ip8800/s2500 ソフトウェアマニュアル コンフィグレーショ …igmp/mld snooping...

659
IP8800/S2500 ソフトウェアマニュアル コンフィグレーションガイド Vol.1 Ver. 4.21 対応 IP88S25-S001-O0

Upload: others

Post on 02-Feb-2021

5 views

Category:

Documents


0 download

TRANSCRIPT

IP8800/S2500 Vol.1 Ver.4.21IP88S25-S001-O0


IPX Novell,Inc.
RSARSA SecurID RSA Security Inc.
sFlow InMon Corp.

MagicPacket Advanced Micro Devices,Inc.

Ver.4.21 25

13 •

• CPU

Ring Protocol / GSRP
• Ring Protocol

MAC



5.3 CLI
OS-L2A 7.1.3
2 18.3 2

IGMP snooping/MLD snooping
2



13.4
5.2.8 CLI
OS-L2A IP8800/S2530-48P2X PoE
RADIUS RADIUS
CPU


OS-L2A 7.1.3 (7)

13.4
10BASE-T/100BASE-TX/1000BASE-T
Ver.4.1 12
2


3.2.4 2 MAC VLAN

ARP
3.2.10


MAC MAC



3.2.10




Ring Protocol
VLAN

DNS



Ring Protocol




Ring Protocol
Ring Protocol
Ring Protocol
Ring Protocol

Ring Protocol

IPv6

VLAN Tag
IGMP snooping/MLD snooping

Tag
VLAN
Tag
Tag








IGMP snooping/MLD snooping
(13) 2 (a)IEEE802.1X IP8800/S2530-24S4X

(17) SML


OS-L2B



IP8800/S2530-48T IP8800/S2530E-48T 48T 48T
IP8800/S2530-48P2X 48P2X 48P2X10G
IP8800/S2530-24TD 24TD 24T
IP8800/S2530-48TD 48TD 48T

https://jpn.nec.com/ip88n/

II
https://jpn.nec.com/ip88n/

AC Alternating Current ACK ACKnowledge ADSL Asymmetric Digital Subscriber Line ALG Application Level Gateway ANSI American National Standards Institute ARP Address Resolution Protocol AS Autonomous System AUX Auxiliary BGP Border Gateway Protocol BGP4 Border Gateway Protocol - version 4 BGP4+ Multiprotocol Extensions for Border Gateway Protocol - version 4 bit/s bits per second *bps BPDU Bridge Protocol Data Unit BRI Basic Rate Interface CC Continuity Check
III

CDP Cisco Discovery Protocol CFM Connectivity Fault Management CIDR Classless Inter-Domain Routing CIR Committed Information Rate CIST Common and Internal Spanning Tree CLNP ConnectionLess Network Protocol CLNS ConnectionLess Network System CONS Connection Oriented Network System CRC Cyclic Redundancy Check CSMA/CD Carrier Sense Multiple Access with Collision Detection CSNP Complete Sequence Numbers PDU CST Common Spanning Tree DA Destination Address DC Direct Current DCE Data Circuit terminating Equipment DHCP Dynamic Host Configuration Protocol DIN Deutsche Industrie Normen DIS Draft International Standard/Designated Intermediate System DNS Domain Name System DR Designated Router DSAP Destination Service Access Point DSCP Differentiated Services Code Point DTE Data Terminal Equipment DVMRP Distance Vector Multicast Routing Protocol E-Mail Electronic Mail EAP Extensible Authentication Protocol EAPOL EAP Over LAN EFM Ethernet in the First Mile EPU External redundant Power Unit ES End System FAN Fan Unit FCS Frame Check Sequence FDB Filtering DataBase FQDN Fully Qualified Domain Name FTTH Fiber To The Home GBIC GigaBit Interface Converter GSRP Gigabit Switch Redundancy Protocol HMAC Keyed-Hashing for Message Authentication IANA Internet Assigned Numbers Authority ICMP Internet Control Message Protocol ICMPv6 Internet Control Message Protocol version 6 ID Identifier IEC International Electrotechnical Commission IEEE Institute of Electrical and Electronics Engineers, Inc. IETF the Internet Engineering Task Force IGMP Internet Group Management Protocol IP Internet Protocol IPCP IP Control Protocol IPv4 Internet Protocol version 4 IPv6 Internet Protocol version 6 IPV6CP IP Version 6 Control Protocol IPX Internetwork Packet Exchange ISO International Organization for Standardization ISP Internet Service Provider IST Internal Spanning Tree L2LD Layer 2 Loop Detection LAN Local Area Network LCP Link Control Protocol LED Light Emitting Diode LLC Logical Link Control LLDP Link Layer Discovery Protocol LLQ+3WFQ Low Latency Queueing + 3 Weighted Fair Queueing LSP Label Switched Path LSP Link State PDU LSR Label Switched Router MA Maintenance Association MAC Media Access Control MC Memory Card MD5 Message Digest 5 MDI Medium Dependent Interface MDI-X Medium Dependent Interface crossover MEP Maintenance association End Point MIB Management Information Base MIP Maintenance domain Intermediate Point
IV

MLD Multicast Listener Discovery MRU Maximum Receive Unit MSTI Multiple Spanning Tree Instance MSTP Multiple Spanning Tree Protocol MTU Maximum Transfer Unit NAK Not AcKnowledge NAS Network Access Server NAT Network Address Translation NCP Network Control Protocol NDP Neighbor Discovery Protocol NET Network Entity Title NLA ID Next-Level Aggregation Identifier NPDU Network Protocol Data Unit NSAP Network Service Access Point NSSA Not So Stubby Area NTP Network Time Protocol OADP Octpower Auto Discovery Protocol OAM Operations,Administration,and Maintenance OSPF Open Shortest Path First OUI Organizationally Unique Identifier packet/s packets per second *pps PAD PADding PAE Port Access Entity PC Personal Computer PCI Protocol Control Information PDU Protocol Data Unit PICS Protocol Implementation Conformance Statement PID Protocol IDentifier PIM Protocol Independent Multicast PIM-DM Protocol Independent Multicast-Dense Mode PIM-SM Protocol Independent Multicast-Sparse Mode PIM-SSM Protocol Independent Multicast-Source Specific Multicast PoE Power over Ethernet PRI Primary Rate Interface PS Power Supply PSNP Partial Sequence Numbers PDU QoS Quality of Service RA Router Advertisement RADIUS Remote Authentication Dial In User Service RDI Remote Defect Indication REJ REJect RFC Request For Comments RIP Routing Information Protocol RIPng Routing Information Protocol next generation RMON Remote Network Monitoring MIB RPF Reverse Path Forwarding RQ ReQuest RSTP Rapid Spanning Tree Protocol SA Source Address SD Secure Digital SDH Synchronous Digital Hierarchy SDU Service Data Unit SEL NSAP SELector SFD Start Frame Delimiter SFP Small Form factor Pluggable SFP+ Enhanced Small Form factor Pluggable SML Split Multi Link SMTP Simple Mail Transfer Protocol SNAP Sub-Network Access Protocol SNMP Simple Network Management Protocol SNP Sequence Numbers PDU SNPA Subnetwork Point of Attachment SPF Shortest Path First SSAP Source Service Access Point STP Spanning Tree Protocol TA Terminal Adapter TACACS+ Terminal Access Controller Access Control System Plus TCP/IP Transmission Control Protocol/Internet Protocol TLA ID Top-Level Aggregation Identifier TLV Type, Length, and Value TOS Type Of Service TPID Tag Protocol Identifier TTL Time To Live UDLD Uni-Directional Link Detection
V

UDP User Datagram Protocol ULR Uplink Redundant UPC Usage Parameter Control UPC-RED Usage Parameter Control - Random Early Detection VAA VLAN Access Agent VLAN Virtual LAN VRRP Virtual Router Redundancy Protocol WAN Wide Area Network WDM Wavelength Division Multiplexing WFQ Weighted Fair Queueing WRED Weighted Random Early Detection WS Work Station WWW World-Wide Web XFP 10 gigabit small Form factor Pluggable
kB( ) 1kB( )1MB( )1GB( )1TB( ) 1024
1024 1024 1024
VI

3.2.5 IP 34
3.2.6 QoS 37
3.2.8 46
3.2.9 47
3.2.10 48
6.4.4 83
6.4.5 84
6.4.7 85
6.5 86
7.3.5 108
7.4 109
9.2.3 telnet 158
9.2.4 ftp 158
10.1.8 166
10.3.4 RADIUS 179
10.4 RADIUS 181
iv

11.1.3 197
11.2 198
11.2.1 198
11.2.2 198
11.2.4 NTP 199
11.2.5 NTP 200
11.2.6 NTP 200
11.2.7 NTP 201
13.2 223
15.1.3 241
15.1.4 241
15.1.5 244
15.1.6 245
15.2 246
15.2.1 246
15.2.2 246
15.3 248
15.3.1 248
16.1.6 258
16.1.7 264
16.1.8 265
16.2.5 269
16.3 272
16.3.1 272
18.1.4 MAC 282
18.1.5 283
18.2 285
18.2.1 285
18.2.2 285
18.2.3 285
18.2.4 286
18.2.5 287
18.2.6 288
18.2.7 288
18.3 289
18.3.1 289
18.5 10BASE-T/100BASE-TX/1000BASE-T 297
18.6 100BASE-FX 24S4X08TC1 299
18.6.1 299
18.7 100BASE-FX 24S4X08TC1 302
18.7.1 302
18.7.2 302
18.10.1 309
18.11.1 312
18.12.1 313
18.13.1 314
18.13.2 314
18.14.1 PoE 315
18.14.2 PoE 316
18.14.3 PoE 317
18.15.1 325
18.15.2 325
18.15.3 325
18.15.4 327
viii

