Manual IronPort Systems 4108GL

483 pages 5.98 mb
Download

Go to site of 483

Summary
  • IronPort Systems 4108GL - page 1

    hp pr oc urve s w itc h 4108gl management and conf igur ation gui de w w w .hp .com/go/hppr ocurv e ...

  • IronPort Systems 4108GL - page 2

    ...

  • IronPort Systems 4108GL - page 3

    HP Procurve Switch 4108G L Management and Configuration Guide Software Release G.01. xx or Later ...

  • IronPort Systems 4108GL - page 4

    Hewlet t-Pa ckard Com pany 8000 Foo thills B oulevar d, m/s 5551 Rosev ille, Calif ornia 95747- 5551 http://ww w.h p.com/go/h pprocurve © Copyright 20 01 Hew lett-Packard Co mpany All Rights Re served. This docume nt contains i nformation which is protected by copyright. Reproduction, adapta tion, or translation without prior permission is prohibi ...

  • IronPort Systems 4108GL - page 5

    iii Pref ace Preface Use of This Guide and Other Pro curve Switch Documentation This guide de scribes how t o use the comm and lin e interfa ce (CLI), me nu interf ace, an d web b rowser in terfa ce for t he HP Pr ocurve Switch 4108GL— also ref erred t o as the Swi tch 410 8GL. ■ If you need inf ormation o n specific pa rameters in the menu int ...

  • IronPort Systems 4108GL - page 6

    iv Pref ace T o Set Up and Install the Switch in Y our Network Use the HP Proc urve Switch 41 08GL Instal lation and Get ting Started Gu ide (shipped w ith the switch) t o guide y ou in the follo wing: ■ Physically insta lling the switch in your network ■ Quickly assigning an IP address and subnet mask, set a Manag er pass- word, and (optiona l ...

  • IronPort Systems 4108GL - page 7

    v Contents Preface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . iii Use of This Guide and Other Procurve Switch Documentation . . . . . . iii Just Want a Quick Start? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . iii To Set Up and Install the Switch in ...

  • IronPort Systems 4108GL - page 8

    vi Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-2 Acces sing the C LI . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-2 Using the CLI . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3- ...

  • IronPort Systems 4108GL - page 9

    vii Switch Me mory and Configurat ion Chapte r Content s . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-1 Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-2 Overview o f Configurat ion File Man agement . . . . . . . . . . . . . . . . . . ...

  • IronPort Systems 4108GL - page 10

    viii IP Addressing with Multiple VLANs . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-4 IP Addressing in a Stac king Environment . . . . . . . . . . . . . . . . . . . . . . . 7-5 Menu: Config uring IP Addre ss, Gateway, an d Time-To-L ive (TTL ) . . 7-5 CLI: C onfiguring IP Address, Gateway, Time-To-Li ve (TTL), and Timep . . . . . . . . ...

  • IronPort Systems 4108GL - page 11

    ix Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-2 Configuring U sername and Password Securi ty . . . . . . . . . . . . . . . . . . 9-3 Menu: Configuring Passwords . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-5 CLI: Setting Manager and Operator Passwor ds ...

  • IronPort Systems 4108GL - page 12

    x Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-2 Viewing Por t Status and Configur ing Port Para meters . . . . . . . . . . 11-2 Menu: Viewing Port Status a nd Configur ing Port Param eters . . . . . 11-5 CLI: Viewing Port Status and Configuring Port Pa rameters . . . . . . . 11 ...

  • IronPort Systems 4108GL - page 13

    xi Configuring CDP Operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-21 Effect of Spa nning Tree (STP) On CDP Packet Transmission . . . . 12-23 How the S witch S elects the IP Address To Inc lude in Outboun d CDP P ackets 12-2 4 CDP Neighbor Data and MIB Objects . . . . . . . . . . . . . . . . . . . . . . . . . 12-25 Op ...

  • IronPort Systems 4108GL - page 14

    xii Web: Viewing and Configuring VLAN Par ameters . . . . . . . . . . . . . . 14-22 VLAN Tagging Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-23 Effect of V LANs on Other Switch Feat ures . . . . . . . . . . . . . . . . . . . . 14-27 VLAN Restrictions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ...

  • IronPort Systems 4108GL - page 15

    xiii CLI: Co nfiguri ng STP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-5 Web: Enab ling or Disa bling S TP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-9 How STP Op erates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-9 STP Fast Mode . . . . . . ...

  • IronPort Systems 4108GL - page 16

    xiv Menu: Entering and Navigat ing in the Event Log . . . . . . . . . . . . . . . 18-17 CLI: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-18 Diagnostic Tools . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-19 Port Auto-Negotiation . . . . . . ...

  • IronPort Systems 4108GL - page 17

    1-1 Select ing a Managem ent Interface 1 Selecting a Management Interface Contents Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-2 Understanding Management Interfaces . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-2 Advantages of Using t he Menu Interface . . . . ...

  • IronPort Systems 4108GL - page 18

    1-2 Selec ting a Ma nagem ent Int erfa ce Overv iew Sele cting a Ma nagemen t Int erfa ce Overview This chapte r describes th e following : ■ Manage ment i nterf aces f or the Sw itch 410 8GL ■ Advantag es of usi ng each i nterface Understanding Management Interfaces Manage ment i nterfaces enab le yo u to re configu re the sw itch a nd to mo n ...

  • IronPort Systems 4108GL - page 19

    1-3 Sele cting a M anagemen t In ter face Adv antage s of Usi ng th e Me nu I nter face Sele cting a Ma nagemen t Interface Advantages of Using the Menu Interface Figure 1-1. Example of the Console Inte rface Display ■ Provides quick, easy management access to a menu -driven subse t of switch con figuratio n and pe rformanc e featur es: The men u ...

  • IronPort Systems 4108GL - page 20

    1-4 Selec ting a Ma nagem ent Int erfa ce Advant ages o f Us ing t he CLI Sele cting a Ma nagemen t Int erfa ce Advantages of Using the CLI Figure 1-2. Exampl e of The Comma nd Prompt ■ Provides a ccess to the compl ete set of the sw itch confi guration, perf or- mance, and di agno stic features. ■ Offers out- of-band acce ss (through the RS-23 ...

  • IronPort Systems 4108GL - page 21

    1-5 Sele cting a M anagemen t In ter face Advant ages of Using the HP We b Brow ser In terf ace Sele cting a Ma nagemen t Interface Advantages of Using the HP W eb Browser Interface Figure 1-3. Example of the HP We b Browser Interfac e ■ Easy access to the swit ch from anyw here on the network ■ Familia r browse r interf ace --locations of wind ...

  • IronPort Systems 4108GL - page 22

    1-6 Selec ting a Ma nagem ent Int erfa ce Advant ages of Us ing H P Top Tool s for Hubs & Swi tches Sele cting a Ma nagemen t Int erfa ce Advantages of Using HP T o pT ools for Hubs & Switches Y ou can operate HP T opT ools from a PC on t he network t o monitor tr affic, manage y our hubs and swit ches, and p roactively r ecommend ne twork ...

  • IronPort Systems 4108GL - page 23

    1-7 Sele cting a M anagemen t In ter face Advan tag es of Usin g HP TopT ools for Hub s & Switc hes Sele cting a Ma nagemen t Interface • Notifies you wh en HP hubs use “ se lf-healing ” feat ures to fix or li mit comm on network p roblem s. • Provide s a list of discov ered d evices, wit h device type, connecti vity status, the number ...

  • IronPort Systems 4108GL - page 24

    1-8 Selec ting a Ma nagem ent Int erfa ce Advant ages of Us ing H P Top Tool s for Hubs & Swi tches Sele cting a Ma nagemen t Int erfa ce ...

  • IronPort Systems 4108GL - page 25

    2-1 Usin g the Me nu Inte rface 2 Using the Menu Interface Contents Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-2 Starting and Ending a Menu Session . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-3 How To Start a Menu Inter face Session . . . . . . . . . . . ...

  • IronPort Systems 4108GL - page 26

    2-2 Using the Menu In terface Overv iew Usin g the Me nu Int erface Overview This chap ter de scribes the fo llowing features : ■ Overvi ew of the Menu Int erface ( page 4-1) ■ Starti ng and en ding a Men u session (p age 2-3 ) ■ The Mai n Menu (page 2 -7) ■ Screen struc ture and navi gati on (pag e 2-9 ) ■ Rebo oting th e sw itch (page 2 ...

  • IronPort Systems 4108GL - page 27

    2-3 Using the Me nu In terf ace Start ing an d Ending a Men u Session Usin g the Me nu Inte rface someone witho ut a password ca n still gain read-only access.) For more information on passwords, se e “ Configur ing Username and Passwor d Secu- rity ” on page 9-3. Menu I nterac tio n with Other I nter face s. ■ The menu int erface displ ays t ...

  • IronPort Systems 4108GL - page 28

    2-4 Using the Menu In terface Star ting and Endi ng a Menu Session Usin g the Me nu Int erface How T o Start a Me nu Interface Session In its fac tory defau lt config uration, th e switch co nsole sta rts with the C LI prompt. T o use the menu int erface with Manage r privileg es, go to the Mana ger level pr ompt and ent er the me nu comma nd. 1. U ...

  • IronPort Systems 4108GL - page 29

    2-5 Using the Me nu In terf ace Start ing an d Ending a Men u Session Usin g the Me nu Inte rface Figure 2-1. The Main Menu with Manager P rivileges For a descr iptio n of Main Me nu feat ures, see “ Ma in Menu Featu res ” on page 2-7. Note T o config ure t he swit ch to sta rt with the menu i nterf ace in stea d of the CL I, go to the Manager ...

  • IronPort Systems 4108GL - page 30

    2-6 Using the Menu In terface Star ting and Endi ng a Menu Session Usin g the Me nu Int erface Figure 2-2. An Asterisk In dicates a Con figuratio n Chang e Requiring a Reboot 1. I n the c urre nt sess ion, if you h ave no t made c onfig uratio n ch anges that requ ire a s wit ch reb oot to acti vate , re turn t o the M ain Menu and p ress [0] (zero ...

  • IronPort Systems 4108GL - page 31

    2-7 Using the Me nu In terf ace Main M enu Featur es Usin g the Me nu Inte rface Main Menu Features Figure 2-3. The Ma in Menu V iew with Manag e r Privil eges The Main Menu g ives you ac cess to these Me nu interface features: ■ Stat us and Counter s: Provides access to display scr eens showing switch info rmation , port st atus and count ers, p ...

  • IronPort Systems 4108GL - page 32

    2-8 Using the Menu In terface Main Me nu Featu res Usin g the Me nu Int erface ■ Command Li ne (CLI): Select s the Comman d Line Inter face at the sam e level (M anage r or Opera tor) that you are a ccessing in the Menu in terface . (See chap ter 3, "Usin g the Co mmand Line In ter face (C LI)". ) ■ Rebo ot Swit ch: Perfor ms a " ...

  • IronPort Systems 4108GL - page 33

    2-9 Using the Me nu In terf ace Scre en Str uctur e and Nav igat ion Usin g the Me nu Inte rface Screen Structure and Nav igation Menu i nterface screens incl ude the se three elements: ■ Param eter f ields and/o r read -on ly info rmat ion su ch as s tatis tics ■ Navigati on and config uration actions, such a s Save, Edit, an d Cancel ■ Help ...

  • IronPort Systems 4108GL - page 34

    2-10 Using the Menu In terface Scre en Str uctur e and Nav igat ion Usin g the Me nu Int erface T able 2-1. How T o Navigate in the M enu Inter face T as k: Actions: Execu te an act ion from the “ Act ions – > ” list at the bot tom of the scre en: Use eit her of the fo llow ing meth ods: • Use the a rrow key s ( [<] ,or [>] ) to hi ...

  • IronPort Systems 4108GL - page 35

    2-1 1 Using the Me nu In terf ace Scre en Str uctur e and Nav igat ion Usin g the Me nu Inte rface T o get Help on i ndividu al parame ter descr iptio ns. In most screens there is a Help option in the Actions line. Wh enever any of the items in the Actions line is highlighted, pr ess [H] , and a separa te help screen is displayed . For exam ple: Fi ...

  • IronPort Systems 4108GL - page 36

    2-12 Using the Menu In terface Reboot ing the Switch Usin g the Me nu Int erface Rebooting the Switch Reboot ing the swit ch from the menu interf ace ■ T erminates all c urrent session s and perform s a reset o f the operat ing system ■ Activa tes any m enu inte rface co nfigur ation changes th at req uire a re boot ■ Resets stat istical coun ...

  • IronPort Systems 4108GL - page 37

    2-1 3 Using the Me nu In terf ace Reboot ing the S witch Usin g the Me nu Inte rface Rebooting T o Act ivate Configu ration Changes. Configuration c hanges for most par ameters in the menu interfa ce become effective a s soon as yo u save them . However , y ou must reb oot the switc h in order to imp lemen t a chan ge in the Maxi mum VLAN s to s up ...

  • IronPort Systems 4108GL - page 38

    2-14 Using the Menu In terface Menu Fe ature s List Usin g the Me nu Int erface Menu Features List Sta tus and Co unte rs • General Sy stem Information • Switch Manageme nt Addre ss Inform ation • Port Stat us • Port Count ers • Address T a ble • Port Addr ess T able • Spanning T ree Info rmation Swi tch C onf igur atio n • System I ...

  • IronPort Systems 4108GL - page 39

    2-1 5 Using the Me nu In terf ace Wher e To Go From Here Usin g the Me nu Inte rface Where T o Go From Here This c hapter provid es an ov ervi ew of t he men u interf ace and how t o use it. The follo wing table indicates w h ere to tu rn for d etailed info rmation o n how to use the in dividu al featur es avail able t hroug h the m enu inte rface ...

  • IronPort Systems 4108GL - page 40

    2-16 Using the Menu In terface Where To Go From Here Usin g the Me nu Int erface ...

  • IronPort Systems 4108GL - page 41

    3-1 Using the Com mand Line Interface (CLI) 3 Using the Command Line Interface (CLI) Chapter Contents Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-2 Accessing the C LI . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-2 Using the ...

  • IronPort Systems 4108GL - page 42

    3-2 Using th e Command Line Interf ace (CLI ) Overv iew Using the Co m mand Line Interface (CLI) Overview The CLI i s a text -based co mmand inte rface for confi guring and monit oring th e switch. The CLI give s you access to the switc h ’ s full set of commands w hile providing the same password protection t hat is used in the web browser inte ...

  • IronPort Systems 4108GL - page 43

    3-3 Using t he Co mmand Line Inter face (C LI) Usin g the CLI Using the Com mand Line Interface (CLI) Startup C onfig file in non-v olatile memor y . If you reboot the switch w ithout first usin g write mem ory , all ch ange s mad e si nce t he las t reb oot o r write memo ry (whichever is later) will be lost. For mor e on switch memory and saving ...

  • IronPort Systems 4108GL - page 44

    3-4 Using th e Command Line Interf ace (CLI ) Using the CLI Using the Co m mand Line Interface (CLI) Caut ion HP strongly re commend s that yo u configure a Manage r password . If a Man- ager passw ord is not co nfigured, then the Mana ger leve l is not password - protec ted, and anyone having in-b and o r out-of -band ac cess to the switch ma y be ...

  • IronPort Systems 4108GL - page 45

    3-5 Using t he Co mmand Line Inter face (C LI) Usin g the CLI Using the Com mand Line Interface (CLI) Manager Privileges Manag er privi leges g ive you three addit ional lev els of a ccess: Mana ger , Global Configura tion, and Cont ext Confi guration. (See figur e .) A " # " charac ter delimits a ny Manage r promp t. For ex ample: HP4108 ...

  • IronPort Systems 4108GL - page 46

    3-6 Using th e Command Line Interf ace (CLI ) Using the CLI Using the Co m mand Line Interface (CLI) Changin g Interfac es. If yo u change from the CLI t o the menu interfac e, or the reverse, yo u will remain at the same priv ilege level. For exa mple, entering the menu com mand from the Operator level of the CLI tak es you t o the Operator p rivi ...

  • IronPort Systems 4108GL - page 47

    3-7 Using t he Co mmand Line Inter face (C LI) Usin g the CLI Using the Com mand Line Interface (CLI) How T o Move Betw een Levels Movin g Betw een t he CL I and the Menu I nterf ace. Wh en moving between int erfaces, the switc h retains th e current privile ge level (Mana ger or Opera tor) . That is, if you ar e at th e Opera tor le vel in th e me ...

  • IronPort Systems 4108GL - page 48

    3-8 Using th e Command Line Interf ace (CLI ) Using the CLI Using the Co m mand Line Interface (CLI) for VLAN 1 and later use the CLI to con figure a differen t IP address of " Y " f or VLA N 1, th en " Y " replac es " X " as th e IP add ress for V LAN 1 in the running- conf ig fi le. ( If yo u sub seque ntly exec ute ...

  • IronPort Systems 4108GL - page 49

    3-9 Using t he Co mmand Line Inter face (C LI) Usin g the CLI Using the Com mand Line Interface (CLI) T yping ? at the Manager level pro duces this listin g: Figure 3-4. Example of the Manager -Level Comman d Listing When - - MORE - - appears, there are mo re comm ands in the li sting. T o list the next screenf ull of comma nds, press the Spa ce ba ...

  • IronPort Systems 4108GL - page 50

    3-10 Using th e Command Line Interf ace (CLI ) Using the CLI Using the Co m mand Line Interface (CLI) telnet terminal HP4108(config)# t As mentioned above, if you t ype part of a co mmand word a nd press [T ab] , the CLI com pletes the cur rent word ( if you have typed enough o f the word f or the CLI to distingu ish it from other possib ilities), ...

  • IronPort Systems 4108GL - page 51

    3-11 Using t he Co mmand Line Inter face (C LI) Usin g the CLI Using the Com mand Line Interface (CLI) Thus, if you wanted to crea te a port trunk group using ports c3-c 6, the abov e conven tions show tha t you could do so using any o f the followin g forms of the trunk command: HP4108(config)# trunk trk1 trunk c3-c6 HP4108(config)# trunk trk1 tru ...

  • IronPort Systems 4108GL - page 52

    3-12 Using th e Command Line Interf ace (CLI ) Using the CLI Using the Co m mand Line Interface (CLI) Figure 3-7. Example of Co ntext-Sensitive Command-List Help Displaying He lp for an Indi vidual Command. Y ou can display He lp for any co mmand that is avail able at the cu rren t cont ext le vel by en teri ng enou gh of the co mmand stri ng to id ...

  • IronPort Systems 4108GL - page 53

    3-13 Using t he Co mmand Line Inter face (C LI) Usin g the CLI Using the Com mand Line Interface (CLI) Figure 3-9. Example o f Help f or a Specific Instan ce of a Comma nd Note that tryi ng to list the help for an ind ividual c ommand fr om a privil ege level that do es not include that c omman d result s in an error me ssage . For exampl e, trying ...

  • IronPort Systems 4108GL - page 54

    3-14 Using th e Command Line Interf ace (CLI ) Using the CLI Using the Co m mand Line Interface (CLI) Figure 3-10. Context-Sp ecific Command s Affecting Port Conte xt HP4108(eth-C5-C8)# ? HP4108(eth-C5-C8)# ? Lists the commands you can use i n the por t or sta tic tr unk contex t, plus th e Manag er , Opera tor , and cont ext comma nds you ca n exe ...

  • IronPort Systems 4108GL - page 55

    3-15 Using t he Co mmand Line Inter face (C LI) Usin g the CLI Using the Com mand Line Interface (CLI) VLAN Contex t . Includes VLAN- speci fic comman ds that appl y only to the selected VLAN, plus Manager a nd Operat or comma nds. The prompt for thi s mode incl udes the VLA N ID of the selec ted VLAN. F or example , if you had alre ady c onfigur e ...

