Page 2 - Information in this document is subject to change without notice.; FCC Warning
DGS-3024 Gigabit Ethernet Switch Manual ii Information in this document is subject to change without notice. © 2005 D-Link Computer Corporation. All rights reserved. Reproduction in any manner whatsoever without the written permission of D-Link Computer Corporation is strictly forbidden. Trademarks ...
Page 3 - Table of Contents
DGS-3024 Gigabit Ethernet Switch Manual iii Table of Contents Preface ..................................................................................................................................................................................ix Intended Readers ...................................
Page 9 - Preface
DGS-3024 Gigabit Ethernet Switch Manual ix Preface The DGS-3024 Manual is divided into chapters that describe the system installation and operating instructions with examples. Section 1, “Introduction” – Describes the Switch and its features. Section 2, “Unpacking and Setup” – Helps you get started ...
Page 11 - Safety Instructions; Safety Cautions
DGS-3024 Gigabit Ethernet Switch Manual xi Safety Instructions Use the following safety guidelines to ensure your own personal safety and to help protect your system from potential damage. Throughout this safety section, the caution icon ( ) is used to indicate cautions and precautions that you need...
Page 12 - General Precautions for Rack-Mountable Products
DGS-3024 Gigabit Ethernet Switch Manual xii Safety Instructions (continued) • To help prevent an electric shock, plug the system and peripheral power cables into properly grounded electrical outlets. These cables are equipped with three-prong plugs to help ensure proper grounding. Do not use adapter...
Page 14 - Protecting Against Electrostatic Discharge
DGS-3024 Gigabit Ethernet Switch Manual xiv Protecting Against Electrostatic Discharge Static electricity can harm delicate components inside your system. To prevent static damage, discharge static electricity from your body before you touch any of the electronic components, such as the microprocess...
Page 15 - Introduction; Features
DGS-3024 Gigabit Ethernet Switch Manual 1 1 Introduction This section describes the features of the DGS-3024. Features The DGS-3024 was designed for departmental and enterprise connections. As an all-gigabit-port Switch, it is ideal for backbone and server connection. Powerful and versatile, the Swi...
Page 17 - Unpacking and Setup; Packing List
DGS-3024 Gigabit Ethernet Switch Manual 3 2 Unpacking and Setup This chapter provides unpacking and setup information for the Switch. Packing List Open the shipping carton of the Switch and carefully unpack its contents. The carton should contain the following items: • A DGS-3024 24-Port Gigabit Lay...
Page 18 - Desktop or Shelf Installation; Figure 2-1. Installing rubber feet for desktop installation; Rack Installation; Figure 2- 2A. Attaching the mounting brackets
DGS-3024 Gigabit Ethernet Switch Manual 4 Desktop or Shelf Installation When installing the Switch on a desktop or shelf, the rubber feet included with the device should first be attached. Attach these cushioning feet on the bottom at each corner of the device. Allow adequate space for ventilation b...
Page 19 - Figure 2- 2B. Installing in an equipment rack; Power on
DGS-3024 Gigabit Ethernet Switch Manual 5 Figure 2- 2B. Installing in an equipment rack Power on The Switch can be used with AC power supply 100-240 VAC, 50 - 60 Hz. The Switch’s power supply will adjust to the local power source automatically and may be powered on without having any or all LAN segm...
Page 21 - Identifying External Components; Front Panel; Rear Panel
DGS-3024 Gigabit Ethernet Switch Manual 7 3 Identifying External Components This chapter describes the front panel, rear panel, side panels, and LED indicators of the DGS-3024. Front Panel The front panel of the Switch consists of LED indicators, an RS-232 communication port, 24 1000BASE-T ports, an...
Page 22 - Figure 3-3. Side panel views of the Switch; Power; RPS; Console; Speed
DGS-3024 Gigabit Ethernet Switch Manual 8 Figure 3-3. Side panel views of the Switch • The system fans are used to dissipate heat. The sides of the system also provide heat vents to serve the same purpose. Do not block these openings, and leave at least 6 inches of space at the rear and sides of the...
Page 23 - Connecting the Switch; Switch to End Node; Figure 4- 1. Switch connected to an End Node
DGS-3024 Gigabit Ethernet Switch Manual 9 4 Connecting the Switch This chapter describes how to connect the DGS-3024 to your Gigabit Ethernet network. Switch to End Node End nodes include PCs outfitted with a 10, 100, or 1000 Mbps RJ-45 Ethernet/Fast Ethernet/Gigabit Ethernet Network Interface Card ...
Page 24 - Switch to Hub or Switch; crossover cable; Switch to Core Router Switch
DGS-3024 Gigabit Ethernet Switch Manual 10 Switch to Hub or Switch These connections can be accomplished in a number of ways using a normal cable. • A 10BASE-T hub or Switch can be connected to the Switch via a two-pair Category 3, 4, 5, or 5e UTP/STP cable. • A 100BASE-TX hub or Switch can be conne...
Page 26 - Introduction to Switch Management; Management Options; Web-based Management Interface
DGS-3024 Gigabit Ethernet Switch Manual 12 5 Introduction to Switch Management Management Options This system may be managed out-of-band through the console port on the front panel or in-band using Telnet. The user may also choose the web-based management, accessible through a web browser. Web-based...
Page 27 - File
DGS-3024 Gigabit Ethernet Switch Manual 13 7. Under Properties, select VT100 for Emulation mode. 8. Select Terminal keys for Function, Arrow, and Ctrl keys. Ensure that you select Terminal keys (not Windows keys). 9. After you have correctly set up the terminal, plug the power cable into the power r...
Page 28 - First Time Connecting to The Switch; NOTE; Enter; Password Protection
DGS-3024 Gigabit Ethernet Switch Manual 14 First Time Connecting to The Switch The Switch supports user-based security that can allow you to prevent unauthorized users from accessing the Switch or changing its settings. This section tells how to log onto the Switch. NOTE: The passwords used to acces...