19.1.5 337
19.1.6 337
19.2 339
19.2.1 339
19.2.2 339
20 2 351
21MAC 361
21.1.2 MAC 362
21.1.4 MAC 2 362
21.1.5 363
x

22.3.1 382
22.4.1 384
22.5.1 387
22.5.2 387
22.5.3 388
22.6.1 389
22.7.1 393
22.7.4 MAC 395
22.8.1 397
22.8.3 MAC VLAN 400
22.8.4 MAC Tagged 400
22.9 VLAN 403
25.1.1 476
25.1.2 476
25.1.3 478
25.2.1 480
25.5.1 499
25.5.2 499
25.5.3 500
25.5.4 501
25.5.5 504
25.6.1 VLAN 507
25.6.3 508
25.6.4 509
25.6.5 509
25.6.6 510
25.6.10 513
25.6.11 514
26Ring Protocol 521
26.1.5 VLAN 524
26.1.6 VLAN 525
26.1.7 525
26.1.8 527
27Ring Protocol /GSRP 541
27.1 Ring Protocol 542
27.1.1 542
27.1.2 543
27.1.3 546
27.1.4 551
27.2 Ring Protocol GSRP 554
27.2.1 554
27.3 556
27.3.1 556
27.3.2 556
27.3.4 Ring Protocol 557
27.4 558
27.4.1 558
27.4.2 558
28.1 IGMP snooping/MLD snooping 560
28.1.1 560
28.2 IGMP snooping/MLD snooping 562
28.3 IGMP snooping 563
28.3.1 MAC 563
29IGMP snooping/MLD snooping 575
29.1 IGMP snooping 576
29.1.1 576
29.1.3 IGMP 576
29.2.1 580
29.2.3 582
29.3.1 583
29.3.3 MLD 583
29.4 MLD snooping 585
29.4.1 585
30IPv4 587
30.1 588
30.2 589
30.2.1 589
30.3 591
30.3.1 591
30.3.3 591
30.3.4 592
31.2.5 RA IPv6 598
31.3 599
31.3.1 599
31.3.3 599
31.3.4 600
32.3 608
32.3.1 608
A.10 IPv4 614
A.11 IPv6 614
A.12 DHCP 615
617





2

LAN
1


48P2X08P16P4X OAN
2

3
SML(Split Multi Link)
(IEEE802.3ad) (IEEE802.1w
IEEE802.1s) GSRP awareAutonomous Extensible Ring Protocol 1Ring Protocol
SML(Split Multi Link) 2 3
1
2


3
3


LED
SD LED

SFP SFP+/SFP 10G





PIN

VLAN Tag-VLAN VLANMAC VLAN VLAN
VLAN L2-VPN
DHCP snooping DHCP IP


QoS
QoS

IEEE802.1XWeb MAC

RoHS
Continuity CheckCCLoopbackLinktrace 2


MIB-II IPv6 ip MIB(RFC4293)RMON MIB

MC


IT
CLISNMP
XMLExtensible Markup LanguageSOAPSimple Object Access ProtocolNetconf IT

13

IP8800/S400,IP8800/S6700,IP8800/S6600,IP8800/S6300,IP8800/
10G
IP LAN AP PD( )

PoE

8
2.1
2.2

snooping 2 QoS

2.1.1
1000BASE-X 1000BASE-X/10GBASE-R
24
4
08PD(DC PoE
10BASE-T/100BASE-TX/1000BASE-TPoE
10
(1) RESET
(1) 10BASE-T/100BASE-TX/1000BASE-T
(2) RESET
(1) RESET
(1) RESET

DC PoEDC DC
DC PoEDC DIN
DC EPU-D

2-13 48T
2-14 48P2X
2-19 08TC1
2-20 16P4X
2
CPU SW MCFLASH PHY Sub CPU PoE
19
PHY ,
/QoS / DMA



Sub CPU Sub Central Processing Unit08P08TC116P4X

PoE PoE/PoE Plus48P2X08P16P4X 30W/
0/1 0/4848P2X 0/1 0/8 08P 0/1 0/1616P4X
3 PSPower Supply


DC EPU-D 1

EPU

Wake on LANSML

SMLSplit Multi Link

22
2
PoE
3
100BASE-FX
3.1.2
24T 24TD
24 4
24S4X 24S4XD
24 4
EPU-A)
EPU-D)
EPU-D)

MC
IP8800/S2500
64MB
RAMDISK

3-4
3-5 RADIUS

4 4 0/25 0/28
48T 48T2X 48P2X 48TD
telnet ftp telnet ftp
RADIUS
IEEE802.1X
RADIUS
4
3.2.4 2
MAC
MAC MAC
3-7 MAC MAC

MAC VLAN




RADIUS

2 VLAN
VLAN VLAN
24 1 10 VLAN 200 11 24
VLAN 1 VLAN 2014
VLAN CPU


VLAN 4094 IP VLANVLAN
128


4094 4094 28672 1024 1024 10000
48T 48T2X 48P2X 48TD
08P 08PD24 08PD 08TC1
VLAN Ethernet-TypeLLC SAP SNAP type





VLAN VLAN
100 VLAN VLAN 2 100 × 2 200

VLAN VLAN
100 VLAN VLAN 2 100 × 2 200

3
3-17
VLAN VLAN
100 VLAN VLAN 2 100 × 2 200

2
MST 0 MST 0 VLAN 256
Ring Protocol
250 256 2
128 200 2
Ring Protocol
PVST+ 2
256 3 768 200
Ring Protocol
256 768 16 200
31

1
2
3
VLAN
VLAN 1024 VLAN VLAN
VLAN VLAN 1023 VLAN
VLAN
VLAN
VLAN VLAN 1023 3 4 1023 3 4
5 2 52
IGMP/MLD snooping IGMP/MLD snooping
MAC MAC MAC


1
IGMP snooping IGMP snooping VLAN
10 16 VLAN IGMP snooping IGMP snooping
160
3
4

4










2 1000 3 1000 3 1000
4 2000 2000 2000
IPv4










2 1000 3 1000 3
4 2000 2000
MLD snooping MLD snooping VLAN
10 16 VLAN MLD snooping MLD snooping
160
3
4
VLAN IP IP VLAN
IP
DHCP


3-23 IP
2 VLAN
IP VLAN MAC

3-24 VLAN
3 IP
IP
IPv4 IPv6 IPv4IPv6

128
32
4

IPv6


ARP
ARP
3-28 ARP
IP


bNDP
NDP
NDP
3-29 NDP

7

IP 80

3.2.6 QoS QoS access-listqos-flow-list

QoS
flow detection out mode
QoS
4

1



3-32
VLAN

1
(1) 0/1 (1)
2
3

3
4
3-33 QoS

VLAN 3-33 QoS

VLAN

1
2
3


3-34


VLAN
MAC IPv4 IPv6 MAC IPv4 IPv6


layer2-1-mirror
layer2-2-mirror
layer2-1

2
3
5 TCP/UDP
TCP/UDP
access-list QoS qos-flow-list TCP/UDP
QoS
VLAN
MAC IPv4 IPv6 MAC IPv4 IPv6
layer2-1-out 128 128
layer2-2-out 128 128
layer2-3-out 128 1 128 2 128 3 128 1 128 2 128 3

3.
IPv4



3
2
1
2

6
IEEE802.1X dot1x timeout reauth-period 3600

Web web-authentication logout polling interval 300

3-40

MAC
1024 2048 6 7

43
IPv4
250
240
0/1 authentication ip access-group AAAAA 0/2 authentication ip access-group BBBBB 0/3 authentication ip access-group AAAAA
ip access-list extended AAAAApermit/deny 11
ip access-list extended BBBBBpermit/deny 13


RADIUS
IPv4 250 2 240 2
256 3 256 3


MAC VLAN MAC 64 3



RADIUS
Web DB ID
ID Web DB RADIUS
RADIUS
1024kB


Web DB 300 2
Web 1024kB 3
Web 4 5

1 100
MAC DB MAC 1024
45
RADIUS
3-44 Wake on LAN
1
DB
Wake on LAN
2
300 1 300
"any" "manual"
3.2.8









ARP VLAN
DHCP snooping VLAN
32 8 8
÷ 2 2
1
2
SML ChGr 2 SML 8

SML 1 SML 7 2 8
SML 3 SML 5 2 8
3
SML 64 SML ChGr SML

3.2.10
1 IEEE802.3ah/UDLD
IEEE802.3ah/UDLD
2 0/25 0/26 2
0/27 0/28 2
48T 48T2X 48P2X 48TD
0/51 0/52 2
SML 1 SML 2


VLAN 1

CFM MA VLAN CFM VLAN
Down MEP MA
Down MEP VLAN
Up MEP MA
VLAN VLAN
CFM
show cfm summary
2
CCM CFM MEP CCM
CFM MEP
3-54 CCM
3
MEP MEP MEP CCM
MEP show cfm remote-mep
L2
MA MEP MIP CFM
1 2 MEP 2 3
8 32 32 32 256 2016
CCM CFM MEP
1 256 2016
10 100 640
1 50 64
49


1 256 1 256 4
1024 ÷ 256 4
3.2.11 LLDP LLDP
3-57 LLDP

256
4.1
4.2
SNMP 4-1
4-1
4-1
4-1
[CR] [CR] [LF]

VT100


115200IP8800/S2530E19200960048002400 1200
TCP/IP telnet ftp
52
speed


IP8800/S2530 IP8800/S2530E 7.1.3
15IP8800/S2530 IP8800/S2530E



VT100



53
IP

SNMP


MC
4.2.3
OFF reload stop "System halt."
OFF
OFF

ON OFF ON

incorrect”
4-4
login: operator Password: …1 No password is set. Please set password! …2 Copyright (c) 2010-20XX ALAXALA Networks Corporation. All rights reserved. > …3
1.


set exec-timeout

5

20
2.