  • IronPort Systems 4108GL - page 56

    3-16 Using th e Command Line Interf ace (CLI ) CLI Contr ol and Edit ing Using the Co m mand Line Interface (CLI) CLI Control and Editing Key st rokes Function [Ctrl] [A] Jumps to the fir st char acter of the co mmand line . [Ctrl] [B] or [<] Mo ves the cu rsor ba ck one char acter . [Ctrl] [C] T erminat es a ta sk and disp lay s th e comman d p ...

  • IronPort Systems 4108GL - page 57

    4-1 Using the HP Web Browser Interface 4 Using the HP W eb Browser Interface Chapter Contents Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-2 General Features . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-3 Web Browser Interfac ...

  • IronPort Systems 4108GL - page 58

    4-2 Using th e HP Web Brows er Interfa ce Overv iew Using th e HP Web Browser Interface Overview The HP web br owser inte rface bui lt into the swi tch lets you easi ly access the switch from a browser -based PC on your netwo rk. This lets you do the following : ■ Optimize y our net work upt ime b y using th e Alert Lo g and other diag nostic too ...

  • IronPort Systems 4108GL - page 59

    4-3 Using the HP Web Brows er Interfa ce Gener al Feat ures Using the HP Web Browser Interface General Features The Swi tch 410 8GL inc lude th ese web b rowser in terface f eatures: Switch Configu ration: • Ports • VLANs and P rimary VLAN • Faul t de tect ion • Port monit oring (mir roring ) • System in formation • Enable/ Disable Mult ...

  • IronPort Systems 4108GL - page 60

    4-4 Using th e HP Web Brows er Interfa ce Web Br owser In terf ace Re quire ments Using th e HP Web Browser Interface W eb Browser Interface Requirements Y ou can use equip ment me eting the f ollowing requirem ents to a ccess the web browser interfac e on your in tranet . T able 4-1. Sy stem Requirements for Accessing the HP Web Browser Interface ...

  • IronPort Systems 4108GL - page 61

    4-5 Using the HP Web Brows er Interfa ce Starti ng an HP Web Browser Inte rface Session with t h e S witch Using the HP Web Browser Interface Starting an HP W eb Browser Interface Session with the Switch Y ou can start a web bro wser session in the following ways: ■ Using a standalon e web bro wser on a netw ork conne ction from a PC or UNIX work ...

  • IronPort Systems 4108GL - page 62

    4-6 Using th e HP Web Brows er Interfa ce Star ting an H P Web Brows er I nterfa ce Sess ion with the Swi tch Using th e HP Web Browser Interface 2. T ype the IP address (or DNS name) of the switch in the brow ser Locatio n or Add ress field an d press [Enter] . (It is not necessary to include http: // .) switch4108 [En ter] (exa mple of a DN S-typ ...

  • IronPort Systems 4108GL - page 63

    4-7 Using the HP Web Brows er Interfa ce Starti ng an HP Web Browser Inte rface Session with t h e S witch Using the HP Web Browser Interface 3. T he web bro wser interf ace automa tica lly s tart s with the Statu s Ove rvie w window displaye d for t he select ed devi ce, as sho wn in fig ure 4- 1. Note If the Registratio n windo w appears, cl ick ...

  • IronPort Systems 4108GL - page 64

    4-8 Using th e HP Web Brows er Interfa ce Tasks for Your Fi rst HP Web Browser I nterface Session Using th e HP Web Browser Interface T asks for Y our Firs t HP W eb Browser Interface Session The first ti me you acc ess the web browse r interfac e, there are three tasks that you should pe rform: ■ Revie w the “ First T ime Instal l ” window ? ...

  • IronPort Systems 4108GL - page 65

    4-9 Using the HP Web Brows er Interfa ce Task s for You r First H P Web Br owser In terfac e Sessi on Using the HP Web Browser Interface This wind ow is the launc hing point for the ba sic configur ation yo u need to perform t o set web browse r interfa ce passwords to maintain se curity an d Fault Detection polic y , which determines the t ypes of ...

  • IronPort Systems 4108GL - page 66

    4-10 Using th e HP Web Brows er Interfa ce Tasks for Your Fi rst HP Web Browser I nterface Session Using th e HP Web Browser Interface Figure 4-3. The Device Passwords Window T o set the passwords: 1. Acc ess the Device Pa sswords scree n by one of the f ollowing me thods: • If the Alert Lo g incl udes a “ First T ime Install ” ev ent ent ry ...

  • IronPort Systems 4108GL - page 67

    4-1 1 Using the HP Web Brows er Interfa ce Task s for You r First H P Web Br owser In terfac e Sessi on Using the HP Web Browser Interface Note Passwords you assign in the web br owser inter face will overwrite pr evious passwords assigned in either t he web browser interface , the Command Prompt, or t he switch con sole. Th at is, the most recentl ...

  • IronPort Systems 4108GL - page 68

    4-12 Using th e HP Web Brows er Interfa ce Tasks for Your Fi rst HP Web Browser I nterface Session Using th e HP Web Browser Interface If Y ou Lose a Password If you lose the pa sswords, you can cl ear the m by pressing the Clear butto n on the front o f the switc h. This action deletes all password and user name protection f rom all of the switch ...

  • IronPort Systems 4108GL - page 69

    4-1 3 Using the HP Web Brows er Interfa ce Suppor t/Mgmt URLs Featur e Using the HP Web Browser Interface Support/Mgmt URLs Feature The Suppor t/Mgmt UR Ls window enables you to cha nge the W orld Wide W eb Universal Re source Lo cator (U RL) for tw o functions: ■ Suppor t URL – a support infor mation site for your swi tch ■ Management S erve ...

  • IronPort Systems 4108GL - page 70

    4-14 Using th e HP Web Brows er Interfa ce Suppor t/Mg mt UR Ls Feat ure Using th e HP Web Browser Interface Support URL This is the site that the swi tch accesse s when you click on t he Support tab on the web br owser int erface. The defaul t URL is: http: //w ww.hp.com /go /proc urv e which is the W o rld W ide W eb site for Hewle tt-Packard ’ ...

  • IronPort Systems 4108GL - page 71

    4-1 5 Using the HP Web Brows er Interfa ce Suppor t/Mgmt URLs Featur e Using the HP Web Browser Interface ■ If you have W orld Wide W eb acces s from yo ur PC or wor kstation , and do not ha ve HP T opT ools inst alled o n your network, e nter the followi ng URL in the Mana gement Se rver URL field show n in figure 4-7 on pag e 4-15 : http: //w w ...

  • IronPort Systems 4108GL - page 72

    4-16 Using th e HP Web Brows er Interfa ce Stat us Repo rtin g Feature s Using th e HP Web Browser Interface Status Reporting Features Brows er el ements cover ed in this s ection incl ude: ■ The Overvi ew window (be low) ■ Port utilization and status (page 4-1 7) ■ The Al ert log ( page 4- 20) ■ The Sta tus bar (page 4 -23) The Overview W ...

  • IronPort Systems 4108GL - page 73

    4-1 7 Using the HP Web Brows er Interfa ce Status R eport ing Fe atures Using the HP Web Browser Interface The Port Utilization and Status Displa ys The Port Utili zation and Status displays show an overvi ew of the stat us of the switch and the amount of ne twork activ ity on each p ort. The follo wing figur e shows a sample readi ng of the Port U ...

  • IronPort Systems 4108GL - page 74

    4-18 Using th e HP Web Brows er Interfa ce Stat us Repo rtin g Feature s Using th e HP Web Browser Interface ■ Maximum Ac tivity Ind icato r: As the bars in the gr aph ar ea ch ange height to refl ect the level of network activi ty on the corresp onding port, they l eave an o utline t o identi fy the ma ximu m activity level that has b een observ ...

  • IronPort Systems 4108GL - page 75

    4-1 9 Using the HP Web Brows er Interfa ce Status R eport ing Fe atures Using the HP Web Browser Interface Port Sta tus Figure 4-12. The Po rt Status Indicator s and Lege nd The Port Stat us indicator s show a symbol for e ach port tha t indicates the general st atus of the por t. There ar e four possi ble statuses: ■ Port Conne cted – the port ...

  • IronPort Systems 4108GL - page 76

    4-20 Using th e HP Web Brows er Interfa ce Stat us Repo rtin g Feature s Using th e HP Web Browser Interface The Alert Log The web brow ser inte rface Alert Log, shown in the lower half of the scre en, shows a list of network occurrences, or alerts , that were d etected by the switch . T ypical alerts are B roadcas t Stor m , indicat ing an exce ss ...

  • IronPort Systems 4108GL - page 77

    4-2 1 Using the HP Web Brows er Interfa ce Status R eport ing Fe atures Using the HP Web Browser Interface Alert T ypes The follo wing table lists the t ypes of al erts that can be gener ated. T a ble 4-2. Alert S trings an d Descriptions Alert Stri ng Alert Descrip tion First T ime Install Importan t insta llation information for your s witch. T o ...

  • IronPort Systems 4108GL - page 78

    4-22 Using th e HP Web Brows er Interfa ce Stat us Repo rtin g Feature s Using th e HP Web Browser Interface Note When troubleshoo ting the sourc es of alerts, it may b e helpfu l to check the switch ’ s Port Status an d Port C ounter wind ows and th e Event Lo g in the consol e interfa ce. V iewing Detail Views of Al ert Log Entries By double cl ...

  • IronPort Systems 4108GL - page 79

    4-2 3 Using the HP Web Brows er Interfa ce Status R eport ing Fe atures Using the HP Web Browser Interface The Status Bar The Stat us Bar is displa yed in the up per lef t corner of the web browser interfa ce screen . Figure 4 -15 shows a n expand ed view o f the stat us bar . Figure 4-15. Example of th e Status Bar The Status ba r consists of f ou ...

  • IronPort Systems 4108GL - page 80

    4-24 Using th e HP Web Brows er Interfa ce Stat us Repo rtin g Feature s Using th e HP Web Browser Interface ■ Product Name. The produc t name of the sw itch to wh ich you ar e connec ted in the c urren t web brow ser interfa ce session . Setting Fault Detection Poli cy One of the po werful fe atures in t he web brow ser interf ace is the F ault ...

  • IronPort Systems 4108GL - page 81

    4-2 5 Using the HP Web Brows er Interfa ce Status R eport ing Fe atures Using the HP Web Browser Interface ■ High Se nsitivity . This policy directs the sw itch to sen d all ale rts to the Alert Lo g. This setting is m ost effect ive on netw orks that ha ve none or few problems. ■ Medium Sensitivi ty . This policy directs the swi tch to send al ...

  • IronPort Systems 4108GL - page 82

    4-26 Using th e HP Web Brows er Interfa ce Stat us Repo rtin g Feature s Using th e HP Web Browser Interface ...

  • IronPort Systems 4108GL - page 83

    5-1 Swi tch Mem ory and Confi gurati on 5 Switch Memory and Conf iguration Chapter Contents Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-2 Overview of Co nfiguration File Management . . . . . . . . . . . . . . . . . . . . . . . . 5-2 Using the CLI To Implement Configuration C ...

  • IronPort Systems 4108GL - page 84

    5-2 Switc h Memory an d Con figurat ion Overv iew Swi tch Mem ory and Confi gurati on Overview This chap ter describes: ■ How switch memory ma nages config uration changes ■ How t he CLI impl emen ts con figur atio n chan ges ■ How the men u interf ace an d web browse r interfa ce implem ent conf igu- ration change s ■ How the switc h provi ...

  • IronPort Systems 4108GL - page 85

    5-3 Switc h Memor y and Conf igur ation Overvie w of C onfigurati on Fil e Ma nagem ent Swi tch Mem ory and Confi gurati on ■ Running Co nfig File: Exists in volatile mem ory and contro ls switch operation . If no conf iguration change s have be en made in the CLI since the switch w as last booted, the r unning-co nfig file is identic al to the s ...

  • IronPort Systems 4108GL - page 86

    5-4 Switc h Memory an d Con figurat ion Using the CL I To Im pleme nt Conf iguration Change s Swi tch Mem ory and Confi gurati on "permanen t". When yo u are satisf ied that the change is satisfac tory , you can make it permanent by exec uting the write memory comman d. Fo r exam ple, suppose you use the followin g comma nd to disable po ...

  • IronPort Systems 4108GL - page 87

    5-5 Switc h Memor y and Conf igur ation Using the CL I To Im pleme nt Conf igura tion Ch ange s Swi tch Mem ory and Confi gurati on How T o Use the CLI T o Reconfigure Sw itch Feat ures. Use this proce- dure to pe rman ently chan ge th e swit ch confi gurat ion (t hat is, to ente r a cha nge in the st artup-co nfig fi le). 1. Use the appropr iate C ...

  • IronPort Systems 4108GL - page 88

    5-6 Switc h Memory an d Con figurat ion Using the CL I To Im pleme nt Conf iguration Change s Swi tch Mem ory and Confi gurati on ■ Manually e nter the ea rlier v alues y ou had f or the change d setting s. (Thi s is r ecomme nded if you wa nt t o rest ore a small numb er of para meter settings t o their prev ious boot-up values.) ■ Update th e ...

  • IronPort Systems 4108GL - page 89

    5-7 Switc h Memor y and Conf igur ation Using the Men u and Web B rows er Int erfaces To Im plement Conf igura tion Ch ange s Swi tch Mem ory and Confi gurati on from ei ther the C LI or the menu inte rface without fi rst exec uting th e write memory comman d in the CLI, the cur rent startup-co nfig file will repl ace the running-con fig file, and ...

  • IronPort Systems 4108GL - page 90

    5-8 Switc h Memory an d Con figurat ion Using t he Men u and We b Browse r Inte rface s To Imp lemen t Conf igurat ion Changes Swi tch Mem ory and Confi gurati on ■ Viewing several related configu ration para meters in the same screen, with their d efault an d curren t settings ■ Immedia tel y chan ging both th e ru nning-c onfi g file an d the ...

  • IronPort Systems 4108GL - page 91

    5-9 Switc h Memor y and Conf igur ation Using the Men u and Web B rows er Int erfaces To Im plement Conf igura tion Ch ange s Swi tch Mem ory and Confi gurati on Figure 5-3. Exampl e of Pendin g Configur ation Changes tha t Can Be Saved or Cancelled Note If you reconfigur e a para meter in th e CLI and then go to t he menu in terface with out exec ...

  • IronPort Systems 4108GL - page 92

    5-10 Switc h Memory an d Con figurat ion Using t he Men u and We b Browse r Inte rface s To Imp lemen t Conf igurat ion Changes Swi tch Mem ory and Confi gurati on Figure 5-4. The Reboot Switch Option in the Main Menu Rebooting T o Act ivate Configu ration Changes. Configuration c hanges for most par ameters bec ome effect ive as soon a s you save ...

  • IronPort Systems 4108GL - page 93

    5-11 Switc h Memor y and Conf igur ation Using Primary and Seco ndary Fl ash Imag e Options Swi tch Mem ory and Confi gurati on Figure 5-5. Indication of a Con figuration Change Re quiring a Re boot Using the W eb Browser Interface T o Implement Configuration Changes Y ou can us e the we b bro wser inter face t o simulta neously sa ve and imple men ...

  • IronPort Systems 4108GL - page 94

    5-12 Switc h Memory an d Con figurat ion Using P rimar y and Secon dary Fl ash Image Option s Swi tch Mem ory and Confi gurati on ■ Primary Flash: The default stora ge for OS (syste m image) fi les. ■ Seco ndary F lash: The addit ional storage fo r either a redunda nt or an alter nate OS (s ystem imag e) fil e. W ith the Pr imary /Second ary fl ...

  • IronPort Systems 4108GL - page 95

    5-13 Switc h Memor y and Conf igur ation Using Primary and Seco ndary Fl ash Imag e Options Swi tch Mem ory and Confi gurati on Figure 5-6. Example Showing the I dentity of the Curre nt Flash Image Determini ng Whethe r the F lash Imag es Are Differen t V ersions. If the flash i mage sizes i n primary and secondary are the same, t hen in almo st ev ...

  • IronPort Systems 4108GL - page 96

    5-14 Switc h Memory an d Con figurat ion Using P rimar y and Secon dary Fl ash Image Option s Swi tch Mem ory and Confi gurati on Figure 5-8. Determining th e OS Version in Primary an d Secondar y Flash OS Downloads The followin g table shows the swi tch ’ s options f or download ing an OS t o flash and boot ing the sw itch from f lash T able 5-1 ...

  • IronPort Systems 4108GL - page 97

    5-15 Switc h Memor y and Conf igur ation Using Primary and Seco ndary Fl ash Imag e Options Swi tch Mem ory and Confi gurati on Local OS Repl acemen t and Rem oval This sectio n describe s comman ds for era sing an OS (flash ima ge) an d copying an ex isti ng OS be tween prim ary and sec ondar y flas h. Note It is not necessar y to erase the con te ...

  • IronPort Systems 4108GL - page 98

    5-16 Switc h Memory an d Con figurat ion Using P rimar y and Secon dary Fl ash Image Option s Swi tch Mem ory and Confi gurati on 1. V erify that there i s a vali d flas h imag e in the secon dary flas h locati on. Th e follow in g figur e in dicate s th at an O S imag e is p resen t in second ary f lash. (If you are un sure wheth er th e imag e is ...

  • IronPort Systems 4108GL - page 99

    5-17 Switc h Memor y and Conf igur ation Using Primary and Seco ndary Fl ash Imag e Options Swi tch Mem ory and Confi gurati on Figure 5-10. Example of Erase Flash Prompt 3. T ype y at the prompt to com plete the fl ash er ase. 4. U se show flash to ver ify erasu re of the s e lected OS flash i mage Figure 5-11. Example of Show Flash Listing After ...

  • IronPort Systems 4108GL - page 100

    5-18 Switc h Memory an d Con figurat ion Using P rimar y and Secon dary Fl ash Image Option s Swi tch Mem ory and Confi gurati on Booting from Pr imary Fl ash. This comm and al ways boots t he switch fro m primar y flash, and exec utes the complete set of subsystem self-t ests. Synta x: boo t For exam ple, to boot t he switch fro m primar y flash w ...

  • IronPort Systems 4108GL - page 101

    5-19 Switc h Memor y and Conf igur ation Using Primary and Seco ndary Fl ash Imag e Options Swi tch Mem ory and Confi gurati on Booting from t he Curr ent OS V ers ion. Reload reboots the switch from the fl ash im age o n whic h the s witc h is cu rrent ly run ning, and sa ves to th e startup-c onfig file a ny config uratio n ch anges c urrent ly i ...

  • IronPort Systems 4108GL - page 102

    5-20 Switc h Memory an d Con figurat ion Using P rimar y and Secon dary Fl ash Image Option s Swi tch Mem ory and Confi gurati on while usin g a vers ion "Y" of th e OS, an d then rebo ot the swit ch wit h an earlie r OS version "X" that does not include a ll of the feat ures foun d in "Y", the OS simply igno res the p ...

  • IronPort Systems 4108GL - page 103

    6-1 Inte rfac e Ac cess and System In formation 6 Interface Access and Syste m Information Chapter Contents Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-2 Interface Ac cess: Console/Serial Link, Web, and Inbound Telnet . . . . . . . 6-3 Menu: Modifying the Interface Access . ...

  • IronPort Systems 4108GL - page 104

    6-2 Interf ace Acce ss and Sys tem Inform ation Overv iew Interf ace Access and System Information Overview This chapte r describ es how t o view and m odify the conf igur atio n for swit ch interf ace access and sw itch system inform atio n . For help on ho w to act ually use th e in terf aces bui lt in to th e swi tch , refe r to: ■ Chap ter 2 ...

  • IronPort Systems 4108GL - page 105

    6-3 Interfa ce Access and Sy stem Informatio n Inte rfac e Acce ss: Co nsole /Ser ial Link, We b, and Inbo und Teln et Inte rfac e Ac cess and System In formation Interface Access: Console/Serial Link, W eb, and Inbound T elnet Interf ace Access Feature s In most cases, the d efault c onfigur ation is a ccept able for sta ndard operat ion. Note Bas ...

