Page 2 - Preface; command
Preface This guide describes how to use the Command Line Interface (CLI) for the Magnum 6K family of switches. For the Web Management Interface please refer to the Web Management Guide. Some simple guidelines which will be useful for configuring and using the Magnum 6K family of switches - If you ne...
Page 3 - Trademarks
ii Trademarks GarrettCom Inc. reserves the right to change specifications, performance characteristics and/or model offerings without notice. GarrettCom, Magnum, S-Ring, Link-Loss-Learn, Converter Switch, Convenient Switch and Personal Switch are trademarks and Personal Hub is a registered trademark...
Page 4 - Table of Contents; – Conventions Followed
Table of Contents 1 – Conventions Followed ...............................................................18 Flow of the User Guide ..........................................................19 2 – Getting Started ............................................................................22 Before s...
Page 5 - – IP Address and System Information
List of commands in this chapter ..........................................33 3 – IP Address and System Information .....................................35 IP Addressing ............................................................................... 35 Importance of an IP address ......................
Page 9 - Chapter 14 – Link Aggregation Control Protocol (LACP)270
Configuring SNMP ................................................................221 Configuring RMON ..............................................................230 List of commands in this chapter ........................................231 19 – Miscellaneous Commands ..............................
Page 12 - List of Figures
List of Figures F IGURE 1 - HyperTerminal screen showing the serial settings ................................................................. 24 F IGURE 2 - Prompt indicating the switch model number as well as mode of operation – note the commands to switch between the levels is not shown here. ......
Page 19 - Chapter; Conventions followed in the manual...; Switch prompt; document we will use; Syntax rules; Syntax
Chapter 1 1 – Conventions Followed Conventions followed in the manual… o best use this document, please review some of the conventions followed in the manual, including screen captures, interactions and commands with the switch, etc. T Box shows interaction with the switch command line or screen cap...
Page 20 - Flow of the User Guide
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Related Topics Related topics show that GarrettCom strongly recommends reading about those topics. You may choose to skip those if you already have prior detailed knowledge on those subjects. j Tool box – Necessary software and hardware...
Page 23 - – Getting Started; First few simple steps ...; Before starting; For initial configuration through the serial/console port; only; be done by using the
Chapter 2 2 – Getting Started First few simple steps … his section explains how the GarrettCom Magnum 6K family of switches can be setup using the console port on the switch. Some of the functionality includes setting up the IP address of the switch, securing the switch with a user name and password...
Page 24 - Magnum switches already have the necessary software loaded on; Console connection
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E The same procedure can also be used for other configuration changes or updates – e.g. changing the IP address, VLAN assignments and more. Once the IP address is assigned and a PC is networked to the switch, the switch’s command line int...
Page 25 - Console setup; HyperTerminal screen showing the serial settings; Console screen
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E The interface through the console or the Console Management Interface (or CMI) enables you to reconfigure the switch and to monitor switch status and performance. Once the switch is configured with an IP address, the Command Line Interf...
Page 26 - commands to switch between the levels is not shown here.; Logging in for the first time; Password – manager; Setting the IP parameters
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E The switch has three modes of operation – Operator (least privilege), Manager and Configuration. The prompts for the switches change as the switch changes modes from Operator to Manager to Configuration. The prompts are shown in Figure ...
Page 27 - Setting IP address on the switch
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Should a situation arise when there are multiple new switches powered up at the same time, there could be a situation of duplicate IP addresses. In this situation, only one Magnum switch will be assigned the IP address of 192.168.1.2 an...
Page 28 - Rebooting the switch; ‘show’; view setup parameters
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Reboot gives an opportunity to save the configuration prior to shutdown. For a reboot – simply type in the command “reboot”. (Note – even though the passwords are not changed, they can be changed later.) Magnum6K25# reboot Proceed on re...
Page 29 - Privilege levels; Manager; enable’; Operator Privileges; User management
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Some of the parameters in the Magnum 6K family of switches are shown above. The list of parameters below indicates some of the key parameters on the switch and the recommendations for changing them (or optionally keeping them the same)....
Page 30 - Add User; In this example, user ‘peter’ was added with Manager privilege.; Delete User; In this example, user ‘peter’ was deleted.; Modify Password; Modify the Privilege Level
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Add User To add a user, use the command “add” as shown below. The user name has to be a unique name and can be up to 24 characters long. The password is recommended to be at least 8 characters long with a mix of upper case, lower case, ...
Page 31 - Changing the privilege levels for a user; Modify Access Privileges for a user; – Creating user access privileges
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Magnum6K25(user)## chlevel user=peter level=1 Access Permission Modified Magnum6K25(user)## F IGURE 10 - Changing the privilege levels for a user In this example, user ‘peter’ was modified to Operator privileges. Modify Access Privilege...
Page 32 - Help; Typing the ‘; Help command; Displaying Help for an Individual Command; followed by enough of the command string to identify the command.; Help for a specific command; Viewing options for a command
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Help Typing the ‘ help ’ command lists the commands you can execute at the current privilege level. For example, typing ‘ help ’ at the Operator level shows Magnum6K25> help logout ping set terminal telnet walkmib Contextless Command...
Page 33 - Context help; OR
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Usage show active-stp show active-snmp show active-vlan show address-table show age show alarm show arp show auth <config|ports> show backpressure show bootmode --more-- F IGURE 14 - Options for the ‘show’ command Context help Oth...
Page 34 - Exiting; List of commands in this chapter
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E OR Magnum6K25> se<TAB> password timeout vlan Magnum6K25> set F IGURE 17 - Listing commands options – note the command was not completed and the TAB key completed the command. Exiting To exit from the CLI interface and termin...
Page 36 - First simple steps to follow...; bootp; Importance of an IP address; Chapter 2 – Setting IP Parameters.
Chapter 3 3 – IP Address and System Information First simple steps to follow… his section explains how the Magnum 6K family of switches can be setup using other automatic methods such as bootp and DHCP . Besides this, other parameters required for proper operation of the switch in a network are disc...
Page 37 - To verify the IP address settings, the; ‘show ipconfig’; command can be used.; Checking the IP settings; DHCP is commonly used for setting up addresses for computers,; Bootp Database
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 36 To verify the IP address settings, the ‘show ipconfig’ command can be used. Magnum6K25> show ipconfig IP Address : 192.168.1.150 Subnet Mask : 255.255.255.0 Default Gateway : 192.168.1.10 Magnum6K25> F IGURE 19 - Checking the I...
Page 38 - This tag must precede the “
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E ht: is the “hardware type”. For the Magnum 6K family of switches, set this to ether (for Ethernet). This tag must precede the “ ha” ta g. ha: is the “hardware address”. Use the switch’s 12-digit MAC address ip: is the IP address to be a...
Page 39 - Changing the boot mode of the switch; Using Telnet; “telnet disable”; command discussed in; any effect to the switch; ‘show console’; command can show the status of the telnet client as well as other
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E switch is put on a network and the specific configurations are loaded from a centralized BootP server Magnum6K25# set bootmode type=dhcp Save Configuration and Restart System Magnum6K25# set bootmode type=auto Save Configuration and Res...
Page 40 - The default port for telnet is 23.; show session
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Magnum6K25# show console Console/Serial Link Inbound Telnet Enabled : Yes Outbound Telnet Enabled : Yes Web Console Enabled : Yes SNMP Enabled : Yes Terminal Type : VT100 Screen Refresh Interval (sec) : 3 Baud Rate : 38400 Flow Control ...