> enable # configure (config)# hostname "OFFICE1" !OFFICE1(config)# end !OFFICE1# copy running-config startup-config Do you wish to copy from running-config to startup-config? (y/n): y OFFICE1#

61
5-3
OFFICE1# configure OFFICE1(config)# system l2-table mode 2 Please execute the reload command after save, because this command becomes effective after reboot. !OFFICE1(config)# end !OFFICE1# copy running-config startup-config Do you wish to copy from running-config to startup-config? (y/n): y @OFFICE1# reload Restart OK? (y/n): y

[Tab]


5.2.2
5-5 ?
> show vlan ? <VLAN ID list> - [1-4094] ex. "5", "10-20" or "30,40" <Display option> - {detail | list | summary} channel-group-number - Display the VLAN information specified by channel-gro
up-number id - A part of VLAN ID mac-vlan - Display the MAC VLAN information port - Display the VLAN information specified by port number
<cr> > show vlan
1.
Tab?
63
5-6 (gigabitethernet )
(config)# interface gigabtiethernet 0/1 [Enter] ^ Error: Invalid parameter. (config)#
5-7 (duplex )
(config)# interface gigabitethernet 0/1 (config-if)# duplex [Enter] ^ Error: Missing parameter. (config-if)#
5.2.4

> sh ip ar [Enter]
>
5-9
> ping 192.168.100.2 …1 PING 192.168.100.2 (192.168.100.2): 56 data bytes 64 bytes from 192.168.100.2: icmp_seq=0 ttl=128 time=3.783 ms 64 bytes from 192.168.100.2: icmp_seq=1 ttl=128 time=2.401 ms 64 bytes from 192.168.100.2: icmp_seq=2 ttl=128 time=2.335 ms 64 bytes from 192.168.100.2: icmp_seq=3 ttl=128 time=2.019 ms ^C ----192.168.100.2 PING Statistics---- 4 packets transmitted, 4 packets received, 0.0% packet loss round-trip min/avg/max = 2.019/2.634/3.783 ms > > …2 > ping 192.168.100.2 …3 64 bytes from 192.168.100.2: icmp_seq=0 ttl=128 time=3.783 ms 64 bytes from 192.168.100.2: icmp_seq=0 ttl=128 time=3.783 ms 64 bytes from 192.168.100.2: icmp_seq=1 ttl=128 time=2.401 ms 64 bytes from 192.168.100.2: icmp_seq=2 ttl=128 time=2.335 ms 64 bytes from 192.168.100.2: icmp_seq=3 ttl=128 time=2.019 ms ^C ----192.168.100.2 PING Statistics---- 4 packets transmitted, 4 packets received, 0.0% packet loss round-trip min/avg/max = 2.019/2.634/3.783 ms >
64
5.
> ping 192.168.100.3 …4 64 bytes from 192.168.100.3: icmp_seq=0 ttl=128 time=3.783 ms 64 bytes from 192.168.100.3: icmp_seq=0 ttl=128 time=3.783 ms 64 bytes from 192.168.100.3: icmp_seq=1 ttl=128 time=2.401 ms 64 bytes from 192.168.100.3: icmp_seq=2 ttl=128 time=2.335 ms 64 bytes from 192.168.100.3: icmp_seq=3 ttl=128 time=2.019 ms ^C ----192.168.100.3 PING Statistics---- 4 packets transmitted, 4 packets received, 0.0% packet loss round-trip min/avg/max = 2.019/2.634/3.783 ms >
1. 192.168.100.2 ping
2.↑
↑ping 192.168.100.2 interval 2 count 1 packetsize 120
Enter

↑ping 192.168.100.2 interval 2 count 1 packetsize 120
IP 23Enter
5. 192.168.100.3 ping
[ ↑ ][ ↓ ][ ← ][ → ]


CLI CLI
5-4 CLI CLI
CLI
set
show users
adduser CLI

Ctrl U
Ctrl W
!> show sysversion
sys
save
no-flash
set
exit

5-10
(config)# spanning-tree mst 5 [?] configuration - Configure the common information used by each MST ins
tance of multiple spanning tree, and enter MST config uration mode
forward-time - Specify the time which state changes take to a bridge interface
hello-time - Specify a BPDU transmitting interval max-age - Specify the maximum time holding the received protoco
l information max-hops - Specify the maximum number of hop about BPDU root - Specify a root transmission-limit - Specify the maximum number of BPDU which can be trans
mitted for one second

68
5-11 [ ]
(dhcp-config)# lease 360 [] <Time hour> - [0-23] <Time min> - [0-59] <Time sec> - [0-59] <cr> (dhcp-config)# lease 360 [Tab] <cr> <Time hour> <Time min> <Time sec>
"lease 360"days [ ]


(config)# aaa authentication mac-authentication <List name> - Specify the RADIUS server list name 1 to 32 character s default - Specify default mac authentication mechanism end-by-reject - Specify end-by-reject mechanism (config)# aaa authentication mac-authentication de ⇒ group - Specify mac authentication mechanism using RADIUS pro tocol local - Specify mac authentication mechanism using local pass word
<List name> "de "de
<List name> "default"
"default" "default"
5-13
<List name> "device" <List name>
"default" "device"
<List name>

5-14
# password <user name> - Specify the user name or enable-mode <cr> #
"<user name>"
"enable-mode"
4
5-15
switchport-backup "startup-active-port-selection" 24
"startup-active-port-sel"

[Enter]
5-16
(config)# snmp-server host 10.0.0.1 traps ABC version - version {1 | 2c | 3}: Specifies SNMP trap version <security level> - {noauth | auth | priv}: Specify SNMP Security Level snmp - SNMP traps send rmon - RMON traps send air-fan - Airfan stop traps send power - Power failure traps send login - Login traps send system-msg - System message trap send temperature - Temperature traps send axrp - Ring Protocol traps send storm-control - Storm-control traps send efmoam - IEEE802.3ah/UDLD traps send poe - PoE traps send dot1x - 802.1X traps send web-authentication - Web authentication traps send mac-authentication - MAC authentication traps send loop-detection - L2 loop detection traps send switchport-backup - Uplink redundant traps send cfm - CFM traps send sml - SML traps send <cr>
70


[Enter]
deny / permitip access-list standard qos

a
<source ipv4> <source ipv6> <source mac>

5-17 ip access-list extended
(config-ext-nacl)# permit <protocol> - 0-255,ah,esp,gre,icmp,igmp,ip,ipinip,ospf,pcp,pim,sct p,tcp,tunnel,udp,vrrp (config-ext-nacl)# permit ip <PARAMs:input format> - permit <prot> {<s-ipv4> <s-ipv4 wild> | host <s-ipv4> | any} [*1] {<d-ipv4> <d-ipv4 wild> | host <d-ipv4> | any} [*2][*3][*4] {[tos <tos>] [precedence <prcd>] | dscp <dscp>} [vlan <vid>] [user-priority <pri>] [cl ass <cls> [mask <cls msk>]] *1:(TCP/UDP)- {eq <s-port> | range <s-port start> <s- port end>} *2:(TCP/UDP)- {eq <d-port> | range <d-port start> <d- port end>} *3:(ICMP)- {<icmp type> [<icmp code>] | <icmp msg>} *4:(TCP)- [ack][fin][psh][rst][syn][urg]
b <cr>
deny/permit/qos <cr> <cr>
[Enter]

5-18 <cr> ip access-list extended
(config-ext-nacl)# permit ip any host <PARAMs:input format> - permit <protocol> {<source ipv4> <source ipv4 wildcar d> | host <source ipv4> | any} [*1] {<destination ipv 4> <destination ipv4 wildcard> | host <destination ip v4> | any} [*2][*3][*4] {[tos <tos>] [precedence <pre cedence>] | dscp <dscp>} [vlan <vlan id>] [user-prior ity <priority>] NOTE: *1:(TCP/UDP)- {eq <source por t> | range <source port start> <source port end>} *2 :(TCP/UDP)- {eq <destination port> | range <destinati on port start> <destination port end>} *3:(ICMP)- [{ <icmp type> [<icmp code>] | <icmp message>}] *4:(TCP )- [ack][fin][psh][rst][syn][urg] <cr>
71
<source ipv4> <source ipv6> <source mac>
5-19 ip access-list extended
(config-ext-nacl)# permit i icmp igmp ip ipinip
(config-ext-nacl)# permit ip a ⇒"any"
7 <interface id list>
monitor session <session no.> source interface <interface id list> [{rx | tx | both}] destination interface <interface id list>
<interface id list>
<interface id list>

(config)# monitor session 1 source interface gigabitethernet 0/1 <monitor frames> - {rx | tx | both}: Set monitor of receiving frames / m onitor of transmitting frames / monitor of receiving and transmitting frames destination - Specify a mirrored port (config)# monitor session 1 source interface gigabitethernet 0/1, gigabitethernet - gigabitethernet <interface no. list>: The type of a p ort is specified in 10BASE-T/100BASE-TX/100BASE-FX/10 00BASE-T/1000BASE-X line Stack disable: "0/1","0/2-4" Stack enable: "1/0/1","2/0/2-4" tengigabitethernet - tengigabitethernet <interface no. list>: The type of a port is specified in 1000BASE-T/1000BASE-X/10GBASE- R line Stack disable: "0/25-26","0/25" Stack enable: "1/0/25-26","2/0/25"

gigabitethernet/tengigabitethernet
5-21 2 <interface id list>

72
5-22 2 <interface id list>

<interface id list>
<cr>
<cr>
show
5-23 2 <interface id list> show
(config)# monitor session 1 source interface gigabitethernet 0/1, gigabitetherne t 0/3 rx destination interface gigabitethernet 0/11, !(config)# show : monitor session 1 source interface gigabitethernet 0/1, gigabitethernet 0/3 rx d estination gigabitethernet 0/11 ⇒
5-24 2 <interface id list> show
(config)# monitor session 1 source interface gigabitethernet 0/1, gigabitetherne t 0/3 rx destination interface gigabitethernet 0/11 gigabitethernet 0/13 !(config)# show : monitor session 1 source interface gigabitethernet 0/1, gigabitethernet 0/3 rx d estination interface gigabitethernet 0/11, gigabitethernet 0/13 ⇒
8
(config)# no ip dhcp excluded-address 192.168.0.1 127.0.0.1⇒ <High address> - Last address of an excluded range⇒ <cr>
[Enter]
excluded-address 192.168.0.1"
[Tab]
# erase white-list address packet all channel-group-number port # erase white-list a Do you wish to erase white-list (address and packet)? (y/n): y #
"a" "address" "all" "a"
"all"
11

() (config)# monitor session 1 source interface gigabitethernet 0/1 both destination interface gigabitethernet 0/24
() (config)# monitor session 1 source interface gigabitethernet both 0/1 destination interface gigabitethernet 0/24
( ) ( )

6.1
6.2
6.3
6.4
6.5


enable
(config)#

1. enable
1

6-5

#
6-6
6-9



6-6


1. 0/1
82
1. 0/1
6.4.4
no
6-11
6-10
(config)# vlan 100 …1 !(config-vlan)# state active …2 !(config-vlan)# exit !(config)# interface gigabitethernet 0/1 …3 !(config-if)# switchport mode access …4 !(config-if)# switchport access vlan 100 …5 !(config-if)# exit !(config)# vlan 100 …6 !(config-vlan)# state suspend …7 !(config-vlan)# exit !(config)# interface gigabitethernet 0/1 …8 !(config-if)# no switchport access vlan …9 !(config-if)# exit !(config)#
1. VLAN 100 VLAN
2. VLAN 100
3. 0/1
4. 0/1
6. VLAN 100
7. VLAN 100
8. 0/1
83
(config)# interface gigabitethernet 0/1 !(config-if)# shutdown …1 !(config-if)# speed 100 …2 !(config-if)# duplex full …3 !(config-if)# no shutdown …4 !(config-if)#
1.
4.
2