  • IronPort Systems 4108GL - page 106

    6-4 Interf ace Acce ss and Sys tem Inform ation Inter face Ac cess: Conso le/Ser ial Li nk, Web, a nd Inbo und Te lnet Interf ace Access and System Information Menu: Modifying the Interface Ac cess The menu int erface en ables y ou to modify these para meters: ■ Inactivi ty T imeout ■ Inbound T elnet E nabled ■ We b A g e n t E n a b l e d T ...

  • IronPort Systems 4108GL - page 107

    6-5 Interfa ce Access and Sy stem Informatio n Inte rfac e Acce ss: Co nsole /Ser ial Link, We b, and Inbo und Teln et Inte rfac e Ac cess and System In formation CLI: Modifying the Interface Access Interface Access Commands Used in This Section Listing t he Current Co nsole/Serial L ink Configura tion. This com- mand lists the current interface a ...

  • IronPort Systems 4108GL - page 108

    6-6 Interf ace Acce ss and Sys tem Inform ation Inter face Ac cess: Conso le/Ser ial Li nk, Web, a nd Inbo und Te lnet Interf ace Access and System Information Recon figure W eb Brow ser Acc ess. In t he d efaul t co nfig urat ion , web brows er acce ss is en able d. Synta x: [ no] we b-manag ement T o disable web browser a ccess: HP4108(config)# n ...

  • IronPort Systems 4108GL - page 109

    6-7 Interfa ce Access and Sy stem Informatio n Inte rfac e Acce ss: Co nsole /Ser ial Link, We b, and Inbo und Teln et Inte rfac e Ac cess and System In formation Figur e 6-3 . Examp le of Ex ecu ting th e Cons ole C omman d wit h Mult ipl e Param ete rs Y ou can also exec ute a series of console c ommands and t hen save th e configu ration and bo ...

  • IronPort Systems 4108GL - page 110

    6-8 Interf ace Acce ss and Sys tem Inform ation System In formation Interf ace Access and System Information System Information Sy stem Information Features Config uring system information is optional , but recom mended. System N ame: Usin g a unique na me helps yo u to identif y individual de vices in stackin g environ ments and wher e you are us ...

  • IronPort Systems 4108GL - page 111

    6-9 Interfa ce Access and Sy stem Informatio n System Info rmatio n Inte rfac e Ac cess and System In formation T i me Zone: The numbe r of minu tes yo ur t ime z one locat ion is to the W est (+) or East (-) of Coordina ted Univer sal T ime (for merly GMT) . The default 0 means no time zone is conf igured. Daylight T ime Rule: Specifies t he day l ...

  • IronPort Systems 4108GL - page 112

    6-10 Interf ace Acce ss and Sys tem Inform ation System In formation Interf ace Access and System Information 3. Ref er to the online help prov ided with t his screen f or further inf ormatio n on configur ation opt ions for t hese feat ures. 4. When you h ave finish ed makin g changes to th e above pa rame ters, press [Ent er] , then press [S] (fo ...

  • IronPort Systems 4108GL - page 113

    6-11 Interfa ce Access and Sy stem Informatio n System Info rmatio n Inte rfac e Ac cess and System In formation Configure a System Name, Co ntact, and Location f or the Swit ch. To help distin guish one sw itch from anot her , conf igure a plain-lan guage iden tity for the sw itch. Synta x: host nam e <name-strin g> snmp-server [ contact < ...

  • IronPort Systems 4108GL - page 114

    6-12 Interf ace Acce ss and Sys tem Inform ation System In formation Interf ace Access and System Information Recon figure t he Age Int erval f or Learn ed MAC Addresses . This com- mand corre sponds to th e MAC Age I nterval in the menu int erface, and is expressed in se conds. Synta x: mac-ag e-time < 10 . . 1000000> (seconds) For exam ple, ...

  • IronPort Systems 4108GL - page 115

    6-13 Interfa ce Access and Sy stem Informatio n System Info rmatio n Inte rfac e Ac cess and System In formation W eb: Confi guring System Parameters In the web bro wser inter face, yo u can en ter the followin g system in formati on: ■ System Name ■ System L ocation ■ System Co ntact For acc ess to the M AC Age Inte rval and the T ime para m ...

  • IronPort Systems 4108GL - page 116

    6-14 Interf ace Acce ss and Sys tem Inform ation System In formation Interf ace Access and System Information ...

  • IronPort Systems 4108GL - page 117

    7-1 Configuring IP Addressin g 7 Configuri ng IP Addressing Contents Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-2 IP Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-3 Just Want a Quick Start? . . . . . . . . . ...

  • IronPort Systems 4108GL - page 118

    7-2 Config uring IP Addre ssing Overv iew Configuring IP Addressing Overview This chapter describ es the switch conf iguration features availabl e in the menu interfac e, CLI an d web browse r interface . For help on how t o use these interfa ces, refer to: ■ Chap ter 2 , “ Using the Menu Interfa ce ” ■ Chap ter 3 , “ Using the Command L ...

  • IronPort Systems 4108GL - page 119

    7-3 Con figur ing IP Addre ssing IP Configu ratio n Configuring IP Addressin g IP Configuration IP Configur ation Featur es IP Ad dress and Subne t Ma sk. Con figuring the switch with an IP address expands your ab ility to manage the switch and use its features . By default, the switch is configur ed to autom atically rece ive IP addre ssing on the ...

  • IronPort Systems 4108GL - page 120

    7-4 Config uring IP Addre ssing IP Confi gurat ion Configuring IP Addressing Just W ant a Quick Start? If you just want to give the switch an IP add ress so that it can c ommunica te on your n etwor k, or if yo u are not u sing VLA Ns, HP reco mmen ds that you use the Swit ch Set up screen to quic kly confi gure IP a ddressing. T o do so, do o ne o ...

  • IronPort Systems 4108GL - page 121

    7-5 Con figur ing IP Addre ssing IP Configu ratio n Configuring IP Addressin g ■ If you change th e IP add ress through either T elnet acce ss or the web browser interface, the connect ion to the sw itch wi ll be lost. Y ou can reconn ect by eith er restart ing T elnet with the n ew IP addr ess or enter ing the new addr ess as the URL in y our we ...

  • IronPort Systems 4108GL - page 122

    7-6 Config uring IP Addre ssing IP Confi gurat ion Configuring IP Addressing Figure 5-1. Example of the IP Servic e Configura tion Screen with out Multiple VLANs Con figured 2. Press [E] (for E dit ). 3. If the sw itch need s to acce ss a rout er , for e xample, to reach o ff-subnet destinations, s elec t the Default Gateway field and e nter th e I ...

  • IronPort Systems 4108GL - page 123

    7-7 Con figur ing IP Addre ssing IP Configu ratio n Configuring IP Addressin g CLI: Configuring IP Address , Gateway , T ime-T o-Live (TTL), and T imep IP Comman ds Used in This Secti on For a listing of the full CLI command set, including synt ax and opt ions, see the CL I comma nd re ferenc e avai labl e on th e HP Pro curv e webs ite at : http: ...

  • IronPort Systems 4108GL - page 124

    7-8 Config uring IP Addre ssing IP Confi gurat ion Configuring IP Addressing Figure 5-3. Example o f Show I P Listing with Non-Defa ult IP Addre ssing Confi gured Conf igur e an IP Addr ess an d Subnet Mask. The following command includes both the IP ad dress and the subnet mask . Y ou must e ither inc lude th e ID of the VL AN for whi ch you are c ...

  • IronPort Systems 4108GL - page 125

    7-9 Con figur ing IP Addre ssing IP Configu ratio n Configuring IP Addressin g Configure T ime-T o-Live (TTL). Use thi s comm and at t he Globa l config prompt to se t the time that a packet o utbound from the switch can exist on the netwo rk. The defa ult setting is 64 seconds. Synta x: ip t tl <number -of-seconds> HP4108(config)# ip ttl 60 ...

  • IronPort Systems 4108GL - page 126

    7-10 Config uring IP Addre ssing IP Confi gurat ion Configuring IP Addressing T able 7-1. Featur es A vailable With and Without IP Addressin g on the Switch DHCP/Bootp Op eration Overview . DHCP/Boot p is used to provi de confi guration dat a from a DH CP or Bootp server to the sw itch. This d ata can b e the I P addre ss, subnet m ask, defau lt ga ...

  • IronPort Systems 4108GL - page 127

    7-11 Con figur ing IP Addre ssing IP Configu ratio n Configuring IP Addressin g 1. DHC P/Boot p request s are a utomatic ally br oadcast on t he local ne twork. (The switch sends one type of request to which eithe r a DHCP or Bo otp server c an re spond.) 2. When a DHCP or Bo otp serv er rece ives the request, it repl ies with a previou sly config ...

  • IronPort Systems 4108GL - page 128

    7-12 Config uring IP Addre ssing IP Confi gurat ion Configuring IP Addressing Bootp O perati on. When a Boo tp server r eceives a r equest it se arches its Bootp da tabase for a re cord ent ry that matc hes the MAC ad dress in the B ootp request from the sw itch. If a m atch is found , the co nfigurat ion data in the asso ciat ed dat abas e record ...

  • IronPort Systems 4108GL - page 129

    7-13 Con figur ing IP Addre ssing IP Configu ratio n Configuring IP Addressin g Note The a b ove Bo otp tab le entry i s a sampl e that wi ll work for the Switc h 4108GL when the a ppropriate addresses an d file nam es are used. Networ k Preparations for Config uring DHCP/Bo otp In its default co nfiguration, t he switch is config ured for DHCP/B o ...

  • IronPort Systems 4108GL - page 130

    7-14 Config uring IP Addre ssing IP Confi gurat ion Configuring IP Addressing Globally A ssigned IP Network Addr esses If you intend to conne ct your net work to ot her networ ks that use g lobally admin ister ed IP ad dresse s, Hewl ett-Pa ckar d stron gly rec ommen ds that y ou use IP addresse s that hav e a network ad dress assign ed to you . Th ...

  • IronPort Systems 4108GL - page 131

    8-1 Time Pro tocol s 8 T i me Protocol s Chapter Contents Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-2 TimeP Time Synchronization . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8- 2 SNTP Time Synchronization . . . . . . . . . . . . . . . . . . . . . . . ...

  • IronPort Systems 4108GL - page 132

    8-2 Time Prot ocols Overv iew Time Pr otocol s Overview This chap ter describes: ■ SNTP T ime Protocol Ope ration ■ T imep Time Protocol Oper ation Using time syn chron ization en sures a unif orm time amo ng inter operating device s. This helps you to ma nage and t roubleshoo t switch ope ration by attachin g meanin gful ti me data to event an ...

  • IronPort Systems 4108GL - page 133

    8-3 Time Prot ocols Overvi ew: Se lecti ng a Tim e Synch roniza tion P rotoc ol or Tur ning O ff Time P rotoc ol Oper ation Time Pro tocol s ular server , it ignores time bro adcasts fro m other SNTP ser vers unless the conf igurab le Poll Interval ex pires thr ee consec utive t imes withou t an upda te recei ved fr om the first-det ected ser ver . ...

  • IronPort Systems 4108GL - page 134

    8-4 Time Prot ocols SNTP: View ing, Select ing, and Conf iguri ng Time Pr otocol s Note that simp ly selecting a time synchro nization prot ocol does n ot enable that p rotocol on t he switch unless y ou also en able the protoc ol itself (step 2 , above) . For exam ple, in t he factor y-default configur ation , T im eP is the selected time synchro ...

  • IronPort Systems 4108GL - page 135

    8-5 Time Prot ocols SNTP : Vie wing, Select ing, and Conf iguri ng Time Pro tocol s T able 8-1.SNTP Parameters Menu: V i ewing and Con figuring SNTP T o V iew , Enable, and Modify SNTP Time Protocol: 1. From the Main Menu, s elect: 2. Switch Co nfigur ation... 1. Sy stem Information SNTP P ara meter Op erat ion Ti m e S y n c Meth od Used to sel ec ...

  • IronPort Systems 4108GL - page 136

    8-6 Time Prot ocols SNTP: View ing, Select ing, and Conf iguri ng Time Pr otocol s Figure 8-4. Th e Sy stem Infor mation Scre en (Default Values) 2. Press [E] (for E di t ). The cursor moves to the Sy st em N ame field. 3. Use [v] to mov e th e cu rsor to th e T ime S ync Me thod field. 4. Use the Space bar to select SN TP , then pre ss [v] once to ...

  • IronPort Systems 4108GL - page 137

    8-7 Time Prot ocols SNTP : Vie wing, Select ing, and Conf iguri ng Time Pro tocol s ii. Enter the IP address of the S NTP server you w ant the swit ch to use for time synchron ization . Note: Thi s step repla ces an y pre viousl y conf igure d serv er IP address. If you will be using backup SNTP se rvers (requ ires use of the CLI), then see “ SNT ...

  • IronPort Systems 4108GL - page 138

    8-8 Time Prot ocols SNTP: View ing, Select ing, and Conf iguri ng Time Pr otocol s CLI: Vi ewing and Confi guring SNTP CLI Comman ds Descri bed in this Sect ion This sectio n describes h ow to use the CLI to view , enable, a nd confi gure SNTP paramet ers. V iewing the Current SNTP Co nfigura tion This comman d lists both the time synchroniza tion ...

  • IronPort Systems 4108GL - page 139

    8-9 Time Prot ocols SNTP : Vie wing, Select ing, and Conf iguri ng Time Pro tocol s Figure 8-6. Exa mple of SNTP Config uration Wh en SNTP Is No t the Select ed T ime Synch roniz ation Met hod Configuring (Enabling o r Disabling) the SNTP M ode Enabling the SNT P mode me ans to co nfigure it for eit her broa dcast o r unicast mode. Re member that t ...

  • IronPort Systems 4108GL - page 140

    8-10 Time Prot ocols SNTP: View ing, Select ing, and Conf iguri ng Time Pr otocol s 3. Enable SNTP for Broad cast mode. 4. View the SNTP configuration again to verify the configuration. The comma nds and output would ap pear as follow s: Figure 8-7. Example of Ena bling SNTP Operati on in Broadca st Mode Enabling SNTP in Unicast Mode. Like br oadca ...

  • IronPort Systems 4108GL - page 141

    8-11 Time Prot ocols SNTP : Vie wing, Select ing, and Conf iguri ng Time Pro tocol s For ex ample, to sele ct SNTP an d confi gure it w ith uni cast mo de a nd an S NTP server at 10.28.22 7.14 1 with the default se rver ve rsion (3) a nd defau lt poll interva l (720 seconds): HP4108(config)# timesync sntp Selects SNTP. HP4108(config)# sntp unicast ...

  • IronPort Systems 4108GL - page 142

    8-12 Time Prot ocols SNTP: View ing, Select ing, and Conf iguri ng Time Pr otocol s Changing t he SNTP Poll In terval. This command lets you sp ecify how long the switch w aits between t ime polling int ervals. The de fault is 720 seco nds an d the ra nge is 30 to 720 se conds . (Thi s para meter is sep arate from the poll in terval pa rameter u se ...

  • IronPort Systems 4108GL - page 143

    8-13 Time Prot ocols TimeP : Vie wing, Select ing, and Conf igurin g Time Pro tocol s Figure 8-11. Exa mple of Disabli ng T ime Sy nchroniza tion by Di sabling the SNT P Mode T imeP: V iewing, Selecting, and Configuring Even tho ugh the T im e Sync M ode is set to Snt p , time syn chronizat ion is disabl ed becaus e no sntp has dis abled the SNTP M ...

  • IronPort Systems 4108GL - page 144

    8-14 Time Prot ocols TimeP: Viewing , Select ing , and Con figur ing Time Pr otocol s T able 8-2.T imep Parameters Menu: V i ewing and Con figuring T imeP T o V iew , Enable, and Modif y the T imeP Pr otoc ol: 1. From the Main Menu, s elect: 2. Switch Co nfigur ation... 1. Sy stem Information SNTP P ara meter Op erat ion Ti m e S y n c Meth od Used ...

  • IronPort Systems 4108GL - page 145

    8-15 Time Prot ocols TimeP : Vie wing, Select ing, and Conf igurin g Time Pro tocol s Figure 8-12. The Sy stem In formation S creen (Defa ult Va lues) 2. Press [E] (for E di t ). The cursor moves to the Sy st em N ame field. 3. Use [v] to mov e th e cu rsor to th e T ime S ync Me thod field. 4. If TIMEP is not already selected, use the Space bar to ...

  • IronPort Systems 4108GL - page 146

    8-16 Time Prot ocols TimeP: Viewing , Select ing , and Con figur ing Time Pr otocol s Note: This ste p replaces a ny previousl y configur ed T imeP serv er IP addr ess. iii. Press [>] to move the cursor to the Poll Interv al field, then go to step 6. 6. In the Poll Interval field, enter the time i n minutes that you want for a T imeP Poll Interv ...

  • IronPort Systems 4108GL - page 147

    8-17 Time Prot ocols TimeP : Vie wing, Select ing, and Conf igurin g Time Pro tocol s For examp le, if you c onfigure t he switch wit h T imeP as th e time sync hroniza- tion method , then enable TimeP in DHCP mode with the default poll interv al, show tim ep lists the followin g: Figure 8-13. Exa mple of T imeP C onfigura tion When T imeP Is the S ...

  • IronPort Systems 4108GL - page 148

    8-18 Time Prot ocols TimeP: Viewing , Select ing , and Con figur ing Time Pr otocol s For exam ple, su ppose: ■ T ime synchronizatio n is configured for SN TP . ■ Y ou want to: 1.V iew the current time synchron ization. 2.Select T imeP as the time synchroniz ation mode. 3.En ab le TimeP for DHCP mod e. 4.View the T imeP configuration. The comma ...

  • IronPort Systems 4108GL - page 149

    8-19 Time Prot ocols TimeP : Vie wing, Select ing, and Conf igurin g Time Pro tocol s For ex ample, to sele ct T imeP and co nfigu re it fo r manu al op eratio n using a T imeP server addr ess of 10.28.2 27.141 and t he default poll interval (72 0 minutes, assu ming the T imeP pol l interval is alre ady set to the defau lt): HP4108(config)# timesyn ...

  • IronPort Systems 4108GL - page 150

    8-20 Time Prot ocols SNTP Unicas t Time P o lling with Multiple SNTP Servers Time Pr otocol s If you then v iewed the TimeP con figuratio n, you would see the follo wing: Figure 8-17. Exa mple of T imeP wit h T ime Sy chronizat ion Disa bled Disa bling t he T imeP Mo de. Disablin g the TimeP m ode m eans to conf igure it as disabled. (Disa bling T ...

  • IronPort Systems 4108GL - page 151

    8-21 Time Prot ocols SNTP Unic ast Ti me Pol ling w ith Mu ltiple S NTP Serv ers Time Pro tocol s all servers in the list without success, it sends an er ror message to the Event Log and re schedule s to try the a ddress list ag ain afte r the config ured Poll Interval time has exp ired. Address Prioritiz ation If you u se the CL I to configu re mu ...

  • IronPort Systems 4108GL - page 152

    8-22 Time Prot ocols SNTP Unicas t Time P o lling with Multiple SNTP Servers Time Pr otocol s Figure 8-19. Example o f SNTP Server Add ress Prioritiza tion Note If ther e are alr eady th ree SNTP ser ver addr esses conf igured on the switch , and you w ant to use the CLI t o replace on e of the exi sting addre sses with a new on e, you m ust d elet ...

  • IronPort Systems 4108GL - page 153

    8-23 Time Prot ocols SNTP Messa ges in the Event Log Time Pro tocol s Menu Interface Operation with Multiple SNTP Server Ad dresses Configu red When you u se the Men u interf ace to co nfigure a n SNTP server IP address, th e new addr ess writes over t he curre nt primary address, if one is c onfigure d. If there are multiple a ddresses configured, ...