Page 29 - Command: create account admin newmanager; SNMP Settings
DGS-3024 Gigabit Ethernet Switch Manual 15 At the CLI login prompt, enter create account admin followed by the <user name> and press the Enter key. You will be asked to provide a password. Type the <password> used for the administrator account being created and press the Enter key. You w...
Page 30 - Traps
DGS-3024 Gigabit Ethernet Switch Manual 16 In SNMP v.1 and v.2, user authentication is accomplished using 'community strings', which function like passwords. The remote user SNMP application and the Switch SNMP must use the same community string. SNMP packets from any station that has not been authe...
Page 31 - Switch Information (Basic; Configuration
DGS-3024 Gigabit Ethernet Switch Manual 17 Figure 5- 3. Show Switch command The Switch's MAC address can also be found from the Web management program on the Switch Information (Basic Settings) window on the Configuration menu. The IP address for the Switch must be set before it can be managed with ...
Page 32 - Figure 5- 4. Assigning the Switch an IP Address; Connecting Devices to the Switch; NOTICE
DGS-3024 Gigabit Ethernet Switch Manual 18 Figure 5- 4. Assigning the Switch an IP Address In the above example, the Switch was assigned an IP address of 10.24.22.8 with a subnet mask of 255.0.0.0. The system message Success indicates that the command was executed successfully. Please remember to sa...
Page 33 - Web-Based Network Management; Login to Web Manager; Login
DGS-3024 Gigabit Ethernet Switch Manual 19 6 Web-Based Network Management Introduction The DGS-3024 offers an embedded Web-based (HTML) interface allowing users to manage the Switch from anywhere on the network through a standard browser, such as Opera, Netscape Navigator/Communicator, or Microsoft ...
Page 34 - Figure 6- 2. Enter Network Password dialog box; OK; Web-based User Interface; Area Function
DGS-3024 Gigabit Ethernet Switch Manual 20 Figure 6- 2. Enter Network Password dialog box Leave both the User Name field and the Password field blank and click OK . This will open the Web-based user interface. The Switch management features available in the Web-based manager are explained below. Web...
Page 36 - IP Address
DGS-3024 Gigabit Ethernet Switch Manual 22 7 Configuration The first Web Manager main folder is Configuration and includes the following windows and sub-folders: IP Address , Switch Information , Advanced Settings , Port Configuration , Port Mirroring , Link Aggregation , IGMP Snooping , Spanning Tr...
Page 37 - Switch Information; Apply
DGS-3024 Gigabit Ethernet Switch Manual 23 Switch Information Figure 7- 2. Switch Information (Basic Settings) window This window is used to enter name, location, and contact information. Click Apply to activate the new settings. The information is described as follows: Parameter Description Device ...
Page 38 - Advanced Settings
DGS-3024 Gigabit Ethernet Switch Manual 24 Advanced Settings Figure 7- 3. Switch Information (Advanced Settings) window The following fields can be set: Parameter Description Serial Port Auto Logout This setting for the restart of the console is 2 Minutes , 5 Minutes , 10 Minutes , 15 Minutes , or N...
Page 40 - Port Configuration; Parameter Description
DGS-3024 Gigabit Ethernet Switch Manual 26 Port Configuration Figure 7- 4. Port Configuration window To configure Switch ports: 1. Choose the port or sequential range of ports using the From and To pull-down menus. 2. Use the remaining pull-down menus to configure the parameters described below: Par...
Page 41 - Flow Control
DGS-3024 Gigabit Ethernet Switch Manual 27 then to use those settings. The other options are 10M/Half , 10M/Full, 100M/Half and 100M/Full , 1000M/Full_M and 1000M/Full_S . There is no automatic adjustment of port settings with any option other than Auto . The Switch allows the user to configure two ...
Page 42 - Port Mirroring; Figure 7- 5. Setup Port Mirroring window
DGS-3024 Gigabit Ethernet Switch Manual 28 Port Mirroring Figure 7- 5. Setup Port Mirroring window To configure a mirror port: 1. Select the Source Port from where you want to copy frames and the Target Port, which receives the copies from the source port. 2. Select Ingress, Egress, or None and chan...
Page 43 - Figure 7- 6. Example of Port Trunk Group
DGS-3024 Gigabit Ethernet Switch Manual 29 Link Aggregation (Port Trunking) Port trunk groups are used to combine a number of ports together to make a single high-bandwidth data pipeline. NOTE : In the current DGS-3024 firmware version, only Static Type Link Agggregation is supported. LACP Type Link...
Page 44 - Link Aggregation
DGS-3024 Gigabit Ethernet Switch Manual 30 The Switch allows the creation of up to four port trunking groups, each group consisting of 2 to 8 links (ports). The aggregated links must be contiguous (they must have sequential port numbers) except the two (optional) Gigabit ports, which can only belong...
Page 45 - IGMP Snooping
DGS-3024 Gigabit Ethernet Switch Manual 31 Figure 7- 8. Port Trunking Configuration window The user-changeable parameters are as follows: Parameter Description Group ID [1-4] Select an ID number for the group, between 1 and 4 . State Trunk groups can be toggled between Enabled and Disabled . This is...
Page 46 - Current IGMP Snooping Group Entries
DGS-3024 Gigabit Ethernet Switch Manual 32 IGMP Snooping Use the Current IGMP Snooping Group Entries window to view IGMP Snooping settings. To modify the settings, click the Modify button of the VLAN ID you want to change. Figure 7- 9. Current IGMP Snooping Group Entries window Clicking the Modify b...
Page 47 - Current IGMP; Static Router Ports Entry; Modify
DGS-3024 Gigabit Ethernet Switch Manual 33 A value between 1 and 25 seconds can be entered, with a default of 10 seconds. Robustness Value A tuning variable to allow for subnetworks that are expected to lose a large number of packets. A value between 2 and 255 can be entered, with larger values bein...