6-13
^ Error: Missing parameter. !(config-if)#

# configure …1 (config)#
# configure …1 (config)#
: : …2 :
!(config)# end …3 !# copy running-config startup-config …4 Do you wish to copy from running-config to startup-config? (y/n) :y #
1.
2.
defined .

copy

ftp
ftp VLAN IP
C:\TEMP backup.cnf
6-16

C:\TEMP>ftp 192.168.0.1 Connected to 192.168.0.1 220 AX2530S-24T FTP server ready User (192.168.0.1:(none)): operator 331 Password required Password: 230 User logged in ftp> asc 200 Type set to A, ASCII mode ftp> ftp> put backup.cnf 200 Port set okay 150 Opening ASCII mode data connection 226 Transfer complete ftp:xxxxxx bytes sent in xx.x Seconds (xx.xx Kbytes/sec) ftp> bye 221 Bye…see you later C:\TEMP>
copy RAMDISK
6-17 copy
> enable # copy ramdisk backup.cnf startup-config Do you wish to copy from RAMDISK to startup-config? (y/n):y #
2
copy
PC
6-19

C:\TEMP>ftp 192.168.0.1 Connected to 192.168.0.1 220 AX2530S-24T FTP server ready User (192.168.0.1:(none)): operator 331 Password required Password: 230 User logged in ftp> asc 200 Type set to A, ASCII mode ftp> ftp> get backup.cnf 200 Port set okay 150 Opening ASCII mode data connection 226 Transfer complete ftp:xxxxxx bytes sent in xx.x Seconds (xx.xx Kbytes/sec) ftp> bye 221 Bye…see you later C:\TEMP>
6.5.2 MC
copy RAMDISK


> enable # copy mc backup.cnf ramdisk backup.cnf …1 # copy ramdisk backup.cnf startup-config …2 Do you wish to copy from RAMDISK to startup-config? (y/n): y #
1. MC RAMDISK
2. RAMDISK
copy RAMDISK MC

> enable # copy startup-config ramdisk backup.cnf …1 # copy ramdisk backup.cnf mc backup.cnf …2 #
1. RAMDISK
6.5.3

7.1
7.2
7.3
7.4
7.5
7.6
set stack disable


1
<switch no.>/ <nif no.>/<port no.>
2

RADIUS NAS ID
syslog
system l2-table mode system receive rate-limit format flash
91
VLAN
L2

IPv6NDPICMPv6
Web
MAC


MC
Web

MC MC MC

MC
mc-configuration
MC
MC
set switch
Changes detected on mc-configuration. Restarting.

MC MC MC
MC
update mc-configuration

3 PoE 48P2X


PoE PoE
PoE

MAC



IGMP snooping
IGMP snooping 28 IGMP snooping/MLD snooping
IGMP snooping
8 2
2

ACL/QoS


96
DHCP snooping Vol.2 15 DHCP
snooping DHCP snooping
10 GSRP aware


13 L2

L2










97
1
48T48T2X48P2X
48 4 8

IP8800/S2530 IP8800/S2530E


<upper limit> 600pps

backup restore
MAC
AX-Config-Master
OAN all



2

100

MAC system mac-address

1

a


7.3.2





3

48
24T4X
24S4X
48T2X
48P2X
1G

49 50

51 52
49 50
c



b
7-8
1 2 4 1 3 4
1 2 4
2 4 7.3.2 4
b
106

107
MAC
MAC
26ae
0234.ffff.fff1 "2"
MAC ID
IP VLAN MAC
IPv6 ID
4
LED
LED
LED
LED
LED 24T24T4X48T48T2X48P2X LED 24S4X

LED
7.4.2
1



3 MC

show mc-file MC

7-11

show tech-support 1
show switch 2

MAC show switch
7.4.3
1





c syslog
reload 3

7.4.4
1
a
ppupdate
13
b


stack
113

1. ON
2. ST1 LED 10 MODE 3






3.
MAC



b

116

MAC

2
IP MAC





Ver.4.3

copy copy running-config copy startup-config




set stack enable/disable/boot

2.

MAC
MAC 180
MAC
300
MAC
aMAC

MAC
MAC



mac-address-table
3600
300
RADIUS

Web web-authentication radius-server dead-interval MAC mac-authentication radius-server dead-interval
6 DHCP IP
DHCP IP IP

8 Web DB MAC DB
Web DB MAC DB
show web-authentication user editshow mac-authentication mac-address edit

2 1

show system



show qos queueing "To-CPU"CPU HOL

15
MAC
Untagged VLAN VLAN
16 IP8800/S2530 IP8800/S2530E
IP8800/S2530 IP8800/S2530E
7.1.3 15IP8800/S2530 IP8800/S2530E

125
8.1
8.2
8-1

A B


1.# show version
Date 20XX/10/20 17:38:02 UTC Model: AX2530S-24T S/W: OS-L2B Ver. 4.0 (Build:yy) H/W: AX-2530-24T-B [SSSSSSSSSSSSSSSSSSSSSS:R]
# A OS-L2B
2.# show version
Date 20XX/10/20 17:39:02 UTC Model: AX2530S-48T S/W: OS-L2B Ver. 4.0 (Build:yy) H/W: AX-2530-48T-B [SSSSSSSSSSSSSSSSSSSSSS:R]
# B OS-L2B 1 A

A





RAMDISK A
2. # set stack enable
Warning: the configuration will be lost on the next reload.
Do you wish to continue? (y/n): y


Warning: stacking is yet to be enabled.
A 1
4. # reload




A 20 10

(config-if)# switchport mode stack
A B 20

B 2
48T
(config-if)# switchport mode stack
5. (config)# switch 2 priority 10
B 2 A 10

MAC
MAC
MAC 26ae

MAC
MAC
B
RAMDISK B
2. # set stack enable
Warning: the configuration will be lost on the next reload.
Do you wish to continue? (y/n): y
B

Warning: stacking is yet to be enabled.
B 2
4. # reload
B




A


(config-if)# switchport mode stack
2. (config)# switch 2 priority 2
B 2 2
6 A B 2
1 A B
2
B


# show switch
show switch A "Master" B
"Stack member"
8.1.3
133
A C



save



1.# show version
Date 20XX/01/31 17:38:02 UTC Model: AX2530S-24T S/W: OS-L2B Ver. 4.0 (Build:yy) H/W: AX-2530-24T-B [SSSSSSSSSSSSSSSSSSSSSS:R]
# A OS-L2B
2.# show version
Date 20XX/01/31 17:39:02 UTC Model: AX2530S-48T S/W: OS-L2B Ver. 4.0 (Build:yy) H/W: AX-2530-48T-B [SSSSSSSSSSSSSSSSSSSSSS:R]
# B C OS-L2B 1 A

RAMDISK A
2. # set stack enable
Warning: the configuration will be lost on the next reload.
Do you wish to continue? (y/n): y


Warning: stacking is yet to be enabled.
A 1
4. # reload


A A

A B C

B 48T 2 2/0/49 2/0/50
C 24S4X 3 3/0/25 3/0/26
A 20 10

(config-if)# switchport mode stack
2. (config)# switch 1 priority 20
A B C 20

(config)# switch 3 provision 2530-24s4x
B C 2 3
48T24S4X
4. (config)# interface gigabitethernet 2/0/49
(config-if)# switchport mode stack
5. (config)# switch 2 priority 10
B 2 A 10

(config-if)# switchport mode stack
7. (config)# switch 3 priority 10
C 3 A 10

MAC
MAC
MAC 26ae

MAC
MAC

MODE
B C



Warning: the configuration will be lost on the next reload.
Do you wish to continue? (y/n): y
# reload




b MODE
1. ON
2. ST1 LED 10 MODE 3






5 A B C
B C

138
8. OS-L2A
show switch B C MAC


1.# show switch
Date 20XX/01/31 17:50:45 UTC Stack status : Enable Switch No : 1 MAC address : 0012.e200.ffa1 System MAC address : 0a12.e200.fff1
No Switch status Model Machine ID Priority OS Ver 1 Master 2530-48t 0012.e200.ffa1 20 4.0 - Restrict(Not initialized) - 0012.e200.ffb1 - - - Restrict(Not initialized) - 0012.e200.ffc1 - -
# Switch status Restrict(Not initialized) MAC






Remote setting is successful <0012.e200.ffb1>.
B MAC 0012.e200.ffb1
3. # set remote 0012.e200.ffb1 switch 2
Remote setting is successful <0012.e200.ffb1>.
B MAC 0012.e200.ffb1 2
4. # set remote 0012.e200.ffb1 stack enable
Remote setting is successful <0012.e200.ffb1>.
B MAC 0012.e200.ffb1enable

B B

139
Remote setting is successful <0012.e200.ffc1>.
C MAC 0012.e200.ffc1
7. # set remote 0012.e200.ffc1 switch 3
Remote setting is successful <0012.e200.ffc1>.
C MAC 0012.e200.ffc1 3
8. # set remote 0012.e200.ffc1 stack enable
Remote setting is successful <0012.e200.ffc1>.
C MAC 0012.e200.ffc1enable

C C



140
A C C

1.# show version
Date 20XX/01/17 03:52:23 UTC Switch number: 1 Model: AX2530S-24T S/W: OS-L2A Ver. 4.0 (Build:yy) H/W: AX-2530-24T-B [SSSSSSSSSSSSSSSSSSSSSS:R]
Switch number: 2

(2) A


# A OS-L2A

Date 20XX/01/17 03:53:12 UTC Model: AX2530S-24S4X S/W: OS-L2B Ver. 4.0 (Build:yy) H/W: AX-2530-24S4X-B [SSSSSSSSSSSSSSSSSSSSSS:R]
# C OS-L2B 1
A

A


A 20 10

C 3
24S4X
(config-if)# switchport mode stack
3. (config)# switch 3 priority 10
C 3 10
142
C
RAMDISK C
2. # set stack enable
Warning: the configuration will be lost on the next reload.
Do you wish to continue? (y/n): y
C

Warning: stacking is yet to be enabled.
C 3
4. # reload
C




A


(config-if)# switchport mode stack
2. (config)# switch 3 priority 2
C 3 2
5 A C 3
A B C 3