  • IronPort Systems 4108GL - page 154

    8-24 Time Prot ocols SNTP Messa ges in the Event Log Time Pr otocol s ...

  • IronPort Systems 4108GL - page 155

    9-1 Using Passwords and TACA CS+ 9 Using Passwords and T ACACS+ T o Protect Against Unauthorized Access Contents Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-2 Configuring U sername and Password Securi ty . . . . . . . . . . . . . . . . . . 9-3 Menu: Configuring Passwords . . . ...

  • IronPort Systems 4108GL - page 156

    9-2 Using Password s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess Overv iew Using Pa sswords a nd TACACS + Overview This chapter describes:. ■ Manager a nd Oper ator passw ords Control access an d privi leges for the com mand lin e and men u inter- faces (throu gh eithe r the co nsole port or T elnet) and the web browse r interfa ce t ...

  • IronPort Systems 4108GL - page 157

    9-3 Using P assword s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess Conf iguring Userna me and Pa ssword Se curity Using Passwords and TACA CS+ • If inco rrec t passw ords ar e ent ered, the T A CAC S+ serve r den ies access to the switch. • If T ACAC S+ is not configure d or the T ACACS+ ser ver is not ac cessi- ble, the swit ch use ...

  • IronPort Systems 4108GL - page 158

    9-4 Using Password s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess Conf iguring Userna me and Pass wor d Security Using Pa sswords a nd TACACS + Note Usernames are option al. Also, in the me nu inte rface an d CLI, you c an config - ure password s, but not use rnames. T o configu re userna mes, use the web browser inter face. T o configu ...

  • IronPort Systems 4108GL - page 159

    9-5 Using P assword s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess Conf iguring Userna me and Pa ssword Se curity Using Passwords and TACA CS+ If the switch has a p assword for bo th the Mana ger and Ope rator lev els, and neithe r is en tere d corr ectly d uring a logo n att empt, a cces s to th e con sole will be denied. If the switch ...

  • IronPort Systems 4108GL - page 160

    9-6 Using Password s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess Conf iguring Userna me and Pass wor d Security Using Pa sswords a nd TACACS + c. Whe n prompted wi th Ente r new password ag ain , retyp e the new pass- word and press [Enter ] . After yo u config ure a passwor d, if you subsequ ently start a ne w console session, you wil ...

  • IronPort Systems 4108GL - page 161

    9-7 Using P assword s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess Conf iguring Userna me and Pa ssword Se curity Using Passwords and TACA CS+ no pass word T o Delete Passwor d Protec tion. This c ommand pro mpts you t o veri fy that you wa nt to clea r the p asswords, t hen cle ars them f rom bo th the Ma nager and Operator lev els. (I ...

  • IronPort Systems 4108GL - page 162

    9-8 Using Password s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ Authentic atio n for Central Co ntrol of Switch Acce ss Security Using Pa sswords a nd TACACS + T ACACS+ Authentication for Central Control of Switch Access Security T ACA CS+ F eatu res T ACA CS+ au then tica tion enab les yo u to u se a centra l serv er t o all ...

  • IronPort Systems 4108GL - page 163

    9-9 Using P assword s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ A uthe ntica tio n for Ce ntral Cont rol o f Sw itch Acc ess S ecuri ty Using Passwords and TACA CS+ T ACACS+ in t he Switch 41 08GL manages au thentic ation of log on attempts through eit her the Co nsole port or T elnet. T ACACS + uses an authe ntication hiera ...

  • IronPort Systems 4108GL - page 164

    9-10 Using Password s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ Authentic atio n for Central Co ntrol of Switch Acce ss Security Using Pa sswords a nd TACACS + ■ Auth entic ation: The proc ess for granting u ser acce ss to a de vice throug h entry o f a user name and password a nd compa rison of this username/p assword pai ...

  • IronPort Systems 4108GL - page 165

    9-11 Using P assword s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ A uthe ntica tio n for Ce ntral Cont rol o f Sw itch Acc ess S ecuri ty Using Passwords and TACA CS+ Notes The eff ectivene ss of TACACS+ se curity depend s on correc tly using your TACAC S+ se rver ap plicat ion. For th is rea son, HP re comm ends that y ou th ...

  • IronPort Systems 4108GL - page 166

    9-12 Using Password s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ Authentic atio n for Central Co ntrol of Switch Acce ss Security Using Pa sswords a nd TACACS + 2. Determine the following: 3. Plan and enter the T ACACS+ server configuration needed to suppo rt T ACACS+ operation for T elnet access (login and enable) to the swi ...

  • IronPort Systems 4108GL - page 167

    9-13 Using P assword s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ A uthe ntica tio n for Ce ntral Cont rol o f Sw itch Acc ess S ecuri ty Using Passwords and TACA CS+ 4. Ensure that the switch has the correct local username and password for Manager access. (If the switch cannot find any designated T ACACS+ servers, the local ...

  • IronPort Systems 4108GL - page 168

    9-14 Using Password s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ Authentic atio n for Central Co ntrol of Switch Acce ss Security Using Pa sswords a nd TACACS + Configur ing T ACACS+ on the Swi tch Before Y ou Begin If you are new t o T ACACS+ au thenticat ion, HP r ecommend s that yo u read the “ General Authen ticatio n S ...

  • IronPort Systems 4108GL - page 169

    9-15 Using P assword s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ A uthe ntica tio n for Ce ntral Cont rol o f Sw itch Acc ess S ecuri ty Using Passwords and TACA CS+ This example show s the default authentica tion confi guration. Figure 9-5. Examp le Listing of the Switch ’ s Authentication Configuration V iewing the Switc ...

  • IronPort Systems 4108GL - page 170

    9-16 Using Password s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ Authentic atio n for Central Co ntrol of Switch Acce ss Security Using Pa sswords a nd TACACS + Configu ring the Switch ’ s Authentication Method s The aaa au thent ication comma nd configur es the acc ess control fo r console port and T elnet a ccess to the s ...

  • IronPort Systems 4108GL - page 171

    9-17 Using P assword s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ A uthe ntica tio n for Ce ntral Cont rol o f Sw itch Acc ess S ecuri ty Using Passwords and TACA CS+ T abl e 9-3. Primary/Secondary Aut hentica tion T abl e Caut ion Regard ing th e Use of Loca l for Login Primary Acce ss During loc al auth entica tion (w hich ...

  • IronPort Systems 4108GL - page 172

    9-18 Using Password s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ Authentic atio n for Central Co ntrol of Switch Acce ss Security Using Pa sswords a nd TACACS + For examp le, here is a set of access option s and the co rrespondi ng comma nds to conf igure t hem: Cons ole Logi n (Opera tor , or Read -Only) Access: Prima ry usi ...

  • IronPort Systems 4108GL - page 173

    9-19 Using P assword s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ A uthe ntica tio n for Ce ntral Cont rol o f Sw itch Acc ess S ecuri ty Using Passwords and TACA CS+ Configurin g the Switch ’ s T ACAC S+ Server Access The tacacs- serve r command configu res these para meters: ■ The hos t IP a ddr ess( es) for up to t hre ...

  • IronPort Systems 4108GL - page 174

    9-20 Using Password s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ Authentic atio n for Central Co ntrol of Switch Acce ss Security Using Pa sswords a nd TACACS + Synta x: t acacs-se rver host < ip-addr > Adds a TACACS + server and option ally [key <k ey-strin g>] ass igns a ser ver-specific en cryp tion key. [no] t ...

  • IronPort Systems 4108GL - page 175

    9-21 Using P assword s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ A uthe ntica tio n for Ce ntral Cont rol o f Sw itch Acc ess S ecuri ty Using Passwords and TACA CS+ Name Defaul t Rang e host < ip-addr > [key < key-s tri ng > none n/ a Specif ies the IP addres s of a devic e runn ing a T ACACS+ s erve r appl icat ...

  • IronPort Systems 4108GL - page 176

    9-22 Using Password s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ Authentic atio n for Central Co ntrol of Switch Acce ss Security Using Pa sswords a nd TACACS + Adding, Removing, or C hanging the Pr iority o f a T ACACS+ Se rver . Suppos e that the sw itch wa s already c onfig ured to u se T ACACS + servers at 10.2 8.227 .10 ...

  • IronPort Systems 4108GL - page 177

    9-23 Using P assword s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ A uthe ntica tio n for Ce ntral Cont rol o f Sw itch Acc ess S ecuri ty Using Passwords and TACA CS+ T o r emove t he 10.28 .227.15 device as a T ACACS+ se rver , yo u would use thi s comm and: HP4108(config)# no tacacs-server host 10.28.227.15 Configuring an E ...

  • IronPort Systems 4108GL - page 178

    9-24 Using Password s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ Authentic atio n for Central Co ntrol of Switch Acce ss Security Using Pa sswords a nd TACACS + Configuring the T imeout Period . The timeout perio d specifies ho w long the swi tch wait s for a r esponse to an au then tication r equest from a T ACA CS+ server b ...

  • IronPort Systems 4108GL - page 179

    9-25 Using P assword s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ A uthe ntica tio n for Ce ntral Cont rol o f Sw itch Acc ess S ecuri ty Using Passwords and TACA CS+ then it uses its o wn local use rname/p assword pairs t o authent i- cate the l ogon requ est. (See " Local Authen tication Process", on page 25.) • ...

  • IronPort Systems 4108GL - page 180

    9-26 Using Password s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ Authentic atio n for Central Co ntrol of Switch Acce ss Security Using Pa sswords a nd TACACS + For lo cal au then tica tion, t he swit ch uses t he ope rator -leve l and ma nager-level username/p assword set (s) previously configure d locally on t he switch. (T ...

  • IronPort Systems 4108GL - page 181

    9-27 Using P assword s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ A uthe ntica tio n for Ce ntral Cont rol o f Sw itch Acc ess S ecuri ty Using Passwords and TACA CS+ Note Configure a key in the switc h only if the T A CACS+ ser ver applic ation has this exact same key co nfigured for the switch. That is, if t he key paramete ...

  • IronPort Systems 4108GL - page 182

    9-28 Using Password s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ Authentic atio n for Central Co ntrol of Switch Acce ss Security Using Pa sswords a nd TACACS + Controlling W eb Browser Interface Access When Using T A CACS+ Authenti cation In r elea se G.01 . xx , configurin g the switch fo r T ACACS+ auth enticati on does no ...

  • IronPort Systems 4108GL - page 183

    9-29 Using P assword s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ A uthe ntica tio n for Ce ntral Cont rol o f Sw itch Acc ess S ecuri ty Using Passwords and TACA CS+ Operating N otes ■ If you configur e Authorize d IP Managers on t he switch, it is not necessary to include an y devices use d as T ACACS+ se rvers in the aut ...

  • IronPort Systems 4108GL - page 184

    9-30 Using Password s and TAC ACS+ To Prote ct Agains t Una uthor ized Ac cess TACA CS+ Authentic atio n for Central Co ntrol of Switch Acce ss Security Using Pa sswords a nd TACACS + ...

  • IronPort Systems 4108GL - page 185

    10-1 Using Authorize IP Manag ers 10 Using Authorized IP Managers for Increased Management Security Chapter Contents Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-2 Using Authorized IP Managers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-4 Access Leve ...

  • IronPort Systems 4108GL - page 186

    10-2 Using Autho rized IP Mana gers for Increa sed Manageme nt Security Overv iew Using Authori zed IP Manag ers Overview The Au thori zed IP M anage rs fe atur e enh ances secu rity on th e swit ch b y usin g IP addresses and masks to determine which stat ions (PCs or workstations) can ac cess th e sw itch th rough the ne twork. This c over s acce ...

  • IronPort Systems 4108GL - page 187

    10-3 Usin g Autho rized IP Manag ers for Incre ased Ma nagemen t Sec urity Overvi ew Using Authoriz ed IP Manag ers 2. If T A CACS+ is co nfigured a nd a T ACA CS+ server issue s a prompt , the correc t passwords mu st be entered from the ma nagement station and verified by the T ACACS+ ser ver . • If inco rrec t passw ords ar e ent ered, the T A ...

  • IronPort Systems 4108GL - page 188

    10-4 Using Autho rized IP Mana gers for Increa sed Manageme nt Security Using A utho rized I P Mana gers Using Authori zed IP Manag ers Using Authorized IP Managers Authoriz ed IP Manager Fe atures This fe ature en ables yo u to en hance se curity on the switch by using IP addresses to authorize whic h stations (PCs or workstations) can access the ...

  • IronPort Systems 4108GL - page 189

    10-5 Usin g Autho rized IP Manag ers for Incre ased Ma nagemen t Sec urity Usin g Autho rized I P Mana gers Using Authoriz ed IP Manag ers Access Levels For ea ch aut horized m anager addre ss, you can config ure either o f these access levels: ■ Manag er: Enables full acc ess to all web browser and c onsole inter face screen s for viewing , con ...

  • IronPort Systems 4108GL - page 190

    10-6 Using Autho rized IP Mana gers for Increa sed Manageme nt Security Using A utho rized I P Mana gers Using Authori zed IP Manag ers auth orized IP a ddresse s. Fo r exam ple, a mask o f 255.255.255.0 and any v a lue for the Aut horized M anager IP paramet er allow s a range of 0 throug h 255 in the 4t h octet of the au thoriz ed IP add ress, wh ...

  • IronPort Systems 4108GL - page 191

    10-7 Usin g Autho rized IP Manag ers for Incre ased Ma nagemen t Sec urity Usin g Autho rized I P Mana gers Using Authoriz ed IP Manag ers Menu: V i ewing and Configur ing IP Authorized Managers From the c onsole Main Menu, select : 2. Switch Con figuratio n . . . 7. IP Authorized Managers Figure 10-1. Examp le of How T o Add an Authorized Mana ger ...

  • IronPort Systems 4108GL - page 192

    10-8 Using Autho rized IP Mana gers for Increa sed Manageme nt Security Using A utho rized I P Mana gers Using Authori zed IP Manag ers Editing o r Deleting an Aut horized Manag er Entry . Go to the IP Ma nag- ers List scree n (figure 1 0-1), highligh t the desi red entry , and pr ess [E] (for Edit ) or [D] (for De lete ). CLI: V iewing and Con fig ...

  • IronPort Systems 4108GL - page 193

    10-9 Usin g Autho rized IP Manag ers for Incre ased Ma nagemen t Sec urity Usin g Autho rized I P Mana gers Using Authoriz ed IP Manag ers Configuring IP A uthorized Managers for the Switch Synta x: ip au thor ized -ma nager s <ip addr ess> [mask <mask-bit s> ] <operat or | m anager> T o Authoriz e Manag er Access. This command a ...

  • IronPort Systems 4108GL - page 194

    10-1 0 Using Autho rized IP Mana gers for Increa sed Manageme nt Security Using A utho rized I P Mana gers Using Authori zed IP Manag ers The fol lowing co mmand r eplaces th e exist ing ma sk and access level for IP addre ss 10. 28.2 27.1 01 w ith 255.0.0.0 an d manager (the de faults) because the com mand do es no t specif y eith er of th ese par ...

  • IronPort Systems 4108GL - page 195

    10-1 1 Usin g Autho rized IP Manag ers for Incre ased Ma nagemen t Sec urity Usin g Autho rized I P Mana gers Using Authoriz ed IP Manag ers T able 10-2. Analy sis of IP Mask for Single-Station Entries Configuring Multipl e Stations Per Authorized Manager IP Entry The mask determi nes whe ther th e IP a ddress o f a stat ion on t he networ k mee ts ...

  • IronPort Systems 4108GL - page 196

    10-1 2 Using Autho rized IP Mana gers for Increa sed Manageme nt Security Using A utho rized I P Mana gers Using Authori zed IP Manag ers T able 10-3. Analy sis of IP Mask for Multiple-Station Entries Figure 10-4. E xample o f How t he Bitmap in the IP Mask Define s Authoriz ed Mana ger Addre sses 1st Octet 2nd Octet 3rd Octet 4th Octet Manager-Lev ...

  • IronPort Systems 4108GL - page 197

    10-1 3 Usin g Autho rized IP Manag ers for Incre ased Ma nagemen t Sec urity Usin g Autho rized I P Mana gers Using Authoriz ed IP Manag ers Additi onal Examples fo r Authoriz ing Mult iple Stat ions Operating an d T roublesh ooting Notes ■ Networ k Security Precauti ons: Y ou can enhanc e your networ k ’ s secu- rity by keepi ng physical acces ...

  • IronPort Systems 4108GL - page 198

    10-1 4 Using Autho rized IP Mana gers for Increa sed Manageme nt Security Using A utho rized I P Mana gers Using Authori zed IP Manag ers ...

  • IronPort Systems 4108GL - page 199

    11-1 Ports: Traffic Control and Tru nkin g 11 Optimizing Port Usage Through T raffic Control and Por t T runki ng Chapter Contents Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-2 Viewing Port Status and Configuring Port P arameters . . . . . . . . . . . . . . . 11-2 Menu: Viewi ...

  • IronPort Systems 4108GL - page 200

    11-2 Optimizi ng Port Usag e Thr ough T raffic Control and Port Tr unking Overv iew Port s: T raff ic Co ntro l and Tr unking Overview This chap ter incl udes: ■ Config uring p orts, inclu ding m ode (spe ed an d duplex), f low co ntrol, a nd broadca st co ntrol par ameters (p age 11-2) ■ Creat ing and modi fyin g a dynami c LACP or static port ...

  • IronPort Systems 4108GL - page 201

    11-3 Opti mizing Port Usage Th rough Traffic Control and Port Trunking Viewin g Port Status and Co nfiguri ng Port Parame ters Ports: Traffic Control and Tr unking T a ble 11-1. Status and P arameter s for Each Port T ype Status or Para met er Descriptio n Enab led Ye s (defa ult): Th e port i s ready f or a netw ork conn ecti on. No: The por t wil ...

  • IronPort Systems 4108GL - page 202

    11-4 Optimizi ng Port Usag e Thr ough T raffic Control and Port Tr unking View ing Po rt S tatus and Con figur ing Port Par ameter s Port s: T raff ic Co ntro l and Tr unking 100/1000Ba se-T ports: • Auto (de fault ): Sens es spee d and nego tiat es with the por t at the ot her end o f the li nk for por t opera tion (MDI-X o r MDI). T o see what ...

  • IronPort Systems 4108GL - page 203

    11-5 Opti mizing Port Usage Th rough Traffic Control and Port Trunking Viewin g Port Status and Co nfiguri ng Port Parame ters Ports: Traffic Control and Tr unking Menu: Viewing Port Status and Configuring Port Parameters From th e menu int erface , you can co nfigu re and vi ew all por t param eter settings an d view all por t status indica tors. ...

  • IronPort Systems 4108GL - page 204

    11-6 Optimizi ng Port Usag e Thr ough T raffic Control and Port Tr unking View ing Po rt S tatus and Con figur ing Port Par ameter s Port s: T raff ic Co ntro l and Tr unking Figure 11-2. Example of Port /T ru nk Sett ings with a T runk Group Configur ed 2. Press [E] (for E dit). T he cursor moves to the Enable d field f or the fi rst por t. 3. Ref ...

  • IronPort Systems 4108GL - page 205

    11-7 Opti mizing Port Usage Th rough Traffic Control and Port Trunking Viewin g Port Status and Co nfiguri ng Port Parame ters Ports: Traffic Control and Tr unking Synta x: show int erfaces br ief show inte rfac e con fig The next two fi gures list example s of the output of the abo ve tw o comman ds for the sam e port co nfigura tion. Figure 11-3. ...