Page 48 - Figure 7- 12. Static Router Ports Settings window; Parameter Description; Member Ports; Current; Spanning Tree
DGS-3024 Gigabit Ethernet Switch Manual 34 Figure 7- 12. Static Router Ports Settings window The following parameters can be viewed or set: Parameter Description VID (VLAN ID) This is the VLAN ID that, along with the VLAN Name, identifies the VLAN where the multicast router is attached. VLAN Name Th...
Page 49 - w Rapid Spanning Tree
DGS-3024 Gigabit Ethernet Switch Manual 35 1. A configuration name defined by an alphanumeric string of up to 32 characters (defined in the Current MST Configuration Identification window in the Configuration Name field). 2. A configuration revision number (named here as a Revision Level (0-65535) a...
Page 50 - Edge Port; STP Bridge Global Settings; STP Bridge
DGS-3024 Gigabit Ethernet Switch Manual 36 Edge Port The edge port is a configurable designation used for a port that is directly connected to a segment where a loop cannot be created. An example would be a port connected directly to a single workstation. Ports that are designated as edge ports tran...
Page 51 - Parameter Description; STP Version
DGS-3024 Gigabit Ethernet Switch Manual 37 Figure 7- 14. STP Bridge Global Settings window - RSTP (default) Figure 7- 15. STP Bridge Global Settings window - MSTP The following parameters can be set: Parameter Description STP Status Use the pull-down menu to enable or disable STP globally on the Swi...
Page 52 - Forwarding BPDU; MST Configuration Table
DGS-3024 Gigabit Ethernet Switch Manual 38 that it is indeed the Root Bridge. This field will only appear here when STP or RSTP is selected for the STP Version. For MSTP, the Hello Time must be set on a port per port basis. See the STP Port Settings section for further details. Max Age (6-40 Sec) Th...
Page 53 - Add
DGS-3024 Gigabit Ethernet Switch Manual 39 Figure 7- 16. Current MST Configuration Identification window The window above contains the following information: Parameter Description Configuration Name A previously configured name set on the Switch to uniquely identify the MSTI (Multiple Spanning Tree ...
Page 55 - Parameter Description; MSTI Settings; Configuration > Spanning Tree > MSTI Settings
DGS-3024 Gigabit Ethernet Switch Manual 41 Figure 7- 19. Instance ID Settings window - Modify The user may configure the following parameters for a MSTI on the Switch. Parameter Description MSTI ID Displays the MSTI ID previously set by the user. Type This field allows the user to choose a desired m...
Page 56 - Figure 7- 20. MSTI Port Information window; Priority
DGS-3024 Gigabit Ethernet Switch Manual 42 Figure 7- 20. MSTI Port Information window To view the MSTI settings for a particular port, select the Port number, located in the top left hand corner of the window and click Apply . To modify the settings for a particular MSTI Instance, click on its hyper...
Page 57 - STP Instance Settings; Spanning Tree > STP Instance Settings
DGS-3024 Gigabit Ethernet Switch Manual 43 STP Instance Settings The following window displays MSTIs currently set on the Switch. To view the following table, click Configuration > Spanning Tree > STP Instance Settings : Figure 7- 22. STP Instance Settings window The following information is d...
Page 58 - STP Instance Operational Status
DGS-3024 Gigabit Ethernet Switch Manual 44 Figure 7- 24. STP Instance Operational Status window – Previously Configured MSTI The following parameters may be viewed in the STP Instance Operational Status windows: Parameter Description Designated Root Bridge This field will show the priority and MAC a...
Page 59 - Max Age; Last Topology Change
DGS-3024 Gigabit Ethernet Switch Manual 45 Max Age The Max Age may be set to ensure that old information does not endlessly circulate through redundant paths in the network, preventing the effective propagation of the new information. Set by the Root Bridge, this value will aid in determining that t...
Page 60 - STP Port Settings; Port Settings
DGS-3024 Gigabit Ethernet Switch Manual 46 STP Port Settings STP can be set up on a port per port basis. To view the following window click Configuration > Spanning Tree > STP Port Settings : Figure 7- 25. STP Port Settings window
Page 61 - Parameter Description
DGS-3024 Gigabit Ethernet Switch Manual 47 In addition to setting Spanning Tree parameters for use on the Switch level, the Switch allows for the configuration of groups of ports, each port-group of which will have its own spanning tree, and will require some of its own configuration settings. An ST...
Page 62 - State; Forwarding; Unicast Forwarding; Figure 7- 26. Setup Static Unicast Forwarding Table window; Multicast Forwarding
DGS-3024 Gigabit Ethernet Switch Manual 48 True . State This drop-down menu allows you to enable or disable STP for the selected group of ports. The default is Enabled . Click Apply to implement changes made. Forwarding Unicast Forwarding Open the Forwarding folder in the Configuration menu and clic...
Page 63 - Figure 7- 27. Static Multicast Forwarding Settings window; VLANs; Understanding IEEE 802.1p Priority
DGS-3024 Gigabit Ethernet Switch Manual 49 Figure 7- 27. Static Multicast Forwarding Settings window The Static Multicast Forwarding Settings window displays all of the entries made into the Switch's static multicast forwarding table. Click the Add button to open the Setup Static Multicast Forwardin...
Page 64 - VLAN Description; Tagging
DGS-3024 Gigabit Ethernet Switch Manual 50 associated with the delivery of time critical data over congested networks. The quality of applications that are dependent on such time critical data, such as video conferencing, can be severely and adversely affected by even very small delays in transmissi...
Page 65 - Ingress port
DGS-3024 Gigabit Ethernet Switch Manual 51 Ingress port – A port on a Switch where packets are flowing into the Switch and VLAN decisions must be made. Egress port – A port on a Switch where packets are flowing out of the Switch, either to another Switch or to an end station, and tagging decisio...
Page 67 - Port VLAN ID
DGS-3024 Gigabit Ethernet Switch Manual 53 Figure 7- 30. IEEE 802.1Q Tag The EtherType and VLAN ID are inserted after the MAC source address, but before the original EtherType/Length or Logical Link Control. Because the packet is now a bit longer than it was originally, the Cyclic Redundancy Check (...