# show switch
show switch A "Master" B C
"Stack member"
8.1.5

144
A D D



(2) A
save



# A OS-L2A

2.# show version
Date 20XX/01/31 18:33:12 UTC Model: AX2530S-24T S/W: OS-L2B Ver. 4.0 (Build:yy) H/W: AX-2530-24T-B [SSSSSSSSSSSSSSSSSSSSSS:R]
# D OS-L2B 1
A

A


A 20 5

D 4
24T
(config-if)# switchport mode stack
3. (config)# switch 4 priority 5
D 4 A 5

MODE
D
Warning: the configuration will be lost on the next reload.
Do you wish to continue? (y/n): y
# reload



b MODE
1. ON
2. ST1 LED 10 MODE 3

147





4 A D
D

show switch D MAC

1.# show switch
Date 20XX/01/31 18:50:15 UTC Stack status : Enable Switch No : 1 MAC address : 0012.e200.ffa1 System MAC address : 0a12.e200.fff1
No Switch status Model Machine ID Priority OS Ver 1 Master 2530-48t 0012.e200.ffa1 20 4.0 2 Stack member 2530-48t 0012.e200.ffb1 10 4.0 3 Stack member 2530-24s4x 0012.e200.ffc1 10 4.0 - Restrict(Not initialized) - 0012.e200.ffd1 - -
# Switch status Restrict(Not initialized) MAC




Remote setting is successful <0012.e200.ffd1>.
D MAC 0012.e200.ffd1
3. # set remote 0012.e200.ffd1 switch 4
Remote setting is successful <0012.e200.ffd1>.
D MAC 0012.e200.ffd1 4
4. # set remote 0012.e200.ffd1 stack enable
Remote setting is successful <0012.e200.ffd1>.
D MAC 0012.e200.ffd1enable

D D


1
(config-if)# switchport mode stack
150
8.1.7
151
1
(config-if)# shutdown
(config-if)# exit
2
(config-if)# no switchport mode
2. (config)# save
NoSwitch status
8-7 show switch
> show switch
Date 20XX/01/31 19:38:56 UTC Stack status : Enable Switch No : 1 MAC address : 0012.e200.ffa1 System MAC address : 0a12.e200.fff1
>
9.1
9.2
9.3

VLAN IPv4/IPv6
22 VLAN30 IPv4 31 IPv6

2. (config)# interface gigabitethernet 0/1
(config-if)# switchport mode access
(config-if)# exit
VLAN 100
speed RS-232C
(config-if)# exit
VLAN ID 100 VLAN ID 100 IPv4
192.168.1.1 255.255.255.0
9.2.3 telnet
(config-line)# exit
IPv4 31 IPv6

telnet IP telnet
ftp TCP IP
tftp UDP
10.1
telnet


aaa authentication enable





adduser
4 7 OS-L2A
line vty
4. IPv4 IPv6 ip access-list standardipv6 access-listip access-groupipv6 access-class
5. telnetftp transport input
ftp-server
6.
set exec-timeout
Vol.2 14
OS-L2A
> enable # adduser newuser User(empty password) add done. Please setting password.
Changing local password for newuser. New password:******** … 1 Retype new password:******** … 2 # exit >
1.
2.
aaa authentication login
RADIUS 10.3.3
enable
ID

> enable # password enable-mode Changing local password for admin. New password: Retype new password: #
aaa authentication enable RADIUS
10.3.3 enable

10.1.5

ftp
ftp-server ftp

line vty <End allocation>

16

164
ip access-list standardipv6 access-listip access-groupipv6 access-class
IP IPv4
IPv6 128

(config-std-nacl)# deny host 192.168.0.254
(config-std-nacl)# permit 192.168.0.0 0.0.0.255
REMOTE
(config-line)# ip access-group REMOTE in
(config-line)# exit

(config-ipv6-nacl)# exit
IPv6 REMOTE6
2. (config)# line vty 0 1
(config-line)# ipv6 access-class REMOTE6 in
(config-line)# exit
64
ip access-group ipv6 access-class IP
deny deny

10.1.8
telnet ftp



########################################## Warning!!! Warning!!! Warning!!! This is our system. You should not login. Please close connection. ##########################################

"##########################################\nWarning!!! Warning!!!
Warning!!!\nThis is our system. You should not login.\nPlease close
connection.\n##########################################\n"
3. (config)# show banner login plain-text
########################################## Warning!!! Warning!!! Warning!!! This is our system. You should not login. Please close connection.
166
telnet ftp

> telnet 10.10.10.10 Trying 10.10.10.10 ... ########################################## Warning!!! Warning!!! Warning!!! This is our system. You should not login. Please close connection. ########################################## login:
10-7 ftp
> ftp 10.10.10.10 Connecting...
167
10. RADIUS
10.2 RADIUS
10.2.1 RADIUS
RADIUS Remote Authentication Dial In User ServiceNASNetwork Access Server
NAS RADIUS
NAS RADIUS
RADIUS
RADIUS
2 Vol.2
168
RADIUS
1 RADIUS
10-3 RADIUS
a RADIUS

enable

NAS-Identifier
169
1
2
OS-L2A
Vol.2 5 2
1
RADIUS RADIUS RADIUS
adduser/password

Service-Type 6 Access-Request Login( =1)Administrative =6 Access-Accept Access-Reject

IPv4 VLAN
Reply-Message 18 Access-Challenge
State


IPv6 VLAN
170
aaa authentication login end-by-reject
enable
aaa authentication enable end-by-reject
group radius RADIUS group <Group name>RADIUS
RADIUS



171
telnet RADIUS RADIUS
RADIUS RADIUS



RADIUS
telnet RADIUS RADIUS
RADIUS RADIUS


RADIUS RADIUS 20

3
RADIUS ×
× RADIUS
RADIUS RADIUS
RADIUS RADIUS
dead-interval 10

2
ID 1 16 1 2
6 128
benable
enable

173
RADIUS 1812 RADIUS
1812 1645
radius-server host auth-port 1645
auth-port 1 65535 RADIUS


2
2
2 RADIUS
Vol.2 5 2
RADIUS RADIUS RADIUS
RADIUS
RADIUS radius-server host
RADIUS RADIUS RADIUS
radius-server dead-interval
RADIUS 3.2
174

CPU 100% RADIUS

RADIUS
RADIUS

RADIUS



RADIUS
RADIUS
server RADIUS RADIUS
radius-server dead-interval RADIUS
radius-server host RADIUS
radius-server key RADIUS
radius-server retransmit RADIUS
radius-server timeout RADIUS
radius-server attribute station-id capitalize
2
RADIUS RADIUS 192.168.10.1 IP
4. (config)# radius-server host 192.168.10.2 key "BBBB1234"
RADIUS RADIUS 192.168.10.2 IP

1. "group radius" "group < >" RADIUS <Method>

RADIUS RADIUS


RADIUS
RADIUS
RADIUS


1. "group radius" "group < >" RADIUS <Method>

RADIUS
RADIUS
177


enable RADIUS

RADIUS
RADIUS RADIUS 192.168.10.1 IP
4. (config)# radius-server host 192.168.10.2 key "BBBB1234"
RADIUS RADIUS 192.168.10.2 IP

1. "group radius" "group < >" RADIUS <method>

RADIUS RADIUS


RADIUS
RADIUS
RADIUS


1. "group radius" "group < >" RADIUS <method>

RADIUS
1 RADIUS
IPv4
(config)# radius-server host 192.168.10.2 key "BBBB1234"
(config)# radius-server host 192.168.10.3 key "CCCC1234"
(config)# radius-server host 192.168.10.4 key "DDDD1234"
(config)# radius-server host 192.168.10.5 key "EEEE1234"
(config)# radius-server host 192.168.10.6 key "FFFF1234"
(config)# radius-server host 192.168.10.7 key "GGGG1234"
(config)# radius-server host 192.168.10.8 key "HHHH1234"
RADIUS IPv4
2. (config)# aaa group server radius LOGIN-SEC
RADIUS RADIUS

IPv6
(config)# radius-server host 3ffe:501:811:ff03::c7c1 key "BBBB1234"
(config)# radius-server host 3ffe:501:811:ff03::c7d0 key "CCCC1234"
(config)# radius-server host 3ffe:501:811:ff03::c7d1 key "DDDD1234"
(config)# radius-server host 3ffe:501:811:ff03::c7e0 key "EEEE1234"
(config)# radius-server host 3ffe:501:811:ff03::c7e1 key "FFFF1234"
(config)# radius-server host 3ffe:501:811:ff03::c7f0 key "GGGG1234"
(config)# radius-server host 3ffe:501:811:ff03::c7f1 key "HHHH1234"
RADIUS IPv6
179
RADIUS RADIUS



radius-server host IP

radius-server key
RADIUS * hold down
10-13 show radius-server RADIUS
> show radius-server
Date 20XX/02/01 09:45:52 UTC <common> [Authentication] * IP address: 192.168.100.254 Port: 1812 Timeout: 5 Retry: 3 Remain: - IP address: 2001::fe Port: 1812 Timeout: 5 Retry: 3 Remain: - [Accounting] * IP address: 192.168.100.254 Port: 1813 Timeout: 5 Retry: 3 Remain: - IP address: 2001::fe Port: 1813 Timeout: 5 Retry: 3 Remain: - <dot1x> [Authentication] * IP address: 2001::fe Port: 1812 Timeout: 5 Retry: 3 Remain: - IP address: 192.168.100.254 Port: 1812 Timeout: 5 Retry: 3 Remain: - [Accounting] * IP address: 2001::fe Port: 1813 Timeout: 5 Retry: 3 Remain: - IP address: 192.168.100.254 Port: 1813 Timeout: 5 Retry: 3 Remain: - <mac-auth> [Authentication] IP address: 192.168.101.254 Port: 1812 Timeout: 5 Retry: 3 Remain: - IP address: 2000::fe Port: 1812 Timeout: 5 Retry: 3 Remain: - * hold down 591 [Accounting] * IP address: 192.168.101.254 Port: 1813 Timeout: 5 Retry: 3 Remain: - IP address: 2000::fe Port: 1813 Timeout: 5 Retry: 3 Remain: - <web-auth>

clear radius-server RADIUS RADIUS
show radius-server statistics RADIUS
clear radius-server statistics RADIUS
181
[Authentication] * IP address: 192.168.100.254
Port: 1812 Timeout: 5 Retry: 3 Remain: - IP address: 2001::fe Port: 1812 Timeout: 5 Retry: 3 Remain: -
[Accounting] * IP address: 192.168.100.254
Port: 1813 Timeout: 5 Retry: 3 Remain: - IP address: 2001::fe Port: 1813 Timeout: 5 Retry: 3 Remain: -
<Group1> [Authentication]
>
2 RADIUS
show radius-server statistics
10-14 show radius-server statistics summary
> show radius-server statistics summary
>
> show radius-server statistics
Date 20XX/02/01 09:45:57 UTC IP address: 192.168.100.254 [Authentication] Current Request: 0 [Tx] Request : 2 Error : 0
Retry : 0 Timeout: 0 [Rx] Accept : 1 Reject : 1 Challenge : 0
Malformed: 0 BadAuth: 0 UnknownType: 0 [Accounting] Current Request: 0 [Tx] Request : 0 Error : 0
Retry : 0 Timeout: 0 [Rx] Responses: 0
Malformed: 0 BadAuth: 0 UnknownType: 0 IP address: 192.168.101.254 [Authentication] Current Request: 0 [Tx] Request : 1 Error : 0
Retry : 3 Timeout: 4 [Rx] Accept : 0 Reject : 0 Challenge : 0
Malformed: 0 BadAuth: 0 UnknownType: 0 [Accounting] Current Request: 0 [Tx] Request : 0 Error : 0
Retry : 0 Timeout: 0 [Rx] Responses: 0
Malformed: 0 BadAuth: 0 UnknownType: 0 IP address: 2000::fe [Authentication] Current Request: 0 [Tx] Request : 1 Error : 0
Retry : 3 Timeout: 4
10. RADIUS
>
11.1
11.2
11.3
NTP 2
SNTP RFC2030
SNTP