  • IronPort Systems 4108GL - page 206

    11-8 Optimizi ng Port Usag e Thr ough T raffic Control and Port Tr unking View ing Po rt S tatus and Con figur ing Port Par ameter s Port s: T raff ic Co ntro l and Tr unking Using the CLI T o Configure Ports. Y ou can c onfigur e one or more o f the followin g port param eters. For details on ea ch option , see T able 11-1 on page 11-3 . Synta x: ...

  • IronPort Systems 4108GL - page 207

    11-9 Opti mizing Port Usage Th rough Traffic Control and Port Trunking Viewin g Port Status and Co nfiguri ng Port Parame ters Ports: Traffic Control and Tr unking Configur ing a Broa dcast Lim it on the Switch. Executin g thi s command config ures the b roadca st limit for al l ports on the switch . Synta x: broad cas t-l imit <0 . . 99> For ...

  • IronPort Systems 4108GL - page 208

    11-1 0 Optimizi ng Port Usag e Thr ough T raffic Control and Port Tr unking Port Tr unki ng Port s: T raff ic Co ntro l and Tr unking Port T runking Port Status an d Con figur ationF eat ure s Port trunkin g allows you to assign up to f our ph ysical links to on e logical lin k (trunk) that fu nctions as a single, highe r -speed li nk prov iding dr ...

  • IronPort Systems 4108GL - page 209

    11-1 1 Opti mizing Port Usage Th rough Traffic Control and Port Trunking Port Tr unking Ports: Traffic Control and Tr unking Port Conne ctions and Co nfiguration: All port trunk links must be point- to-point connectio ns between the Switch 4108GL and anot her switch , router , server , or w orkstatio n configu red for p ort trunking . No interven i ...

  • IronPort Systems 4108GL - page 210

    11-1 2 Optimizi ng Port Usag e Thr ough T raffic Control and Port Tr unking Port Tr unki ng Port s: T raff ic Co ntro l and Tr unking link is restored, th at link is automatica lly included in the traffic distri bution again. The LACP opt ion also offers a stand by link capabilit y , which enables you to ke ep links in re serve for se rvice if one ...

  • IronPort Systems 4108GL - page 211

    11-1 3 Opti mizing Port Usage Th rough Traffic Control and Port Trunking Port Tr unking Ports: Traffic Control and Tr unking T able 11-4. T runk Co nfigur ation Prot ocols Prot ocol T r unking Opt ions LACP (802.3a d) Provide s dynamic a nd stati c LACP trun king opt ions. • Dynamic LA CP — Use th e switch-n egoti ated dyn amic LACP trunk when ...

  • IronPort Systems 4108GL - page 212

    11-1 4 Optimizi ng Port Usag e Thr ough T raffic Control and Port Tr unking Port Tr unki ng Port s: T raff ic Co ntro l and Tr unking T able 11-5. General Op eratin g Rul es for Por t T runks Media: All por ts on both ends o f a trun k group mu st ha ve the same medi a type and mo de (s peed a nd dup lex). The sw itch blocks an y trunke d links t h ...

  • IronPort Systems 4108GL - page 213

    11-1 5 Opti mizing Port Usage Th rough Traffic Control and Port Trunking Port Tr unking Ports: Traffic Control and Tr unking Span ning T re e Pr otoco l (ST P): STP op era tes as a gl obal s ett ing on the switch (one instan ce o f STP per sw itch ). Ho wever , you can adj ust ST P pa ramet ers on a pe r -port basi s. A s tatic tru nk of any t ype ...

  • IronPort Systems 4108GL - page 214

    11-1 6 Optimizi ng Port Usag e Thr ough T raffic Control and Port Tr unking Port Tr unki ng Port s: T raff ic Co ntro l and Tr unking Menu: V i ewing and Configur ing a Static T runk G roup Importa nt Config ure port tru nking before you conn ect the tru nked lin ks to another switch, routing switch, or server . Otherwise, a b roadcast stor m could ...

  • IronPort Systems 4108GL - page 215

    11-1 7 Opti mizing Port Usage Th rough Traffic Control and Port Trunking Port Tr unking Ports: Traffic Control and Tr unking • All ports in a trunk must hav e the same media t ype and mode (suc h as 10/1 00T X set t o 100FD x, or 10 0FX set to 100 FDx). The fl ow con trol settings must also be the sam e for all ports in a given trunk. T o verify ...

  • IronPort Systems 4108GL - page 216

    11-1 8 Optimizi ng Port Usag e Thr ough T raffic Control and Port Tr unking Port Tr unki ng Port s: T raff ic Co ntro l and Tr unking During the Save process, traffic on the ports config ured for trunkin g will be delay ed for severa l second s. If th e Span ning T ree Protoc ol is enabled , the delay may be up to 3 0 seconds. 8. Co nnect the trunk ...

  • IronPort Systems 4108GL - page 217

    11-1 9 Opti mizing Port Usage Th rough Traffic Control and Port Trunking Port Tr unking Ports: Traffic Control and Tr unking This example uses a port list to specify only the switch ports an administrator wants to view: Figure 11-8. Example of a Sh ow T runk Listing for Spec ific Ports The show trun k command in this exa mple does not inc lude a po ...

  • IronPort Systems 4108GL - page 218

    11-2 0 Optimizi ng Port Usag e Thr ough T raffic Control and Port Tr unking Port Tr unki ng Port s: T raff ic Co ntro l and Tr unking In the foll owing ex ample, p orts C1 and C 2 have been pr evious ly configur ed for a static LA CP trunk. (For mor e on “ Ac tive ” , see tab le 11 -7 o n p age 11-2 7. ) Figure 11-10. Example of a Show LA CP Li ...

  • IronPort Systems 4108GL - page 219

    11-2 1 Opti mizing Port Usage Th rough Traffic Control and Port Trunking Port Tr unking Ports: Traffic Control and Tr unking Using the CLI T o Configure a Static or Dynamic T runk Group Importa nt Config ure port tru nking before you conn ect the tru nked lin ks between switches. Oth erwise, a br oadcast storm could occ ur . (If you ne ed to conne ...

  • IronPort Systems 4108GL - page 220

    11-2 2 Optimizi ng Port Usag e Thr ough T raffic Control and Port Tr unking Port Tr unki ng Port s: T raff ic Co ntro l and Tr unking HP4108(config)# no trunk c4-c5 ...

  • IronPort Systems 4108GL - page 221

    11-2 3 Opti mizing Port Usage Th rough Traffic Control and Port Trunking Port Tr unking Ports: Traffic Control and Tr unking Enabling a Dynamic LACP T runk Group. In th e defaul t port config u ra- tion, al l port s on the switch a re set to LA CP pa ssive. Howe ver , to enab le the switch to autom atically f orm a trunk g roup that is dyna mic on ...

  • IronPort Systems 4108GL - page 222

    11-2 4 Optimizi ng Port Usag e Thr ough T raffic Control and Port Tr unking Port Tr unki ng Port s: T raff ic Co ntro l and Tr unking Removing Po rts from a Dynamic LACP T runk Group. T o re move a por t from dyna mic LAC P trunk o peration, y ou must t urn off L ACP on t he port . (On a port in an o peratin g, dynam ic LACP trunk, y ou ca nnot ch ...

  • IronPort Systems 4108GL - page 223

    11-2 5 Opti mizing Port Usage Th rough Traffic Control and Port Trunking Port Tr unking Ports: Traffic Control and Tr unking T runk Group Operation Using LACP The switc h can a utomatic ally configu re a dy namic LA CP trunk group or you can man ually co nfigure a static L ACP trunk group . The met hods for displaying Note LACP requir es full-dupl ...

  • IronPort Systems 4108GL - page 224

    11-2 6 Optimizi ng Port Usag e Thr ough T raffic Control and Port Tr unking Port Tr unki ng Port s: T raff ic Co ntro l and Tr unking T able 11-6. LACP T run k T ypes LACP P ort T run k Configura tion Oper atio n Dynamic LACP This optio n automat icall y esta bli shes an 802.3ad-comp liant trun k group , with LACP for th e por t T ype para meter an ...

  • IronPort Systems 4108GL - page 225

    11-2 7 Opti mizing Port Usage Th rough Traffic Control and Port Trunking Port Tr unking Ports: Traffic Control and Tr unking Default Port Operation In the defa ult configu ration, a ll ports are co nfigured f or passive LACP . How- ever , if LACP is not conf igured , the port will not try t o detect a t runk conf ig- uration and will opera te as a ...

  • IronPort Systems 4108GL - page 226

    11-2 8 Optimizi ng Port Usag e Thr ough T raffic Control and Port Tr unking Port Tr unki ng Port s: T raff ic Co ntro l and Tr unking LACP Notes and Restriction s Changin g T runking Methods. T o c onvert a tru nk from static to dynamic, you mu st first elimin ate the st atic t runk. Static LACP T runks. Where a port is config ured fo r LACP ( Acti ...

  • IronPort Systems 4108GL - page 227

    11-2 9 Opti mizing Port Usage Th rough Traffic Control and Port Trunking Port Tr unking Ports: Traffic Control and Tr unking regar d for how tha t traffi c is handle d by the dev ice at the other end of the trunked lin ks. Simila rly , the switch handles incomin g traff ic from the tr unked links as if it we re from a trunked sour ce. Use the T run ...

  • IronPort Systems 4108GL - page 228

    11-3 0 Optimizi ng Port Usag e Thr ough T raffic Control and Port Tr unking Port Tr unki ng Port s: T raff ic Co ntro l and Tr unking Outbound T raffic Distribution Acr oss T runk ed Links All three trunk group op tions (LACP , T runk, and F EC) use source -destina tion address pa irs (SA/DA) for distri buting outb ound traff ic over trunke d links ...

  • IronPort Systems 4108GL - page 229

    11-3 1 Opti mizing Port Usage Th rough Traffic Control and Port Trunking Port Tr unking Ports: Traffic Control and Tr unking Figure 11-13. Example of Port-T runked Net work T abl e 11-8. Exampl e of Li nk Assign ments in a T runk Group (SA/ DA Distri bution) Sourc e: Destinati on: Link: Node A Nod e W 1 Node B Nod e X 2 Node C N ode Y 3 Node D Nod ...

  • IronPort Systems 4108GL - page 230

    11-3 2 Optimizi ng Port Usag e Thr ough T raffic Control and Port Tr unking Port Tr unki ng Port s: T raff ic Co ntro l and Tr unking ...

  • IronPort Systems 4108GL - page 231

    12-1 Monitor i ng and Mana ging the Switch 12 Configuri ng for Network Management Applications Chapter Contents Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-2 SNMP Management Feat ures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-2 Configuring for SNMP ...

  • IronPort Systems 4108GL - page 232

    12-2 Config uring fo r Network M anagement Applica tions Overv iew Moni torin g and Ma nagi ng the Sw itch Overview Y ou can manage the switch via SNMP fro m a networ k manageme nt station . For this purp ose, HP recommen ds HP T opT ools for Hubs & Switche s — an easy-to-in stall and use ne twork man agement app lication that runs on y our W ...

  • IronPort Systems 4108GL - page 233

    12-3 Confi guri ng for Net work Ma nagem ent App licat ions Overvi ew Monitor i ng and Mana ging the Switch ■ Supported Stand ard MIBs i nclu de: • Bridge MIB (RFC 1493) dot1dBase, dot1 dTp, dot1dStp • Ethern et MAU MIB (RFC 151 5) dot3IfM auBasic Group • Interf aces Evoluti on MIB (RFC 15 73) ifGeneral Group, ifRc vAddre ssGroup, ifSt ackG ...

  • IronPort Systems 4108GL - page 234

    12-4 Config uring fo r Network M anagement Applica tions Overv iew Moni torin g and Ma nagi ng the Sw itch Configuri ng for SNMP Access to the Switch SNMP acce ss requires an IP address a nd subnet m ask configure d on the switch. (See “ IP Configura tion ” on page 7-3. ) If you are using DHCP/Bo otp to config ure the switc h, ensure th at the ...

  • IronPort Systems 4108GL - page 235

    12-5 Confi guri ng for Net work Ma nagem ent App licat ions Overvi ew Monitor i ng and Mana ging the Switch SNMP Communities SNMP Com muni ty Feat ures Use SNMP communities to restrict access to the switch by SNM P management stations by adding, edit ing, or dele ting SNMP c ommunitie s. Y ou can config ure up to fi ve SN MP comm unities, each with ...

  • IronPort Systems 4108GL - page 236

    12-6 Config uring fo r Network M anagement Applica tions Overv iew Moni torin g and Ma nagi ng the Sw itch Figur e 12-1. Th e SNMP Com munit ies Scr een (De fault Values) 2. Press [A] (for Add ) to display the followin g screen: Figure 12-2. The SNMP Add or Edit Screen Need Help? If you nee d informati on on the optio ns in each field, pr ess [Ent ...

  • IronPort Systems 4108GL - page 237

    12-7 Confi guri ng for Net work Ma nagem ent App licat ions Overvi ew Monitor i ng and Mana ging the Switch Listing Cu rrent Communit y Names and V alues. Listing Co mmunity Names. This command lists the data forcur rently con - figu red SNM P commu nity n ames ( along with trap rece iver s and t he sett ing fo r auth enti cat ion tra ps — see ? ...

  • IronPort Systems 4108GL - page 238

    12-8 Config uring fo r Network M anagement Applica tions Overv iew Moni torin g and Ma nagi ng the Sw itch Synta x: snmp-server [ contact <cont act-str> ] [loc ation <loc atio n-str > ] Both fiel ds allo w up to 48 ch arac ter s, wi tho ut s pace s. For exam ple, t o config ure th e switch wi th "Site -LAN-Ext .449" a nd a loc ...

  • IronPort Systems 4108GL - page 239

    12-9 Confi guri ng for Net work Ma nagem ent App licat ions Overvi ew Monitor i ng and Mana ging the Switch Note F ixed or "W ell -Known" T ra ps: The Sw itch 410 8GL auto matical ly sends f ixed traps (su ch as "col dStart", "wa rmStart", "linkDown ", and "lin kUp") to trap receive rs using a publ ...

  • IronPort Systems 4108GL - page 240

    12-1 0 Config uring fo r Network M anagement Applica tions Overv iew Moni torin g and Ma nagi ng the Sw itch In the next example, the show snmp-ser ver com mand s hows that t he swi tch has been previously conf igured to send S NMP traps t o managem ent stations belonging to t he “ public ” , “ red-t eam ” , and “ blue-te am ” communit ...

  • IronPort Systems 4108GL - page 241

    12-1 1 Confi guri ng for Net work Ma nagem ent App licat ions Overvi ew Monitor i ng and Mana ging the Switch Note If you do not specify the even t level ( [<no ne | all | non -info | critic al | deb ug>] ) then the switchwill not se nd even t log me ssages as trap s. "W ell-Kno wn" traps and thresho ld traps (if c onfigured) will s ...

  • IronPort Systems 4108GL - page 242

    12-1 2 Config uring fo r Network M anagement Applica tions CDP Moni torin g and Ma nagi ng the Sw itch CDP CDP Fe ature s Introduction In a S witch 4108 G L, CDP-v1 (Cisco Discover y Proto col, versi on 1) provid es data that aids SN MP-based network ma pping utilitie s designed to discover device s running CD P in a netw ork. T o make this dat a a ...

  • IronPort Systems 4108GL - page 243

    12-1 3 Confi guri ng for Net work Ma nagem ent App licat ions CDP Monitor i ng and Mana ging the Switch An SNMP utili ty can prog ressively disc over CD P devices in a net work by: 1. Reading a given device ’ s CDP Neighbor t able (in the Management Infor - mation Base, or MIB) t o learn about other , neighbor CDP devices 2. Using the information ...

  • IronPort Systems 4108GL - page 244

    12-1 4 Config uring fo r Network M anagement Applica tions CDP Moni torin g and Ma nagi ng the Sw itch Figur e 12-5 . Exampl e of Ho w the Swi tch Sto res D ata on Neighb or CDP D evice s Outgoing Packets A Switch 4108GL running CDP perio dically transm its a one-hop CDP pa cket out each of its por ts. This packet contains da ta describing th e swi ...

  • IronPort Systems 4108GL - page 245

    12-1 5 Confi guri ng for Net work Ma nagem ent App licat ions CDP Monitor i ng and Mana ging the Switch Figure 12-6. E xample o f Outg oing CDP Packet Operation Incoming CDP Packets When a CDP-enab led Swi tch 410 8GL rec eives a CDP p acket fr om ano ther C DP devi ce, it enters t hat device ’ s data in th e CDP Neighb ors table, along with the ...

  • IronPort Systems 4108GL - page 246

    12-1 6 Config uring fo r Network M anagement Applica tions CDP Moni torin g and Ma nagi ng the Sw itch neighbor pair s are as follows: A /1, A /2, A/3, A/B, B /C. No te that "C" a nd "E" are not neighbors be cause the in tervenin g CDP-disable d switch "D" does not forward CDP packets; i.e . is not tr ansparen t to CDP ...

  • IronPort Systems 4108GL - page 247

    12-1 7 Confi guri ng for Net work Ma nagem ent App licat ions CDP Monitor i ng and Mana ging the Switch Using th e exam ple i n figure 12-7: The CDP Neigh bor table for switc hes "A" and "B" w ould ap pear similar t o these: Switch A: Switch B: Figur e 12-8 . Exam ple of Viewable CDP Nei ghbo r T able for Swit ches "A" ...

  • IronPort Systems 4108GL - page 248

    12-1 8 Config uring fo r Network M anagement Applica tions CDP Moni torin g and Ma nagi ng the Sw itch Non-C DP device s (that i s, de vices that are not capa ble of runnin g CDP) ar e transpar ent to C DP operati on. Howe ver , an in tervenin g CDP-awar e devi ce that is CDP-disable d is not tran sparent. Fo r example , in figure 12-7 (page 16 ), ...

  • IronPort Systems 4108GL - page 249

    12-1 9 Confi guri ng for Net work Ma nagem ent App licat ions CDP Monitor i ng and Mana ging the Switch V iewing the Switch ’ s Curr ent CDP Conf igu rati on This command lists th e switch ’ s glo bal and per -por t CDP c onfigura tion. (In the factory default con figu ration, the switch run s CDP on all ports w ith a hold time of 180 se conds ...

  • IronPort Systems 4108GL - page 250

    12-2 0 Config uring fo r Network M anagement Applica tions CDP Moni torin g and Ma nagi ng the Sw itch Figure 12-10. Example of CDP Neighbors T able Listing Figure 12-11 illustr ates a topology of CDP-enabl ed devices for the CDP Neigh- bors tab le listin g in figur e 12-10. Figure 12-11. Examp le of CDP-Ena bled Devices in a T opology for the List ...

  • IronPort Systems 4108GL - page 251

    12-2 1 Confi guri ng for Net work Ma nagem ent App licat ions CDP Monitor i ng and Mana ging the Switch Figur e 12- 12. View of th e CDP Nei ghbo rs T able Immed iat ely Af ter Executi ng cd p clea r Configuring CDP Operation Enabling or D isabling C DP Operati on on the Swi tch. Enabl ing CDP operation (the defa ult) on the sw itch ca uses the swi ...

  • IronPort Systems 4108GL - page 252

    12-2 2 Config uring fo r Network M anagement Applica tions CDP Moni torin g and Ma nagi ng the Sw itch Enabling or D isabling C DP Operati on on Individu al Ports. In the factory-de fault con figuration, th e switch ha s all ports en abled an d transmit- ting CDP pa ckets. Disablin g CDP on a port prev ents that port from se nding outbound CDP pack ...

  • IronPort Systems 4108GL - page 253

    12-2 3 Confi guri ng for Net work Ma nagem ent App licat ions CDP Monitor i ng and Mana ging the Switch For e xamp le, if the s witch ’ s transmit interval for CDP packets was set to a non-def ault value , you would use this comm and to re set it to one minute: Switch 4108GL(config) cdp timer 60 Changin g the Hold Time (CDP Packe t Time-To-Liv e ...

