisabledDisabled2563600606030303023
2GE2DisabledDisabled2563600606030303023
3GE3DisabledDisabled2563600606030303023
4GE4DisabledDisabled2563600606030303023
5GE5DisabledDisabled2563600606030303023
6GE6DisabledDisabled2563600606030303023
7GE7DisabledDisabled2563600606030303023
8GE8DisabledDisabled2563600606030303023

Edit Port Setting

PortGE1-GE2
Port Control● Disabled○ Force Authorized○ Force Unauthorized○ Auto
Reauthentication□ Enable
Max Hosts256(1 - 256, default 256)
Common Timer
Reauthentication3600Sec (300 - 2147483647, default 3600)
Inactive60Sec (60 - 65535, default 60)
Quiet60Sec (0 - 65535, default 60)
802.1x Parameters
TX Period30Sec (1 - 65535, default 30)
Supplicant Timeout30Sec (1 - 65535, default 30)
Server Timeout30Sec (1 - 65535, default 30)
Max Request2(1 - 10, default 2)
Web-Based Parameters
Max Login□ Infinite3(3 - 10, default 3)

AIRLIVE L3POE-XGS4804-400 - Port Setting - 1

Interface data are as follows.

Configuration ItemsDescription
PortPort list
Port ControlForce Authorized: Port is force authorized and all clients have network accessibility. Force Unauthorized: Port is force unauthorized and all clients Auto: Need passing authentication procedure to get network accessibility
ReauthenticationEnable the port reauthentication
Max HostsThe port max hosts number for multi-auth mode
ReauthenticationThe port reauthentication period value with unit second if the reauthentication time is not assigned by local database or remote authentication server
InactiveThe port inactive timeout value
Quietthe port quiet period value
TX PeriodThe port 802.1x EAP TX period value
Supplicant TimeoutThe port supplicant timeout value
Server TimeoutThe port 802.1x server timeout value
Max RequestThe port 802.1x max EAP request value
Max LoginThe port WEB authentication max login attempt number

14.5.3 MAC-Based Local Account

Instructions:

  1. Click the "Security > Management Manager > MAC-Based Local Account", enter configuration interface as follows:

MAC-Based Local Account Table
AIRLIVE L3POE-XGS4804-400 - Instructions: - 1

text_image Showing All entries Showing 0 to 0 of 0 entries MAC Address Control VLANTimeout (Sec) Reauthentication Inactive 0 results found. Add Edit Delete First Previous 1 Next Last

14.5.4 WEB-Based Local Account

Instructions:

  1. Click the "Security > Management Manager > WEB-Based Local Account", enter

configuration interface as follows:

WEB-Based Local Account Table
AIRLIVE L3POE-XGS4804-400 - Instructions: - 1

text_image Showing All entries Showing 0 to 0 of 0 entries Username VLAN Timeout (Sec) Reauthentication Inactive 0 results found. Add Edit Delete First Previous 1 Next Last

14.5.5 Sessions

Instructions:

  1. Click the "Security > Management Manager > Sessions", view sessions interface as follows:

AIRLIVE L3POE-XGS4804-400 - Instructions: - 1

text_image Sessions Table Showing All entries Showing 0 to 0 of 0 entries Session ID Port MAC Address Current Type Status Operational Information Authorized Information VLAN Session Time Inactivated Time Quiet Time VLAN Reauthentication Period Inactive Timeout 0 results found. Clear Refresh First Previous 1 Next Last

14.6 DoS

14.6.1 Property

Enable the Attack Resistance option to make the switch more secure.

Instructions

  1. Click the "Security > DoS > Property" to the "DoS Global Configuration" interface as follows.

AIRLIVE L3POE-XGS4804-400 - Instructions - 1

text_image POD Enable Land Enable UDP Blat Enable TCP Blat Enable DMAC = SMAC Enable Null Scan Attack Enable X-Mas Scan Attack Enable TCP SYN-FIN Attack Enable TCP SYN-RST Attack Enable ICMP Fragment Enable TCP-SYN Enable Note: Source Port < 1024 TCP Fragment Enable Note: Offset = 1 Ping Max Size Enable IPv4 Enable IPv6 512 Byte (0 - 65535, default 512) TCP Min Hdr size Enable 20 Byte (0 - 31, default 20) IPv6 Min Fragment Enable 1240 Byte (0 - 65535, default 1240) Smurf Attack Enable 0 Netmask Length (0 - 32, default 0) Apply

14.6.2 Port Setting

DoS attack resistance is enabled based on ports. Instructions

  1. Click the "Security > DoS > Port Setting" as follows:

Port Setting Table

EntryPortState
1GE1Disabled
2GE2Disabled
3GE3Disabled
4GE4Disabled
  1. Select and "Edit" the port to enable or disable the DoS attack resistance function as

follows.

Edit Port Setting

AIRLIVE L3POE-XGS4804-400 - Port Setting - 1

text_image Port GE1 State ✓ Enable Apply Close

14.7 Dynamic ARP Inspection

14.7.1 Property

Instructions

  1. Click the "Security > Dynamic ARP Inspection > Property" enter global configuration interface as follows:

AIRLIVE L3POE-XGS4804-400 - Property - 1

text_image State VLAN Enable Available VLAN VLAN 1 VLAN 5 Selected VLAN Apply
  1. Select the port and "Edit" to enter the port configuration interface as follows:

Port Setting Table

EntryPortTrustSource MAC AddressDestination MAC AddressIP AddressRate Limit
1GE1DisabledDisabledDisabledDisabledUnlimited
2GE2DisabledDisabledDisabledDisabledUnlimited
3GE3DisabledDisabledDisabledDisabledUnlimited
4GE4DisabledDisabledDisabledDisabledUnlimited
5GE5DisabledDisabledDisabledDisabledUnlimited
6GE6DisabledDisabledDisabledDisabledUnlimited

Edit Port Setting

AIRLIVE L3POE-XGS4804-400 - Edit Port Setting - 1

text_image Port GE1-GE2 Trust Enable Source MAC Address Enable Destination MAC Address Enable IP Address Enable Rate Limit 0 pps (1 - 50, default 0), 0 is Unlimited Apply Close

14.7.2 Statistics

Instructions

  1. Click the "Security > Dynamic ARP Inspection > Statistics" view DAI statistics as follows:

Statistics Table

EntryPortForwardSource MAC FailureDestination MAC FailureSource IP Validation FailureDestination IP Validation FailureIP-MAC Mismatch Failure
1GE1000000
2GE2000000
3GE3000000
4GE4000000
5GE5000000
6GE6000000
7GE7000000
8GE8000000

14.8 DHCP Snooping

For sake of security, the network administrator may need to record the IP address of a user surfing the Internet and to confirm the correspondence between the IP address obtained from DHCP Server and the host's MAC address.

Switch can record the user's IP address through the secure DHCP relay at the network layer.

Switch can monitor DHCP messages and record the user's IP address through DHCP Snooping at the data link layer. In addition, private DHCP Server in the network may lead to wrong IP address for the user. To ensure that users obtain IP addresses through legal DHCP Server, the DHCP Snooping security mechanism divides the ports into Trust Port and Untrust Port.

Trust Port directly or indirectly connects legal DHCP Server. It forwards the DHCP

messages received to ensure the correct IP address for DHCP Client. Untrust Port connects illegal DHCP Server. DHCPACK and DHCPOFFER messages received from the DHCP Server on the Untrust Port will be discarded to prevent incorrect IP addresses.

AIRLIVE L3POE-XGS4804-400 - DHCP Snooping - 1

flowchart
graph TD
    A["DHCP Client"] -->|Eth1/0/1| B["Switch A (DHCP Snooping)"]
    C["DHCP Client"] -->|Eth1/0/2| B
    D["DHCP Client"] -->|Eth1/0/1| B
    E["DHCP Server"] --> F["Internet"]
    G["Switch B (DHCP Relay)"] --> F

Typical Networking of DHCP Snooping

The following methods are used to obtain the IP address and user MAC address from DHCP Server:

  • Snooping the DHCPREQUEST message
  • Snooping the DHCPACK message

14.8.1 Property

Enable DHCP Snooping

Instructions:

  1. Click the "Security > DHCP Snooping > Property". DHCP Snooping interface is divided into global configuration and port configuration. Select the port to be modified in the port configuration and "Edit" the details as follows:

AIRLIVE L3POE-XGS4804-400 - Property - 1

text_image State VLAN Enable Available VLAN VLAN 1 VLAN 10 VLAN 100 Selected VLAN Apply

Port Setting Table

AIRLIVE L3POE-XGS4804-400 - Port Setting Table - 1

EntryPortTrustVerify ChaddrRate Limit
1GE1DisabledDisabledUnlimited
2GE2DisabledDisabledUnlimited
3GE3DisabledDisabledUnlimited
4GE4DisabledDisabledUnlimited
5GE5DisabledDisabledUnlimited
6GE6DisabledDisabledUnlimited
7GE7DisabledDisabledUnlimited
8GE8DisabledDisabledUnlimited

Edit Port Setting

AIRLIVE L3POE-XGS4804-400 - Edit Port Setting - 1

text_image Port GE1-GE2 Trust Enable Verify Chaddr Enable Rate Limit 0 pps (1 - 300, default 0), 0 is Unlimited

AIRLIVE L3POE-XGS4804-400 - Edit Port Setting - 2

Interface data are as follows.

Configuration ItemsDescription
StateEnable and disable the DHCP Snooping
VLANValid VLAN No. of DHCP Snooping
PortConfigure the port No. of DHCP Snooping
TrustWhether the port is a Trust Port
Client Address InspectionWhether the consistency inspection for Client addresses is enabled
Rate LimitWhether the port enables rate limit and configures the value
  1. Fill in corresponding configuration items.
  2. "Apply" and finish as follows.