Page 41 - – managing and viewing multiple telnet sessions; “show session”; command. The user operator session is then terminated using the; “kill session”; The default port – port 23 is used for telnet.; Setting serial port parameters
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Magnum6K25# user Magnum6K25(user)## useraccess user=peter service=telnet enable Telnet Access Enabled. Magnum6K25(user)## exit Magnum6K25# show session Current Sessions: SL # Session Id Connection User Name User Mode 1 1 163.10.10.14 ma...
Page 42 - Warning; To see the current settings of the serial port, use the; ‘show serial’; Querying the serial port settings; System parameters; commands are used frequently. They are; ‘show sysconfig’; and; ‘show setup’; commands are shown below.; changed
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Warning – changing these parameters through the serial port will cause loss of connectivity – the parameters of the terminals software (e.g. Hyper Terminal etc.) will also have to be changed to match the new settings. To see the current...
Page 43 - Using a unique name helps you to identify individual devices in a; System Contact and System Information:; This is helpful for identifying the
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Magnum6K25# show sysconfig System Name : Magnum6K25 System Contact : [email protected] System Location : HO, Fremont, CA Boot Mode : manual Inactivity Timeout(min) : 10 Address Age Interval(min) : 300 Inbound Telnet Enabled : Yes W...
Page 44 - Date and time; using the; ‘set’; resets the time. Other relevant date and time commands are:
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Date and time It may be necessary to set the day, time or the time zone manually. This can be done by using the ‘set’ command with the necessary date and time options. These are listed below: Syntax set timezone GMT=[+ or -] hour=<0-...
Page 45 - Setting the system daylight saving time; Network time; Set the IP parameters on the switch
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 44 Daylight savings location name : USA Magnum6K25# F IGURE 30 - Setting the system daylight saving time See Appendix 3 for additional information on Daylight Savings Time. The lists of countries for the time zone are Australia, Belgium...
Page 46 - Setting up SNTP services; Saving and loading configuration; Saving the configuration on a tftp server
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Magnum6K25# sntp Magnum6K25(sntp)## setsntp server=204.65.129.201 timeout=3 retry=3 SNTP server is added to SNTP server database Magnum6K25(sntp)## sync hour=5 Magnum6K25(sntp)## sntp enable Do not forget to enable sntp for time synchro...
Page 47 - show ftp
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 46 software is updated, it is advised to save the configurations. The re-loading of the configuration is not usually necessary; however, in certain situations it maybe needed and it is advised to save configurations before a software up...
Page 49 - Config files
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Prior to Release 3.2, the configuration was saved only as a binary object (file). With Release 3.2 and beyond, the configuration can be saved in the older format – binary object or in a newer format as an ASCII (readable) file. The new ...
Page 50 - ; – Contents of the config file
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E # rights in Technical Data and Computer Software clause at # 52.227-7013. # # This file is provided as a sample template to create a backup # of Magnum 6K switch configurations. As such, this script # provides insights into the configur...
Page 51 - – Creating host entries on MNS-6K; Displaying configuration; ‘show config’; command is
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E computed and stored in the file will not be matched. Should you want to edit, edit the System portion of the file only. GarrettCom recommends editing the “script” file (see below) Note 2 – File names cannot have special characters such ...
Page 53 - show config’; command output; displaying specific modules using the
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E <additional lines deleted for succinct viewing> F IGURE 37 – ‘ show config’ command output Magnum6K25# show config module=snmp [HARDWARE] type=Magnum6K25 slotB=8 Port TP Module #####################################################...
Page 54 - command line; Erasing configuration; – resets the system configuration. The module-name
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E snmp_access=enable web_access=enable --more— <additional lines deleted for succinct viewing> F IGURE 39 – displaying configuration for different modules. Note – multiple modules can be specified on the command line Erasing configu...
Page 55 - ‘kill config save=system’; Erasing configuration without erasing the IP address; Displaying Serial Number
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E tacacs TACACS+ settings auth 802.1x Settings igmp IGMP Settings smtp SMTP settings If the module name is not specified the whole configuration is erased. For example, ‘kill config save=system’ preserves the system IP address, netmask an...
Page 56 - Where; dhcp; bootp or other modes; – do not set the IP address automatically; auto
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E List of commands in this chapter Syntax set bootmode type=<dhcp|bootp|manual|auto> [bootimg=<enable|disable>] [bootcfg=[<enable|disable>] – assign the boot mode for the switch Where <dhcp|bootp|manual|auto> - whe...
Page 58 - Other commands
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Syntax tftp <get|put> [type=<app|config|oldconf|script|hosts|log>] [host=<hostname>] [ip=<ipaddress>] [file=<filename>] – upload and download information using tftp command Where <get|put> - different...
Page 60 - Next generation IP addressing; It is assumed here that the user is familiar with IP addressing; Introduction to IPv6
Chapter 4 4 – IPv6 Next generation IP addressing his section explains how the access to the GarrettCom Magnum MNS-6K can setup using IPv6 instead of IPv4 addressing described earlier. IPv6 provides a much larger address space and is required today by many. T Assumptions j It is assumed here that the...
Page 61 - What’s changed in IPV6?
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E and IPv6 hosts. The transition to a new version of the Internet Protocol is normally incremental, with few or no critical interdependencies. Most of today's internet uses IPv4, which is now nearly twenty years old. IPv4 has been remarka...
Page 62 - ‘ping’; show ipv6; - displays the IPv6 information
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E IPv6 Addressing IPv6 addresses are 128-bits long and are identifiers for individual interfaces and sets of interfaces. IPv6 addresses of all types are assigned to interfaces, not nodes. Since each interface belongs to a single node, any...
Page 63 - Example; show ipconfig
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Magnum 6K25# ipconfig ? ipconfig : Configures the system IP address, subnet mask and gateway Usage ipconfig [ip=<ipaddress>] [mask=<subnet-mask>] [dgw=<gateway>] Magnum 6K25# ipconfig ip=fe80::220:6ff:fe25:ed80 mask=ff...
Page 65 - – Access Considerations; Securing the switch access....; security as well as securing access for users and computers on a; Passwords; ‘set password’; Changing password for a given account
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Chapter 5 5 – Access Considerations Securing the switch access…. his section explains how the access to the GarrettCom Magnum MNS-6K can be secured. Further security considerations are also covered such as securing access by IP address ...
Page 66 - Port Security; disable; drop mode; Network security hinges on the ability to allow or deny access to; Configuring Port Security; Port security configuration mode
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Port Security The port security feature can be used to block computers from accessing the network by requiring the port to validate the MAC address against a known list of MAC addresses. This port security feature is provided on an Ethe...
Page 68 - specified MAC addresses); Enabling and disabling port security
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Note 1: There is a limitation of 200 MAC addresses per port and 500 MAC addresses per Switch for Port Security. Note 2: All the commands listed above have to be executed under the port-security configuration mode. Syntax clear <histo...
Page 70 - port or specific ports or a range of ports can be queried as shown; – Removing a MAC address from port security; Setting the logging on a port; ‘enable ps’
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 00:01:03:e2:27:89 00:07:50:ef:31:40 00:e0:29:22:15:85 00:03:47:ca:ac:45 00:30:48:70:71:23 00:c1:00:7f:ec:00 11 ENABLE NONE NONE ENABLE 0 00:c1:00:7f:ec:00 13 ENABLE NONE NONE DISABLE 0 00:c1:00:7f:ec:00 F IGURE 51 – Allowing specific MA...
Page 71 - ‘signal port’; to make a log entry or send a trap)
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 8) Disable access to the network for unauthorized devices (Use ‘action port=11 <diable|drop>’ depending on whether the port should be disabled or the packed dropped. Follow that with a ‘show port-security’ command to verify the se...