  • IronPort Systems 4108GL - page 254

    12-2 4 Config uring fo r Network M anagement Applica tions CDP Moni torin g and Ma nagi ng the Sw itch ■ Switch "A" sends outbou nd CDP pack ets on the forwa rding link, and the switch " B" CDP Neighbo rs table shows swit ch "A" on on ly one port. ■ Switch "B" sends outbou nd CDP packet s on both links, a ...

  • IronPort Systems 4108GL - page 255

    12-2 5 Confi guri ng for Net work Ma nagem ent App licat ions CDP Monitor i ng and Mana ging the Switch Figure 12-15. Example of IP Addr ess Selecti on when the CDP Ne ighbor Has Multiple VLANs with IP Addresses CDP Neighbor Data and MIB Objects The switch pla ces the da ta receive d from inbou nd CDP pack ets into its MI B (Manage ment Info rmatio ...

  • IronPort Systems 4108GL - page 256

    12-2 6 Config uring fo r Network M anagement Applica tions CDP Moni torin g and Ma nagi ng the Sw itch T able 12-2. CDP Neighbors Da ta CDP Neighb or Data Displayed Neig hbors Ta b l e MIB Addre ss T ype No Y es Alwa y s "1" ( IP addre ss only). CDP Ca che Addr ess No Y e s IP addr ess of so urce dev ice. Software V ersion Y es Y es ASCII ...

  • IronPort Systems 4108GL - page 257

    12-2 7 Confi guri ng for Net work Ma nagem ent App licat ions CDP Monitor i ng and Mana ging the Switch Displaying CDP Neighbor Data. T o display the su perset of CD P neighb or data held in the MIB , use the walk mib command . Synta x: walkmib < MIB-id entifier > For exa mple, with t wo CDP de vice s conne cted t o ports A1 and A3 on the swi ...

  • IronPort Systems 4108GL - page 258

    12-2 8 Config uring fo r Network M anagement Applica tions CDP Moni torin g and Ma nagi ng the Sw itch CDP- Capabl e Hubs. Some hubs ar e capable of running CDP , but also forward C DP pack ets as if the hub itself w ere transp arent to C DP . Such hubs will appe ar in the switch ’ s CDP Ne ighbor table and will also maint ain a CDP neighbor tabl ...

  • IronPort Systems 4108GL - page 259

    13-1 HP Proc urve Stack Manageme nt 13 HP Procurve Stack Management Chapter Contents Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-3 HP Procurve Stack Managemen t . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-4 Which Devices Support Stacking? . . . . . . . . . . ...

  • IronPort Systems 4108GL - page 260

    13-2 HP P rocurv e Stac k Managem ent Chap ter Co ntent s HP Proc urve Stack Manageme nt Transmission Interval . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-46 Stacking Operation with Multiple VLANs Configured . . . . . . . . . . . 13-46 Web: Viewing and Configuring St acking . . . . . . . . . . . . . . . . . . . . ...

  • IronPort Systems 4108GL - page 261

    13-3 HP P rocurv e Stac k Mana gemen t Overvi ew HP Proc urve Stack Manageme nt Overview This chapter describes how to use y our netwo rk to stack swi tches withou t the need for an y spec iali zed ca blin g — page 1 3-4. For gener al inform atio n on how to u se the swi tch ’ s built-in in terfaces, see: ■ Chap ter 2 , “ Using the Menu Int ...

  • IronPort Systems 4108GL - page 262

    13-4 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt HP Procurve Stack Management Stac king Featu res HP Pr ocur ve Sta ck Ma nagem ent ( terme d stacking ) enables y ou to use a single IP addr ess an d standar d netw ork ca bling t o manage a gro up of u p to 1 6 total switches in the same IP subne ...

  • IronPort Systems 4108GL - page 263

    13-5 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt ■ Simplify ma nagement of small workgr oups or wirin g closets while scaling y our networ k to handl e incr eased ba ndwidth demand. ■ Elimina te any sp ecializ ed cables for stack ing con nectivit y and remove the distanc e barrie rs that typi ...

  • IronPort Systems 4108GL - page 264

    13-6 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt Components of HP Procurve Stack Managem ent T a ble 13-1. Stacki ng Defin itions Figure 13-1. Illustration of a Switch Moving from Candidat e to Member General Stacking Operation After you co nfigure one sw itch to op erate as the Comma nder of a ...

  • IronPort Systems 4108GL - page 265

    13-7 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt Figure 13-2. Example of Stacking with One Commande r Controlling Access to Wiring Closet Switches Interfac e Options. Y ou ca n configur e stacking through the switch ’ s menu interfac e, CLI, or the web browse r interface . For informa tion on h ...

  • IronPort Systems 4108GL - page 266

    13-8 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt ■ Ther e is no li mit on the nu mber of s tacks in t he sam e I P subnet (broadc ast domain), how ever a switch can belong to only on e stack. ■ If multiple V LANs are conf igured, stacki ng uses on ly the primary VLAN on any switch. In the fa ...

  • IronPort Systems 4108GL - page 267

    13-9 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt Note In the default stac k configu ration, the Candidate Auto Jo in pa rameter is enab led, b ut the C omm ander Auto Gra b paramete r is disabl ed. This prevents Candida tes from automa tically joini ng a stack prem aturely or join ing the wrong s ...

  • IronPort Systems 4108GL - page 268

    13-1 0 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt Overview of Configur ing and Bringin g Up a Stack This process assumes that: ■ All switch es you want to inc lude in a stack are co nnecte d to the same subnet (b roadcast do main). ■ If VLANs are en abled on th e switches you want to inclu ...

  • IronPort Systems 4108GL - page 269

    13-1 1 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt T a ble 13-3. Stacki ng Con figuratio n Guide The easiest way to a utomatically create a stac k is to: 1. Configure a switch as a Commander . 2. Configure IP addressing and a stack name on the Commander . 3. Set the Commander ’ s Auto Grab para ...

  • IronPort Systems 4108GL - page 270

    13-1 2 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt General Steps for Creati ng a Sta ck This section describe s the general sta ck creation pr ocess. For the detailed config uration proc esses, see page s 13-14 throu gh 13-38 for the menu interfa ce and pag es 13-31 through 13- 43 for th e CLI. ...

  • IronPort Systems 4108GL - page 271

    13-1 3 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt 3. For automatically or manually pulling Candidate switches into a stack, you can leave such switches in their default stacking configuration. If you need to access Candidate switches through your network before they join the stack, ass ign IP ad ...

  • IronPort Systems 4108GL - page 272

    13-1 4 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt Using the Menu Interface T o V iew Stack Status and Configure Stacki ng Using the Menu Interface T o View and Configur e a Commander Switch 1. Configure an IP address and subnet mask on the Commander switch. (See Chapter 7, “ Confi gur ing IP ...

  • IronPort Systems 4108GL - page 273

    13-1 5 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt Figure 13-6. The Default Stac k Configuration S creen 4. Move the cursor to the Stack State field by pressing [E] (for E dit ). Then use the Space bar to select the C ommander option. 5. Press the downarrow key to display the Commander configurat ...

  • IronPort Systems 4108GL - page 274

    13-1 6 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt Using the Menu T o Manage a Candidate Sw itch Using the men u interfac e, you ca n perform t hese actio ns on a Candi date switch: ■ Add ( “ push ” ) t he Candida te into an existing stack ■ Modify th e Candidat e ’ s stacking conf igu ...

  • IronPort Systems 4108GL - page 275

    13-1 7 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt T able 13-4.Candidate Config uration Options in the Menu Interface Using the Me nu T o “ Push ” a S witch Into a St ack, M odify the Switch ’ s Configura tion, or Disable Stacking on the Switch. U se T eln et or the web browser in terface t ...

  • IronPort Systems 4108GL - page 276

    13-1 8 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt 4. Do one of the foll owing: • T o di sable stack ing on the Cand idate, use the Space bar to select the Disabled o ption, then go to step 5. Note: Using t he menu inte rface to disa ble stacking on a Candidate remove s th e Candi date f rom a ...

  • IronPort Systems 4108GL - page 277

    13-1 9 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt Using the Co mmander ’ s M enu T o Manually Add a Candid ate to a Stack . In t he defaul t configurat ion, you must manually ad d stack Me mbers from the Candidate pool. Re asons for a switch remaining a Cand idate instea d of beco ming a Membe ...

  • IronPort Systems 4108GL - page 278

    13-2 0 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt Figure 13-10. Example of Candi date List in Stac k Management Scre en 3. Either accept the disp layed switch number or ent er another available number . (The range is 0 - 15, wit h 0 reserved for the Commander .) 4. Use the downarrow key to move ...

  • IronPort Systems 4108GL - page 279

    13-2 1 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt Figure 13-11. Example of Stac k Managem ent Screen Af ter New Member Adde d Using the Command er ’ s M enu T o Move a Memb er F rom On e Stac k to Anot her . Where two or more stacks exist in the same subnet ( broadcast doma in), you can easi l ...

  • IronPort Systems 4108GL - page 280

    13-2 2 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt Y ou will then see the Stackin g Status (All) sc reen: Figure 13-12. Example of How the Sta cking Status (All) Scre en Helps Y ou Fin d Member MAC Addresses 3. In the Stacking Status (All) screen, find the Member switch that you want to move and ...

  • IronPort Systems 4108GL - page 281

    13-2 3 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt 8. Do one of the foll owing: • If the stack conta ining t he Mem ber you are m oving h as a Ma nager password, pr ess the dow narro w key to sele ct the C andidat e Password field, then t ype the pa ssword. • If the sta ck conta ining the Mem ...

  • IronPort Systems 4108GL - page 282

    13-2 4 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt 4. St ack Ma nageme nt Y ou will then see the Stack Ma nagemen t screen: Figure 13-13. Example of Stac k Management Scre en with Stac k Members Listed 2. Use the downarrow key to select the Member yo u want to remove from the stack. Figure 13-14 ...

  • IronPort Systems 4108GL - page 283

    13-2 5 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt Using the Commander T o Access Member Switches for Configuration Changes and Monitor ing T raffic After a Can didat e beco mes a stac k Member, you can use that stack ’ s Co mmander to ac cess t he Mem ber ’ s co nsole interfa ce for the same ...

  • IronPort Systems 4108GL - page 284

    13-2 6 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt Figur e 13 -17. Th e eX ecute Comm and D is play s th e C onsol e Ma in Men u fo r th e Selec ted Stack M ember 2. Y ou can now make conf iguration changes and/or vi ew status data f or the selected Member in the same way that you would if you w ...

  • IronPort Systems 4108GL - page 285

    13-2 7 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt 3. Press [B] (for B ack ) to return to the St acking Me nu. 4. T o displ ay Stack Co nfigura tion men u for the switch yo u are movi ng, sele ct 3. Stack Confi gurati on 5. Press [E] (for E dit ) to select the Stack St ate para meter . 6. U se t ...

  • IronPort Systems 4108GL - page 286

    13-2 8 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt Using Any Stacke d Switc h T o V iew the St atus for All Sw itche s with Stacking Enabled. Th is proce d ure d isplays t he gene ral stat us of all switc hes in the IP sub net ( broad cast domain ) that hav e stacki ng en able d. 1. Go to the co ...

  • IronPort Systems 4108GL - page 287

    13-2 9 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt Figure 13-19. Example of the Co mmander ’ s St acking Status Sc reen V iewing Member St atus. This proc edure di splays the Member ’ s stacking informa tion plus th e Comman der ’ s status, IP address, and MAC address. T o d isplay t h e st ...

  • IronPort Systems 4108GL - page 288

    13-3 0 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt Figure 13-20. Example of a Member ’ s Stac king Status Sc reen V iewi ng Candid ate Statu s. This procedure displ ays the C andidate ’ s stackin g configur ation. T o displ ay th e sta tus for a C andid ate: 1. Use T el net (if the Candi dat ...

  • IronPort Systems 4108GL - page 289

    13-3 1 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt Using the CLI T o V iew Stack St atus and Confi gure Stacking The CL I enab les you t o do all of the sta cking task s available throug h the menu interfac e.) T able 13- 6. CLI Comma nds f or Confi guring Stack ing on a Sw itch CLI C ommand Oper ...

  • IronPort Systems 4108GL - page 290

    13-3 2 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt [no] stac k memb er <switch- num> mac-ad dress <ma c-add r> [passw ord <p assword -str> ] Comma nder : Adds a Candi date t o stack memb ership . “ No ” form removes a Member from stac k membersh ip. T o easily determi ne th ...

  • IronPort Systems 4108GL - page 291

    13-3 3 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt Using the CLI T o View Stack Status Y ou can list the stack st atus for an indiv idual swit ch and fo r other switch es that h ave been d iscovered in the sa me subnet . Synta x: show stack [cand idates | view | all] V iewing the Stat us of an In ...

  • IronPort Systems 4108GL - page 292

    13-3 4 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt V iewing the S tatus o f all St ack-Ena bled Swi tches D iscovered in the IP Subne t. The next example list s all the stack- configu red switch es discov ered in the IP sub net. Bec ause t he Sw itch 4108G L on w hich t he show stack al l comm a ...

  • IronPort Systems 4108GL - page 293

    13-3 5 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt Using the CLI T o Configure a Commander Sw itch Y ou can config ure any sta cking-ena bled swit ch to be a Com mander as long a s the int ended stac k name does not alread y exist on t he broad cast domain . (When you con figu re a Comman der , y ...

  • IronPort Systems 4108GL - page 294

    13-3 6 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt Figure 13-26. Example of the Co mmander ’ s Sho w Stack Screen with Only the Comma nde r Disc overed Using a Member ’ s CLI to Convert the Me mber to the C ommander of a New Stack. This pr ocedure requir es that you fi rst remo ve the Member ...

  • IronPort Systems 4108GL - page 295

    13-3 7 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt Figure 13-27. Example of Using a Me mber ’ s CLI T o Convert the Me mber to the Commander of a New Stack Adding to a S tack or Moving Switches Between Stacks Y ou can add switc hes to a stack by adding disco vered Cand idates or by moving switc ...

  • IronPort Systems 4108GL - page 296

    13-3 8 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt Using the Co mmander ’ s CLI T o M anually Add a Can didate to th e Stack . T o manually a dd a candidate, yo u will use: ■ A switch num ber ( SN ) to assign to th e new member . Me mber SNs range from 1 to 15. T o see which SNs are alre ady ...

  • IronPort Systems 4108GL - page 297

    13-3 9 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt For exa mple, if th e HP 800 0M in th e abov e listi ng did not have a Manag er password and you wanted to make it a st ack Member with an SN of 2 , you would e xecute th e followi ng command : HP4108(config)# stack member 2 mac-address 0060b0-df ...

  • IronPort Systems 4108GL - page 298

    13-4 0 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt ■ The Ca ndidate ’ s Auto Join is set to Ye s ( and you do n ot want to enable Auto Grab on the C ommande r) or the Candidat e ’ s Auto Join i s set to No . ■ Either yo u know the MAC address o f the Commander fo r the stack into which y ...

  • IronPort Systems 4108GL - page 299

    13-4 1 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt Synta x: stack memb er < swit ch-nu mber > m ac-ad dres s < mac- addr > [p assword < password -str >] In the dest ination Commander , use show stack all to find th e MAC a ddress of the Mem ber you want to pull into the destinat ...

  • IronPort Systems 4108GL - page 300

    13-4 2 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt Synta x: no stack name <st ack na me> stack join <mac-address> If you don ’ t know the MAC addr ess of the dest inatio n Command er , yo u can use show st ack all to id ent ify it. For ex ample, suppose yo u have a Switch 4108GL op ...

  • IronPort Systems 4108GL - page 301

    13-4 3 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt Synta x: [no] stack member < switch-nu m > mac-addr ess < mac-addr > Use show stack view to li st the stack Membe rs. For example, suppose tha t you wante d to use the C omman der to remove the “ North S ea ” Member from the foll ...

  • IronPort Systems 4108GL - page 302

    13-4 4 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt Y ou would then execut e this comma nd in the “ Nort h Sea ” switch ’ s CLI to remo ve the s witch from t he sta ck: North Sea(config)# no stack join 0030c1-7fec40 Using the CLI T o Access Mem ber Switches for Con figuration Changes and T ...

  • IronPort Systems 4108GL - page 303

    13-4 5 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt SNMP Community Operation i n a Stack Comm u nit y Memb ersh ip In the defa ult stacking co nfiguration, w hen a Candid ate joins a stac k, it auto matica lly be comes a Memb er of any SNMP commun ity to w hich t he Command er belong s, even thoug ...

  • IronPort Systems 4108GL - page 304

    13-4 6 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt Note that in t he above e xample (f igure 13-37 ) you cannot use the pu blic communit y throu gh the Comma nder to access any o f the Member sw itches. For e xample, y ou can use th e public communi ty to a ccess the MIB in switch es 1 and 3 by ...

  • IronPort Systems 4108GL - page 305

    13-4 7 HP P rocurv e Stac k Mana gemen t HP Pr ocurve Stac k Manag ement HP Proc urve Stack Manageme nt ■ Stacki ng uses only the primary VLAN on eac h switch in a stack. ■ The p rimar y VLA N can be ta gged or unta gged as ne eded in th e stacking pat h from switch to swit ch. ■ The same VL AN ID (VI D) must be a ssigned to th e primary VLAN ...

  • IronPort Systems 4108GL - page 306

    13-4 8 HP P rocurv e Stac k Managem ent HP P rocurv e St ack Ma nag ement HP Proc urve Stack Manageme nt Status Messages Stacking screens and listings display these status messages: Message Condition Actio n or Remedy Cand idate Auto -join Ind icates a s witc h con figur ed with S tack Sta te set to Candid ate, Au to Join set to Ye s (the default), ...

  • IronPort Systems 4108GL - page 307

    14-1 Port-Based V irtual LANs (VLANs) and GVRP 14 Port-Based V irtual LANs (VLANs) an d GVRP Contents Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-3 Port-B ased Virt ual LA Ns (Stati c VLAN s) . . . . . . . . . . . . . . . . . . . . . . 14-4 Overview of Using VLANs . . . . . . . ...

  • IronPort Systems 4108GL - page 308

    14-2 Port -Based Virt ual LANs (VLANs ) and G VRP Conte nts Port-Ba sed Virtual LANs (VLANs) and GVRP Configuring GVRP On a Switch . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-37 Menu: Viewing and Configuring GVRP . . . . . . . . . . . . . . . . . . . . 14-37 CLI: Viewing and Co nfiguring GVRP . . . . . . . . . . . . . . . . . . . ...

  • IronPort Systems 4108GL - page 309

    14-3 Port-B ased Virtual LA Ns (VLANs) an d GVRP Overvi ew Port-Based V irtual LANs (VLANs) and GVRP Overview This chapt er describe s the follow ing featur es and h ow to conf igure the m with the switch ’ s built-in int erface s: ■ Port-Based VLANs — Page 14 -4: ■ GVRP — Page 14- 30: For gener al inform atio n on how to u se the swi tch ...

  • IronPort Systems 4108GL - page 310

    14-4 Port -Based Virt ual LANs (VLANs ) and G VRP Port -Based Virt ual LAN s (Stat ic V LANs) Port-Ba sed Virtual LANs (VLANs) and GVRP Port-Based V irtual LANs (Static VLANs) VLAN Fe ature s A VLAN is a group of ports designa ted by the switch as belonging to the same broadca st domain . (That is, all por ts carrying traffic f or a particu lar sub ...

  • IronPort Systems 4108GL - page 311

    14-5 Port-B ased Virtual LA Ns (VLANs) an d GVRP Port-Based Vi rtual LANs (Stati c VLANs) Port-Based V irtual LANs (VLANs) and GVRP eliminat ed and ba ndwidth is sav ed by not allo wing pac kets to flo od out all ports. An ex ternal router is req uired to ena ble separate VLA Ns on a switch t o communic ate with each othe r . For example , referr i ...