Page 68 - Tagging and Untagging
DGS-3024 Gigabit Ethernet Switch Manual 54 table). If the PVID of the port that received the packet is different from the PVID of the port that is to transmit the packet, the Switch will drop the packet. Within the Switch, different PVIDs mean different VLANs (remember that two VLANs cannot communic...
Page 69 - Default VLANs; VLAN Name; VLAN and Trunk Groups; Static VLAN Entry
DGS-3024 Gigabit Ethernet Switch Manual 55 Default VLANs The Switch initially configures one VLAN, VID = 1, called "default." The factory default setting assigns all ports on the Switch to the "default." Packets cannot cross VLANs. If a member of one VLAN wants to connect to another ...
Page 72 - Parameter Description
DGS-3024 Gigabit Ethernet Switch Manual 58 Figure 7- 35. GVRP Settings window The following fields can be set: Parameter Description From/To These two fields allow you to specify the range of ports that will be included in the VLAN that you are creating using the GVRP Settings window. Ingress Check ...
Page 73 - Frame Type; PVID; GVRP; SNTP Settings; Time Setting
DGS-3024 Gigabit Ethernet Switch Manual 59 Frame Type This field denotes the type of frame that will be accepted by the port. The user may choose between Tagged Only , which means only VLAN tagged frames will be accepted, and Admit_All , which means both tagged and untagged frames will be accepted. ...
Page 75 - Time Zone and DST
DGS-3024 Gigabit Ethernet Switch Manual 61 Month Enter the current month, if you would like to update the system clock. Day Enter the current day, if you would like to update the system clock. Time in HH MM SS Enter the current time in hours and minutes, if you would like to update the system clock....
Page 76 - QoS
DGS-3024 Gigabit Ethernet Switch Manual 62 Daylight Saving Time State Use this pull-down menu to enable or disable the DST Settings. Daylight Saving Time Offset in Minutes Use this pull-down menu to specify the amount of time that will constitute your local DST offset - 30 , 60 , 90 , or 120 minutes...
Page 77 - Advantages of QoS
DGS-3024 Gigabit Ethernet Switch Manual 63 Advantages of QoS QoS is an implementation of the IEEE 802.1p standard that allows network administrators a method of reserving bandwidth for important functions that require a large bandwidth or have a high priority, such as VoIP (voice-over Internet Proto...
Page 79 - Traffic Control
DGS-3024 Gigabit Ethernet Switch Manual 65 Traffic Control Use the Traffic Control window to enable or disable storm control and adjust the threshold for multicast/broadcast/DLF (Destination Look Up Failure) storms. Traffic control settings are applied to individual Switch modules. To view the follo...
Page 81 - Figure 7- 41. User Priority Configuration window; QoS Scheduling Mechanism; Figure 7- 42. QoS Scheduling Mechanism window
DGS-3024 Gigabit Ethernet Switch Manual 67 This window allows you to assign a default 802.1p priority to any given port on the Switch. The priority queues are numbered from 0, the lowest priority, to 7, the highest priority. Click Apply to implement your settings. 802.1p User Priority The DGS-3024 a...
Page 82 - Strict; QoS Output Scheduling; Figure 7- 43. QoS Output Scheduling window; MAC Notification; MAC Notification Global Settings
DGS-3024 Gigabit Ethernet Switch Manual 68 Strict The highest class of service is the first to process traffic. That is, the highest class of service will finish before other queues empty. RoundRobin Use the weighted round-robin ( WRR ) algorithm to handle packets in an even distribution in priority...
Page 83 - Figure 7- 44. MAC Notification Global Settings window; Parameter Description; MAC Notification Port Settings
DGS-3024 Gigabit Ethernet Switch Manual 69 Figure 7- 44. MAC Notification Global Settings window The following parameters may be modified: Parameter Description State Enable or disable MAC notification globally on the Switch Interval (sec) [1~2147483647] The time in seconds between notifications. Hi...
Page 84 - Figure 7- 45. MAC Notification Port Settings window; To
DGS-3024 Gigabit Ethernet Switch Manual 70 Figure 7- 45. MAC Notification Port Settings window The following parameters may be set: Parameter Description From and To Select a port or group of ports to enable for MAC notification using the pull-down menus. State Enable MAC Notification for the ports ...
Page 85 - System Log Server
DGS-3024 Gigabit Ethernet Switch Manual 71 System Log Server The Switch can send Syslog messages to up to four designated servers using the System Log Server. In the Configuration folder, click System Log Server , to view the window shown below. Figure 7- 46. System Log Servers window The parameters...
Page 86 - UDP Port; System Log Servers
DGS-3024 Gigabit Ethernet Switch Manual 72 Numerical Facility Code 0 kernel messages 1 user-level messages 2 mail system 3 system daemons 4 security/authorization messages 5 messages generated internally by Syslog line printer subsystem 7 network news subsystem 8 UUCP subsystem 9 clock daemon 10 sec...
Page 87 - Port Access Entity; Authentication Server
DGS-3024 Gigabit Ethernet Switch Manual 73 Port Access Entity 802.1x Port-Based Access Control The IEEE 802.1x standard is a security measure for authorizing and authenticating users to gain access to various wired or wireless devices on a specified Local Area Network by using a Client and Server ba...
Page 88 - Authenticator; Configuration > Advanced Settings; Authentic RADIUS Server Setting
DGS-3024 Gigabit Ethernet Switch Manual 74 network by exchanging secure information between the RADIUS server and the Client through EAPOL packets and, in turn, informs the Switch whether or not the Client is granted access to the LAN and/or Switch services. Figure 7- 50. Authentication Server Authe...
Page 89 - Client
DGS-3024 Gigabit Ethernet Switch Manual 75 Client The Client is simply the workstation that wishes to gain access to the LAN or Switch services. All workstation must be running software that is compliant with the 802.1x protocol. For users running Windows XP, the software is included within the oper...