Page 72 - Steps for setting up port security on a specific port; Logs; Code Description
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Magnum6K25# F IGURE 54 – Steps for setting up port security on a specific port Once port security is setup, it is important to manage the log and review the log often. If the signals are sent to the trap receiver, the traps should also ...
Page 73 - The; ‘show log’; command displays the log information and the; ‘clear log’
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E The ‘show log’ command displays the log information and the ‘clear log’ command clears the log entries. Syntax show log [fatal|alert|crit|error|warn|note|info|debug] – display the log Syntax clear log [fatal|alert|crit|error|warn|note|i...
Page 74 - date and time; Severity; Authorized managers
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E F IGURE 55 – Show log and clear log command. The show log command indicates the type of log activity in the S column The log shows the most recent intrusion at the top of the listing. If the log is filled when the switch detects a new i...
Page 77 - removeall
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 76 Syntax removeall – remove all IP addresses of trusted hosts Syntax show ip-access – display all trusted hosts Syntax clear <history|log [1..5 |informational |activity |critical |fatal |debug] |terminal |arp|portstats|addr] – clear...
Page 78 - – Access Using RADIUS; Using a RADIUS server to authenticate access....; Port Based Network Access Control
Chapter 6 6 – Access Using RADIUS Using a RADIUS server to authenticate access…. he IEEE 802.1x standard, Port Based Network Access Control , defines a mechanism for port- based network access control that makes use of the physical access characteristics of IEEE 802 LAN infrastructure. It provides a...
Page 79 - The details of the 802.1x authentication are shown below
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E allowing access to services that are accessible via that port. The authenticator is responsible for communication with the supplicant and for submitting the information received from the supplicant to a suitable authentication server. T...
Page 80 - x authentication details
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 79 F IGURE 58 – 802.1x authentication details 1. The supplicant (laptop/host) is initially blocked from accessing the network. The supplicant wanting to access these services starts with an EAPOL-Start frame 2. The authenticator (Magnum...
Page 81 - Limits the authentication of a single host per port
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E The Magnum MNS-6K software implements the 802.1x authenticator. It fully conforms to the standards as described in IEEE 802.1x, implementing all the state machines needed for port-based authentication. The Magnum MNS-6K Software authent...
Page 85 - – securing the network using port access
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Magnum6K25(auth)## show-port reauth Port Reauth Status Reauth Period (sec) ================================================= 1 Enabled 300 2 Enabled 3600 3 Enabled 3600 4 Enabled 3600 5 Enabled 3600 6 Enabled 3600 7 Enabled 3600 8 Enabl...
Page 87 - port –
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 86 Syntax reauth port=<num|list|range> [status=<enable|disable>] [period=<10-86400>] - set values on how the authenticator (Magnum 6K switch) does the re-authentication with the supplicant or PC port – [mandatory] – po...
Page 88 - – Access Using TACACS+; Using a TACACS+ server to authenticate access....; based access control protocol. TCP offers a reliable connection-
Chapter 7 7 – Access Using TACACS+ Using a TACACS+ server to authenticate access…. ACACS+, short for Terminal Access Controller Access Control System, protocol provides access control for routers, network access servers and other networked computing devices via one or more centralized servers. TACAC...
Page 90 - TACACS packet format
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E is authentication where the user is verified against the network user database. The second stage is authorization, where it is determined whether the user has operator access or manager privileges. TACACS+ Packet Packet encryption is a ...
Page 92 - – Configuring TACACS+; show status of TACACS or servers configured as TACACS+
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E ID TACACS+ Server Port Encrypt Key ================================================ 1 10.21.1.170 49 Enabled secret 2 10.21.1.123 49 Enabled some 3 -- -- -- -- 4 -- -- -- -- 5 -- -- -- -- Magnum6K25(user)## tacserver delete id=2 TACACS+...
Page 94 - – Port Mirroring and Setup; An Ethernet switch sends traffic from one port to another port,; Port mirroring
Chapter 8 8 – Port Mirroring and Setup Setup the ports for network speeds, performance as well as for monitoring…. his section explains how individual characteristics of a port on the GarrettCom Magnum 6K family of switches are setup. For monitoring a specific port, the traffic on a port can be mirr...
Page 95 - Enabling port mirroring; “prtmr diable”; port mirror and then assign the new port as described above; Port setup; – enter the device configuration mode; device; – sets up the Magnum 6K switch in the device configuration mode; name; and can be a server name, user name or any other name
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E The set of commands show how port 11 is mirrored on port 13. Any traffic on port 11 is also sent on port 13. Magnum6K25# show port-mirror Sniffer Port : 0 Monitor Port : 0 Mirroring State : disabled Magnum6K25# port-mirror Magnum6K25(po...
Page 96 - – sets up flow control on the port. See Flow Control section below; bp; – disable – disables the port from operation; Speed settings
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E speed – specifically sets the speed to be 10 or 100Mbps. Note – this works only with 10/100 ports – with 10Mbps ports, the option is ignored. No error is shown. See speed settings section below. flow – sets up flow control on the port. ...
Page 97 - device connected to the port; Flow Control; Disabled; flow control packets; Enabled; and processes received flow control packets.
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E with the 802.3u standard, then the port configuration on the switch must be manually set to match the port configuration on the other device. Possible port setting combinations for copper ports are: • 10HDx: 10 Mbps, Half-Duplex • 10FDx...
Page 98 - Back Pressure
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E where xonlimit can be from 3 to 30, default value is 4 xofflimit from 3 to 127, default value is 6 Syntax show flowcontrol Back Pressure Back Pressure is for half duplex operations and the controls provided indicates the number of buffe...
Page 100 - Setting up back pressure and flow control on ports
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Port Flow Control : Disable Port Back Pressure : Disable Magnum6K25(device)## setport port=11 flow=enable bp=enable Magnum6K25(device)## show port Keys: E = Enable D = Disable H = Half Duplex F = Full Duplex M = Multiple VLAN's NA = Not...
Page 101 - Preventing broadcast storms; show broadcast-protect
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Preventing broadcast storms The Magnum 6K family of switches is capable of detecting and limiting storms on each port. A network administrator can also set the maximum rate of broadcast packets (frames) that are permitted from a particu...
Page 102 - Please refer to the above section on broadcast storms.
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 16 Enabled 19531 0 NO Magnum6K25(device)## rate-threshold port=11 rate=3500 Broadcast Rate Threshold set Magnum6K25(device)## show broadcast-protect ====================================================================== PORT | STATUS | ...
Page 104 - – VLAN; hort for; virtual; a VLAN creates separate collision domains or network
103 9 – VLAN Create separate network segments (collision domains) across Magnum 6K family of switches….. hort for virtual LAN (VLAN) , a VLAN creates separate collision domains or network segments that can span multiple Magnum 6K family of switches. A VLAN is a group of ports designated by the switc...
Page 106 - Tag VLAN or Port VLAN?
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 105 F IGURE 69 – routing between different VLANs is performed using a router or a Layer 3 switch (L3- switch) The Magnum 6K family of switches supports up to 32 VLANs per switch Tag VLAN or Port VLAN? What is the difference between tag ...
Page 107 - Private VLANs
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E In the tag VLAN, an identifier called the VLAN identifier (VID) is either inserted or manipulated. This manipulated VLAN tag allows VLAN information to be propagated across devices or switches, allowing VLAN information to span multiple...
Page 108 - Using Port VLANs; Configure at least one VLAN in addition to the default VLAN; Creating VLANs; Creating VLAN; and to configure VLAN related commands
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E The reasons Private VLANs are constructed are for security. For example, if some confidential data were residing on VLAN 5, then only the people connected to that switch on VLAN 5 can have access to that information. No one else can acc...