Multicast
set clock ntp NTP
Unicast



NTP NTP

NTP
11-2 Unicast
3 Broadcast
NTP
NTP
NTP
5 SNTP
1. 1980 1 1 2038 1 17
NTP
2. 2
2

RFC1305 NTP 3 NTP SNTP
NTP
no sntp client NTP
11.2.4 NTP




NTP
ntp broadcast client




11-7
ntp server NTP NTP
NTP
ntp peer
A B NTP
NTP C
190
11-8
NTP A NTP ( B) NTP
NTP C
B NTP ( A)
C NTP
ntp peer NTP
ntp peer
A



11.1.2(8)
NTP

11.1.2(8)
7 NTP

1
2
(
2

2
NTP NTP

NTP
b NTP

NTP LI 3
NTP
NTP
11-15

ntp peer
11-14
RFC1305/RFC5905

delay
15


NTP 16
Reference IDref id IP
reach=0 8
195
b
offset ± (low) (high) offset
low high truechimer falseticker
falseticker
10.5 12.2 falseticker

show ntp associations "remotes" "x"

outlier


RFC1305/5905

"#"
NTP
NTP

ntp peerntp server ntp broadcast client
4. NTP

NTP
17 1999


reload NTP
NTP 10
6. RFC1305/5905 NTP dispersion 1 NTP
ntp server prefer
dispersion dispersion 1 NTP
prefer
7. NTP "23:59:60" "00:00:00" 11-6
UTC
11-6 UTC
8. 1980 1 1 2038 1 17
NTP
11.1.3
No. UTC
197
JSTUTC +9

JSTUTC +9
2. (config)# exit
# copy running-config startup-config

VLAN
NTP
ntp trusted-key
sntp client no sntp client SNTP NTP

11. NTP
Do you wish to copy from running-config to startup-config? (y/n): y

#
2011 2 22 15 30
11.2.3 SNTP NTP

ntp interval
NTP
NTP




2. (config)# no ntp interval
3. (config)# no ntp server 192.168.1.2
SNTP SNTP
ntp server 192.168.1.2
SNTP NTP
NTP SNTP 11-7
NTP
clock timezone
NTP NTP



IP 192.168.1.100



IP 192.168.1.2 NTP
200




NTP NtP001
3. (config)# ntp trusted-key 1
NTP
NTP (192.168.1.100) 1
1 NTP


2 (ntp broadcast client)
NTP
3. (config)# ntp trusted-key 3
NTP 3
201

NTP


3. (config)# ntp trusted-key 2
NTP 2
NTP (192.168.1.200) 2
2
NTP
NTP
No.2 3
3. (config)# ntp trusted-key 1
NTP 1

3. (config)# ntp trusted-key 3
NTP 3
5. (config-if)# ntp broadcast key 3
(config-if)# exit
203
11-19
11.3.3 SNTP
ntp-client SNTP
11-20 SNTP
Activate NTP Client NTP-Server : 192.1.0.254, Source-Address : --- Mode : Unicast, Interval : 120(s)
NTP Execute History(Max 10 entry) NTP-Server Source-Address Mode Set-NTP-Time Status 192.1.0.254 --- Unicast 20XX/08/03 19:51:05 1 192.1.0.254 --- Unicast 20XX/08/03 19:49:05 1 192.1.0.254 --- Unicast 20XX/08/03 19:47:05 1 192.1.0.254 --- Unicast 20XX/08/03 19:45:05 1 192.1.0.254 --- Unicast 20XX/08/03 19:43:05 1 192.1.0.254 --- Unicast 20XX/08/03 19:41:05 1 192.1.0.254 --- Unicast 20XX/08/03 19:39:05 1 192.1.0.254 --- Command 20XX/08/03 19:38:27 -2 192.2.0.254 --- Unicast 20XX/08/03 19:37:30 Timeout 192.1.0.254 --- Unicast 20XX/08/03 19:37:18 Timeout
SNTP NTP
show clock
show ntp-client SNTP ×
204

> show ntp associations
>
12.1
12.2

DNS DNS
IP DNS
DNS
ipv6 host DNS IPv4 IPv6
IPv4
208
2 IPv6
12.2.3 DNS
1 DNS

ip domain lookup no ip domain lookup DNS
ip domain name DNS
ip domain reverse-lookup no ip domain reverse-lookup DNS

192.168.0.1
2 DNS
DNS
13.1
13.2

system logging format-add

system receive alarm logging no system receive alarm logging CPU

system recovery no system recovery

64
reload

>
> show version
>
set logging console


> show system
Date 20XX/02/12 23:09:11 UTC System Name : - Contact : - Locate : - MAC address : 0012.e2b2.37dd Switch Machine ID Boot Date Boot reason Elapsed time 1 0012.e2a2.d273 20XX/02/09 21:54:56 Reload 3 days 01:14: 15 2 0012.e2b2.37dd 20XX/02/09 21:53:42 Reload 3 days 01:15: 29 Switch ST1 LED ST2 LED 1 Green Orange 2 Green Green Brightness mode : normal MC configuration mode : disabled Power redundancy-mode : check is not executed
Environment Fan PS EPU Current Temperature Running time( total) Switch Speed EPU-Fan Accumulated Running time( critical) 1 active active notconnect 60.82 W normal 1448 days and 0 hours normal - 6.81 kWh 0 days and 0 hours 2 active active notconnect 59.53 W normal 1393 days and 12 hours normal - 6.84 kWh 0 days and 0 hours
File System < RAMDISK information > used 140,288 byte free 31,316,992 byte total 31,457,280 byte < RAMDISK files > There is no file. ( RAMDISK ) < MC information > MC : not connect
Device Resources IP Interface Entry : 3(max entry=128) IP Address Entry : 3(max entry=128) IPv4 ARP Entry : 2(max entry=2560) IPv6 NDP Entry : 0(max entry=256) MAC-address Table Entry : 32415(max entry=32768)
System Layer2 Table Mode : 1 Switch Limit queue length 1 64 2 64 Flow detection mode : layer2-2 Used resources for filter(Used/Max) MAC IPv4 Port 1/0/1-52 : - 0/256 Port 2/0/1-52 : - 0/256 VLAN : - 0/256 Used resources for QoS(Used/Max) MAC IPv4
214
13.
>
> show system
Date 20XX/08/21 17:04:04 UTC System: AX2530S-24T Ver. 4.21 (Build:yy) Name : - Contact : - Locate : - Machine ID : 0012.e262.aaa1 Boot Date : 20XX/08/20 17:03:05 Boot reason : Power-on Elapsed time : 1 days 00:00:59 LED ST1 LED : Green ST2 LED : Light off Brightness mode : normal MC configuration mode : disabled Zero-touch-provisioning status : enabled(no change)
Environment Power redundancy-mode : check is not executed Fan : - Speed : - PS : active EPU : notconnect EPU Fan : - Current wattage : 21.53 W Accumulated wattage : 0.02 kWh Temperature : normal Accumulated running time total : 309 days and 6 hours critical : 15 days and 20 hours
File System < RAMDISK information > used 140,288 byte free 31,316,992 byte total 31,457,280 byte < RAMDISK files > There is no file. ( RAMDISK ) < MC information > MC : not connect
Device Resources IPv4 Routing Entry(static) : 5(max entry=128) IPv4 Routing Entry(connected) : 22(max entry=128) IP Interface Entry : 4(max entry=128) IP Address Entry : 4(max entry=128) IPv4 ARP Entry : 11(max entry=2560) IPv6 NDP Entry : 7(max entry=256) MAC-address Table Entry : 35(max entry=32768)
System Layer2 Table Mode : 1 Limit queue length : 64 Flow detection mode : layer2-2 Used resources for filter(Used/Max) MAC IPv4 Port 0/1-28 : - 2/256 VLAN : - 2/256 Used resources for QoS(Used/Max) MAC IPv4
215
13.
>

> show system capacities
Date 20XX/11/30 12:00:00 UTC < VLAN information > VLAN : 892 VLAN x Port : 9260
>
system fan mode
13-6
> show environment
Date 20XX/01/31 09:55:21 UTC Fan environment Switch Fan Speed Mode 1 active normal 2 (cool) 2 - - -
Power environment Switch PS EPU EPU-Fan 1 active notconnect - 2 active notconnect -
Temperature environment Switch Main Warning level 1 27 degrees C normal 2 36 degrees C normal
Temperature-warning-level Switch Current(status/setting) Average(status/setting) 1 27/37 degrees C -/- degrees C period 0 day(s)
2 36/37 degrees C -/- degrees C period 0 day(s)
>
> show environment
Date 20XX/07/27 18:12:36 UTC Fan environment Fan : active Speed : normal Mode : 1 (silent) EPU Fan : -
Power environment PS : active EPU : notconnect
Temperature environment Main : 29 degrees C Warning level : normal
Temperature-warning-level current status : 29/32 degrees C Temperature-warning-level average status : 28/30 degrees C period 30 day(s)
>