Port Setting Table

AIRLIVE L3POE-XGS4804-400 - Port Setting Table - 1

EntryPortTrustVerify ChaddrRate Limit
1GE1EnabledEnabled100
2GE2EnabledEnabled100
3GE3DisabledDisabledUnlimited
4GE4DisabledDisabledUnlimited

14.8.2 Statistics

Instructions

  1. Click the "Security > Dynamic ARP Inspection > Statistics" view DHCP Snooping statistics as follows:

Statistics Table

AIRLIVE L3POE-XGS4804-400 - Statistics Table - 1

EntryPortForwardChaddr Check DropUntrust Port DropUntrust Port with Option82 DropInvalid Drop
1GE100000
2GE200000
3GE300000
4GE400000
5GE500000
6GE600000
7GE700000

14.8.3 Option82 Property

Private DHCP Servers in the network may lead to wrong IP addresses obtained by users. DHCP Snooping security mechanism based on PS7024 Ethernet switch divides the ports into Trust Port and Untrust Port in order to provide the IP addresses through legal DHCP Servers.

  • Trust Port directly or indirectly connects legal DHCP Server. It ensures the correct IP address for DHCP Client by forwarding the DHCP messages received.
  • Untrust Port connects illegal DHCP servers. DHCP ACK and DHCPOFFER messages responded by DHCP Server on untrusted ports will be discarded to prevent incorrect IP addresses.

Option 82 is the Relay Agent Information Option in DHCP messages, which records

the location of DHCP Client. When the DHCP relay (or DHCP Snooping device) receives the request, message sent from DHCP Client to DHCP Server, administrators can add the Option 82 to locate the DHCP Client and control the security, cost, etc. More flexible approaches to address allocation are created by the servers supporting Option 82 in line with the IP addresses and other parameters allocation policies.

Up to 255 sub-options are contained in the Option 82. At least one sub-option should be defined if Option 82 is defined. The current device supports 2 sub-options: Circuit ID Sub-option and Remote ID Sub-option

Manufacturers usually fill options as needed since RFC 3046 fails to uniform the Option 82 options. As the DHCP relay device, Ethernet switch supports the extended padding formats for Option 82 sub-options and the padding defaults are as follows:

  • Sub-option 1: VLAN No. and port index (port physical number minuses 1) of the port receiving the Request message sent by DHCP Client.
  • Sub-option 2: bridge MAC address of DHCP relay device receiving the DHCP Client Request message.

Sub-option 1: VLAN No. and port index (port physical number minuses 1) of the port receiving the Request message sent by DHCP Client as follows.

Sub-option Type (0x01)Length (0x06)Circuit ID Type (0x00)Circuit ID Length (0x04)
VLAN IDPort Index

Sub-option 2: bridge MAC address of DHCP relay device receiving the DHCPREQUEST message of DHCP Client.

07152331
Sub-option Type (0x02)Length (0x08)Remote ID Type (0x00)Remote ID Length (0x06)
MAC Address

DHCP Relay Supporting Mechanism of Option 82

The processes of DHCP Client acquiring IP address from DHCP Server through DHCP relay is basically the same as that directly from DHCP Server. Steps of discovery, provision, selection, and validation are essential. The supporting mechanism of DHCP relay is introduced as follows:

(1) DHCP relay will check the Option 82 in the DHCPREQUEST message received and handle it accordingly.
- For existing Option 82 messages, DHCP relay will process according to the configuration policies (discarding, replacing with relay Option 82, or maintaining original Option 82), and then forward to DHCP Server.
- For messages without Option 82, DHCP relay will add and forward the new messages to DHCP Server.
(2) DHCP relay will peel off Option 82 from the response message received from DHCP Server, and then forward the message with DHCP configuration info to DHCP Client.

Description:

DHCP Client transmits a DHCPDISCOVERY message and a DHCPREQUEST message. DHCP relay will add Option 82 to both messages due to different processing mechanisms of DHCP Servers of manufacturers for Request message. Some devices handle Option 82 in the DHCPDISCOVERY message, while others handle it in the DHCPREQUEST message.

A switch configured with DHCP Snooping and Option 82 functions receives DHCPREQUEST messages with Option 82 sent by DHCP Clients. DHCP Snooping takes different processing mechanisms according to different configuration processing strategies and sub-option contents.

Instructions:

  1. Click the "Security > DHCP Snooping > Option82 Property". Global and port configurations are contained. Select the port to be configured and "Edit" the details as follows:

AIRLIVE L3POE-XGS4804-400 - Description: - 1

text_image Remote ID User Defined Operational Status Remote ID 00:4F:4C:00:05:A0(Switch Mac in Byte Order) Apply

Port Setting Table

EntryPortStateAllow Untrust
1GE1DisabledDrop
2GE2DisabledDrop
3GE3DisabledDrop
4GE4DisabledDrop
5GE5DisabledDrop
6GE6DisabledDrop
7GE7DisabledDrop

Edit Port Setting

AIRLIVE L3POE-XGS4804-400 - Edit Port Setting - 1

text_image Port GE1-GE2 State Enable Allow Untrust Keep Drop Replace Apply Close

Interface data are as follows.

Configuration ItemsDescription
Remote IDFill in the Remote ID fields in Option 82 (such as user-defined XXXX)
PortWhether the port No. of Option 82 is enabled
Untrust Port AccessUntrust Port processes messages with Option 82 enabled: Maintaining: leave Option 82 in the message unchanged and forward itDiscarding: discard the messageReplacing: replace and forward the Option 82 field in th message according to the Circuit ID configuration

Description:

☐ Option 82 field independently configures Circuit ID or Remote ID sub-options. It can be configured individually or simultaneously in no specific order.

DHCP Option 82 must be configured in the user bar, otherwise DHCP messages sent to DHCP Server won't carry Option 82.

When receiving the DHCP response message from DHCP Server, the message containing Option 82 will be forwarded after deleting the field, or forwarded directly if the message contains no Option 82.

  1. Fill in corresponding configuration items.
  2. "Apply" and finish as follows.

AIRLIVE L3POE-XGS4804-400 - Edit Port Setting - 2

text_image Remote ID User Defined aaaaa Operational Status Remote ID aaaaa

Apply

Port Setting Table

EntryPortStateAllow Untrust
1GE1EnabledReplace
2GE2EnabledReplace
3GE3EnabledReplace
4GE4DisabledDrop
5GE5DisabledDrop

Illustration of DHCP Snooping Typical Configuration

As shown below, Switch port GE1-5 is connected to DHCP Server, and ports GE1-1, 2 and 3 are connected to DHCP Client A, B and C respectively.

  • Enable the DHCP Snooping on the switch.
  • Set the GE1-5 as the trust port of DHCP Snooping.

- Enable the Option 82 supporting function on the switch. For GE1-3 message flowing through the port, fill in the Option 82 according to the default configuration of Circuit ID and Remote ID.

Network Diagram

AIRLIVE L3POE-XGS4804-400 - Network Diagram - 1

flowchart
graph TD
    A["DHCP Server"] -->|ge1/5| B["Switch"]
    B -->|ge1/3| C["Client C"]
    B -->|ge1/2| D["Client B"]
    B -->|ge1/1| E["Client A"]

Configure DHCP snooping to support Option 82

Instructions:

  1. Enable the DHCP Snooping of switch. Click the "Security > DHCP Snooping > Property" in the navigation bar to enable the function as follows:

AIRLIVE L3POE-XGS4804-400 - Instructions: - 1

text_image State VLAN Enable Available VLAN Selected VLAN VLAN 1 VLAN 10 VLAN 20 Apply
  1. Set the GE1-5 as the trust port of DHCP Snooping, fill in corresponding configurations and "Edit" as follows:

Port Setting Table

EntryPortTrustVerify ChaddrRate Limit
1GE1EnabledDisabledUnlimited
2GE2EnabledDisabledUnlimited
3GE3EnabledDisabledUnlimited
4GE4EnabledDisabledUnlimited
5GE5EnabledDisabledUnlimited
  1. Configure on the port GE3 so that user defined remote ID can be set by Option 82. Click the "Security > DHCP Snooping > Option82 Property", check and configure the port. "Apply" and finish as follows:

AIRLIVE L3POE-XGS4804-400 - Port Setting Table - 1

text_image Remote ID User Defined aaaaaa Operational Status Remote ID aaaaaa Apply

Port Setting Table

EntryPortStateAllow Untrust
1GE1DisabledDrop
2GE2DisabledDrop
3GE3EnabledReplace
4GE4DisabledDrop
5GE5DisabledDrop
  1. Configure on the port GE3 so that the circuit ID can be set by Option 82. Click the

"Security > DHCP Snooping > Option82 Circuit ID" to configure the port. "Apply" and finish as follows:

Option82 Circuit ID Table
AIRLIVE L3POE-XGS4804-400 - Port Setting Table - 1

text_image Showing All entries Showing 1 to 1 of 1 entries Port VLAN Circuit ID GE3 1 ge1/3 Add Edit Delete First Previous 1 Next Last

14.9 IP Source Guard

IP source guard (IPSG) is a port traffic filtering technology based on IP / Mac, which can prevent IP address spoofing attacks in LAN. IPSG can ensure that the IP address of the terminal device in the layer 2 network will not be hijacked, and it can also ensure that the unauthorized device cannot access the network or attack the network through its own specified IP address, resulting in network crash and paralysis

14.9.1 Port Setting

Instructions

  1. Click the "Security > IP Source Guard > Port Setting" enter port configuration interface as follows:

Port Setting Table

EntryPortStateVerify SourceCurrent EntryMax Entry
1GE1DisabledIP0Unlimited
2GE2DisabledIP0Unlimited
3GE3DisabledIP0Unlimited
4GE4DisabledIP0Unlimited
5GE5DisabledIP0Unlimited
6GE6DisabledIP0Unlimited
7GE7DisabledIP0Unlimited
8GE8DisabledIP0Unlimited

Edit Port Setting

AIRLIVE L3POE-XGS4804-400 - Edit Port Setting - 1

text_image Port GE1-GE2 State Enable Verify Source IP IP-MAC Max Entry 0 (1 - 50, default 0), 0 is Unlimited Apply Close

Interface data are as follows.