Page 112 - Using Tag VLANs; Older versions of MNS-6K the use of tag VLANs needed the; ingress
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Status : Active ======================== PORT | STATUS ======================== 14 | DOWN VLAN ID : 30 Name : marketing Status : Active ======================== PORT | STATUS ======================== 14 | DOWN Magnum6K25(port-vlan)## ex...
Page 119 - – Example for Tag VLAN; Tag VLANs and Management
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E ---------------------------------------------------- PORT | MODE | STATUS ---------------------------------------------------- 14 | TAGGED | DOWN 15 | TAGGED | DOWN 16 | TAGGED | DOWN VLAN ID: 30 Name : marketing Status : Active -------...
Page 124 - Create and manage alternate paths to the network; . This means a single spanning tree is created to make
Chapter 10 10 – Spanning Tree Protocol (STP) Create and manage alternate paths to the network panning Tree Protocol was designed to avoid loops in an Ethernet network. An Ethernet network using switches can have redundant paths – this may however cause loops and to prevent the loops MNS-6K software ...
Page 125 - the variables; Using STP
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Variable or Attribute Default Value STP capabilities Disabled reconfiguring general operation priority 32768 Bridge maximum age 20 seconds Hello time 2 seconds Forward delay 15 seconds Reconfiguring per-port STP path cost 0 Priority 327...
Page 126 - Viewing STP configuration
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Bridge Hello Time : 2 Bridge Max Age : 20 Root Port : 0 Root Path Cost : 0 Designated Root : 80:00:00:20:06:25:ed:80 Designated Root Priority : 32768 Root Bridge Forward Delay : 15 Root Bridge Hello Time : 2 Root Bridge Max Age : 20 RST...
Page 127 - STP Port status information
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Designated Root : shows the MAC address of the bridge in the network elected or designated as the root bridge. Normally when STP is not enabled the switch designates itself as the root switch Designated Root Priority : shows the designa...
Page 137 - Transition from STP to RSTP
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E RSTP switches (bridges) generate their own configuration messages, even if they fail to receive one from the root bridge. This leads to quicker failure detection • RSTP offers edge port recognition, allowing ports at the edge of the net...
Page 138 - Configuring RSTP; rstp
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E GarrettCom recommends that all your network devices be updated to support RSTP. RSTP offers convergence times typically of less than one second. However, to make best use of RSTP and achieve the fastest possible convergence times there ...
Page 139 - shared LAN segments
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Syntax port port=<number|list|range> [status=<enable|disable>] [migration=<enable>] [edge=<enable|disable>] [p2p=<on|off|auto>] Example port port=<number|list|range> p2p= off - Set the “point-to-point...
Page 140 - Enabling RSTP and reviewing the RSTP variables
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Designated Root Priority : 0 Root Bridge Forward Delay : 15 Root Bridge Hello Time : 02 Root Bridge Max Age : 20 Topology Change count : 0 Time Since topology Chg : 12 F IGURE 79 – Enabling RSTP and reviewing the RSTP variables The vari...
Page 141 - – Reviewing the RSTP port parameters
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Root Bridge Forward Delay : indicates the designated root bridge’s forward delay. This is the time the switch waits before it switches from the listening to the forwarding state. The default is 15 seconds. This value can be set between ...
Page 142 - Gbps
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Port Type STP Path cost RSTP Path cost 10 Mbps 100 2,000,000 100 Mbps 19 200,000 1 Gbps 4 20,000 10 Gbps 2 2,000 Figure 81 – Path cost as defined in IEEE 802.1d (STP) and 802.1w (RSTP) State: indicates the STP state of individual ports....
Page 144 - Age
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Age : This is the maximum time a message with STP information is allowed by the switch before the switch discards the information and updates the address table again. Value ranges from 6 to 40 seconds with default value of 20 seconds Ma...
Page 150 - Speed up recovery from faults in Ethernet networks; order to participate in S-Ring configurations.
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Chapter 12 12 – RS-Ring™, S-Ring™ and Link-Loss-Learn™ (LLL) Speed up recovery from faults in Ethernet networks -Ring and RS-Ring use ring topology to provide fast recovery from faults. These are based on industry standard STP and RSTP ...
Page 151 - The ring is made up of devices which are; managed switches; only from
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E • The ring is made up of devices which are managed switches only from Magnum 6K family of switches • Each of the switches in the ring topology are configured for RSTP • The RS-Ring product license key is configured on each switch in the...
Page 152 - S-Ring faults can be software signaled to alarm contacts.; on each switch; Faster recover times than S-Ring or RSTP are needed by the network
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 1. The S-Ring feature is a separately licensed module for the MNS-6K software package. This module must be enabled by means of a software key 2. Only one switch is the “Ring Master”. That switch has S-Ring Software authorized (enabled) ...
Page 153 - RSTP has to be enabled on all Magnum 6K switches in the ring; Speed; device in the network should be a managed switch. RS-Ring requires; all devices; – multiple rings may be implemented with S-Ring running on; Managed Switches; – RS-Ring requires all devices in the ring are managed
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 152 4. The same license key needs to be configured for each switch on the ring and RS-Ring capability has to be enabled on all switches (and hence all the devices in the ring have to be a managed Magnum 6K switches) 5. RS-Ring topologie...
Page 154 - Comparing resiliency methods; RSTP
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Comparing resiliency methods So far we have briefly covered S-Ring with LLL, RS-Ring, RSPT as well as STP. The table below summarizes some decision criteria on selecting RSPT vs STP vs S-Ring (and LLL) vs RS-Ring. RS-Ring S-Ring with LL...
Page 156 - designated RING_CLOSED
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E F IGURE 84 – Normal RSTP/STP operations in a series of switches. Note – this normal status is designated RING_CLOSED BP DU Tra ffic ForwardingPort BlockingPort BP DU Tra ffic ForwardingPort BlockingPort This normal status is designated ...
Page 159 - Ring learn features; ”, causes the scanning of all ports in
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E through the two strings for all normal LAN traffic to move as needed to maintain LAN operations. When the fault is cured, the re-emergence of the ring structure enables the BPDU packets to flow again between the ring’s port-pair. This i...
Page 160 - Activating S-Ring on the switch
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Configuring S-Ring S-Ring is a licensed software feature from GarrettCom Inc. Before using the S-Ring capabilities; authorize the use of the software with the license key. To obtain the license key, please contact GarrettCom Inc. Sales ...
Page 162 - If the BPDU stream is broken, or it finds the; show lll
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Port 1 Port 2 Status Magnum6K25(stp)## s-ring add port=1,7 Ports 1 and 7 Configured for sRing Operation Magnum6K25# show s-ring Magnum Ring Status: sRing Status: ENABLED Port 1 Port 2 Status 1 7 CLOSED F IGURE 88 – S-Ring configuration ...
Page 163 - participating in S-Ring; RSTP Operation with RS-Ring; , each of the managed Magnum 6K switch knows of the neighbor and the
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 162 Magnum6K25# stp Magnum6K25(stp)## lll enable Link-Loss-Learn Enabled. Magnum6K25(stp)## lll add port=1,2,3 Added Ports: 1,2,3 Magnum6K25(stp)## show lll Link-Loss-Learn Status: LLL Status: ENABLED LLL Enabled on Ports: 1,2,3 Magnum6...
Page 164 - unmanaged switches cannot participate in RS-Ring.
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E F IGURE 90 – More than one RS-Ring cannot be defined per managed Magnum 6K switch. Note – unmanaged switches cannot participate in RS-Ring. Ring 1 Ring 2 Ring 1 Ring 2 The port-pairs may be of any media type, and the media type does not...