  • IronPort Systems 4108GL - page 312

    14-6 Port -Based Virt ual LANs (VLANs ) and G VRP Port -Based Virt ual LAN s (Stat ic V LANs) Port-Ba sed Virtual LANs (VLANs) and GVRP Figur e 14-2 . Examp le of Ov erla ppin g VLAN s Usin g the Sam e Serv er Similarly , using 8 02.1Q-compli ant switches , you can conne ct multiple VLA Ns through a sin gle switch-to-switch li nk. Figur e 14-3 . Ex ...

  • IronPort Systems 4108GL - page 313

    14-7 Port-B ased Virtual LA Ns (VLANs) an d GVRP Port-Based Vi rtual LANs (Stati c VLANs) Port-Based V irtual LANs (VLANs) and GVRP Figure 14-4. Exa mple of T agged and Unt agged V LAN T echnology in the Sam e Network For more informa tion on VLANs, re fer to : ■ “ Overv iew of Usin g VLA Ns ” (page 1 4-7) ■ “ Menu : Config urin g VLAN P ...

  • IronPort Systems 4108GL - page 314

    14-8 Port -Based Virt ual LANs (VLANs ) and G VRP Port -Based Virt ual LAN s (Stat ic V LANs) Port-Ba sed Virtual LANs (VLANs) and GVRP to ensure th at multip le instances o f DHCP or Bootp on di fferent VLA Ns do not result in conflicting configurati on values for the switch. The primary VLAN is the VLAN the switc h uses to run and man age these f ...

  • IronPort Systems 4108GL - page 315

    14-9 Port-B ased Virtual LA Ns (VLANs) an d GVRP Port-Based Vi rtual LANs (Stati c VLANs) Port-Based V irtual LANs (VLANs) and GVRP Figure 14-5. Comparing P er -Port VLAN Op tions With an d Without GVRP T able 14-1. Per-Port VLAN Configu ration Optio ns Examp le of Per -Port VLAN Config uration with GV RP Disable d (the d efault) Exam ple of Pe r - ...

  • IronPort Systems 4108GL - page 316

    14-1 0 Port -Based Virt ual LANs (VLANs ) and G VRP Port -Based Virt ual LAN s (Stat ic V LANs) Port-Ba sed Virtual LANs (VLANs) and GVRP Gene ral Steps for U sing VL ANs 1. Plan your VLA N strateg y and create a map of the logical top ology that will result fro m configur ing VLA Ns. Include consider ation for the inte raction between V LANs and o ...

  • IronPort Systems 4108GL - page 317

    14-1 1 Port-B ased Virtual LA Ns (VLANs) an d GVRP Port-Based Vi rtual LANs (Stati c VLANs) Port-Based V irtual LANs (VLANs) and GVRP Menu: Configuring VLAN Parameters In the facto ry default sta te, support is e nabled for up to eight VLANs. (Y ou can change the switch V LAN conf iguration t o support up to 30 VLANs.) A lso, all ports on the sw it ...

  • IronPort Systems 4108GL - page 318

    14-1 2 Port -Based Virt ual LANs (VLANs ) and G VRP Port -Based Virt ual LAN s (Stat ic V LANs) Port-Ba sed Virtual LANs (VLANs) and GVRP ■ T o change t he maxim um numbe r of VLA Ns, type the new num ber (1 - 30 allowe d; defa ult 8) . ■ T o design ate a diff erent VLAN a s th e prima ry V LAN, sele ct the Primary VLAN field and use the spa ce ...

  • IronPort Systems 4108GL - page 319

    14-1 3 Port-B ased Virtual LA Ns (VLANs) an d GVRP Port-Based Vi rtual LANs (Stati c VLANs) Port-Based V irtual LANs (VLANs) and GVRP Adding or Editing VLAN Names Use this proc edure t o add a n ew VLAN or to edit the name of an exist ing VLAN. 1. F rom th e M ain Men u se lect : 2. Switch Config uration 8. VLAN Menu . . . 2. VLAN Names If multip l ...

  • IronPort Systems 4108GL - page 320

    14-1 4 Port -Based Virt ual LANs (VLANs ) and G VRP Port -Based Virt ual LAN s (Stat ic V LANs) Port-Ba sed Virtual LANs (VLANs) and GVRP Figure 14-9. Example of VLAN Names Screen with a New VLAN Added 6. Repeat steps 2 th rough 5 to add more VLANs. Rememb er tha t you c an add VLANs un til y ou reac h the n umber specif ied in the Maximum VLANs to ...

  • IronPort Systems 4108GL - page 321

    14-1 5 Port-B ased Virtual LA Ns (VLANs) an d GVRP Port-Based Vi rtual LANs (Stati c VLANs) Port-Based V irtual LANs (VLANs) and GVRP Figure 14-10. Example of VLAN Port Assignment Screen 2. T o ch ange a port ’ s VLAN assignment(s): a. Press [E] (for E dit ). b. Use the arrow k eys t o sel ect a VLAN assi gnme nt you w ant to chan ge. c. P ress t ...

  • IronPort Systems 4108GL - page 322

    14-1 6 Port -Based Virt ual LANs (VLANs ) and G VRP Port -Based Virt ual LAN s (Stat ic V LANs) Port-Ba sed Virtual LANs (VLANs) and GVRP Figure 14-11. Example of VLAN Assignments for Specific Ports For info rmat ion on VLA N tag s ( “ Untagged ” and “ T agged ” ), refer to “ VLAN T agg ing Info rmation ” on pa ge 14- 23. d. If you are ...

  • IronPort Systems 4108GL - page 323

    14-1 7 Port-B ased Virtual LA Ns (VLANs) an d GVRP Port-Based Vi rtual LANs (Stati c VLANs) Port-Based V irtual LANs (VLANs) and GVRP VLAN Comman ds Used in this Section Displaying the Switch ’ s VLAN Configura tion. The next comman d lists the V LANs cu rrently ru nning in the sw itch, wi th VID , VLAN name, and VLAN status. Dynamic VLANs appear ...

  • IronPort Systems 4108GL - page 324

    14-1 8 Port -Based Virt ual LANs (VLANs ) and G VRP Port -Based Virt ual LAN s (Stat ic V LANs) Port-Ba sed Virtual LANs (VLANs) and GVRP Displaying t he Configurati on for a Parti cular VLAN . Th is comma nd uses the VID to identify and di splay the da ta for a specif ic static or dyna mic VLAN. Synta x: show vlan < vlan-id > Figure 14-13. E ...

  • IronPort Systems 4108GL - page 325

    14-1 9 Port-B ased Virtual LA Ns (VLANs) an d GVRP Port-Based Vi rtual LANs (Stati c VLANs) Port-Based V irtual LANs (VLANs) and GVRP Changing t he Number of VLANs Allo wed on the S witch. By default, the swi tch allows a maximum of 8 VL ANs. Y ou can specif y any value from 1 to 30. (If GVR P is en abled , this s ettin g incl udes an y dyna mic VL ...

  • IronPort Systems 4108GL - page 326

    14-2 0 Port -Based Virt ual LANs (VLANs ) and G VRP Port -Based Virt ual LAN s (Stat ic V LANs) Port-Ba sed Virtual LANs (VLANs) and GVRP Creatin g a New St atic VLA N Changin g the VL AN Context Level. W ith this comman d, enter ing a new VID crea tes a new static VL AN. Entering the VI D or nam e of a n existi ng static VLAN places you in t he co ...

  • IronPort Systems 4108GL - page 327

    14-2 1 Port-B ased Virtual LA Ns (VLANs) an d GVRP Port-Based Vi rtual LANs (Stati c VLANs) Port-Based V irtual LANs (VLANs) and GVRP Converting a Dynamic V LAN to a Static V LAN. If GVRP is runnin g on the switc h and a port dynamica lly joins a VLAN , you ca n use the ne xt command t o conv ert the d ynami c VLAN to a static VLAN. (For GVR P and ...

  • IronPort Systems 4108GL - page 328

    14-2 2 Port -Based Virt ual LANs (VLANs ) and G VRP Port -Based Virt ual LAN s (Stat ic V LANs) Port-Ba sed Virtual LANs (VLANs) and GVRP (For in formation on dy namic VL AN and G VRP o peratio n, see “ GVRP ” on page 14 -30.) For examp le, suppose you have a VLAN name d VLAN1 00 with a VI D of 100, and a ll ports a re s et to No for thi s VL A ...

  • IronPort Systems 4108GL - page 329

    14-2 3 Port-B ased Virtual LA Ns (VLANs) an d GVRP Port-Based Vi rtual LANs (Stati c VLANs) Port-Based V irtual LANs (VLANs) and GVRP 3. Cli ck on [Add/Remove VL ANs] . For web-ba sed Help on how to u se the web brow ser interfa ce screen, clic k on the [?] button pro vided on the web browse r screen. VLAN T agging Information VLAN tagg ing enables ...

  • IronPort Systems 4108GL - page 330

    14-2 4 Port -Based Virt ual LANs (VLANs ) and G VRP Port -Based Virt ual LAN s (Stat ic V LANs) Port-Ba sed Virtual LANs (VLANs) and GVRP Figure 14-17. Exa mple of T a gged a nd Untagged VLAN Port Assignments ■ In switch X: • VLANs assigne d to ports X1 - X6 can all be unta gged because there is only one V LAN assignme nt per port. Re d VLAN tr ...

  • IronPort Systems 4108GL - page 331

    14-2 5 Port-B ased Virtual LA Ns (VLANs) an d GVRP Port-Based Vi rtual LANs (Stati c VLANs) Port-Based V irtual LANs (VLANs) and GVRP Note Each 802.1Q-complia nt VLAN must ha ve its own uniqu e VID number , and that VLAN must be given the same VID in every device in w hich it is configured. T h a t i s , i f t h e R e d V L A N h a s a V I D o f 1 ...

  • IronPort Systems 4108GL - page 332

    14-2 6 Port -Based Virt ual LANs (VLANs ) and G VRP Port -Based Virt ual LAN s (Stat ic V LANs) Port-Ba sed Virtual LANs (VLANs) and GVRP Figure 14-19. Example of Networked 802.1Q-Co mpliant Devices with Multiple VLANs on Some Ports The VLANs assigne d to ports X3, X4, Y2, Y3, and Y4 ca n all be untagg ed because th ere is only on e VLAN a ssigned ...

  • IronPort Systems 4108GL - page 333

    14-2 7 Port-B ased Virtual LA Ns (VLANs) an d GVRP Port-Based Vi rtual LANs (Stati c VLANs) Port-Based V irtual LANs (VLANs) and GVRP To s u m m a r i z e : Effect of VLANs on Other Switch Fe atures Spanning T ree Protocol Operation with VLANs Becau se the Swit ch 4108G L follows th e 802.1Q V LAN recom menda tion to use single-instance spanning tr ...

  • IronPort Systems 4108GL - page 334

    14-2 8 Port -Based Virt ual LANs (VLANs ) and G VRP Port -Based Virt ual LAN s (Stat ic V LANs) Port-Ba sed Virtual LANs (VLANs) and GVRP VLAN MAC Ad dresses The switch has one unique MAC ad dress for each of its VLAN inte rfaces. Y ou can send an 802. 2 test packet to this MAC address to verify conne ctivity to the switch. Likewise , you can a ssi ...

  • IronPort Systems 4108GL - page 335

    14-2 9 Port-B ased Virtual LA Ns (VLANs) an d GVRP Port-Based Vi rtual LANs (Stati c VLANs) Port-Based V irtual LANs (VLANs) and GVRP VLAN Restricti ons ■ A port must be a membe r of at least on e VLAN. In the factory de fault config uration, all po rts are a ssigned to the defaul t VLAN (DEF AUL T_ VLAN; VI D = 1). ■ A port ca n be a ssign ed ...

  • IronPort Systems 4108GL - page 336

    14-3 0 Port -Based Virt ual LANs (VLANs ) and G VRP GVRP Port-Ba sed Virtual LANs (VLANs) and GVRP GVRP GVRP — GARP VLAN Reg istration P rotocol — is an app lication o f the Ge neric Attr ibut e Re gistr atio n Pr otoc ol — GARP . GVRP is defined in the IEEE 802 .1Q standa rd, and G ARP is def i ned in the IEEE 8 02.1D- 1998 standa rd. Note T ...

  • IronPort Systems 4108GL - page 337

    14-3 1 Port-B ased Virtual LA Ns (VLANs) an d GVRP GVRP Port-Based V irtual LANs (VLANs) and GVRP General Operation When GVR P is enabl ed on a sw itch, the VID for any stat ic VLANs con figured on the swi tch i s advertis ed (u sing BPDUs — Bridge Protocol Data Unit s) out all port s, regardl ess of whethe r a port is up or assig ned to any part ...

  • IronPort Systems 4108GL - page 338

    14-3 2 Port -Based Virt ual LANs (VLANs ) and G VRP GVRP Port-Ba sed Virtual LANs (VLANs) and GVRP For exam ple, i n the foll owing figure, T ag ged VLAN ports on switch “ A ” and switch “ C ” ad vertise VLANs 22 and 33 to por ts on ot her GVR P-enab led switches that can dynam ically join the VLANs. Figure 14-21. Example of GVRP Operation ...

  • IronPort Systems 4108GL - page 339

    14-3 3 Port-B ased Virtual LA Ns (VLANs) an d GVRP GVRP Port-Based V irtual LANs (VLANs) and GVRP Note also t hat a port belong ing t o a T agged or Un tagg ed st atic V LAN h as the se configura ble optio ns: ■ Send VL AN advert isemen ts, and also r eceive advertisem ents fo r VLANs on other port s and dynami cally join those VLA Ns. ■ Send V ...

  • IronPort Systems 4108GL - page 340

    14-3 4 Port -Based Virt ual LANs (VLANs ) and G VRP GVRP Port-Ba sed Virtual LANs (VLANs) and GVRP T able 14-2. Options for Handling “ Unknown VLAN ” Advertisements: The CLI show gvrp command and the menu interf ace VLA N Support scre en show a swi tch ’ s curren t GVRP con figuratio n, including the Unknown VLAN settings. Figure 14-22. Examp ...

  • IronPort Systems 4108GL - page 341

    14-3 5 Port-B ased Virtual LA Ns (VLANs) an d GVRP GVRP Port-Based V irtual LANs (VLANs) and GVRP Per -Port Opti ons for Dynamic VLAN Advert ising and Joining Initiating Advertisements. A s des cribe d in the prec eding section , to enable dynamic join s, GVRP must be enabl ed and a port must be conf igured to Learn (the de fault). How ever , to se ...

  • IronPort Systems 4108GL - page 342

    14-3 6 Port -Based Virt ual LANs (VLANs ) and G VRP GVRP Port-Ba sed Virtual LANs (VLANs) and GVRP As the prec eeding ta ble indica tes, when yo u enable GV RP , a port that ha s a T agg ed o r Unt agged st atic V LAN h as the opt ion f or bo th g ener atin g ad vertis e- ments an d dynamica lly joining ot her VLANs. Note In table 14-3, abo ve, the ...

  • IronPort Systems 4108GL - page 343

    14-3 7 Port-B ased Virtual LA Ns (VLANs) an d GVRP GVRP Port-Based V irtual LANs (VLANs) and GVRP Planning for G VRP Oper ation These step s outlin e the proce dure for set ting up dyna mic VLA Ns for a seg- ment. 1. D eterm ine th e VLA N topo log y you wa nt for ea ch se gmen t (broa dca st domai n) on your ne twork . 2. Determin e the VL ANs tha ...

  • IronPort Systems 4108GL - page 344

    14-3 8 Port -Based Virt ual LANs (VLANs ) and G VRP GVRP Port-Ba sed Virtual LANs (VLANs) and GVRP 2. Switch Con figuratio n . . . 8. VLAN Menu . . . 1. VLAN Support Figure 14-23. The VLAN Support Scre en (Defau lt Configu ration) 2. Do the followin g to enable GVRP and disp lay the Un known V LAN fields: a. Press [E] (for E dit ). b. Use [v] to mo ...

  • IronPort Systems 4108GL - page 345

    14-3 9 Port-B ased Virtual LA Ns (VLANs) an d GVRP GVRP Port-Based V irtual LANs (VLANs) and GVRP CLI: Vi ewing and Con figuring GVRP GVRP Comman ds Used in This Se ction Displaying the Switch ’ s Current GVRP Configur ation. This command shows whether GVRP is disabled, a long with the c urrent sett ings for the maximum nu mber of VLANs a nd the ...

  • IronPort Systems 4108GL - page 346

    14-4 0 Port -Based Virt ual LANs (VLANs ) and G VRP GVRP Port-Ba sed Virtual LANs (VLANs) and GVRP Enabling an d Disabling GVRP on th e Switch. This comman d enabl es GVRP on th e swit ch. Synta x: gvrp This exam ple ena bles GVRP: HP4108(config)# gvrp This example disa bles GVRP op eratio n on the switch: HP4108(config)# no gvrp Enabling and Disab ...

  • IronPort Systems 4108GL - page 347

    14-4 1 Port-B ased Virtual LA Ns (VLANs) an d GVRP GVRP Port-Based V irtual LANs (VLANs) and GVRP Displaying th e Static and Dyna mic VLANs Activ e on the Switch. The show vlans command lists all VLANs present in the switch. Synta x: show vlan s For example, in t he following i llustration , switch “ B ” has one sta tic VLAN (the default VLA N) ...

  • IronPort Systems 4108GL - page 348

    14-4 2 Port -Based Virt ual LANs (VLANs ) and G VRP GVRP Port-Ba sed Virtual LANs (VLANs) and GVRP Converting a Dynamic V LAN to a Static V LAN. If a port o n the switch has joined a dy namic VLAN , you can use the followi ng command t o convert that dy namic VLAN to a st atic V LAN: Synta x: stat ic < dynamic - vlan-id > For ex ample, to con ...

  • IronPort Systems 4108GL - page 349

    14-4 3 Port-B ased Virtual LA Ns (VLANs) an d GVRP GVRP Port-Based V irtual LANs (VLANs) and GVRP ■ Conver ting a dynamic VLAN to a st atic VLA N and then e xecutin g the write memory comman d saves the VLAN in the startup-c onfig file and make s it a pe rmanen t pa rt of the swi tch ’ s VLAN co nfigura tion. ■ W ithin the same broadc ast dom ...

  • IronPort Systems 4108GL - page 350

    14-4 4 Port -Based Virt ual LANs (VLANs ) and G VRP GVRP Port-Ba sed Virtual LANs (VLANs) and GVRP ...

  • IronPort Systems 4108GL - page 351

    15-1 Multime dia Traffic Control with I P Multicast (IGMP) 15 Multimed ia T raff ic Control with IP Multic ast (IGMP) Chapter Contents Chapter Contents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-1 Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ...

  • IronPort Systems 4108GL - page 352

    15-2 Multimed ia Traff ic Co ntrol wit h IP Mu lticast ( IGMP) Overv iew Multime dia Traffic Control with I P Multicast (IGMP) Overview This chapt er describe s the follow ing featur es and h ow to conf igure the m with the switch ’ s built-in int erface s: ■ Multimedia T raffic C ontrol wi th IP Mult icast (IGMP) : Use the switch to redu ce un ...

  • IronPort Systems 4108GL - page 353

    15-3 Multimed ia Traffi c Control with I P Multicast (IGM P) Gener al Ope ratio n and Fe atures Multime dia Traffic Control with I P Multicast (IGMP) General Operation and Features IGMP Feat ures In a n etwork where IP multi cast traff ic is t ransmitte d for various multi media applica tions, you ca n use the sw itch to re duce un necessar y bandw ...