Page 90 - Configure Authenticator
DGS-3024 Gigabit Ethernet Switch Manual 76 … 802.1X Client 802.1X Client 802.1X Client 802.1X Client 802.1X Client 802.1X Client 802.1X Client 802.1X Client 802.1X Client Network access controlled port Network access uncontrolled port RADIUS Server Ethernet Switch Figure 7- 53. Example of Typical Po...
Page 93 - Local users
DGS-3024 Gigabit Ethernet Switch Manual 79 TxPeriod This sets the TxPeriod of time for the authenticator PAE state machine. This value determines the period of an EAP Request/Identity packet transmitted to the client. The default setting is 30 seconds. QuietPeriod This allows you to set the number o...
Page 94 - Capability
DGS-3024 Gigabit Ethernet Switch Manual 80 Figure 7- 57. 802.1x Capability Settings window To set up the Switch's 802.1x port-based authentication, select which ports are to be configured in the From and To fields. Next, enable the ports by selecting Authenticator from the drop-down menu under Capab...
Page 97 - RADIUS Server; Port Access Entity > RADIUS Server
DGS-3024 Gigabit Ethernet Switch Manual 83 RADIUS Server The RADIUS feature of the Switch allows you to facilitate centralized user administration as well as providing protection against a sniffing, active hacker. Click Port Access Entity > RADIUS Server to open the Authentic RADIUS Server Settin...
Page 98 - Static ARP Settings
DGS-3024 Gigabit Ethernet Switch Manual 84 Static ARP Settings The Address Resolution Protocol (ARP) is a TCP/IP protocol that converts IP addresses into physical addresses. This table allows network managers to view, define, modify and delete ARP information for specific devices. Static entries can...
Page 99 - Security; Trusted Host; Figure 8- 1. Security IP Management window
DGS-3024 Gigabit Ethernet Switch Manual 85 8 Security The second Web Manager main folder is Security and includes the following windows and sub-folders: Trusted Host , Secure Socket Layer (SSL) , Secure Shell (SSH) , and Access Authentication Control , as well as secondary windows. Trusted Host Go t...
Page 100 - Hash Algorithm; Download Certificate
DGS-3024 Gigabit Ethernet Switch Manual 86 3. Hash Algorithm : This part of the ciphersuite allows the user to choose a message digest function which will determine a Message Authentication Code. This Message Authentication Code will be encrypted with a sent message to provide integrity and prevent ...
Page 102 - SSH Configuration
DGS-3024 Gigabit Ethernet Switch Manual 88 NOTE: Enabling the SSL command will disable the web-based Switch management. To log on to the Switch again, the header of the URL must begin with https://. Entering anything else into the address field of the web browser will result in an error and no authe...
Page 103 - Figure 8- 4. Current SSH Configuration Settings window; Session Rekeying
DGS-3024 Gigabit Ethernet Switch Manual 89 Figure 8- 4. Current SSH Configuration Settings window To configure the SSH server on the Switch, modify the following parameters and click Apply : Parameter Description SSH Server Status Use the pull-down menu to enable or disable SSH on the Switch. The de...
Page 104 - SSH Algorithm; Figure 8- 5. Encryption Algorithm window; Parameter Description
DGS-3024 Gigabit Ethernet Switch Manual 90 SSH Algorithm This window allows the configuration of the desired types of SSH algorithms used for authentication encryption. There are three categories of algorithms listed and specific algorithms of each may be enabled or disabled by using their correspon...
Page 105 - Data Integrity Algorithm; Public Key
DGS-3024 Gigabit Ethernet Switch Manual 91 AES128-CBC Use the pull-down to enable or disable the Advanced Encryption Standard AES128 encryption algorithm with Cipher Block Chaining. The default is Enabled . AES192-CBC Use the pull-down to enable or disable the Advanced Encryption Standard AES192 enc...
Page 106 - SSH User Authentication; Security Management > Secure Shell > SSH User Authentication Mode; Current Accounts; Parameter
DGS-3024 Gigabit Ethernet Switch Manual 92 SSH User Authentication The following windows are used to configure parameters for users attempting to access the Switch through SSH. To access the following window, click Security Management > Secure Shell > SSH User Authentication Mode . Figure 8- 6...
Page 107 - Host Name; Host IP; Access Authentication Control; TACACS
DGS-3024 Gigabit Ethernet Switch Manual 93 publickey on a SSH server for authentication. Host Name Enter an alphanumeric string of no more than 32 characters to identify the remote SSH user. This parameter is only used in conjunction with the Host Based choice in the Auth. Mode field. Host IP Enter ...
Page 108 - Enable Admin; Authentication Policy & Parameters; Security > Access Authentication Control > Policy and Parameters; Parameters Description
DGS-3024 Gigabit Ethernet Switch Manual 94 authentication is made, the second server host in the list will be queried, and so on. The built-in Authentication Server Groups can only have hosts that are running the specified protocol. For example, the TACACS Authentication Server Groups can only have ...
Page 109 - Application Authentication Settings; Authentication Server Group
DGS-3024 Gigabit Ethernet Switch Manual 95 Click Apply to implement changes made. Application Authentication Settings This window is used to configure Switch configuration applications (console, Telnet, SSH, web) for login at the user level and at the administration level (Enable Admin ) utilizing a...
Page 110 - Figure 8- 10. Authentication Server Group Settings window; Authentication Server Group Settings
DGS-3024 Gigabit Ethernet Switch Manual 96 Figure 8- 10. Authentication Server Group Settings window This window displays the Authentication Server Groups on the Switch. The Switch has four built-in Authentication Server Groups that cannot be removed but can be modified. To modify a particular group...
Page 111 - Authentication Server Host; Figure 8- 13. Authentication Server Host Settings window; Figure 8- 14. Authentication Server Host Setting - Add window
DGS-3024 Gigabit Ethernet Switch Manual 97 NOTE: The user must configure Authentication Server Hosts using the Authentication Server Hosts window before adding hosts to the list. Authentication Server Hosts must be configured for their specific protocol on a remote centralized server before this fun...