Page 165 - Activating RS-Ring on the switch; – STP Configuration mode
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Rings are simple structures. Either one port of a pair is forwarding or both are. Not complicated; not much to go wrong. Configuring RS-Ring RS-Ring is a licensed software feature from GarrettCom Inc. Before using the RS-Ring capabiliti...
Page 169 - Fault tolerance options for edge devices; the network is greatly simplified by the using dual-homing.
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Chapter 13 13 – Dual-Homing Fault tolerance options for edge devices esigning and implementing high-availability Ethernet LAN topologies in networks can be challenging. Traditionally, the choices for redundancy for edge of the network d...
Page 171 - Dual-homing ports can span different modules in a switch
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 170 switches upstream. With MNS-6K, the user has to define the set of ports which make up the dual-home ports. F IGURE 95 – Using S-Ring, RS-Ring and dual-homing, it is possible to build networks resilient not only to a single link fail...
Page 172 - Configuring Dual-Homing; dualhome; dualhome del
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Dual-Homing Modes There are two modes in which the dual-homing works. The first one is where the ports are “equivalent” i.e. if one port fails, the other one take over, however, if the first (failed) port recovers, the active port does ...
Page 173 - – configuring dual-homing
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Magnum 6K25# dualhome ? dualhome : Configures Dual homing Usage dualhome <enter> Magnum 6K25# show dualhome Dual Homing Status : DISABLED Magnum 6K25# dualhome Magnum 6K25(dualhome)## dualhome add port1=10 port2=11 Dual Homing Por...
Page 175 - Increase Network throughput and reliability; Increased link capacity – the effective throughput is increased
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Chapter 14 14 – Link Aggregation Control Protocol (LACP) Increase Network throughput and reliability ink aggregation Link Aggregation Control Protocol (LACP) is part of an IEEE specification (IEEE 802.3ad) that allows several physical p...
Page 176 - LACP will not work on Half Duplex ports.; both; Port Security will not work with the ports configured for LACP.; LACP Configuration
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E The performance is improved because the capacity of an aggregated link is higher than each individual link alone. 10Mbps or 10/100Mbps or 100Mbps ports can be grouped together to form one logical link. Instead of adding new hardware to ...
Page 177 - – Some valid LACP configurations.; is highlighted below where
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E F IGURE 97 – Some valid LACP configurations. Should trunks be created so as to span multiple ports, a “trunk mismatch” error message is printed on the console. An example of an incorrect configuration is shown below. F IGURE 98 – an inc...
Page 178 - Switch 2
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E F IGURE 99 – In this figure, even though the connections are from one module to another, this is still not a valid configuration (for LACP using 4 ports) as the trunk group belongs to two different VLANs. VLAN 20 VLAN 10 Switch 2 Switch...
Page 181 - This architecture is not recommended
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E F IGURE 104 – This architecture is not recommended S-Ring 2 S-Ring 1 LACP can be used for creating a reliable network between two facilities connected via a wireless bridge. As shown in the figure below, four trunk ports are connected t...
Page 182 - lacp - enable the LACP configuration module within CLI; Facility 2
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 181 F IGURE 105 – Creating a reliable infrastructure using wireless bridges (between two facilities) and LACP. “A” indicates a Wi-Fi wireless Bridge or other wireless Bridges. The list of commands to configure, edit and manage LACP on t...
Page 184 - – Configuring LACP; Link Down; Link is down or the cable is not connected; Half duplex; A Half Duplex port – Half Duplex ports cannot participate in LACP; Loop Detected; When no LACPDU was received (or cannot be received) from the; Speed Mismatch; All ports in a trunk should have the same speed. If one port’s speed
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Port Priority Trunk ===================== 13 32768 Link Down 14 32768 Link Down 15 32768 Link Down Magnum 6K25(lacp)## add port=12 Port(s) added successfully. Magnum 6K25(lacp)## show lacp Orphan Ports: Port Priority Trunk =============...
Page 185 - Trunk Mismatch; The other switch sent a BPDU which did not match the trunk; – The network for the ‘show lacp’ command listed below; Switch 3
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Trunk Mismatch The other switch sent a BPDU which did not match the trunk information associated with this port. This happens when the port is connected to a different switch, or a different module in the Magnum 6K switch The output of ...
Page 187 - 5 – Quality of Service; Prioritize traffic in a network
Chapter 15 15 – Quality of Service Prioritize traffic in a network uality of Service (QoS) refers to the capability of a network to provide different priorities to different types of traffic. Not all traffic in the network has the same priority. Being able to differentiate different types of traffic...
Page 188 - DiffServ and QoS; ToS and DSCP; Priority (based on application or business requirements)
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E the packet into one of the two queues, and depending on the precedence levels the queue could be rearranged to meet the QoS requirements. QoS refers to the level of preferential treatment a packet receives when it is being sent through ...
Page 189 - IP Precedence; IP Precedence ToS Field in an IP Packet Header; ToS byte
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E IP Precedence IP Precedence utilizes the three precedence bits in the IPv4 header's Type of Service (ToS) field to specify class of service for each packet. You can partition traffic in up to eight classes of service using IP precedence...
Page 190 - Configuring QoS; qos –; enter the QoS configuration mode
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Not all packets received on a port have high priority. IGMP and BPDU packets have high priority by default. The Magnum 6K family of switches has the capability to set the priorities based on three different functions. They are Port QoS ...
Page 191 - Setting Hardware traffic queue behavior; Port weight settings and the meaning of the setting
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Syntax set-weight weight=<0-7> - sets the port priority weight for All the ports. Once the weight is set, all the ports will be the same weight across the switch. The valid value for weight is 0-7. A weight is a number calculated ...
Page 196 - Multicast traffic on a network
195 16 – IGMP Multicast traffic on a network nternet G roup M anagement P rotocol (IGMP) is defined in RFC 1112 as the standard for IP multicasting in the Internet. It is used to establish host memberships in particular multicast groups on a single network. The mechanisms of the protocol allows a ho...
Page 198 - – IGMP concepts – advantages of using IGMP
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E F IGURE 113 – IGMP concepts – advantages of using IGMP • PCs 1 and 4, switch 2, and all of the routers are members of an IP multicast group. (The routers operate as queriers.) • Switch 1 ignores IGMP traffic and does not distinguish bet...
Page 199 - – IGMP concepts – Isolating multicast traffic in a network; IP Multicast Filters; – Traffic to IP multicast
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E The next figure (below) shows a network running IP multicasting using IGMP without a multicast router. In this case, the IGMP-configured switch runs as a querier. PCs 2, 5, and 6 are members of the same IP multicast group. IGMP is confi...
Page 200 - IGMP Support; IGMP is disabled as a default.
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E groups in the IP address range of 224.0.0.0 to 224.0.0.255 will always be flooded because addresses in this range are “well known” or “reserved” addresses. Thus, if IP Multicast is enabled and there is an IP multicast group within the r...
Page 201 - which will be described
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E For a Layer 2 IGMP environment, all Magnum 6K family of switches have to be enabled in the IGMP-L2. This is done using the CLI command 'set igmp mode=l2' which will be described later. In a Layer 2 network, without IGMP-L2, there is no ...
Page 203 - Configuring IGMP
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E • Multicast forwarding is done based on MAC addresses – so datagram to IP addresses 224.1.2.3 and 239.129.2.3 can be forwarded on the same port groups. It is not possible to do forwarding based on IP addresses as the Magnum 6K family of...