Configuration ItemsDescription
PortPort list
StateEnable or disable IPSG
Verify SourceDefault IP Source Guard filter source IP address. The “IP-MAC” filters not only source IP address but also source MAC address
Max EntryMaximum number of ports allowed

14.9.2 IMPV Binding

In DHCP network, users (non-DHCP users) obtaining IP addresses statically may attack the network by imitating DHCP Server, constructing DHCP Request message, etc. Legal DHCP users may suffer from security risks when using the network normally.

Enabling the static MAC entries based on the interface generated by DHCP Snooping binding table can prevent such attacks. The device then, based on the DHCP Snooping binding table corresponding to all DHCP users, automatically executes the command to generate static MAC entries and disable the interface's learning ability of dynamic entries. Only messages that match the source MAC and static MAC entries can flow through the interface. Therefore, for non-DHCP users, only the messages of static MAC entries that are manually configured by the administrators can flow through, while others will be discarded.

Instructions:

  1. Click the "Security > IP Source Guard > IMPV Binding", "Add" a new binding group of IP-MAC-Port-VLAN as follows:

IP-MAC-Port-VLAN Binding Table
AIRLIVE L3POE-XGS4804-400 - IMPV Binding - 1

text_image Showing All entries Showing 0 to 0 of 0 entries Port VLAN MAC Address IP Address Binding Type Lease Time 0 results found. Add Edit Delete First Previous 1 Next Last

Add IP-MAC-Port-VLAN Binding
AIRLIVE L3POE-XGS4804-400 - IMPV Binding - 2

text_image Port GE1 VLAN (1 - 4094) Binding IP-MAC-Port-VLAN IP-Port-VLAN MAC Address IP Address / 255.255.255.255 Apply Close

Interface data are as follows.

Configuration ItemsDescription
PortThe port No. of binding group
VLANVLAN ID bound
BindingSelect the binding relation from IPMV and IPV
MAC AddressMAC address bound
IP AddressIP address bound
  1. Fill in corresponding configuration items.
  2. "Apply" and finish as follows.

IP-MAC-Port-VLAN Binding Table
AIRLIVE L3POE-XGS4804-400 - IMPV Binding - 3

text_image Showing All entries Showing 1 to 1 of 1 entries Port VLAN MAC Address IP Address Binding Type Lease Time GE1 1 00:00:11:11:22:22 192.168.1.123 / 255.255.255.255 IP-MAC-Port-VLAN Static N/A Add Edit Delete First Previous 1 Next Last
  1. Click the "Security > IP Source Guard > Save Database" enter database interface as follows:

AIRLIVE L3POE-XGS4804-400 - IMPV Binding - 4

text_image Type None Flash TFTP Filename Address Type Hostname IPv4 Server Address Write Delay 300 Sec (15 - 86400, default 300) Timeout 300 Sec (0 - 86400, default 300)

Apply

15 ACL

Expanding network scale and mounting flow strengthen the position of network security control and bandwidth allocation. Packet filtering prevents illegal users from accessing, control flow and saves network resources. ACL (Access Control List) filters packets by configuring the message matching rules and processing methods.

The switch port receiving messages analyzes the field according to the current ACL rules. Once a specific message is identified, it will be allowed or forbidden to flow through according to predetermined policies.

The packet matching rules defined by ACL can also be referenced by other functions requiring flow distinction such as the definition of QoS flow classification rules. ACL can filter packets by setting matching rules and processing methods. ACL is a collection of permission and denial conditions applicable to packets. When the interface receives the packets, the switch compares the fields and ACL to determine the permitted and denied packets subject to specified standards. ACL classifies packets by matching conditions, which can be the source/destination MAC address, source/destination IP address, port No. and so on. ACL classifies packets by matching conditions, which can be the source/destination address, port No., etc. ACL can be divided into the following categories according to application purposes:

Basic IP ACL formulates rules based only on the source IP address of packets. ACL ID ranges from 100 to 999. Advanced IP ACL prepares rules according to packets' source/destination IP address, protocol types carried by IP, and Layer 3 or 4 info such as protocol characteristics. ACL ID ranges from 100 to 999.

L2 ACL: Rules are made according to the packets' source/destination MAC address, 802.1p priority, and L2 info such as protocol type. ACL ID ranges from 1 to 99.

15.1 MAC ACL

L2 ACL: Rules are made according to source/destination MAC address, VLAN priority, and L2 info such as protocol type.

Instructions:

  1. Click on the "ACL > MAC ACL" in the navigation bar as follows.

AIRLIVE L3POE-XGS4804-400 - MAC ACL - 1

text_image ACL Name Apply

Interface data are as follows.

Configuration ItemsDescription
ACL NameName the MAC ACL Rules
  1. Click on the "ACL > MAC ACE" in the navigation bar, "Add" the ACL name as follows:

ACE Table

AIRLIVE L3POE-XGS4804-400 - ACE Table - 1

text_image ACL Name a Showing All entries Showing 0 to 0 of 0 entries Sequence Action Source MAC Destination MAC Ethertype VLAN 802.1p Address Mask Address Mask Value Mask 0 results found. Add Edit Delete First Previous 1 Next Last

Interface data are as follows.

Configuration ItemsDescription
ACL NameACL rule list is prepared based on MAC ACL configuration.
  1. Fill in corresponding configuration items.

AIRLIVE L3POE-XGS4804-400 - ACE Table - 2

text_image ACL Name a Sequence 1 (1 - 2147483647) Action ● Permit ○ Deny ○ Shutdown Source MAC □ Any 00:00:00:00:20:00 / FF:FF:FF:FF:FF:00 (Address / Mask) Destination MAC □ Any 00:00:00:00:10:00 / FF:FF:FF:FF:FF:00 × (Address / Mask) Ethertype ✓ Any 0x (0x600 ~ 0xFFFF) VLAN ✓ Any (1 - 4094) 802.1p ✓ Any / (Value / Mask) (0 - 7)

Apply Close

Interface data are as follows.

Configuration ItemsDescription
ACL NameACL rule list is prepared based on MAC ACL configuration.
SequenceMAC ACL ranges from 1 to 2,147,483,647
ActionACL actions are divided into "Permit" or "Deny", as well as "Shutdown".
Source MACEnter the source MAC address and mask of ACL rules with the format of H.H.H.H.H.H. Select "Any" to represent any MAC address
Destination MACEnter the destination MAC address and mask of ACL rules with the format of H.H.H.H.H.H. Select "Any" to represent any MA address
EtherTypeEnter the Ethernet type of ACL rules ranging from 0 x 600 to 0 x FFFF, select "Any" to represent any type.
VLANEnter the VLAN of ACL rules ranging from 1 to 4,094, select "Any" to represent any VLAN
802.1pEnter the VLAN priority and mask of ACL rules ranging from 1 to 7, select "Any" to represent any VLAN priority
  1. "Apply" and finish as follows.

ACE Table

AIRLIVE L3POE-XGS4804-400 - ACE Table - 1

text_image ACL Name a Showing All entries Showing 1 to 1 of 1 entries Sequence Action Source MAC Destination MAC Ethertype VLAN 802.1p Address Mask Address Mask Value Mask 1 Permit 00:00:00:00:20:00 FF:FF:FF:FF:FF:00 00:00:00:00:10:00 FF:FF:FF:FF:FF:00 Any Any Any Add Edit Delete First Previous 1 Next Last

15.2 IPv4 ACL

IPv4-based ACL (Basic IP ACL) formulates rules as per the source IP address of packets only. ACL ID ranges from 100 to 999.

Advanced IP ACL Rules are made according to the packets' source/destination IP address, protocol type carried by IP, and Layer 3 or 4 info such as protocol characteristics. ACL ID ranges from 100 to 999.

Instructions

  1. Click on the "ACL > IPv4 ACL" in the navigation bar as follows.

AIRLIVE L3POE-XGS4804-400 - IPv4 ACL - 1

text_image ACL Name Apply

Interface data are as follows.

Configuration ItemsDescription
ACL NameName the IPv4 ACL rules
  1. Click on the "ACL > IPv4 ACE" in the navigation bar, "Add" the ACL Name as follows:

ACE Table

AIRLIVE L3POE-XGS4804-400 - ACE Table - 1

text_image ACL Name B Showing All entries Showing 0 to 0 of 0 entries Sequence Action Protocol Source IP Destination IP Source Port Destination Port TCP Flags Type of Service ICMP Address Mask Address Mask DSCP IP Precedence Type Code 0 results found. Add Edit Delete First Previous Next Last

Interface data are as follows.

Configuration ItemsDescription
ACL NameACL rule list is made based on IPv4 ACL configuration.
  1. Fill in corresponding configuration items.

AIRLIVE L3POE-XGS4804-400 - ACE Table - 2

text_image ACL Name Sequence 100 (1 - 2147483647) Action ● Permit ○ Deny ○ Shutdown ● Any ○ Select ICMP ○ Define (0 - 255) Source IP ✓ Any (Address / Mask) Destination IP ✓ Any (Address / Mask) Type of Service ● Any ○ DSCP (0 - 63) ○ IP Precedence (0 - 7) Source Port ● Any ○ Single (0 - 65535) ○ Range (0 - 65535) Destination Port ● Any ○ Single (0 - 65535) ○ Range (0 - 65535) TCP Flags Urg: ○ Sat ○ Unset ● Don't care Ack: ○ Set ○ Unset ● Don't care Psh: ○ Set ○ Unset ● Don't care Rst: ○ Set ○ Unset ● Don't care Syn: ○ Set ○ Unset ● Don't care Fin: ○ Set ○ Unset ● Don't care ICMP Type ● Any ○ Select Echo Reply ○ Define (0 - 255) ICMP Code ● Any ○ Define (0 - 255)

AIRLIVE L3POE-XGS4804-400 - ACE Table - 3

Interface data are as follows.