Page 112 - Key; Login Method Lists
DGS-3024 Gigabit Ethernet Switch Manual 98 IP Address The IP address of the remote server host the user wishes to add. Protocol The protocol used by the server host. The user may choose one of the following: TACACS - Enter this parameter if the server host utilizes the TACACS protocol. XTACACS - Ent...
Page 113 - Figure 8- 15. Login Method List Settings window; Delete; Figure 8- 17. Login Method List – Add window
DGS-3024 Gigabit Ethernet Switch Manual 99 Figure 8- 15. Login Method List Settings window The Switch contains one Method List that is set and cannot be removed, yet can be modified. To delete a Login Method List defined by the user, click the under the Delete heading corresponding to the entry desi...
Page 114 - Enable Method Lists; Security > Access Authentication Control > Enable Method Lists
DGS-3024 Gigabit Ethernet Switch Manual 100 methods to this method list: tacacs - Adding this parameter will require the user to be authenticated using the TACACS protocol from a remote TACACS server. xtacacs - Adding this parameter will require the user to be authenticated using the XTACACS protoco...
Page 116 - Configure Local Enable Password; Figure 8- 21. Configure Local Enable Password window
DGS-3024 Gigabit Ethernet Switch Manual 102 tacacs - Adding this parameter will require the user to be authenticated using the TACACS protocol from a remote TACACS server. xtacacs - Adding this parameter will require the user to be authenticated using the XTACACS protocol from a remote XTACACS serve...
Page 117 - Security > Access Authentication Control > Enable Admin
DGS-3024 Gigabit Ethernet Switch Manual 103 a password configured by the administrator that will support the "enable" function. This function becomes inoperable when the authentication policy is disabled. To view the following window, click Security > Access Authentication Control > En...
Page 118 - Management; User Accounts; Figure 9- 1. User Account Management window; Access Right
DGS-3024 Gigabit Ethernet Switch Manual 104 9 Management The third Web Manager main folder is Management and includes the following windows and sub-folders: User Accounts and SNMPV3 , as well as secondary windows. User Accounts The Switch allows you to set up and manage user accounts in the followin...
Page 119 - Admin and User Privileges
DGS-3024 Gigabit Ethernet Switch Manual 105 The information on the window is described as follows: Parameter Description User Name Enter a user name in this field. New Password Enter the desired new password in this field. Confirm New Password Enter the new password a second time. Access Right Displ...
Page 120 - Management Admin User; Save Configuration; SNMP Manager; public; private
DGS-3024 Gigabit Ethernet Switch Manual 106 Management Admin User Configuration Yes Read Only Network Monitoring Yes Read Only Community Strings and Trap Stations Yes Read Only Update Firmware and Configuration Files Yes No System Utilities Yes No Factory Reset Yes No User Account Management Add/Upd...
Page 121 - SNMP User Table
DGS-3024 Gigabit Ethernet Switch Manual 107 Using SNMPv3 individual users or groups of SNMP managers can be allowed to perform or be restricted from performing specific SNMP management functions. The functions allowed or restricted are defined using the Object Identifier (OID) associated with a spec...
Page 122 - SNMP View Table
DGS-3024 Gigabit Ethernet Switch Manual 108 SHA - Specifies that the HMAC-SHA authentication protocol will be used. This field is only operable when the Encryption field has been checked. This field will require the user to enter a password. Priv-Protocol None - Specifies that no authorization proto...
Page 123 - Figure 9- 7. SNMP View Table Configuration window; SNMP Group Table
DGS-3024 Gigabit Ethernet Switch Manual 109 Figure 9- 7. SNMP View Table Configuration window The SNMP Group created with this table maps SNMP users (identified in the SNMP User Table) to the views created in the previous window. The following parameters can be set: Parameter Description View Name T...
Page 124 - SNMP; SNMP Group Table Configuration
DGS-3024 Gigabit Ethernet Switch Manual 110 To delete an existing SNMP Group Table entry, click the corresponding under the Delete heading. To display the current settings for an existing SNMP Group Table entry, click the hyperlink for the entry under the Group Name. Figure 9- 9. SNMP Group Table Di...
Page 125 - Security Model; Security Level; SNMP Community Table
DGS-3024 Gigabit Ethernet Switch Manual 111 Security Model SNMPv1 – Specifies that SNMP version 1 will be used. SNMPv2 – Specifies that SNMP version 2c will be used. The SNMPv2 supports both centralized and distributed network management strategies. It includes improvements in the Structure of Manag...
Page 126 - Figure 9- 11. SNMP Community Table Configuration window; SNMP Host Table
DGS-3024 Gigabit Ethernet Switch Manual 112 Figure 9- 11. SNMP Community Table Configuration window The following parameters can be set: Parameter Description Community Name Type an alphanumeric string of up to 32 characters that is used to identify members of an SNMP community. This string is used ...
Page 127 - SNMP Engine ID
DGS-3024 Gigabit Ethernet Switch Manual 113 Figure 9- 12. SNMP Host Table window To add a new entry to the Switch's SNMP Host Table, click the Add button in the upper left-hand corner of the window. This will open the SNMP Host Table Configuration window, as shown below. Figure 9- 13. SNMP Host Tabl...
Page 129 - Monitoring; Port Utilization
DGS-3024 Gigabit Ethernet Switch Manual 115 10 Monitoring The fourth Web Manager main folder is Monitoring and includes the following windows and sub-folders: Port Utilization , Packets , Errors , Size , MAC Address , Switch History Log , IGMP Snooping Group , IGMP Snooping Forwarding , VLAN Status ...
Page 130 - Packets
DGS-3024 Gigabit Ethernet Switch Manual 116 Parameter Description Time Interval Select the desired setting between 1s and 60s , where "s" stands for seconds. The default value is one second. Record Number Select the number of times the Switch will be polled between 20 and 200 . The default v...