Page 204 - – Enabling IGMP and query the status of IGMP; IGMP State; specifies maximum amount of time in seconds that can elapse
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E MCAST is disabled Magnum6K25(igmp)## show igmp IGMP State : Enabled ImmediateLeave : Disabled Querier : Enabled Querier Interval : 125 Querier Response Interval : 10 Multicasting unknown streams : Disabled Magnum6K25(igmp)## igmp disabl...
Page 205 - Group IP; column shows the multicast groups.; Port No; shows the port where the multicast group is being detected.; Timer; column shows the number of leave messages received from this port
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Syntax show-group – shows the multicast groups Magnum6K25(igmp)## show-group GroupIp PortNo Timer LeavePending ------------------------------------------------------------------------ 224.1.0.1 9 155 0 224.0.1.40 9 155 0 Magnum6K25(igmp...
Page 210 - eneric; in static VLANs configured on a switch.
Chapter 17 17 – GVRP Generic Attribute Registration Protocol (GARP) VLAN Registration Protocol (GVRP) eneric A ttribute R egistration P rotocol (GARP) and VLAN registration over GARP is called GVRP. GVRP is defined in the IEEE 802.1q and GARP in the IEEE 802.1p standards. In order to utilize the cap...
Page 211 - GVRP Operations; GVRP operation – see description below; Port 5 receives advertisement
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E configured as untagged on every port of the Magnum 6K family of switches. That is, on ports used as GVRP links, leave the default VLAN set to untagged and configure other static VLANs on the ports as either “Tagged or Forbid ” . (“Forbi...
Page 212 - VLAN settings on other GVRP enabled switches
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 11. Port 2 receives advertisement of VID 3. (Port 2 was already statically configured for VIDs 1, 2, 3) If a static VLAN is configured on at least one port of a switch, and that port has established a link with another device, then all ...
Page 213 - Operations; – Port settings for GVRP operations
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E VLANs must be disabled in GVRP-unaware devices to allow tagged packets to pass through. A GVRP-aware port receiving advertisements has these options: • If there is no static VLAN with the advertised VID on the receiving port, then dynam...
Page 214 - – Command to check for dynamically assigned VLANs; – Converting a dynamic VLAN to a static VLAN
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Magnum6K25# gvrp Magnum6K25(gvrp)## show-vlan ============================================ VLAN ID | NAME | VLAN STATUS ============================================ 1 | Default VLAN | Static Active 2 | Blue | Static Active 10 | dyn10 | ...
Page 215 - – GVRP options
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Per-Port Static VLAN Options Per Port “unknown VLAN” (GVRP) configuration Tagged or Untagged Auto Forbid Learn Generate advertisements. Forward advertisements for other VLANs Receive advertisements and dynamically join any advertised VL...
Page 216 - Configuring GVRP; show gvrp
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Configuring GVRP The commands used for configuring GVRP are Syntax show gvrp - shows whether GVRP is disabled, along with the current settings for the maximum number of VLANs and the current Primary VLAN Syntax gvrp <enable|disable &...
Page 217 - – GVRP configuration example; GVRP Operations Notes; “save”; command to save the
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E ============================================ VLAN ID | NAME | VLAN STATUS ============================================ 1 | Default VLAN | Static Active 2 | Blue | Static Active 10 | dyn10 | Static Active Magnum6K25(gvrp)## set-forbid vl...
Page 219 - Managing your network using SNMP; network management information.; Simple Network Management Protocol (SNMP); – A network management protocol that
Chapter 18 18 – SNMP Managing your network using SNMP imple Network Management Protocol (SNMP) enables management of the network. There are many software packages which provide a graphical interface and a graphical view of the network and its devices. The graphical interface and view would not be po...
Page 220 - Simple Network Management Protocol Version 3 (SNMPv3); receiver; Data integrity
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Simple Network Management Protocol Version 3 (SNMPv3) – The third version of SNMP, the enhancements made to secure access, different levels of access and security. SNMP engine – A copy of SNMP that can either reside on the local or remo...
Page 221 - Notification host; notifications that can be sent to each user in the group; Traps; Security via configuration of SNMP communities
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Notification host – An SNMP entity to which notifications (traps and informs) are to be sent Notify view – A view name (not to exceed 64 characters) for each group that defines the list of notifications that can be sent to each user in ...
Page 222 - RFC 2104, Keyed Hashing for Message Authentication; Configuring SNMP; System; – enter the SNMP Configuration mode
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E • RMON MIB (RFC 1757) • RMON: groups 1, 2, 3, and 9 (Statistics, Events, Alarms, and History) • Version 1 traps (Warm Start, Cold Start, Link Up, Link Down, Authentication Failure, Rising Alarm, Falling Alarm) RFC 1901-1908 – SNMPv2 • R...
Page 223 - “set; quickcfg
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Syntax community [write=<write community>] [read=<read community>] [trap=<trap community>] – set the necessary community strings Syntax authtraps <enable|disable> - enables or disables authentication traps genera...
Page 231 - – Configuring SNMP – most of the command here are SNMP v3 commands; Configuring RMON
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Magnum6K25(snmpv3)## show-user id=1 User ID : 1 User Name : jsmith User Type : read-write Auth. Pass something Priv. Pass : Auth. Type : MD5 Auth. Level : auth Subtree : Magnum6K25(snmpv3)## exit Magnum6K25# show snmp SNMPv3 Configurati...
Page 233 - mgrip
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Syntax snmpv3 – enter the SNMP V3 configuration mode – note enable SNMP V3 by using the “set snmp” command which follows Syntax show active-snmp – shows the version of SNMP currently in use Syntax community [write=<write community>...
Page 236 - 9 – Miscellaneous Commands; Improving productivity and manageability; Alarm Relays; SUSTAINED
Chapter 19 19 – Miscellaneous Commands Improving productivity and manageability here are several features built into the Magnum 6K family of switches which help with the overall productivity and manageability of the switch. These items are examined individually in this chapter. T Alarm Relays In a w...
Page 237 - – Predefined conditions for the relay; alarm; – enter the alarm configuration mode
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 236 Event ID Event Description Signal Type 1 S-RING OPEN SUSTAINED 2 Cold Start MOMENTARY 3 Warm Start MOMENTARY 4 Link Up MOMENTARY 5 Link Down MOMENTARY 6 Authentication Failure MOMENTARY 7 RMON Rising Alarm 9 MOMENTARY 8 RMON Falling...
Page 238 - show alarm; - displays the current status of Alarm system
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Syntax period time=<1..10> - sets the duration of relay action for the momentary type signal. This may be needed to adjust to the behavior of the circuit or relay. Default is 3 seconds. Time is in seconds Syntax del event=<even...
Page 240 - – Setting up the external electrical relay and alerts; Email
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 8 RMON Falling Alarm MOMENTARY 9 Intruder Alarm MOMENTARY 10 Link Loss Learn Triggered MOMENTARY 11 Broadcast Storm Detected MOMENTARY 12 STP/RSTP Reconfigured MOMENTARY Magnum6K25(alarm)## alarm disable Alarm system Disabled Magnum6K25...
Page 241 - smtp; config; recipients
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E either POP3 or IMAP for receiving messages that have been arrived from the outside world. While SMTP (and its related protocols such as POP3, IMAP etc.) are useful transports for sending and receiving emails, it is extremely beneficial ...
Page 243 - retry
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E retry – [optional] specifies how many times to retry if an error occurs when sending email. Range from 0 to 3. Default is 0. Syntax smtp <enable|disable> - enables or disables SMTP to send SNMP alerts by email Magnum6K25# smtp Mag...
Page 245 - – setting SMTP to receive SNMP trap information via email; Serial Connectivity; highlighted fields are the ones to change as described
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Magnum6K25(smtp)## exit Magnum6K25# F IGURE 132 – setting SMTP to receive SNMP trap information via email Email alerts can be forwarded to be received by other devices such as Cell phones, pagers etc. Most interfaces to SMTP are already...