Configuration ItemsDescription
ACL NameACL rule list is made based on IPv4 ACL configuration.
SequenceIPv4 ACL ranges from 1 to 2,147,483,647.
ActionACL actions are divided into “Permit” or “Deny”, as well as “Shutdown”.
ProtocolIt is required to select the protocol type such as ICMP, TCP and UDP. Select “Any” to represent any protocol.
Source IPEnter the source IP and mask of ACL rules. Select “Any” to represent any source IP.
Destination IPEnter the destination IP and mask of ACL rules. Select “Any” to represent any destination IP.
Type of ServiceEnter the service type of ACL rules, such as DSCP (0-63) and IP priority (0-7). Select “Any” to represent any service type.
Source PortEnter the source port of ACL rules, such as single port No. range segment (0-65,535). Select “Any” to represent any source port.
Destination PortEnter the destination port of ACL rules, such as single port No. or range segment (0-65,535). Select “Any” to represent any destination port.
TCP FlagsEnter the TCP flags of ACL rules, such as URG, ACK, PSH, RST, SYN, FIN, with the actions such as “Set”, “Unset” and “Don't care”.
ICMP TypeEnter the ICMP message type of ACL rules. Select “Any” to represent any ICMP type.
ICMP CodeEnter the ICMP Code value of ACL rules. Select “Any” to represent any field value.
  1. "Apply" and finish as follows.

AIRLIVE L3POE-XGS4804-400 - ACE Table - 4

text_image ACE Table ACL Name B Showing All entries Showing 1 to 1 of 1 entries Sequence Action Protocol Source IP Destination IP Source Port Destination Port TCP Flags Type of Service ICMP Address Mask Address Mask DSCP IP Precedence Type Code 100 Permit Any (IP) Any Any Any Any Any Any Any Add Edit Delete First Previous 1 Next Last

15.3 IPv6 ACL

Instructions

  1. Click the "ACL > IPv6 ACL" in the navigation bar as follows.

AIRLIVE L3POE-XGS4804-400 - Instructions - 1

text_image ACL Name Apply

Interface data are as follows.

Configuration ItemsDescription
ACL NameName the IPv6 ACL rules
  1. Click the "ACL > IPv6 ACE" in the navigation bar, "Add" the ACL Name as follows:

AIRLIVE L3POE-XGS4804-400 - Instructions - 2

text_image ACE Table ACL Name c Showing All entries Showing 0 to 0 of 0 entries Sequence Action Protocol Source IP Destination IP Source Port Destination Port TCP Flags Type of Service ICMP Address Prefix Address Prefix DSCP IP Precedence Type Code 0 results found. Add Edit Delete First Previous Next Last

Interface data are as follows.

Configuration ItemsDescription
ACL NameACL rule list is made based on IPv6 ACL configuration.
  1. Fill in corresponding configuration items

AIRLIVE L3POE-XGS4804-400 - Instructions - 3

text_image ACL Name Sequence b 100 (1 - 2147483647) Action Permit Deny Shutdown Any Select TCP Define (0 - 255) Source IP Any / (Address / Prefix (0 - 128)) Destination IP Any / (Address / Prefix (0 - 128)) Type of Service Any DSCP (0 - 63) IP Precedence (0 - 7) Source Port Any Single (0 - 65535) Range - (0 - 65535) Destination Port Any Single (0 - 65535) Range - (0 - 65535) TCP Flags Urg: Set Unset Don't care Ack: Set Unset Don't care Psh: Set Unset Don't care Rst: Set Unset Don't care Syn: Set Unset Don't care Fin: Set Unset Don't care ICMP Type Any Select Destination Unreachable Define (0 - 255) ICMP Code Any Define (0 - 255)

AIRLIVE L3POE-XGS4804-400 - Instructions - 4

Interface data are as follows.

Configuration ItemsDescription
ACL NameACL rule list is made based on IPv6 ACL configuration.
SequenceIPv6 ACL ranges from 1 to 2,147,483,647.
ActionACL actions are divided into “Permit” or “Deny”, as well as “Shutdown”.
ProtocolIt is required to select the protocol type such as ICMP, TCP and UDP. Select “Any” to represent any protocol.
Source IPEnter the source IP and mask of ACL rules. Select “Any” to represent any source IP.
Destination IPEnter the destination IP and mask of ACL rules. Select “Any” to represent any destination IP.
Type of ServiceEnter the service type of ACL rules, such as DSCP (0-63) and IP priority (0-7). Select “Any” to represent any service type.
Source PortEnter the source port of ACL rules, such as single port No. range segment (0-65,535). Select “Any” to represent any source port.
Destination PortEnter the destination port of ACL rules, such as single port No. or range segment (0-65,535). Select “Any” to represent any destination port.
TCP FlagsEnter the TCP flags of ACL rules, such as URG, ACK, PSH, RST, SYN, FIN, with the actions such as “Set”, “Unset” and “Don’t care”.
ICMP TypeEnter the ICMP message type of ACL rules. Select “Any” to represent any ICMP type.
ICMP CodeEnter the ICMP code value of ACL rules. Select “Any” to represent any field value.
  1. "Apply" and finish as follows.

AIRLIVE L3POE-XGS4804-400 - Instructions - 5

text_image ACE Table ACL Name c Showing All entries Showing 1 to 1 of 1 entries Sequence Action Protocol Source IP Destination IP Source Port Destination Port TCP Flags Type of Service ICMP Address Prefix Address Prefix DSCP IP Precedence Type Code 100 Permit Any (IP) Any Any Any Any Any Any Any Any Add Edit Delete First Previous Next Last

15.4 ACL Binding

Once the list is created, it must be bound to each required interface.

Instructions:

  1. Click the "ACL > ACL Binding" in the navigation bar as follows.

ACL Binding Table

EntryPortMAC ACLIPv4 ACLIPv6 ACL
1GE1
2GE2
3GE3
4GE4

Interface data are as follows.

ConfigurationItemsDescription
MAC ACLMAC ACL name bound to the port
IPv4 ACLIPv4 ACL name bound to the port (mutually exclusive with IPv6 ACL)
IPv6 ACLIPv6 ACL name bound to the port (mutually exclusive with IPv4 ACL)
  1. Fill in corresponding configuration items, taking the created MAC ACL a, IPv4 ACL b, IPv6 ACL c as examples.

  2. "Apply" and finish as follows.

Add ACL Binding

AIRLIVE L3POE-XGS4804-400 - Add ACL Binding - 1

text_image Port GE3 Note: ACL without any rules cannot be bound MAC ACL a ✓ IPv4 ACL b ✓ IPv6 ACL None ✓ Apply Close

16 QoS

QoS (Quality of Service) assesses the ability of service providers to meet customer needs and the ability of transmitting packets over the Internet. Diversified services can be assessed based on different aspects. QoS usually refers to the evaluation of service capabilities that support core requirements such as bandwidth, delay, delay variation, and packet loss rate during delivery. Bandwidth, also known as throughput, refers to the average business flow within a certain period of time, with the unit of Kbit/s. Delay refers to the average time required for business flowing through the network. For a network device, the followings are general levels of delay requirements. There are two delay levels, that is, the high-priority business can be served as soon as possible by scheduling method of priority queue, while the low-priority business gets services after that. Delay variation refers to the time change of business flowing through the network. Packet loss rate refers to the percentage of lost business flow during transmission. As modern transmission systems are very reliable, information is often lost in network congestion. Packet loss due to queue overflow is the most common situation.

All messages in a traditional IP network are treated equally. Every network device processes the messages on a FIFO basis, and makes every effort to transmit them to destinations without guaranteeing reliability, transfer delay, or other performance.

Network service quality is constantly improved as new applications keep springing up in the rapidly changing IP network. For example, VoIP, video and other delay-

sensitive services have set higher standards on message transmission delay. Message transmission in a short period has been the common trend. In order to support voice, video and data services with different requirements, the network needs to identify business types and provide corresponding services.

The ability to distinguish business types is the prerequisite to provide corresponding services, so the traditional best-effort service no longer meets the application needs. Therefore, QoS comes into being. It regulates the network flow to avoid and handle network congestion and reduce packet loss rate. Meanwhile, users can enjoy dedicated bandwidths while business can improve service quality, thus perfecting the network service capacity.

QoS priorities vary with message types. For instance, the VLAN message uses 802.1p, also known as the CoS (Class of Service) field, while the IP message uses DSCP. To maintain the priority, these fields need to be mapped at the gateway connected with various networks when messages flow through the network.

802.1p priority in the VLAN frame header

Typically, VLAN frames are interacted between Layer 2 devices. The PRI field (i.e. 802.1p priority), or CoS field, in the VLAN frame header identifies the quality of service requirements according to the definitions in IEEE 802.1Q.

802.1p priority in the VLAN frame

AIRLIVE L3POE-XGS4804-400 - QoS - 1

flowchart
graph TD
    A["Destination address"] --> B["Source address"]
    B --> C["802.1Q Tag"]
    C --> D["Length /Type"]
    D --> E["Data"]
    E --> F["FCS"]
    G["16bits"] --> H["TPID"]
    H --> I["3bits"]
    I --> J["PRI"]
    J --> K["CFI"]
    K --> L["VLAN ID"]
    style G fill:#4CAF50,stroke:#388E3C
    style H fill:#4CAF50,stroke:#388E3C
    style I fill:#4CAF50,stroke:#388E3C
    style J fill:#4CAF50,stroke:#388E3C
    style K fill:#4CAF50,stroke:#388E3C
    style L fill:#4CAF50,stroke:#388E3C

The 802.1Q header contains 3-bit PRI fields. PRI field defines 8 CoS of business priority ranging from 7 to 0 from high to low.

IP Precedence/DSCP Field

According to RFC791 definition, ToS (Type of Service) domain in the IP message header is composed of 8 bits. Among them, the 3-bit long Precedence field, as located in the following, identifies the IP message priority.