Page 135 - Errors
DGS-3024 Gigabit Ethernet Switch Manual 121 Figure 10- 7. Tx Packets Analysis window (table for Bytes and Packets) The following fields may be set or viewed: Parameter Description Time Interval Select the desired setting between 1s and 60s , where "s" stands for seconds. The default value is...
Page 138 - Clear
DGS-3024 Gigabit Ethernet Switch Manual 124 Clear Clicking this button clears all statistics counters on this window. View Table Clicking this button instructs the Switch to display a table rather than a line graph. View Line Chart Clicking this button instructs the Switch to display a line graph ra...
Page 140 - Size
DGS-3024 Gigabit Ethernet Switch Manual 126 View Table Clicking this button instructs the Switch to display a table rather than a line graph. View Line Chart Clicking this button instructs the Switch to display a line graph rather than a table. Size The Web Manager allows packets received by the Swi...
Page 142 - MAC Address
DGS-3024 Gigabit Ethernet Switch Manual 128 Show/Hide Check whether or not to display 64, 65-127, 128-255, 256-511, 512-1023, and 1024-1518 packets received. Clear Clicking this button clears all statistics counters on this window. View Table Clicking this button instructs the Switch to display a ta...
Page 143 - Find
DGS-3024 Gigabit Ethernet Switch Manual 129 Figure 10- 14. MAC Address Table window The following fields can be viewed or set: Parameter Description VLAN ID Enter a VLAN ID for the forwarding table to be browsed by. MAC Address Enter a MAC address for the forwarding table to be browsed by. Find Allo...
Page 144 - Switch History Log
DGS-3024 Gigabit Ethernet Switch Manual 130 MAC Address The MAC address entered into the address table. Port The port that the MAC address above corresponds to. Learned How the Switch discovered the MAC address. The possible entries are Dynamic, Self, and Static. Next Click this button to view the n...
Page 145 - Next
DGS-3024 Gigabit Ethernet Switch Manual 131 Figure 10- 15. Switch History window The Switch can record event information in its own logs, to designated SNMP trap receiving stations, and to the PC connected to the console manager. Click Next to go to the next page of the Switch History Log. Clicking ...
Page 146 - IGMP Snooping Group; IGMP Snooping Table
DGS-3024 Gigabit Ethernet Switch Manual 132 Parameter Description Sequence A counter incremented whenever an entry to the Switch's history log is made. The table displays the last entry (highest sequence number) first. Time Displays the time in days, hours, and minutes since the Switch was last rest...
Page 147 - IGMP Snooping Forwarding; VLAN Status
DGS-3024 Gigabit Ethernet Switch Manual 133 IGMP Snooping Forwarding This window will display the current IGMP snooping forwarding table entries currently configured on the Switch. To view the following screen, open the Monitoring folder and click the IGMP Snooping Forwarding link. Figure 10- 17. IG...
Page 148 - Router Port; Session Table; Figure 10- 20. Current Session Table window
DGS-3024 Gigabit Ethernet Switch Manual 134 Router Port This displays the Switch's ports that are currently configured as router ports. A router port configured by a user (using the console or Web-based management interfaces) is displayed as a static router port, designated by an S. A router port th...
Page 149 - Port Access Control; RADIUS Authentication; Figure 10- 21. RADIUS Authentication window
DGS-3024 Gigabit Ethernet Switch Manual 135 Port Access Control RADIUS Authentication Figure 10- 21. RADIUS Authentication window .
Page 150 - Maintenance; TFTP Services; Download Firmware; Figure 11- 1. Download Firmware from TFTP Server window; Download Configuration File; Figure 11- 2. Download Settings from TFTP Server window
DGS-3024 Gigabit Ethernet Switch Manual 136 11 Maintenance The fifth Web Manager main folder is Maintenance and includes the following windows and sub-folders: TFTP Services , Ping Test , Save Changes , Reboot Services , and Logout , as well as secondary windows. TFTP Services Trivial File Transfer ...
Page 151 - Save Settings; Figure 11- 3. Upload Settings to TFTP Server window; Save History Log; Figure 11- 4. Upload Log to TFTP Server window; Ping Test
DGS-3024 Gigabit Ethernet Switch Manual 137 Enter the IP address of the TFTP server and specify the location of the Switch settings file on the TFTP server. Click Start to record the IP address of the TFTP server and to initiate the file transfer. Save Settings To upload the Switch settings to a TFT...
Page 152 - Start; Save Changes
DGS-3024 Gigabit Ethernet Switch Manual 138 Figure 11- 5. Ping Test window The user may use the Infinite times radio button, in the Repeat Pinging for field, which will tell the ping program to keep sending ICMP Echo packets to the specified IP address until the program is stopped. The user may opt ...
Page 153 - Figure 11- 7. Save Configuration Confirmation dialog box; Reboot Services; Reboot; Reset
DGS-3024 Gigabit Ethernet Switch Manual 139 Figure 11- 7. Save Configuration Confirmation dialog box Click the OK button to continue. Once the Switch configuration settings have been saved to NV-RAM, they become the default settings for the Switch. These settings will be used every time the Switch i...
Page 154 - Reset Config; Reset System; Logout
DGS-3024 Gigabit Ethernet Switch Manual 140 Reset gives the option of retaining the Switch's User Accounts and History Log while resetting all other configuration parameters to their factory defaults. If the Switch is reset using this window, and Save Changes is not executed, the Switch will return ...
Page 156 - Technical Specifications; Performance
DGS-3024 Gigabit Ethernet Switch Manual 142 A Technical Specifications Performance Transmission Method Store-and-forward RAM Buffer 512Kbytes per device Packet Filtering/ Forwarding Rate Full-wire speed for all connections. 1,488,095 pps per port (for 1000Mbps) MAC Address Learning Automatic update....
Page 157 - General; Standards
DGS-3024 Gigabit Ethernet Switch Manual 143 General Standards IEEE 802.3 10BASE-T Ethernet IEEE 802.3u 100BASE-TX Fast Ethernet IEEE 802.3z Gigabit Ethernet IEEE 802.1Q Tagged VLAN IEEE 802.1P Tagged Packets IEEE 802.3ab 1000BASE-T IEEE 802.3x Full-duplex Flow Control ANSI/IEEE 802.3 NWay auto-negot...