Page 246 - Miscellaneous commands; show history
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Note – this is needed if you plan to cut and paste between a serial window and another file. This allows the buffer management of the serial port on the Magnum 6K family of switches. Miscellaneous commands Some of the commands listed be...
Page 247 - – History commands; Prompt
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Baud Rate : 38400 Data : 8 Parity : No Parity Stop : 1 Flow Control : None Magnum6K25# show history 1 : show version 2 : show setup 3 : show serial 4 : show history Magnum6K25# !1 show version MNS-6K Ver: 3.6 Date:Oct 20 2006 Time:17:22...
Page 248 - – Setting custom prompts; Ping; – use the ping command to test; – Using the ping command
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Magnum6K25# snmp Magnum6K25(snmp)## setvar sysname=Core System variable(s) set successfully Magnum6K25(snmp)## exit Magnum6K25# set prompt $n Core# set prompt $n$b$i Core 192.168.5.5# set prompt $n$b$i$b Core 192.168.5.5 # snmp Core 192...
Page 249 - FTP modes; System Events
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Many devices do not respond to ping or block ping commands. Make sure that the target device does respond or the network does allow the ping packets to propagate through. FTP modes The file transfer protocol or ftp is supported on MNS-6...
Page 250 - – Event log shown on the screen
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E important to erase the log periodically or use syslog capability to download the logs to a syslog server. The event log window contains 22 log entry lines. Magnum6K25# show log S DATE TIME Log Description -- -------- -------- ----------...
Page 251 - – Using exportlog to export the event log information
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Magnum6K25# exportlog Usage exportlog mode=<serial|tftp|ftp> [<ipaddress>] [file=<name>] [doctype=<raw|html>] Magnum6K25# exportlog mode=tftp 192.168.5.2 file=eventlog doctype=html Do you wish to export the event...
Page 254 - – Listing of severity - sorted by subsystem and severity; MAC Address Table
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Subsystem Description Severity TCP/IP Duplicate IP a.b.c.d sent from MAC address XXXXXX C TCP/IP Unable to allocate memory for an ICMP packet C TCP/IP IP packet from a.b.c.d , with checksum error dropped D TCP/IP Bad IP fragments from a...
Page 255 - command displays the internal switching
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Sometimes it is useful to see which port a specific packet will be switched to by examining the internal MAC address table. The ‘show address-table’ command displays the internal switching table. Magnum6K25# show address-table Sl# MAC A...
Page 258 - APPENDIX; Chapter 2 – Getting Started
APPENDIX 1 APPENDIX 1 - Command listing by Chapter A rich environment – this Appendix provides a reference to the commands by chapter Chapter 2 – Getting Started Syntax ipconfig [ip=<ip-address>] [mask=<subnet-mask>] [dgw=<gateway>] – to set IP address on the switch Syntax save – s...
Page 262 - time; Chapter 4 – IPv6
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Syntax climode <script|console|show> - set the interactive CLI mode on (console) or off (script). To see the mode – use the show option Syntax more <enable|disable|show> - enable or disable the scrolling of lines one page at...
Page 264 - Chapter 6 – Access Using Radius
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Syntax allow ip=<ipaddress> mask=<netmask> service=<name|list> - allow specific IP address or range of addresses as a trusted host(s) Syntax deny ip=<ipaddress> mask=<netmask> service=<name|list> - de...
Page 271 - Chapter 13 – Dual-Homing; Chapter 15 – Quality of Service
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Chapter 13 – Dual-Homing Syntax dualhome – enter the dual-homing configuration sub-system Syntax dualhome <enable|disable> – enable or disable dual-homing Syntax dualhome add port1=<port#> port2=<port#> – dual-homing s...
Page 273 - Chapter 18 – SNMP
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Synta x set-qi interval=<value> - The IGMP querier router periodically sends general host-query messages. These messages are sent to ask for group membership information. This is sent to the all-system multicast group address, 224...
Page 278 - - display the current ftp operation mode
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 277 Syntax !<n> - repeat the “n”th command (as indicated by a show history) Syntax show history – show the last 25 commands executed – if less than 25 commands are executed, only those commands executed are shown Syntax <Up-arr...
Page 281 - clear logs or specific type of logs; options for a command; enter the VLAN configuration commands
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Command Description clear <history|log [1..5 |informational |activity |critical |fatal |debug] |terminal |arp|portstats|addr] clear command to clear various aspects of the MNS-6K information – most notably “clear addr” – clears the a...
Page 283 - changing the privilege level; engineid string; configure flow control buffers; where; operations
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Command Description enable <user-name> changing the privilege level engineid string = <string> Every agent has to have an engineID (name) to be able to respond to SNMPv3 messages. The default engine ID value is “6K_v3Engine”...
Page 286 - qos
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Command Description port-mirror <enter> configure port mirror settings port-security configure port security settings priority [port=<number|list|range>] value=<0-255 | 0-65535> specifies the port or switch level prior...
Page 288 - set the ftp mode of operation
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Command Description set ftp mode=<normal|passive> set the ftp mode of operation set igmp mode= <normal|l2> set the IGMP mode. Normal is when a L3 device is in the network and is the IGMP root. The IGMP-L2 is used when there ...
Page 290 - setting the port characteristic for an 802.1x
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Command Description setport port=<num|list|range> [status=<enable|disable>] [control=<auto|forceauth|forceunauth>] [initialize=<assert|deassert>] setting the port characteristic for an 802.1x network setport port...
Page 291 - . The default value is
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Command Description set-qi interval=<value> The IGMP querier router periodically sends general host-query messages. These messages are sent to ask for group membership information. This is sent to the all-system multicast group ad...
Page 295 - “set snmp”
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Command Description show-router displays detected IGMP-enabled router ports show-stats port=<num> displays 802.1x related statistics show-timers show the values of the timers set for RSTP show-trap [id=<id#>] shows the confi...
Page 296 - activate the VLAN configuration; STP Configuration mode
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Command Description start vlan=<name|number|list|range> activate the VLAN configuration static vlan=<VID> convert a dynamic VLAN to a static VLAN statistics def-owner=<string> def- comm=<string> define the RMON s...
Page 297 - - different tftp operations – get
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Command Description timers forward-delay=<4-30> hello=<1-10> age=<6-40> change the STP Forward Delay, Hello timer and Aging timer values tftp <get|put> [type=<app|config|oldconf|script|hosts|log>] [host=<...
Page 298 - a part of the View based Access control model; upload and download information using xmodem
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E Command Description user <add|delete> id=<id> [username=<name>] [usertype=<readonly|readwrite>] [authpass=<pass-phrase>] [privpass=<pass-phrase>] [level=<noauth|auth|priv>] [subtree=<oid>]...
Page 299 - Intentionally left blank
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 298 Intentionally left blank
Page 300 - APPENDIX 3 - Daylight Savings; Daylight Savings Time; Alaska; Middle Europe and Portugal
APPENDIX 3 APPENDIX 3 - Daylight Savings No time like the present... Daylight Savings Time Magnum6K Switches provide a way to automatically adjust the system clock for Daylight Savings Time (DST) changes. In addition to the value "none" (no time changes), there are fifteen pre-defined settin...
Page 301 - time zones and states in US, have been implemented in MNS-6K
M A G N U M 6 K S W I T C H E S , M N S - 6 K U S E R G U I D E 300 Australia, Belgium, Canada, Chile, Cuba, Egypt, France, Finland, Germany, Greece, Iraq, Italy, London, Namibia, Portugal, Russia, Spain, Sweden, Switzerland, Syria, USA Note – as of Release 3.7, the new daylight saving times dates e...