IP Precedence/DSCP Field

AIRLIVE L3POE-XGS4804-400 - QoS - 2

flowchart
graph TD
    A["Version Length"] --> B["ToS 1 Byte"]
    B --> C["Len"]
    C --> D["ID"]
    D --> E["Flags/offset"]
    E --> F["TTL"]
    F --> G["Proto"]
    G --> H["FCS"]
    H --> I["IP-SA"]
    I --> J["IP-DA"]
    J --> K["Data"]
    L["0 1 2 3 4 5 6 7"] --> M["Precedence"]
    M --> N["D"]
    M --> O["T"]
    M --> P["R"]
    M --> Q["C"]
    R["IP Precedence"] --> S["DSCP"]

0 to 2 bits are Precedence fields representing the 8 priorities of message

transmission ranging from 7 to 0 from high to low, with either Level 7 or 6 as the highest priority that is generally reserved for routing or updating network control communication. User-level applications only have access to Level 0 to 5.

ToS domain, in addition to Precedence fields, also includes D, T and R bits: D-bit represents the Delay requirement (0 for normal delay and 1 for low delay). T-bit represents the throughput (0 for normal throughput and 1 for high throughput). R-bit represents the reliability (0 for normal reliability and 1 for high reliability). ToS domain reserves the 6 and 7 bits.

RFC1349 redefines the ToS domain by adding a C-bit to represent the Monetary Cost. The IETF DiffServ group then redefines the 0 to 5 bits of ToS domain in the IPv4 message header of RFC2474 as DSCP and renames it as DS (Differentiated Service) byte as shown in the figure above.

The first 6 bits (0-5 bits) of DS field distinguish the DSCP (DS Code Point), and the higher 2 bits (6-7 bits) are reserved. The lower 3 bits (0-2 bits) are CSCP (Class Selector Code Point), with the same CSCP value representing the DSCP of the same class. DS nodes select corresponding PHB (Per-Hop Behavior) according to DSCP values.

16.1 General

16.1.1 Property

Network congestion resulting from the competition for resource use rights among messages at the same time is usually solved by queue scheduling, thus avoiding intermittent congestions. Queue scheduling technologies include SP (Strict-Priority), WFQ (Weighted Fair Queue), WRR (Weighted Round Robin), and DRR (Deficit Round Robin, which is also expanded from RR technology).

Instructions for global and port scheduling configuration

  1. Click the "QoS > General > Property" in the navigation bar as follows.

AIRLIVE L3POE-XGS4804-400 - Property - 1

text_image State Trust Mode Enable CoS DSCP CoS-DSCP IP Precedence Apply

Port Setting Table

EntryPortCoSTrustRemarking
CoSDSCPIP Precedence
1GE10EnabledDisabledDisabledDisabled
2GE20EnabledDisabledDisabledDisabled
3GE30EnabledDisabledDisabledDisabled
4GE40EnabledDisabledDisabledDisabled

Interface data of global configuration are as follows.

Configuration ItemsDescription
StateSwitch of global QoS function
Trust ModeIt can be divided into CoS, DSCP, CoS-DSCP and IP priority

Interface data of port configuration are as follows.

Configuration ItemsDescription
CoSRanging from 0 to 7
Port Trust ModeSwitch of port QoS function
CoSMark the CoS field
DSCPMark the DSCP field
IP PriorityMark the IP Priority field

16.1.2 Queue Scheduling

  1. Click the "QoS > General > Queue Scheduling". "Apply" and finish as follows.

Queue Scheduling Table

QueueMethod
Strict PriorityWRRWeightWRR Bandwidth (%)
11
22
33
44
55
69
713
815

Apply

Interface data are as follows.

Configuration ItemsDescription
Strict PrioritySP mode
WRRWRR mode
WeightBandwidth percentage of WRR accounted for by Queue

16.1.3 CoS Mapping

  1. Click the "QoS > General > CoS Mapping" in the navigation bar. "Apply" and finish as follows.

CoS to Queue Mapping

CoSQueue
01▼
12▼
23▼
34▼
45▼
56▼
67▼
78▼

AIRLIVE L3POE-XGS4804-400 - CoS Mapping - 1

Queue to CoS Mapping

QueueCoS
10▼
21▼
32▼
43▼
54▼
65▼
76▼
87▼

AIRLIVE L3POE-XGS4804-400 - CoS Mapping - 2

Interface data are as follows.

Configuration ItemsDescription
CoS802.1p priority
QueuePort queue

16.1.4 DSCP Mapping

  1. Click the "QoS > General > DSCP Mapping". "Apply" and finish as follows.

DSCP to Queue Mapping

DSCPQueueDSCPQueueDSCPQueueDSCPQueue
0 [CS0]1 ▼16 [CS2]3 ▼32 [CS4]5 ▼48 [CS6]7 ▼
11 ▼173 ▼335 ▼497 ▼
21 ▼18 [AF21]3 ▼34 [AF41]5 ▼507 ▼
31 ▼193 ▼355 ▼517 ▼
41 ▼20 [AF22]3 ▼36 [AF42]5 ▼527 ▼
51 ▼213 ▼375 ▼537 ▼
61 ▼22 [AF23]3 ▼38 [AF43]5 ▼547 ▼
71 ▼233 ▼395 ▼557 ▼
8 [CS1]2 ▼24 [CS3]4 ▼40 [CS5]6 ▼56 [CS7]8 ▼
92 ▼254 ▼416 ▼578 ▼
10 [AF11]2 ▼26 [AF31]4 ▼426 ▼588 ▼
112 ▼274 ▼436 ▼598 ▼
12 [AF12]2 ▼28 [AF32]4 ▼446 ▼608 ▼
132 ▼294 ▼456 ▼618 ▼
14 [AF13]2 ▼30 [AF33]4 ▼46 [EF]6 ▼628 ▼
152 ▼314 ▼476 ▼638 ▼

Apply

Queue to DSCP Mapping

QueueDSCP
10 [CS0]▼
28 [CS1]▼
316 [CS2]▼
424 [CS3]▼
532 [CS4]▼
640 [CS5]▼
748 [CS6]▼
856 [CS7]▼

Apply

Interface data are as follows.

Configuration ItemsDescription
DSCPValue of IP DHCP domain priority
QueuePort queue
  1. Click the "QoS > General > IP Precedence Mapping", enter this page and click "Apply", finish as follows.

IP Precedence to Queue Mapping

IP PrecedenceQueue
01▼
12▼
23▼
34▼
45▼
56▼
67▼
78▼

Apply

Queue to IP Precedence Mapping

QueueIP Precedence
10▼
21▼
32▼
43▼
54▼
65▼
76▼
87▼

Apply

Interface data are as follows.

Configuration ItemsDescription
IP PrecedenceValue of IP TOS domain priority
QueuePort queue

16.2 Rate limit

16.2.1 Ingress / Egress Port

It refers to the rate restriction on transmitting and receiving data at physical interfaces.

Restrict the rate limiting at the egress before transmitting flow, thus controlling all outgoing message flow;

Restrict the rate limiting at the ingress before receiving flow, thus controlling all incoming message flow;

Instructions:

  1. Click the "QoS > Rate Limit > Ingress / Egress Port" in the navigation bar to choose a rate-limiting port and check the current configuration as follows:

Ingress / Egress Port Table

EntryPortIngressEgress
StateRate (Kbps)StateRate (Kbps)
1GE1DisabledDisabled
2GE2DisabledDisabled
3GE3DisabledDisabled
4GE4DisabledDisabled
5GE5DisabledDisabled
6GE6DisabledDisabled
7GE7DisabledDisabled
  1. Select the port (s) for rate limiting, "Edit" it at the bottom to switch the function and specify the rate. "Apply" and finish as follows:

Edit Ingress / Egress Port
AIRLIVE L3POE-XGS4804-400 - Ingress / Egress Port - 1

text_image Port GE1-GE3 Ingress ✓ Enable 1000000 Kbps (16 - 1000000) Egress ✓ Enable 1000000 Kbps (16 - 1000000) Apply Close

Interface data are as follows.

Configuration ItemsDescription
IngressEnabledRate limiting switch
RateRate ranges from 16 to 1,000,000 Kbps
EgressEnabledRate limiting switch
RateRate ranges from 16 to 1,000,000 Kbps

16.2.2 Egress Queue

Instructions for egress queue configuration

  1. Click the "QoS > Rate Limit > Egress Queue" in the navigation bar as follows.

Egress Queue Table

AIRLIVE L3POE-XGS4804-400 - Egress Queue - 1

text_image Entry Port Queue 1 Queue 2 Queue 3 Queue 4 Queue 5 Queue 6 Queue 7 Queue 8 State CIR (Kbps) State CIR (Kbps) State CIR (Kbps) State CIR (Kbps) State CIR (Kbps) State CIR (Kbps) 1 GE1 Disabled Disabled Disabled Disabled Disabled Disabled Disabled Disabled Disabled 2 GE2 Disabled Disabled Disabled Disabled Disabled Disabled Disabled Disabled Disabled 3 GE3 Disabled Disabled Disabled Disabled Disabled Disabled Disabled Disabled Disabled 4 GE4 Disabled Disabled Disabled Disabled Disabled Disabled Disabled Disabled Disabled 5 GE5 Disabled Disabled Disabled Disabled Disabled Disabled Disabled Disabled Disabled 6 GE6 Disabled Disabled Disabled Disabled Disabled Disabled Disabled Disabled Disabled 7 GE7 Disabled Disabled Disabled Disabled Disabled Disabled Disabled Disabled 8 GE8 Disabled Disabled Disabled Disabled Disabled Disabled Disabled Disabled Disabled
  1. Select the port and "Edit" to enter the port configuration interface as follows.