Page 158 - Cable Lengths; Standard
DGS-3024 Gigabit Ethernet Switch Manual 144 B Cable Lengths Use the following table to as a guide for the maximum cable lengths: Standard Media Type Maximum Distance DEM-310GT: SFP Transceiver for 1000BASE-LX, Single-mode fiber module 10km DEM-311GT: SFP Transceiver for 1000BASE-SX, Multi-mode fiber...
Page 159 - Glossary
DGS-3024 Gigabit Ethernet Switch Manual 145 C Glossary 1000BASE-T – A specification for Gigabit Ethernet over copper wire (IEEE Std. 802.3ab). The standard defines 1 Gb/s data transfer over distances of up to 100 meters using four pairs of CAT-5 balanced copper cabling and a 5-level coding scheme. I...
Page 162 - Warranty and Registration Information; (All countries and regions excluding USA); Wichtige Sicherheitshinweise
Warranty and Registration Information (All countries and regions excluding USA) Wichtige Sicherheitshinweise 1. Bitte lesen Sie sich diese Hinweise sorgfältig durch. 2. Heben Sie diese Anleitung für den spätern Gebrauch auf. 3. Vor jedem Reinigen ist das Gerät vom Stromnetz zu trennen. Vervenden Sie...
Page 163 - Limited Warranty
FAILURE OR INTERRUPTION OF A D- LINK PRODUCT, HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY. THIS LIMITATION WILL APPLY EVEN IF D-LINK HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. IF YOU PURCHASED A D-LINK PRODUCT IN THE UNITED STATES, SOME STATES DO NOT ALLOW THE LIMITATION OR EXCLUSION OF L...
Page 167 - Product Registration
Product Registration Register your D-Link product online at http://support.dlink.com/register/ Product registration is entirely voluntary and failure to complete or return this form will not diminish your warranty rights.
Page 168 - D-Link Europe Limited Product Warranty
Trademarks Copyright 2005 D-Link Corporation. Contents subject to change without prior notice. D-Link is a registered trademark of D-Link Corporation/ D-Link Systems Inc. All other trademarks belong to their respective proprietors. Copyright statement No part of this publication may be reproduced in...
Page 169 - Warrantor
use or storage; or (f) fire, water, acts of God or other catastrophic events. This warranty shall also not apply to any particular product if any D-LINK serial number has been removed or defaced in any way. D-LINK IS NOT RESPONSIBLE FOR DAMAGE THAT OCCURS AS A RESULT OF YOUR FAILURE TO FOLLOW THE IN...
Page 170 - D-Link Europe Limited Produktgarantie; Allgemeine Bedingungen
D-Link Europe Limited Produktgarantie Allgemeine Bedingungen Die hierin beschriebene eingeschränkte Garantie wird durch D-LINK (Europe) Ltd. Gewährt (im Folgenden: „D-LINK“). Diese eingeschränkte Garantie setzt voraus, dass der Kauf des Produkts nachgewiesen wird. Auf Verlangen von D-LINK muss auch ...
Page 171 - Leistungsumfang der eingeschränkten Garantie; Garantiegeber; Edgware Road; Produkttyp
eingeschränkten Garantie eine Reparatur benötigen, so sind Sie berechtigt, gemäß den Bedingungen dieser eingeschränkten Garantie Garantiedienste in Anspruch zu nehmen. Diese eingeschränkte Garantie gilt nur für denjenigen, der das D-LINK Hardware-Produkt ursprünglich als originärer Endbenutzer gekau...
Page 172 - D-Link Europe a limité la garantie des produits; Conditions Générales
D-Link Europe a limité la garantie des produits Conditions Générales La Garantie Produit Limitée énoncée ci-dessous émane de D-LINK (Europe) Ltd. (ci-après « D-LINK »). Cette Garantie Produit Limitée n’est valable que sur présentation de la prevue d’achat. D-LINK peut également exiger la présentatio...
Page 173 - Exécution de la Garantie Produit Limitée; Garant; Type de produit
présentes dès lorsque que votre matériel de marque D-LINK nécessite une réparation pendant la Période de Garantie Produit Limitée. La présente Garantie Produit Limitée s’applique uniquement à l’acheteur utilisateur final initial du Produit Matériel D-LINK. Elle est non cessible à quiconque se procur...
Page 174 - Garantía limitada del producto D-LINK Europa; Condiciones generales
Garantía limitada del producto D-LINK Europa Condiciones generales Esta garantía la ofrece D-LINK (Europe) Ltd. (en este documento, "D-LINK"). La garantía limitada del producto sólo es válida si se acompaña del comprobante de la compra. También deberá presentarse la tarjeta de garantía si D-...
Page 176 - D-Link Europe Termini di Garanzia dei Prodotti; Generalità
D-Link Europe Termini di Garanzia dei Prodotti Generalità La presente Garanzia viene fornita da D-LINK (Europe) Ltd. (di seguito denominata "DLINK"). Essa viene riconosciuta solo se accompagnata dalla prova di acquisto. D-LINK può richiedere anche l’esibizione della presente cartolina di gar...
Page 178 - Offices
Offices U.S.A 17595 Mt. Herrmann Street Fountain Valley, CA. 92708 TEL: 714-885-6000 FAX: 866-743-4905 URL: www.dlink.com Canada 2180 Winston Park Drive Oakville, Ontario, L6H 5W1 Canada TEL: 1-905-8295033 FAX: 1-905-8295223 URL: www.dlink.ca Europe (U. K.) 4th Floor, Merit House Edgware Road, Colin...
Page 179 - Registration Card; (All Countries and Regions excluding USA)
Registration Card (All Countries and Regions excluding USA) Print, type or use block letters. Your name: Mr./Ms_____________________________________________________________________________ Organization: ________________________________________________ Dept. ____________________________ Your title at...