Page 303 - Step
U P D A T I N G M N S - 6 K – S T E P 1 Step 1 1. Getting Started Decide which version to use….. his document describes how to upgrade the MNS-6K software on a Magnum 6K switch. The methods described for updating the MNS-6K software are either locally at the console port on the Magnum 6K switch or r...
Page 304 - Selecting the proper version; Software upgrade matrix; Upgrade Path; following the steps listed below; Downloading the MNS-6K software; Access GarrettCom’s FTP site through any standard browser
U P D A T I N G M N S - 6 K – S T E P 1 2) Enough disk space to store and retrieve the configuration files as well as copy software files from GarrettCom. We recommend at least 15MB of disk space for this purpose 3) Connection to the Internet. Make sure the connection does not block FTP file transfe...
Page 305 - NOTE; – the common error is to use; m6kuser; and the password as; m6kuser –
U P D A T I N G M N S - 6 K – S T E P 1 b) If the site uses another socket number for ftp connections, use the socket number at the end of the URL. For example, if the network administrator has setup a firewall to use socket number 1684, the URL would be as follows: ftp://ftp.garrettcom.com:1684 c) ...
Page 306 - Accessing the GarrettCom site for download.; Table 1
U P D A T I N G M N S - 6 K – S T E P 1 F IGURE 141 – Accessing the GarrettCom site for download. Note – if the browser does not support the login prompt, you can type in the user name and password on the URL as follows: ftp://m6kuser:[email protected] 3) After successful login, select the ...
Page 307 - Select the proper version to use after successful login; file in the binary mode (especially if you are using a
U P D A T I N G M N S - 6 K – S T E P 1 F IGURE 142 – Select the proper version to use after successful login 4) Navigate to the folder MNS-6K. See Figure 3. (There are other folders with additional software, MIBs as well as additional useful information for the Magnum-6K switches which you may want...
Page 308 - Use the copy command to copy the files to the proper location; Next steps
U P D A T I N G M N S - 6 K – S T E P 1 307 F IGURE 144 – Use the copy command to copy the files to the proper location 6) Make sure you remember where the files are stored as these files will be needed for the next step. Next steps 1) Access the GarrettCom Magnum 6K switch. The access can be over t...
Page 309 - Preparing to load the software; Accessing the switch
U P D A T I N G S O F T W A R E – S T E P 2 Step 2 2. Preparing to load the software Backup your existing configuration….. nce the MNS-6K software is downloaded from the GarrettCom site, it is strongly recommended that the existing configuration of the switch is preserved before the MNS-6K software ...
Page 310 - Network Access; process described in this document.; Saving the Configuration
U P D A T I N G S O F T W A R E – S T E P 2 309 F IGURE 145 - HyperTerminal screen showing the serial settings Network Access Prerequisites - a PC (or workstation/computer) with telnet software and the IP address of the Magnum 6K switch (or DNS name associated with the switch) to be upgraded. Access...
Page 311 - ‘saveconf’; Serial Connection; ‘saveconf’; Example of saveconf command using serial interface
U P D A T I N G S O F T W A R E – S T E P 2 1) Serial file transfer capability such as X-modem or equivalent 2) TFTP server 3) FTP server As a good practice, GarrettCom recommends that you should have all these capabilities available on your local computer if you plan to upgrade additional switches ...
Page 312 - the Windows XP based HyperTerminal screen is shown
U P D A T I N G S O F T W A R E – S T E P 2 F IGURE 148 – Invoke the “Receive File” to start the Xmodem transfer program. In the figure above the Windows XP based HyperTerminal screen is shown Once the “Receive File” is invoked (as shown in Figure 8) follow the dialog to save the file in the proper ...
Page 313 - Status window for Xmodem (using HyperTerminal under Windows XP); Example using TFTP; Example of saveconf command for tftp
U P D A T I N G S O F T W A R E – S T E P 2 F IGURE 150 – Status window for Xmodem (using HyperTerminal under Windows XP) When the file transfer is completed, the window shown in Figure 10 exits and the completion message is displayed as shown in Figure 11. Successfully uploaded the configuration Ma...
Page 314 - Using FTP would be the same as Figure 12, except replace
U P D A T I N G S O F T W A R E – S T E P 2 313 This will save the file 6kconfig-10.11 to the specified IP address (192.168.10.99) in the default TFTP folder. Using FTP would be the same as Figure 12, except replace 'mode=tftp' with 'mode=ftp' In some situations (e.g. routed networks), TFTP or FTP s...
Page 315 - Before loading the MNS-6K software; Continue to use the access method defined in steps 1 and 2.; mode; downloaded from the GarrettCom site (as described in steps 1 and 2).
U P D A T I N G S O F T W A R E – S T E P 3 Step 3 3. Loading the MNS-6K software Load the new version of the MNS-6K image….. T this stage, the Magnum MNS-6K software has been downloaded from the GarrettCom site, and the configuration saved. The Magnum-6K switch is now ready to upload the new MNS-6K...
Page 316 - Upgrade using serial connection; Once the transfer is complete, the dialog is shown in Figure 15.
U P D A T I N G S O F T W A R E – S T E P 3 Serial Connection Prerequisites - make sure the directory and the file name of the MNS-6K software image downloaded in steps 1 and 2 is known. To use the serial connection to update the MNS-6K image, the command dialog is shown below: Magnum6K25# show vers...
Page 317 - upgrading the switch using the serial interface
U P D A T I N G S O F T W A R E – S T E P 3 Upgrade is Successful. Please reboot Magnum 6Kxx to start the application Magnum6K25# reboot Proceed on rebooting the switch? [ 'Y' or 'N' ] Y Do you wish to save current configuration? [ 'Y' or 'N' ] Y (The switch will now reboot. After the reboot, the Ma...
Page 318 - step 4 – updating boot code; Dialog for upgrading the image using tftp
U P D A T I N G S O F T W A R E – S T E P 3 317 Magnum6K25# show version Version 2.6.0, Build Date: Jan 29 2004, Time: 12:02:32 Magnum6K25# upgrade mode=tftp 192.168.10.99 file=Rel3.0.bin Do you wish to upgrade the image? [ 'Y' or 'N'] Y Upgrade is Successful. Please reboot Magnum 6Kxx to start the ...
Page 319 - Figure 7
U P D A T I N G S O F T W A R E – S T E P 4 Step 4 4. (Optional Step) Restoring the configuration Optionally, restore back the original configuration and update the boot code….. t this optional step, the original configuration has been saved, MNS-6K image copied from the www.garrettcom.com site and ...
Page 320 - Updating boot code over the network; As discussed in; console port; be manually updated by using the; ‘upgrade’; command discussed below. This allows the boot code to be; upgrade mode=bl; the boot loader upgrade is completed
U P D A T I N G S O F T W A R E – S T E P 4 319 Updating boot code over the network As discussed in step 1 – selecting the proper version , with either upgrade path (to Version 2.7.1B or to Version 3.0), the boot code will be updated. At boot up time, the Magnum 6K switch identifies that there is a ...
Page 322 - Index
I N D E X Index !!, 276 !<n>, 277 802.1d, 123, 127, 135, 136, 138, 141, 148, 268 802.1q, 209 802.1Q, 103, 106, 123 802.1w, 135, 136, 141, 150, 151 802.1x, 77, 78, 79, 80, 85, 263 access, 50, 73, 74, 75, 229, 262 action, 66, 67, 70, 75, 262 action port, 66 add, 29, 33, 69, 108, 109, 114, 122, 1...