Edit Egress Queue

AIRLIVE L3POE-XGS4804-400 - Egress Queue - 2

bar | Port | GE1-GE2 | Enable | Kbps (16 - 1000000) | | :--- | :--- | :--- | :--- | | Queue 1 | 1000000 | | | | Queue 2 | 1000000 | Enable | | | Queue 3 | 1000000 | Enable | | | Queue 4 | 1000000 | Enable | | | Queue 5 | 1000000 | Enable | | | Queue 6 | 1000000 | Enable | | | Queue 7 | 1000000 | Enable | | | Queue 8 | 1000000 | Enable | | The data is already in the required format for the displayed table. The values are estimated based on the 'Kbps' label in the image.

Apply

Close

17 Diagnostics

17.1 Logging

It configures log switch, info integration, aging time and configuration level. It also uploads the switch's work logs to the TFTP Server.

Instructions:

  1. Click the "Diagnostics > Logging > Property" in the navigation bar to switch logs enable/disable, select the egress terminal, configure the severity level, etc. as follows:

AIRLIVE L3POE-XGS4804-400 - Logging - 1

text_image State Enable Aggregation Enable Aging Time 300 Sec (15 - 3600, default 300) Console Logging State Enable Minimum Severity Notice Note: Emergency, Alert, Critical, Error, Warning, Notice RAM Logging State Enable Minimum Severity Notice Note: Emergency, Alert, Critical, Error, Warning, Notice Flash Logging State Enable Minimum Severity Notice Note: Emergency, Alert, Critical, Error, Warning, Notice Apply
  1. Click the "Diagnostics > Logging > Remote Server" in the navigation bar to add and view the server configuration as follows:

Remote Server Table
AIRLIVE L3POE-XGS4804-400 - Logging - 2

text_image Entry Server Address Server Port Facility Minimum Severity 0 results found. Add Edit Delete
  1. "Add" a new remote log server and "Edit" the selected configuration. "Apply" and finish as follows:

Add Remote Server

AIRLIVE L3POE-XGS4804-400 - Add Remote Server - 1

text_image Address Type Hostname IPv4 IPv6 Server Address Server Port 514 (1 - 65535, default 514) Facility Local 7 Minimum Severity Notice Note: Emergency, Alert, Critical, Error, Warning, Notice Apply Close

17.2 Ping

Ping command checks the availability of specified IP addresses and host names and transmits statistics accordingly.

Instructions:

  1. Click the "Diagnostics > Ping" in the navigation bar to enter a host name or an IP address, as well as the number of tests as follows:

AIRLIVE L3POE-XGS4804-400 - Ping - 1

text_image Address Type ○ Hostname ● IPv4 ○ IPv6 Server Address 192.168.1.111 Count 4 (1 - 65535) Ping Stop
  1. Click the "Ping" to accept the packet-transmitting test from system to verify address validity, and output the result as follows:
Packet Status
StatusSuccess.
Transmit Packet4
Receive Packet4
Packet Lost0 %
Round Trip Time
Min0 ms
Max0 ms
Average0 ms

17.3 Traceroute

Traceroute measures the duration from transmitting a small packet to receiving it back from the target device.

Instructions:

  1. Click the "Diagnostics > Traceroute" in the navigation bar to enter a host name or IP address to define the message existence time as follows:

AIRLIVE L3POE-XGS4804-400 - Traceroute - 1

text_image Address Type ○ Hostname ● IPv4 Server Address 192.168.1.122 Time to Live □ User Defined 30 (2 - 255, default 30) Apply Stop
  1. "Apply" to test and output the result as follows:

Traceroute Result

traceroute to 192.168.1.122 (192.168.1.122), 30 hops max, 38 byte packets 1 192.168.1.122 (192.168.1.122) 0.000 ms 0.000 ms 0.000 ms

17.4 Copper Test

Copper test evaluates the ingress cable state and locates the faults (about 5 m by error) according to the reflected voltage strength

Instructions:

  1. Click the "Diagnostics > Copper Test" in the navigation bar to select a port for test as follows:

AIRLIVE L3POE-XGS4804-400 - Copper Test - 1

text_image Port GE1 Copper Test
  1. Click the "Copper Test" and output the result as follows:

Copper Test Result

Cable Status
PortGE1
ResultOpen Cable
Length2.92 M

17.5 Fiber Module

Can be used to view optical module DDM information

Instructions:

  1. Click the "Diagnostics > Fiber Module" in the navigation bar to select a port for test as follows:

Fiber Module Table

PortTemperature (C)Voltage (V)Current (mA)Output Power (mW)Input Power (mW)OE PresentLoss of Signal
TE1N/SN/SN/SN/SN/SRemoveLoss
TE2N/SN/SN/SN/SN/SRemoveLoss
TE3N/SN/SN/SN/SN/SRemoveLoss
TE4N/SN/SN/SN/SN/SRemoveLoss

17.6 UDLD

UDLD (Unidirectional Link Detection): it is a Cisco private layer-2 protocol, which is used to monitor the physical configuration of Ethernet link connected by

optical fiber or twisted pair. When one-way link appears (it can only transmit to one direction, for example, I can send data to you, you can also receive it, but I can't receive the data you sent to me), UDLD can detect this situation, close the corresponding interface and send it Warning message. One-way links may cause many problems, especially spanning trees, which may cause loopback. Note: UDLD needs to be supported by devices at both ends of the link to run normally.

17.6.1 Property

Global and port switch configuration

Instructions:

  1. Click the "Diagnostics > UDLD > Property" in the navigation bar to select a port for test as follows:

AIRLIVE L3POE-XGS4804-400 - Property - 1

text_image Message Time 15 Sec (1 - 90, default 15) Apply

Port Setting Table

EntryPortModeBidirectional StateOperational StatusNeighbor
1GE1DisabledUnknown0
2GE2DisabledUnknown0
3GE3DisabledUnknown0
4GE4DisabledUnknown0
5GE5DisabledUnknown0
6GE6DisabledUnknown0
  1. Select the port and click "Edit" to enter the Edit interface as follows:

Edit Port Setting

AIRLIVE L3POE-XGS4804-400 - Edit Port Setting - 1

text_image Port GE1 Mode Disabled Normal Aggressive Apply Close

Interface data are as follows.

Configuration ItemsDescription
PortPort id
ModeUDLD port modeDisabled: Disable port functionNormal: UDLD can detect one-way links and mark the port as undetermined to generate system logsAggressive: UDLD can detect the unidirectional link. It will try to rebuild the link and send UDLD messages for 8 seconds continuously. If there is no UDLD echo response, the port will be placed in the errdisable state

17.6.2 Neighbor

UDLD periodically sends hello packets (also known as advertisement or probe probe) on each active interface.

When the Hello packet is received by the switch, the message is stored until the aging time is expired. When Hello is received again before the expiration of the aging time, the aging time is refreshed.

When a new neighbor or a neighbor requests to resynchronize the cache, a series of UDLD probe / echo (Hello) packets are sent.

Instructions:

  1. Click the "Diagnostics > UDLD > Neighbor" in the navigation bar to select a port for test as follows:

Neighbor Table

AIRLIVE L3POE-XGS4804-400 - Neighbor Table - 1

text_image Entry Expiration Time Current Neighbor State Device ID Device Name Port ID Message Interval Timeout Interval 0 results found. Refresh

Interface data are as follows.

Configuration ItemsDescription
EntrySerial No. of neighbor
Expiration TimeRemaining aging time
Current Neighbor StateStatus of neighbors
Device IDDevice id of neighbors
Device NameDevice name of neighbors
Port IDThe ID of the connected interface
Message IntervalMessage interval for neighbors
Timeout IntervalTimeout interval for neighbors

18 Management

18.1 User Account

Users can check and modify the current username, password and authority of the switch.

Instructions:

  1. Click the "Management > User Account" in the navigation bar to discover the username of "admin" and the privilege of "Admin" by default as follows:

AIRLIVE L3POE-XGS4804-400 - User Account - 1

text_image User Account Showing All entries Showing 1 to 1 of 1 entries Username Privilege admin Admin Add Edit Delete First Previous 1 Next Last
  1. "Add" a new user account and "Edit" the selected user attribute as follows:

Add User Account
AIRLIVE L3POE-XGS4804-400 - User Account - 2

text_image Username Password Confirm Password Privilege • Admin • User Apply Close

Edit User Account
AIRLIVE L3POE-XGS4804-400 - User Account - 3

text_image Username admin Password Confirm Password Privilege Admin User Apply Close

18.2 Firmware

System version firmware upgrade

Instructions:

  1. Click the "Management > Firmware > Upgrade" in the navigation bar as follows:

AIRLIVE L3POE-XGS4804-400 - Instructions: - 1

text_image File Type Image FactoryFile Action Upgrade Method TFTP HTTP Filename Choose File No file chosen Apply

18.3 Configuration

18.3.1 Upgrade

System configuration upgrade or backup

Instructions for configuration file upgrade:

  1. Click the "Management > Configuration > Upgrade" click the "Upgrade" in mode of "TFTP" or "HTTP", select the corresponding files to be upgraded (servers should be illustrated in TFTP mode). "Apply" and finish as follows:

AIRLIVE L3POE-XGS4804-400 - Upgrade - 1

text_image Action Upgrade Backup Method TFTP HTTP Configuration Running Configuration Startup Configuration Backup Configuration RAM Log Flash Log Filename Choose File No file chosen Apply

Instructions for file backup configuration:

  1. Click the "Backup" in mode of "TFTP" or "HTTP", select the files or logs to be upgraded (servers should be illustrated in TFTP mode). "Apply" and finish as follows.

AIRLIVE L3POE-XGS4804-400 - Upgrade - 2

text_image Action Upgrade Backup Method TFTP HTTP Configuration Running Configuration Startup Configuration Backup Configuration RAM Log Flash Log

AIRLIVE L3POE-XGS4804-400 - Upgrade - 3

18.3.2 Save Configuration

Save system configuration or restore configuration to factory default Instructions:

  1. Click the "Management > Configuration > Save Configuration" in the navigation bar as follows:
Source FileRunning Configuration Startup Configuration Backup Configuration
Destination FileStartup Configuration Backup Configuration

AIRLIVE L3POE-XGS4804-400 - Save Configuration - 1

Note:

- Click the "Factory Reset" and "Device Restart" to restore factory settings. Save the "Running Configuration" as the "Start Configuration" (which can be saved as "Backup Configuration" or "Running Configuration") and the "Backup Configuration" (which can be saved as the "Start Configuration" or "Running Configuration").