> show environment temperature-logging
>
> show environment temperature-logging
Date 20XX/12/16 21:54:23 UTC Date 0:00 6:00 12:00 18:00 20XX/12/16 30.0 30.3 28.0 27.8 20XX/12/15 31.0 32.0 29.8 31.1
217
13.
>


SFP

show logging console
E5
System message mode : E5 >
show logging

1
/ : :
system logging format-add / / : :

show logging
show logging reference
show authentication logging

show logging
2 show authentication logging
IEEE802.1X show dot1x logging
Web show web-authentication logging
MAC show mac-authentication logging
syslog syslog TIMESTAMP

Jun 4 13:36:58 "hostname" [1]: WHT 06/04 13:36:58
Jun 4 13:36:58 "hostname" [1]: WHT 20XX/06/04 13:36:58
13.1.6

ARP
ARP
ARP CPU
IPv6
NDP
NDP IPv6
IPv4 IPv6


DHCP
NTP



2


CPU show qos queueing HOL

QoS
CoS

URL
Web
MAC

224.128.0.0/24 IGMP snooping
28.5 IGMP snooping/MLD snooping 2

ICMPv6 MLD snooping CPU
IGMP snooping
221
ARP MAC
13.1.7 CPU

5
540 / S2530 720 / S2530E 5
360 / S2530 480 / S2530E
system receive alarm parameters
no system receive alarm logging


64
13-11
> show receive alarm dump
Date 20XX/03/05 19:07:56 UTC Stack status : Enable Switch No : 4 MAC address : 0012.e2a4.f44c No. Date/Time Size Port Data 1 20XX/03/05 72 2/0/48 0012e2a4 f44c0012 e2beaf0e 8100cd05
19:07:32.467 08060001 08000604 00010012 e2beaf0e 0ad7c80e 0012e2a4 f44c0ad7 c8fea3df 5e0e951d 1fe10b50 38d930b6 a5106cf3
2 20XX/03/05 72 1/0/48 0012e2a4 f44c0012 e2beaf0f 8100cd05 19:07:32.470 08060001 08000604 00010012 e2beaf0f
0ad7c80f 0012e2a4 f44c0ad7 c8feb40f b618648e bb5bbec5 cf5ce1bc 1d1a9152
3 20XX/03/05 72 3/0/48 0012e2a4 f44c0012 e2beaf01 8100cd05 19:07:32.472 08060001 08000604 00010012 e2beaf01
0ad7c801 0012e2a4 f44c0ad7 c8feb562 61b799fb b5d58387 98bc95b8 37882ea4
4 20XX/03/05 72 2/0/48 0012e2a4 f44c0012 e2beaf02 8100cd05 19:07:32.475 08060001 08000604 00010012 e2beaf02
0ad7c802 0012e2a4 f44c0ad7 c8fe633b 021606a2 4d9ff320 8a71ddfe cd4ae71e

>

RAMDISK ftp


CLI set exec-timeout set terminal pager
password enable-mode
Web
7 OS-L2A
2



2.
restore "stack"
7 OS-L2A
4. Ver.3.1.A
ID 1 IDoperator 1

ID 9 1 17
MAC MAC DB
DHCP snooping
Wake on LAN 2 WOL DB
Wake on LAN



1
Web
"<!-- Original_URL -->"
Ver.3.5





"ramdisk" "page"

6 1
6 1
7
b



c
E9

227

snmp-server engineID local


copyerase startup-config
set stackset switch set remote switchset remote licenseset remote stack

restorereload
ppupdateset licenseerase license
format flash
MAC commit mac-authenticationload mac-authentication
Wake on LAN commit wol-deviceload wol-devicecommit wol-authenticationload wol-authentication
Web set access-redirect html-fileclear access-redirect html-file
SNMP set snmp-server engineID local
228
14.1 MC
14.2 MC
14.3 MC
MC
MC



2. MC
update mc-configuration
update mc-configuration
MC

MC LEDACC LED
3MC
MC
MC
4
4
2
3 SMLOS-L2A
SML
MC
MC
4
4

update mc-configuration MC 14-1 MC
MC

2 MC
MC
MC LEDACC LED MC
MC MC MC

235


ppupdate 2 MC RAMDISK ftptftp
MC


237






2. AX-Network-ManagerDHCP
IP

AX-Network-ManagerTFTP

ppupdate


A-2 MACaa2 backupA2
A-2 B-2
15-3 A-2


15-4
AX-Network-Manager MAC
MAC aa2 MAC bb2
242
AX-Network-Manager backupA4 MAC aa2 bb2

LAN
15-5
15-6
AX-Network-Manager VLAN



MC
SMLOS-L2A
VLAN VLAN1
VLAN

244
245
VLAN

VLAN 4094
3. (config)# system zero-touch-provisioning

2


246

SFP SFP+/SFP 10G
2

×
LED
1 LED
LED
LED
LED ST1/ST2/ACC
LED PWR LEDPSIN1/PSIN208TC1
PoE Status LEDTEMPPWRPORT
08PLED

ST1
ST2
ACC
LINK
T/R
1 808P08TC1 1 1616P4X 1 2424T24T4X 1 4848T48T2X48P2X
system port-led LED LED

system port-led LED
enable economy disable
LED LED LED LED
ST1


OFF

SML 1
251
2
3
10BASE-T/100BASE-TX/1000BASE-T
LED


ACC





system port-led LED
enable economy disable
LED LED LED LED
252

2.
PWR LEDPSIN1/PSIN208TC1
PoE Status LEDTEMPPWRPORT08P

253
SFP SFP+/SFP 10G LED
2

10BASE-T/100BASE-TX/
1000BASE-T SFP SFP+/SFP 10G



ifAdminStatus Set
2
16.1.4
PWR LED

power-control port cool-standby

RESET
16-6 WOL
SFP 2 4 2
0/23 0/24 24T4X24S4X
10BASE-T/100BASE-TX/1000BASE-T 0/23 SFP 0/25 2
16-6 WOL

24T24TD 0/1 0/22 0/23 0/24 0/25 0/26 0/27 0/28
24T4X 0/1 0/22 0/23 0/24 0/25 0/28
48T48TD 0/1 0/46 0/47 0/48 0/49 0/50 0/51 0/52
48T2X48P2X 0/1 0/46 0/47 0/48 0/49 0/50 0/51 0/52
24S4X24S4XD 0/1 0/22 0/23 0/24 0/25 0/28
2 × × × ×



4






10 48T
(system fan mode)


system fan mode 2
system fan-control

system fan mode 1

258

b

c









a


2011 6 2 5 2011 6
1 20 2011 6 6 8

260

261

8 30 17 8 20
20 8

262
2011 6 4 16
20
MIB


24





Unsaved changes would be lost when the machine goes to sleep!
Do you exit "configure" without save ? (y/n):
"n" save







set power-control schedule

3.
6.
UDLD
L2


DHCP snooping DHCP
IP
Windows ipconfig/release ipconfig/renew
DHCP

267
LED
LED


LED
MC
LED
(config)# system port-led trigger interface gigabitethernet 0/1,
gigabitethernet 0/20
LED 0/1 0/20 MC

16.2.3

end-time 110104 0600 action enable
2010 12 28 23 2011 1 4 6
3. (config)# schedule-power-control time-range 2 date start-time 111228 2300
end-time 120104 0600 action enable
2011 12 28 23 2012 1 4 6
4. (config)# schedule-power-control time-range 3 date start-time 121228 2300
end-time 130104 0600 action enable
2012 12 28 23 2013 1 4 6
5. (config)# end
Unsaved changes would be lost when the machine goes to sleep!
Do you exit "configure" without save ? (y/n):


(config)# save

2 LED

(config)# schedule-power-control port cool-standby

shutdown
270

end-time mon 0800 action enable
20 8
3. (config)# schedule-power-control time-range 2 date start-time 110404 1600
end-time 110404 2000 action disable
2011 4 4 16 20



3
gigabitethernet 0/1, gigabitethernet 0/4
3. (config)# schedule-power-control time-range 1 infinity action enable

4. (config)# end
Unsaved changes would be lost when the machine goes to sleep!
Do you exit "configure" without save ? (y/n):


(config)# save

4
LED show system Brightness mode
13.1.3
> show power-control port
>
show system Fan13.1.3

16.3.5
> show power-control schedule XX0801
>
> show power
Date 20XX/08/04 09:49:05 UTC Elapsed time 0days 12:11:44 Current wattage Accumulated wattage 73.36 W 0.99 kWh
>
17.1
17.2
17.3

ppupdate



18.8 1000BASE-X
18.9 1000BASE-X
18.12 SFP+/SFP 10G
18.13 SFP+/SFP 10G
18.14 PoE 48P2X08P16P4X
18.15 PoE 48P2X08P16P4X
18.16 PoE 48P2X08P16P4X
18.17
18.18
18.19
10BASE-T/100BASE-TX/1000BASE-T 1000BASE-X




aPreamble SFD
64 2 1010...1011( 62 '10' 2 '11')
64

TYPE LENGTH
0x05DD Ethernet V2.0
2 LLC
IEEE802.2 LLC 1(UI ) Ethernet V2 LLC



MAC

18.1.5






LACP
1 0/1

bandwidth
description
duplex
duplex

mtu MTU


285
tengigabitethernet 0/25
1 0/1 0/100/15 0/20 10G
0/25
0/10
2. (config-if)# shutdown
inactivate inactive active
disable active
no shutdown
save
MTU

4

0/10 MTU 8192 VLAN Tag
8206 VLAN Tag 8210


(config-if)# shutdown
2. (config-if)# no shutdown
10BASE-T 100BASE-TX
MTU 1500
2 MTU
4110 VLAN Tag 4114



10BASE-T 100BASE-TX
MTU 1500
287
0/10
(config-if)# exit
0/10
(config-if)# exit
Status up
show port
18-5
> show port
>
test interfaces
289


…10BASE-T100BASE-TX


( ) ×
2

3



18-8
desired
18-8
18-7
18-8
desired
18-8
18-8

on off
desired on on
on on
on off
desired on on
desired on on
on off
desired on on
off on on
off on
desired on on
on on
off off
desired on on
desired on on
off on
desired on on
desired on on on
off on
desired on on
on on
off on
desired on on
desired on on
off on
desired on on
off off off
off off
desired off off
on off
off off
desired on off
293