Instructions for the second method of system preservation:

  1. Click the "Save" on the upper right to save the running configuration as the start configuration as follows.

AIRLIVE L3POE-XGS4804-400 - Note: - 1

text_image Save | Logout | Reboot | Debug

Save running configuration to startup configuration. Do you want to continue?

OK

Cancel

18.4 SNMP

SNMP (Simple Network Management Protocol) is widely used in TCP/IP network. It manages devices by the central computer which operates network management software (i.e. network management workstation). SNMP is:

  • Simple: The polling-driving SNMP has the fundamental functionality set that is applicable to small-scale environment with fast speed and low cost. Besides, UDP-driven SNMP is compatible with most devices. Powerful: SNMP aims to ensure the management info transmission between two nodes so that administrators can retrieve, modify and troubleshoot the info easily. There are 3 common versions, namely SNMPv1, v2c and v3. Its system contains NMS (Network Management System), Agent, Management object and MIB (Management Information Base).
  • NMS, as the management center, will manage all devices. Each device under management includes the resident Agent, MIB and management objects. NMS interacts with the Agent running on the management object which will operate the MIB to execute NMS orders.

SNMP management model

AIRLIVE L3POE-XGS4804-400 - SNMP - 1

flowchart
graph TD
    A["NMS"] <--> B["Agent"]
    B <--> C["MIB"]
    C <--> D["Management object"]
    style A fill:#f9f,stroke:#333
    style B fill:#ccf,stroke:#333
    style C fill:#cfc,stroke:#333
    style D fill:#fcc,stroke:#333

NMS

● As the network administrator, NMS manages/monitors network devices by SNMP

on its server. It can request the Agent to inquire or modify specified parameter(s). NMS can receive the Trap actively sent by the Agent to be updated with the states of the managed devices.

Agent

- As an agent process of the managed devices, it maintains device data and responds to the NMS requests by reporting management data. Agent will fulfill relevant orders through MIB Table and transmit the results back to NMS after receiving its request. Devices will take the initiative to transmit info related to the current statues of devices to NMS through Agent once a fault or another event occurs.

Management object

- It refers to the object under management. Each device may have more than one objects, including a piece of hardware (e.g. an interface board), partial hardware and software (e.g. routing protocol), as well as other configuration item sets

MIB

- MIB is a database specifying the variables maintained by the management object (i.e. the info that can be inquired and set by the Agent). MIB defines the attributes of the management object, including the name, state, access right and data type. The following functions can be realized through MIB: Agent will master the instant device info by inquiring MIB and set the state configuration items by changing MIB.

18.4.1 View

  1. Click the "Management > SNMP > View" in the navigation bar as follows.

AIRLIVE L3POE-XGS4804-400 - View - 1

text_image View Table Showing All entries Showing 1 to 1 of 1 entries View OID Subtree Type all .1 Included Add Delete First Previous 1 Next Last

Interface data are as follows.

Configuration ItemsDescription
ViewView name
OID SubtreeView OID
TypeView type: “Included” or “Excluded”
  1. "Add" the corresponding configuration, "Apply" and finish.

Add View

AIRLIVE L3POE-XGS4804-400 - Add View - 1

text_image View OID Subtree Type Included Excluded Apply Close

18.4.2 Group

  1. Click the "Management > SNMP > Group" in the navigation bar as follows.

Group Table

AIRLIVE L3POE-XGS4804-400 - Group Table - 1

text_image Showing All entries Showing 0 to 0 of 0 entries Group Version Security Level View Read Write Notify 0 results found. First Previous 1 Next Last

Configure SNMP View to associate a non-default view with a group.

AIRLIVE L3POE-XGS4804-400 - Group Table - 2

Interface data are as follows.

Configuration ItemsDescription
GroupGroup name
VersionV1, V2, V3
Security LevelSecurity level
ViewViews are divided into view reading, writing and notification.
  1. Click the "Add" to fill in corresponding configuration. "Apply" and finish.

Add Group

AIRLIVE L3POE-XGS4804-400 - Add Group - 1

text_image Group Version Security Level View SNMPv1 SNMPv2 SNMPv3 No Security Authentication Authentication and Privacy Read all Write all Notify all Apply Close

18.4.3 Community

  1. Click the "Management > SNMP > Community" in the navigation bar as follows.

Community Table

AIRLIVE L3POE-XGS4804-400 - Community Table - 1

text_image Showing All entries Showing 1 to 1 of 1 entries Community Group View Access public all Read-Only First Previous 1 Next Last The access right of a community is defined by a group under advanced mode. Configure SNMP Group to associate a group with a community Add Edit Delete

Interface data are as follows.

Configuration ItemsDescription
CommunityCommunity configuration
GroupGroup name
ViewView name
Access:Authority: read only or read-write
  1. "Add" the corresponding configuration. "Apply" and finish.

Add Community

AIRLIVE L3POE-XGS4804-400 - Add Community - 1

text_image Community Type Basic Advanced View all Access Read-Only Read-Write Group Apply Close

18.4.4 User

  1. Click the "Management > SNMP > User" in the navigation bar as follows.

User Table

AIRLIVE L3POE-XGS4804-400 - User Table - 1

text_image Showing All entries Showing 0 to 0 of 0 entries User Group Security Level Authentication Method Privacy Method 0 results found. First Previous 1 Next Last Configure SNMP Group to associate an SNMPv3 group with an SNMPv3 user. Add Edit Delete

Interface data are as follows.

Configuration ItemsDescription
UserUsername
GroupGroup name
Security LevelSecurity level
Authentication MethodAuthentication mode
Privacy MethodEncryption mode
  1. "Add" the corresponding configuration. "Apply" and finish.

Add User

AIRLIVE L3POE-XGS4804-400 - Add User - 1

text_image User Group Security Level No Security Authentication Authentication and Privacy Authentication Method None MD5 SHA Password Privacy Method None DES Password Apply Close

18.4.5 Engine ID

  1. Click the "Management > SNMP > Engine ID" in the navigation bar as follows.

AIRLIVE L3POE-XGS4804-400 - Engine ID - 1

text_image Local Engine ID Engine ID User Defined 80006a92031c2aa3003424 (10 - 64 Hexadecimal Characters) Apply

Remote Engine ID Table

AIRLIVE L3POE-XGS4804-400 - Remote Engine ID Table - 1

text_image Showing All entries Showing 0 to 0 of 0 entries Server Address Engine ID 0 results found. Add Edit Delete First Previous 1 Next Last
  1. Click the "User Automation" to fill in corresponding ID value. "Apply" and finish.

18.4.6 Trap Event

  1. Click the "Management > SNMP > Trap Event" in the navigation bar as follows.

AIRLIVE L3POE-XGS4804-400 - Trap Event - 1

text_image Authentication Failure ✓ Enable Link Up / Down ✓ Enable Cold Start ✓ Enable Warm Start ✓ Enable

Apply

Interface data are as follows.

Configuration ItemsDescription
Authentication FailureAuthentication error
Link Up / DownPort link up/down
Cold startCold start
Warm startWarm start
  1. "Apply" and finish.

18.4.7 Notification

  1. Click the "Management > SNMP > Notification" in the navigation bar as follows.

Notification Table

AIRLIVE L3POE-XGS4804-400 - Notification Table - 1

text_image Showing All entries Showing 0 to 0 of 0 entries Server Address Server Port Timeout Retry Version Type Community / User Security Level 0 results found. First Previous 1 Next Last For SNMPv1.2 Notification, SNMP Community needs to be defined. For SNMPv3 Notification, SNMP User must be created. Add Edit Delete

AIRLIVE L3POE-XGS4804-400 - Notification Table - 2

text_image Address Type Hostname IPv4 IPv6 Server Address SNMPv1 SNMPv2 SNMPv3 Version Type Trap Inform Community / User private ▼ Security Level No Security Authentication Authentication and Privacy Server Port Use Default 162 (1 - 65535, default 162) Timeout Use Default 15 Sec (1 - 300, default 15) Retry Use Default 3 (1 - 255, default 3)

AIRLIVE L3POE-XGS4804-400 - Notification Table - 3

Interface data are as follows.

Configuration ItemsDescription
Address TypeAddress type: “Host Name”, “IPv4” or “IPv6”
Server AddressServer address info
VersionSNMP versions: v1, v2 and v3
TypeNotification type: “Trap” or “Inform”
Community / UserCommunity or username
Security LevelSecurity level
Server port162 by default ranging from 1 to 65,535
TimeoutTimeout period: 15s by default ranging from 1 to 300s.
RetryThe retry interval ranges from 1 to 255s with 3s by default.
  1. "Add" the corresponding configuration. "Apply" and finish.

18.5 RMON

RMON (Remote Monitoring) is a MIB defined by the IETF (Internet Engineering Task Force) and significantly emphasizes the MIB II standard. It mainly monitors data flow in a network segment or even the whole network, which is one of the widely used network management standards. RMON includes NMS (Network Management Station) and

Agent running on various Network devices. RMON Agent running on network monitors or detectors will track and count flow info (e.g. the total number of messages on a network segment during a certain period of time, or that of correct messages sent to a host) on the network segment connected to the port. Based on SNMP architecture, RMON is compatible with the existing SNMP framework. SNMP monitors remote network devices in a more efficient and active manner to supervise subnet operation. RMON can reduce communication flow between NMS and SNMP Agent to manage the large-scale interconnection network conveniently and effectively. Multiple monitors can collect data by 2 means: The exclusive RMON probe is used to collect data, and the NMS directly manages info and controls network resources. All RMON MIB info can be obtained. RMON Agent with direct access to network devices (router, switch, HUB, etc.) will become the network facility with RMON probe function. RMON NMS exchanges data with SNMP Agent with SNMP basic command to collect network management info. However, limited by device resources, it generally fails to obtain all data of RMON MIB. Most devices collect data from only four groups: alarm, event, history and statistics groups. Area-type switch realizes RMON in the second way. RMON Agent directly accessing switches will become the network facility with RMON probe function. By running the SNMP Agent supported by switches, NMS can obtain overall flow, error statistics, performance statistics and other info on the network segments connected to ports, in order to manage the network.

18.5.1 Statistics

The statistics group info reflects the statistics of each monitoring interface on the switch, namely the info accumulated from the beginning of group creation. Statistics include the number of network conflicts, CRC error messages, too-small (too-large) data messages, broadcast/multicast messages, bytes and messages received, etc. With the RMON statistics and management functions, port usage and errors occurred can be monitored and counted respectively.

Instructions

  1. Click the "Management > RMON > Statistics" in the navigation bar as follows, which reveals the port-related message statistics.

AIRLIVE L3POE-XGS4804-400 - Instructions - 1

text_image Statistics Table Refresh Rate 9 sec Entry | Post | Bytes Covered | Drop Events | Packets Received | Broadcast Packets | Multiscale Packets | CRC & Align Users | Underpass Packets | Overpass Packets | Fragments | Jabbers | Collisions | Frames of 64 Bytes | Frames of 08 to 127 Bytes | Frames of 128 to 258 Bytes | Frames of 236 to 511 Bytes | Frames of 512 to 1023 Bytes | Frames Greater than 1024 Bytes 1 GE1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 GE2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 3 GE3 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 4 GE4 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 5 GE5 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 6 GE6 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 7 GE7 8 GE8 9 GE9 10 GE10 11 GE11 12 GE12 13 GE13 14 GE14 15 GE15 16 GE16 17 GE17 18 GE18 19 GE19 20 GE20 21 GE21 22 GE22 23 GE23 24 GE24 25 GE25 26 GE26 27 GE27 28 GE28 29 GE29 30 GE30 31 GE31 32 GE32 33 GE33 34 GE34 35 GE35 36 GE36 37 GE37 38 GE38 39 GE39 40 GE40 41 GE41 42 GE42 43 GE43 44 GE44 45 GE45 46 GE46 47 GE47 48 GE48 49 GE49 50 GE50 51 GE51 52 GE52 53 GE53 54 GE54 55 GE55 56 GE56 57 GE57 58 GE58 59 GE59 60 GE60 61 GE61 62 GE62 63 GE63 64 GE64 65 GE65 66 GE66 67 GE67 68 GE68 69 GE69 70 GE70 71 GE71 72 GE72 73 GE73 74 GE74 75 GE75 76 GE76 77 GE77 78 GE78 79 GE79 80 GE80 81 GE81 82 GE82 83 GE83 84 GE84 85 GE85 86 GE86 87 GE87 88 GE88 89 GE89 90 GE90 91 GE91 92 GE92 93 GE92 94 GE93 95 GE93 96 GE94 97 GE94 98 GE95 99 GE95 100 GE96
  1. "Clear" and "Refresh" the statistics of the selected port. "View" such statistics as follows.

View Port Statistics

AIRLIVE L3POE-XGS4804-400 - View Port Statistics - 1

text_image Port Refresh Rate Received Bytes (Octets) Drop Events Received Packets Broadcast Packets Received Multicast Packets Received CRC & Align Errors Undersize Packets Oversize Packets Fragments Jabbers Collisions Frames of 64 Bytes Frames of 65 to 127 Bytes Frames of 128 to 255 Bytes Frames of 256 to 511 Bytes Frames Greater than 1024 Bytes GE8 None 5 sec 10 sec 30 sec Clear Refresh Close
  1. Select the specified refresh frequency to operate automatically.

18.5.2 History

Once configuring the RMON history group, the switches will periodically collect and temporarily store the network statistics for processing ease, providing historical data on network segment flow, error packets, broadcast packets, bandwidth utilization, and other statistics. Historical data management can be used to set up devices in terms of historical data collection including periodical collection and maintenance of the data of specified ports.

Instructions

  1. Click the "Management > RMON > History" in the navigation bar as follows.

History Table

AIRLIVE L3POE-XGS4804-400 - History Table - 1

text_image Showing All entries Showing 0 to 0 of 0 ent Entry Port Interval Owner Sample Maximum Current The SNMP service is currently disabled. For RMON configuration to be effective, the SNMP service must be enabled. Add Edit Delete View

Interface data are as follows.

Configuration ItemsDescription
EntrySerial No. of event groups
PortPorts to be counted
IntervalSampling interval ranging from 1 to 3,600 (unit: s), with 1,800s by default.
OwnerOwner
MaximumThe max number of samples ranges from 0 to 50, with 50 t default.
CurrentCurrent number of samples
  1. "Add" corresponding configuration items to configure history group.

Add History

AIRLIVE L3POE-XGS4804-400 - Add History - 1

text_image Entry 1 Port GE1 Max Sample 50 (1 - 50, default 50) Interval 1800 (1 - 3600, default 1800) Owner

AIRLIVE L3POE-XGS4804-400 - Add History - 2

  1. "Apply" and finish as follows.

History Table

EntryPortIntervalOwnerSample
MaximumCurrent
1GE118005050

The SNMP service is currently disabled. For RMON configuration to be effective, the SNMP service must be enabled.

AIRLIVE L3POE-XGS4804-400 - History Table - 1

18.5.3 Event

Defining event No. and process way, event group is mainly for the events triggered by alarm group configuration items and extended alarm group configuration items. There are several solutions to them: recording in a log table; transmitting a Trap messages to NMS; recording a log and transmitting a Trap message; Don't care. Instructions

  1. Click the "Management > RMON > Event" in the navigation bar as follows.

Event Table
AIRLIVE L3POE-XGS4804-400 - Event - 1

text_image Showing All entries Showing 0 to 0 of 0 entries Entry Community Description Notification Time Owner 0 results found. First Previous 1 Next Last The SNMP service is currently disabled. For RMON configuration to be effective, the SNMP service must be enabled. Add Edit Delete View

Interface data are as follows.

Configuration ItemsDescription
EntrySerial No. of event groups
CommunityCommunity name
DescriptionDescription
NotificationNotification
TimerTime
OwnerOwner
  1. "Add" corresponding configuration items to configure the event group.

Add Event
AIRLIVE L3POE-XGS4804-400 - Event - 2

text_image Entry 1 Notification None Event Log Trap Event Log and Trap Community Default Community Description Default Description Owner Apply Close
  1. "Add" and finish as follows.

Event Table
AIRLIVE L3POE-XGS4804-400 - Event - 3

text_image Showing All entries Showing 1 to 1 of 1 entries Entry Community Description Notification Time Owner 1 Default Description Default Description Event Log and Trap First Previous 1 Next Last The SNMP service is currently disabled. For RMON configuration to be effective, the SNMP service must be enabled. Add Edit Delete View

18.5.4 Alarm

RMON alarm management monitors specific alarm variables, such as port statistics. An alarm event occurs when the value of monitored data exceeds the defined threshold in the corresponding direction, which will be treated according to the prescribed treatment mode. Event definition is realized in event group. After the user defines the alarm entry, the system will process as follows: The alarm-variable defined by sampling-time should be sampled and the value should be compared with the threshold. For higher threshold, the corresponding event will be triggered.

  1. Click the "Management > RMON > Alarm" in the navigation bar as follows.

Alarm Table
AIRLIVE L3POE-XGS4804-400 - Alarm - 1

text_image Showing All entries Showing 0 to 0 of 0 entries Entry Port Counter Sampling Interval Owner Trigger Rising Falling Name Value Threshold Event Threshold Event 0 results found. First Previous 1 Next Last The SNMP service is currently disabled. For RMON configuration to be effective, the SNMP service must be enabled. Add Edit Delete

Interface data are as follows.

Configuration ItemsDescription
EntrySerial No. of alarm groups
PortEnter the ports to be counted
CounterSample parameters of alarms
IntervalSampling interval ranges from 1 to 2,147,483,647 with the unit of second. 100s by default.
SamplingSample types: Absolute and Delete
OwnerOwner
Threshold (Rising)The threshold of rising edge ranges from 0 to 2,147,483,647.
Event (Rising)Event group index. Corresponding event will be activated when alarm is triggered.
Threshold (Falling)The threshold of falling edge ranges from 0 to 21,474,836,475.
Event (Falling)Event group index. Corresponding event will be activated when alarm is triggered.
  1. "Add" corresponding configuration items to configure the alarm group.

Add Alarm
AIRLIVE L3POE-XGS4804-400 - Alarm - 2

text_image Entry 1 Port GE1 Counter Drop Events Sampling Absolute Delta Interval 100 Sec (1 - 2147483647, default 100) Owner Trigger Rising Falling Rising and Falling Rising Threshold 100 (0 - 2147483647, default 100) Event 1 - Default Description Falling Threshold 20 (0 - 2147483647, default 20) Event 1 - Default Description Apply Close
  1. "Apply" and finish as follows.

Alarm Table
AIRLIVE L3POE-XGS4804-400 - Alarm - 3

text_image Showing All entries Showing 1 to 1 of 1 entries Entry Port Counter Sampling Interval Owner Trigger Rising Falling Name Value Threshold Event Threshold Event 1 GE1 DropEvents 0 Absolute 100 Rising 100 Default Description 20 Default Description The SNMP service is currently disabled For RMON configuration to be effective, the SNMP service must be enabled Add Edit Delete First Previous 1 Next Last
Table of contents Click a title to access it
Manual assistant
Powered by Anthropic
Waiting for your message
Product information

Brand : AIRLIVE

Model : L3POE-XGS4804-400

Category : Network switch