1
2
BI_Dx
off off
desired off off
desired on on
off off
desired on on
on on
off off
desired on on
desired on on
off off
desired on on
RJ45 MDI MDI-X
1 BI_DA TD TD BI_DB RD RD
2 BI_DA TD TD BI_DB RD RD
3 BI_DB RD RD BI_DA TD TD
4 BI_DC Unused Unused BI_DD Unused Unused
5 BI_DC Unused Unused BI_DD Unused Unused
6 BI_DB RD RD BI_DA TD TD
7 BI_DD Unused Unused BI_DC Unused Unused
8 BI_DD Unused Unused BI_DC Unused Unused


Tag 22.1.5 VLAN Tag Tag
100BASE-TX1000BASE-T

6


× MAC DA FCS


auto auto 10 100 1000
auto 10 100 auto 1000 or
auto 100 or
auto 10
1 On 1 10 100 1000 10 100 1000 10 100
2 2 10 100 10 100 10
3 3 10 10




18.4.2 10BASE-T/100BASE-TX/1000BASE-T SFPSFP-T SFP-T SFP SFP+/SFP 10BASE-T/
100BASE-TX/1000BASE-T

/
48T2X 48P2X
0/51 0/52 1000BASE-T SFP+/SFP
24S4X24S4XD 0/1 0/24 10BASE-T/100BASE-TX/1000BASE-T SFP
0/25 0/28 1000BASE-T SFP+/SFP
08P08PD2408PD, 08TC1
16P4X 0/17 0/20 1000BASE-T SFP+/SFP
(6)
100Mbit/s 10Mbit/s
duplex


(config-if)# shutdown
(config-if)# shutdown
duplex

18.5.2


(config-if)# shutdown
MDI
MDI MDI MDI-X
HUB

0/10
(config-if)# exit
298
18.6.1
100BASE-FX
1
a100BASE-FX

100BASE-FX
b100BASE-FX


×
2

18-15
100BASE-FX ,
18-15
3

Tag 22.1.5 VLAN Tag Tag

4 100BASE-FX

18.6.2 100BASE-FX SFP SFP 1000BASE-XSFP 100BASE-FX

24S4X24S4XD
08TC1

× MAC DA FCS


18.7.1
(config-if)# shutdown
(config-if)# shutdown
1000BASE-BX 1000Mbit/s
1000BASE-SX

1000BASE-LH1000BASE-LHB
1000BASE-BX40-D/1000BASE-BX40-U

×
2



18-20
18-20
desired
18-20
18-19
18-20
desired
18-20
18-20

on
off
desired desired

on
off
desired desired

on off
desired on on
on on
on off
desired on on
desired on on
on off
desired on on
off on on
off on
desired on on
305

off off
desired on on
desired on on
off on
desired on on
desired on on on
off on
desired on on
on on
off on
desired on on
desired on on
off on
desired on on
off off off
off off
desired off off
on off
off off
desired on off
desired off off
off off
desired off off
desired on on
off off
desired on on
on on
off off
desired on on
desired on on
off off
desired on on

Tag 22.1.5 VLAN Tag Tag

5 1000BASE-X
× MAC DA FCS


1000Mbit/s duplex

(config-if)# shutdown
speed duplex

(config-if)# shutdown
18.10.1
10GBASE-R
1
a10GBASE-R
2

18-23
10GBASE-R ,
18-23
3

Tag 22.1.5 VLAN Tag Tag


on
off
desired desired

on
off
desired desired

× MAC DA FCS




(config-if)# shutdown
18.12.1
1
SFP+/SFP 10GBASE-R SFP+1000BASE-X SFP SFP-T
SFP+/SFP
a10GBASE-R
18.10 10GBASE-R 10G
b1000BASE-X/1000BASE-T 1000BASE-X
18.8 1000BASE-X

100BASE-TX/1000BASE-T
10GBASE-R 10GBASE-R 18.10
10GBASE-R 10G

10GBASE-R SFP+ duplex duplex
1000BASE-X SFP SFP-T
duplex
duplex
tengigabitethernet
duplex
(config-if)# shutdown
duplex
duplex

18.14.1 PoE
30.0W



PoE

3

18-26 PoE
1 PoE
aClass
Class Class
18-25
b


18.0W 20.0W
Class 0 30.0W

425W 240W 250W
0/1 0/48 30.0W 30.0W
Class 0 15.4W
Class 1 4.0W
Class 2 7.0W
Class 3 15.4W
Class 4 30.0W

18.
c
PoE 18-26 PoE
PoE


PoE


inline delay
18.14.4






425W



18-26 PoE

Class 0 ×15.4W
Class 1 ×4.0W
Class 2 ×7.0W
Class 3 ×15.4W
Class 4 ×30.0W

18.14.5
1

power inline
critical
high
low
never
critical
high
×


off
on

inactivate interface ×
activate interface ×
"faulty"

inactivate power inline inact
offshutdown no shutdown off
on
denied

faulty shutdown off
activate power inline off
on
faulty
activate power inline off
on
inact
b "denied"



power inline


6



3
interface range

PoE 7 OS-L2A
10 PoE




PoE no power inline delay

18.15.1
PoE

PoE
(config-if)# power inline never
18.15.3

18-26 PoE

power inline delay PoE PoE





Please execute 'reload all' command after save,
because this command becomes effective after reboot.

3. (config-sw)# end
# copy running-config startup-config
Do you wish to copy from running-config to startup-config? (y/n): y



Please execute the reload command after save,
because this command becomes effective after reboot.

2. (config)# end
# copy running-config startup-config
Do you wish to copy from running-config to startup-config? (y/n): y

3. @# reload



(config-if)# power inline allocation limit 20000
0/1 20000mW20W
2. (config-if)# exit
18.15.5 PoE
PoE shutdown power inline never

PoE
PoE 300 60 PoE 0/1 0/10critical
PoE high

PoE 300 60
2. (config)# interface range gigabitethernet 0/1-10
0/1 0/10
0/1 0/10
4. (config-if-range)# exit
18.16.1
PoE
Status onPriority Class IEEE802.3af/IEEE802.3at
Power/Vol/Cur / /
PoE Status wait
show power inline
18-9 PoE 48P2X
> show power inline Please wait a little.
Date 20XX/08/22 20:15:07 UTC System Wattage: Switch Priority Control Threshold(W) Total Allocate(W) Total Power(W) 1 enable 425.0 30.8 1.4 2 disable 425.0 0.0 0.0 …1. 3 enable 425.0 90.8 40.0 4 enable 425.0 397.8 186.0 Total 1700.0 519.4 227.4 Port Counts : 192 Port Status Priority Class Alloc(mW) Power(mW) Vol(V) Cur(mA) Description 1/0/1 on low 0 15400 700 55.5 14 POE-SW1 1/0/2 off low - 0 0 0.0 0 POE-SW1 1/0/3 off low - 0 0 0.0 0 POE-SW1 1/0/47 off critical - 0 0 0.0 0 POE-SW1 1/0/48 on critical 0 15400 700 55.2 14 POE-SW1 2/0/1 off high - 0 0 0.0 0 POE-SW2 2/0/2 off high - 0 0 0.0 0 POE-SW2 : : : 3/0/1 off never - 0 0 0.0 0 POE-SW3 3/0/2 on low 4 30000 19300 54.7 353 POE-SW3 3/0/3 off low - 0 0 0.0 0 POE-SW3 3/0/4 off low - 0 0 0.0 0 POE-SW3 3/0/5 on low 0 15400 700 55.0 14 POE-SW3 : : :

activate power inline
inactivate power inline
18.
>
18-10 PoE
> show power inline Please wait a little.
>
source destination Down source
Up Down destination Up
destination source
destination 4 source source
source destination
Down source Up
source destination
source destination
link-relay source
show interfacesshow port destination "inactive"

0/2 0/4
destination

331



18-12
destination 0/2
source 0/25 26
3. (config-if)# exit
0/2
destination 0/4
source 0/25 26
6. (config-if)# exit
0/4

> show link-relay
>


LACP
2


Duplex

MAC
IPv4/IPv6
TCP/UDP
TCP/UDP
MAC
VLAN

LACPDU


channel-group mode
0/10/2
(config-if-range)# exit
19.2.3 LACP
passive
channel-group mode

LACP
0/10/2
(config-if-range)# exit
0/10/2 LACP 3 LACP active
LACPDU passive
LACPDU LACPDU
(config-if)# exit
100
(config-if)# lacp port-priority 100
4 LACPDU
LACPDU long30 short1
340
19.
long30 short1

(config-if)# channel-group periodic-timer short


19.2.4





(config-if-range)# channel-group 3 mode on
(config-if-range)# exit
3
3
(config-if)# exit
ip arp inspection trust
ip dhcp snooping trust
switchport backup flush-request transmit

(config-if-range)# channel-group 3 mode on
(config-if-range)# exit
2. (config)# interface port-channel 3
(config-if)# shutdown
(config-if)# exit
3



(config-if)# shutdown
2. (config-if)# no channel-group
344
interface port-channel
19-4


(config-if-range)# shutdown
(config-if-range)# exit

3 0/10/2
channel-group mode
3
19-3



3
3 3
3
3. (config-if)# exit
(config-if)# exit
(config-if)# lacp port-priority 300
128
LACP

> show channel-group
Date 20XX/12/06 18:20:48 UTC ChGr: 31 Mode: LACP CH Status : Down Elapsed Time: - Max Active Port: 8 MAC address : - VLAN ID: 4093 Actor System : Priority: 128 MAC: 0012.e2a4.fe51 Key: 31 Partner System : - Port Information 0/23 Down State: Detached 0/25 Down State: Detached ChGr: 32 Mode: LACP CH Status : Up Elapsed Time: 00:15:16 Max Active Port: 8 Description : lab network MAC address : 0012.e254.ba14 VLAN ID: 4093 Periodic Timer : Long Actor System : Priority: 128 MAC: 0012.e2a4.fe51 Key: 32 Partner System : Priority: 128 MAC: 0012.e2a8.85a2 Key: 32 Port Information 0/26 Up State: Distributing ChGr: 33 Mode: LACP CH Status : Down Elapsed Time: - Max Active Port: 8 MAC address : - VLAN ID: 4093 Actor System : Priority: 128 MAC: 0012.e2a4.fe51 Key: 33 Partner System : - Port Information 0/22 Up State: Detached ChGr: 64 Mode: Static CH Status : Up Elapsed Time: 00:15:21 Max Active Port: 8 MAC address : 0012.e254.ba12 VLAN ID: 4093 Port In