  • IronPort Systems 4108GL - page 354

    15-4 Multimed ia Traff ic Co ntrol wit h IP Mu lticast ( IGMP) Gener al Oper ation and Fea tures Multime dia Traffic Control with I P Multicast (IGMP) Note IGMP config uration o n the Switc h 4108G L operates a t the VLA N contex t level. If you a re not u sing VLA Ns, then conf igure I GMP in VL AN 1 ( the de fault VL AN) cont ext. IGMP T erms ■ ...

  • IronPort Systems 4108GL - page 355

    15-5 Multimed ia Traffi c Control with I P Multicast (IGM P) Gener al Ope ratio n and Fe atures Multime dia Traffic Control with I P Multicast (IGMP) IGMP Operati ng Featur es Basic Operation In the factor y default config uration, IGMP is disab led. If multiple VL ANs are not config ured, you must configure IGM P on the defa ult VLAN (DEF AUL T_VL ...

  • IronPort Systems 4108GL - page 356

    15-6 Multimed ia Traff ic Co ntrol wit h IP Mu lticast ( IGMP) CLI: Confi gurin g and Di spla ying IG MP Multime dia Traffic Control with I P Multicast (IGMP) ■ Querier C apability: The swi tch perf orms this fu ncti on f or IG MP o n VLANs ha ving an IP addr ess when there is no ot her de vice i n the VLAN actin g as quer ier . Se e “ Querier ...

  • IronPort Systems 4108GL - page 357

    15-7 Multimed ia Traffi c Control with I P Multicast (IGM P) CLI: Co nfi gurin g and Disp layi ng IGMP Multime dia Traffic Control with I P Multicast (IGMP) V iewing t he Current IGMP Configur ation. This c om ma nd l ist s th e IGM P config uration for all VLANs c onfigured on the swit ch or for a specific V LAN. Synta x: show ip igm p config IGMP ...

  • IronPort Systems 4108GL - page 358

    15-8 Multimed ia Traff ic Co ntrol wit h IP Mu lticast ( IGMP) CLI: Confi gurin g and Di spla ying IG MP Multime dia Traffic Control with I P Multicast (IGMP) Figure 15-2. Example Listing of IGMP Configura tion for A Specific VLAN Enabling or Disabling IGMP on a VLAN. Y ou can en able IGM P on a VLAN, along w ith the last -saved or de fault IGMP c ...

  • IronPort Systems 4108GL - page 359

    15-9 Multimed ia Traffi c Control with I P Multicast (IGM P) CLI: Co nfi gurin g and Disp layi ng IGMP Multime dia Traffic Control with I P Multicast (IGMP) Configuring Per -Port IGMP Packet Control. Use t his co mmand in the VLAN con text to speci fy how each po rt should hand le IGMP tra ffic. Synta x: vlan < vid > ip igm p [auto < port- ...

  • IronPort Systems 4108GL - page 360

    15-1 0 Multimed ia Traff ic Co ntrol wit h IP Mu lticast ( IGMP) CLI: Confi gurin g and Di spla ying IG MP Multime dia Traffic Control with I P Multicast (IGMP) HP4108 (vlan 1)# no ip igmp Return s IGMP traf fic to high-priority-forward “ normal ” prior ity . HP4108 > show ip igmp config Show comman d to display results of above high-prior i ...

  • IronPort Systems 4108GL - page 361

    15-1 1 Multimed ia Traffi c Control with I P Multicast (IGM P) How IGMP Operates Multime dia Traffic Control with I P Multicast (IGMP) How IGMP Operates The Intern et Group Mana gement Pr otocol (IGM P) is an inter nal protoco l of the Inter net Proto col (IP) su ite. IP manages mu lticast tr affic by u sing switches, multica st routers, and host s ...

  • IronPort Systems 4108GL - page 362

    15-1 2 Multimed ia Traff ic Co ntrol wit h IP Mu lticast ( IGMP) How IGMP Operate s Multime dia Traffic Control with I P Multicast (IGMP) Thus, IGMP ident ifies membe rs of a multicast g roup (within a subnet) and allows I GMP-config ured hosts (and routers) t o join or leave m ulticast g roups. IGMP Data. T o di splay da ta showing active group ad ...

  • IronPort Systems 4108GL - page 363

    15-1 3 Multimed ia Traffi c Control with I P Multicast (IGM P) How IGMP Operates Multime dia Traffic Control with I P Multicast (IGMP) Automatic Fast-Leave IGMP IGMP Oper ation Prese nts a "Delay ed Leave" Problem. Where m ultiple IGMP clie nts are conn ected to th e same port o n an IGMP d evice (swi tch or router ), if only on e IGMP c ...

  • IronPort Systems 4108GL - page 364

    15-1 4 Multimed ia Traff ic Co ntrol wit h IP Mu lticast ( IGMP) How IGMP Operate s Multime dia Traffic Control with I P Multicast (IGMP) In the n ext figure, automatic F ast-Leave o perates o n the switch ports for IGMP client s "3A" and "5B", but not on the swi tch port for IGMP clients "7A " and 7B, Server "7C& ...

  • IronPort Systems 4108GL - page 365

    15-1 5 Multimed ia Traffi c Control with I P Multicast (IGM P) How IGMP Operates Multime dia Traffic Control with I P Multicast (IGMP) Configuration Option s for Forced Fast-Leave Note o n VLAN Number s: In the HP Pr ocurve Swi tch 4108G L, the walk mib and setmib comman ds use an intern al VLAN number (and no t the VLA N ID, or VID) to d isplay or ...

  • IronPort Systems 4108GL - page 366

    15-1 6 Multimed ia Traff ic Co ntrol wit h IP Mu lticast ( IGMP) How IGMP Operate s Multime dia Traffic Control with I P Multicast (IGMP) - OR - walkmib 1.3.6.1.4.1.11.2.14.11.5.1.7.1.15.3.1.5 The resultin g display lists t he Forced Fast- Leave state for a ll ports i n the switch, by VLAN. ( A port belo nging to more than one VL AN will be list ed ...

  • IronPort Systems 4108GL - page 367

    15-1 7 Multimed ia Traffi c Control with I P Multicast (IGM P) How IGMP Operates Multime dia Traffic Control with I P Multicast (IGMP) Figure 15-5. Examp le Listing the For ced Fast-Lea ve State for a Single Port on the Default VLAN Configuring Per -Po rt Forced Fast-Leave IGMP In the factory -default configura tion, Forced Fast-Lea ve is di sabled ...

  • IronPort Systems 4108GL - page 368

    15-1 8 Multimed ia Traff ic Co ntrol wit h IP Mu lticast ( IGMP) How IGMP Operate s Multime dia Traffic Control with I P Multicast (IGMP) DEFAULT_CONFIG: setmib hpSwitchIgmpPortForcedLe- aveState.1.49 -i 1 Figure 15-6. E xample o f Chan ging the Forced Fa st-Leave Configur ation on Port 49 Using the Swi tch as Querier Querier Operation The func tio ...

  • IronPort Systems 4108GL - page 369

    15-1 9 Multimed ia Traffi c Control with I P Multicast (IGM P) The Swi tch E xclud es W ell-Kn own o r Res erved Mult icast Addr esses from I P Mul ticast Filt ering Multime dia Traffic Control with I P Multicast (IGMP) In the abo ve scenari o, if the ot her device ce ases to operat e as a Querier on the default VL AN, then t he switch detect s thi ...

  • IronPort Systems 4108GL - page 370

    15-2 0 Multimed ia Traff ic Co ntrol wit h IP Mu lticast ( IGMP) The Sw itch Excl udes We ll-Kno wn or Rese rved Multicas t Addre sses from IP Mu lticast Filteri ng Multime dia Traffic Control with I P Multicast (IGMP) Note: IP Mult ica st Filt ers. IP multica st addresses oc cur in the range fro m 224. 0.0.0 t hroug h 239. 255.2 55.2 55 (whi ch co ...

  • IronPort Systems 4108GL - page 371

    16-1 Spanni ng Tree Protocol (STP) 16 Spann ing T ree Prot ocol (STP) Chapter Contents Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-2 Menu: Configuring STP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-4 CLI: Configuring STP . . . . . . . ...

  • IronPort Systems 4108GL - page 372

    16-2 Span ning Tree Pro tocol (S TP) Overv iew Spanni ng Tree Prot ocol (STP) Overview STP Fe atu res Use the Spanning T ree Protocol (STP — IEEE 802.1D ) to ensu re that only one active pat h at a time exists be tween a ny two node s on the networ k. In networks w here t here is mo re than on e physic al, act ive path be twee n any two nodes, en ...

  • IronPort Systems 4108GL - page 373

    16-3 Spanni ng Tree Pr otocol (STP) Overvi ew Spanni ng Tree Protocol (STP) As rec ommende d in the IE EE 802. 1Q VLAN stan dard, t he Switch 4 108GL uses single-insta nce STP . (As a result, the switch gener ates untagged Bridge Protocol Data Units — BPDU s.) This implementation creates a single spanning tree to m ake sure ther e are n o network ...

  • IronPort Systems 4108GL - page 374

    16-4 Span ning Tree Pro tocol (S TP) Menu : Confi gurin g STP Spanni ng Tree Prot ocol (STP) Menu: Configuring STP 1. F rom th e M ain Men u, s elec t: 2. Switch Con figuratio n . . . 4. Span ning T ree Ope rati on 2. Press [E] (for E dit ) to highl ight the Spanning T ree Enab led parameter . 3. Press the Space bar to select Ye s . ( Ye s in this ...

  • IronPort Systems 4108GL - page 375

    16-5 Spanni ng Tree Pr otocol (STP) CLI: Confi guring ST P Spanni ng Tree Protocol (STP) 7. When you are fi nished edi ting par ameters, press [En ter] to re turn to t h e Actions line. 8. Press [S] to save the currentl y displaye d STP para meter set tings , then return to the Main Me nu. CLI: Confi guring ST P STP Co mmands Use d in This Sectio n ...

  • IronPort Systems 4108GL - page 376

    16-6 Span ning Tree Pro tocol (S TP) CLI: Confi gur ing ST P Spanni ng Tree Prot ocol (STP) Figure 16-2. Example o f the Defaul t STP Con figuration Listing Enabling or Disabling STP . Ena bling S TP imple ments the sp anning-t ree protocol f or all physica l ports on the sw itch, rega rdless of whe ther multiple VLANs are configur ed. Disabli ng S ...

  • IronPort Systems 4108GL - page 377

    16-7 Spanni ng Tree Pr otocol (STP) CLI: Confi guring ST P Spanni ng Tree Protocol (STP) Caut ion Because incorrect S TP setti ngs can adversel y aff ect netwo rk perf orma nce, HP reco mmends that you use the de fault STP pa ramete r settings. Y ou shou ld not chang e these se ttings u nless you h ave a stro ng under standing of how STP operate s. ...

  • IronPort Systems 4108GL - page 378

    16-8 Span ning Tree Pro tocol (S TP) CLI: Confi gur ing ST P Spanni ng Tree Prot ocol (STP) For exa mple, to conf igure a m aximum -age of 30 sec onds an d a hell o-time of 3 seconds for STP: HP4108(config)# spanning-tree maximum-age 30 hello-time 3 Reconfigu ring Per -Port STP Oper ation on the Switch . This comm and enab les STP (if not already e ...

  • IronPort Systems 4108GL - page 379

    16-9 Spanni ng Tree Pr otocol (STP) Web: Enabling o r Disa bling STP Spanni ng Tree Protocol (STP) W eb: Enab ling or Disabling STP In the w eb browse r inter face yo u can e nable or disa ble STP on t he switch. T o config ure other ST P feature s, telnet to the swit ch console and use th e CLI. T o enable o r disable STP on t he switch: 1. Cli ck ...

  • IronPort Systems 4108GL - page 380

    16-1 0 Span ning Tree Pro tocol (S TP) How ST P Oper ates Spanni ng Tree Prot ocol (STP) Figure 16-3. Example of Redun dant Paths Betwe en T wo Nod es STP Fast Mode For standa rd STP op eration , when a netw ork conne ction is esta blished on a device that is ru nning STP , the por t used for the conn ection goe s throu gh a sequence of states (Lis ...

  • IronPort Systems 4108GL - page 381

    16-1 1 Spanni ng Tree Pr otocol (STP) How ST P Opera tes Spanni ng Tree Protocol (STP) If you en counte r end node s that rep eated ly indica te serve r access failu re whe n attempt ing t o bring up th eir n etwork connect ion, and you have e nabled STP on the switch, t ry chan ging the co nfigura tion of the switch port s associated with those en ...

  • IronPort Systems 4108GL - page 382

    16-1 2 Span ning Tree Pro tocol (S TP) How ST P Oper ates Spanni ng Tree Prot ocol (STP) STP Operation with 802.1Q VLANs As recomme nded in the I EEE 802.1Q VLAN standa rd, when spanni ng tree is enable d on the switch, a sin gle spanni ng tree is con figured fo r all ports acr oss the switch, inc luding tho se in separat e VLANs (that is, single-i ...

  • IronPort Systems 4108GL - page 383

    16-1 3 Spanni ng Tree Pr otocol (STP) How ST P Opera tes Spanni ng Tree Protocol (STP) ...

  • IronPort Systems 4108GL - page 384

    16-1 4 Span ning Tree Pro tocol (S TP) How ST P Oper ates Spanni ng Tree Prot ocol (STP) ...

  • IronPort Systems 4108GL - page 385

    17-1 Mon itor ing an d An alyzi ng Switch Op eration 17 Monitoring and Analyzing Switch Operation Contents Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-2 Status and Counters Da ta . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17- 3 Menu Access T ...

  • IronPort Systems 4108GL - page 386

    17- 2 Monit oring and An alyzin g Sw itch Opera tio n Overv iew Monito ring and Analyz ing Sw itch O perat ion Overview The Switch 4 108GL has seve ral built- in tools for moni toring, an alyzin g, and troubles hooting swit ch and ne twork oper ation: ■ Status : Includ es opti ons for display ing gene ral switch in format ion, man- agement ad dre ...

  • IronPort Systems 4108GL - page 387

    17-3 Monit oring an d Anal yzing Swi tch Oper ation Status an d Counter s Data Mon itor ing an d An alyzi ng Switch Op eration Status and Counter s Data This sectio n describe s the sta tus and co unters scre ens avai lable t hrough the switch console interface and/ or the web brow ser interfa ce. Note Y ou can a ccess all co nsole scre ens from th ...

  • IronPort Systems 4108GL - page 388

    17- 4 Monit oring and An alyzin g Sw itch Opera tio n Stat us and Co unter s Data Monito ring and Analyz ing Sw itch O perat ion Menu Access T o Status and Counters Beginni ng at the Main Menu, displ ay the Stat us and Co unters menu by select- ing: 1. Stat us and C ounter s Figure 17-1. The Status and Counters Menu Each of t h e abo ve menu i tems ...

  • IronPort Systems 4108GL - page 389

    17-5 Monit oring an d Anal yzing Swi tch Oper ation Status an d Counter s Data Mon itor ing an d An alyzi ng Switch Op eration Genera l System Inf ormation Menu Access From the c onsole Main Menu, select : 1. Stat us and C ounter s 1. General Sy stem Information Figure 17-2. Example of Ge neral Switch Information This scree n dynamica lly indic ate ...

  • IronPort Systems 4108GL - page 390

    17- 6 Monit oring and An alyzin g Sw itch Opera tio n Stat us and Co unter s Data Monito ring and Analyz ing Sw itch O perat ion Switch Management Address Informatio n Menu Access Fro m the Mai n Me nu, se lect: 1 Statu s and Count ers . . . 2. Switch Management Addr ess Information Figure 17-3. Example of Management Addre ss Information with VLANs ...

  • IronPort Systems 4108GL - page 391

    17-7 Monit oring an d Anal yzing Swi tch Oper ation Status an d Counter s Data Mon itor ing an d An alyzi ng Switch Op eration Module Information Use this featur e to determin e whi ch slots have modu les installed a nd which type(s) of modules are insta lled. Menu: Displaying Port Status Fro m the Mai n Me nu, se lect: 1. Statu s and Coun ters . . ...

  • IronPort Systems 4108GL - page 392

    17- 8 Monit oring and An alyzin g Sw itch Opera tio n Stat us and Co unter s Data Monito ring and Analyz ing Sw itch O perat ion Port Status The web br owser inte rface and the conso le interf ace show t he same p ort status data. Menu: Displaying Port Status Fro m the Mai n Me nu, se lect: 1. Statu s and Coun ters . . . 4. Port S tatus Figur e 17- ...

  • IronPort Systems 4108GL - page 393

    17-9 Monit oring an d Anal yzing Swi tch Oper ation Status an d Counter s Data Mon itor ing an d An alyzi ng Switch Op eration V iewing Port and T runk Group Statisti cs and Flow Control Statu s These feat ures enab le you to dete rmine the traffic pa tterns fo r each port since the last re boot or reset of the switch. Y ou can d isplay: ■ A gene ...

  • IronPort Systems 4108GL - page 394

    17- 10 Monit oring and An alyzin g Sw itch Opera tio n Stat us and Co unter s Data Monito ring and Analyz ing Sw itch O perat ion Menu Access to Port and T ru nk Statistics T o acce ss this screen from the Main Menu, select: 1. Statu s and Coun ters . . . 4. Port Count ers Figur e 17 -6. Exa mple of Po rt C oun ters on t he M enu Inte rfac e T o vi ...

  • IronPort Systems 4108GL - page 395

    17- 11 Monit oring an d Anal yzing Swi tch Oper ation Status an d Counter s Data Mon itor ing an d An alyzi ng Switch Op eration CLI Access T o Port and T runk Grou p Statistics T o Display the Port Counter Su mmary Report. This comma nd pro vides an over view of por t activ ity for all p orts on the sw itch. Synta x: show inte rfac es T o Display ...

  • IronPort Systems 4108GL - page 396

    17- 12 Monit oring and An alyzin g Sw itch Opera tio n Stat us and Co unter s Data Monito ring and Analyz ing Sw itch O perat ion Vi ewing the Switch ’ s MAC Addr ess T ables These fe atures hel p you to view: ■ The MAC addresses that t he switch has learned from network devices attache d to the sw itch ■ The port on which ea ch MAC a ddress ...

  • IronPort Systems 4108GL - page 397

    17- 13 Monit oring an d Anal yzing Swi tch Oper ation Status an d Counter s Data Mon itor ing an d An alyzi ng Switch Op eration Menu Access to the MAC Addr ess Views and Searches Per -VLAN MAC- Address V iewing and Searchin g. This feat ure le ts you determine which switch port on a sel ected VL AN is being use d to communi- cate with a spe cific ...

  • IronPort Systems 4108GL - page 398

    17- 14 Monit oring and An alyzin g Sw itch Opera tio n Stat us and Co unter s Data Monito ring and Analyz ing Sw itch O perat ion Finding the Port Conn ection for a Specific De vice on a V LAN. This featur e uses a d evice ’ s MAC ad dress that you enter to identi fy the port used by th at devi ce. 1. Proc eeding from figure 17-8 , press [S] (for ...

  • IronPort Systems 4108GL - page 399

    17- 15 Monit oring an d Anal yzing Swi tch Oper ation Status an d Counter s Data Mon itor ing an d An alyzi ng Switch Op eration Figure 17-10.List ing MAC Addresses for a S pecific Por t 2. Use th e Space bar to select the por t you wan t to l ist or se arch for MAC addresses, then press [Ent er] to list the MAC addre sses detect ed on that port. D ...

  • IronPort Systems 4108GL - page 400

    17- 16 Monit oring and An alyzin g Sw itch Opera tio n Stat us and Co unter s Data Monito ring and Analyz ing Sw itch O perat ion Correspond ing Port Numbers. For example, to list the learned MAC address on ports A1 t hrough A4 and port A6: HP4108> show mac-address a1-a4,a6 T o List All Learned MAC Addr esses on a VLAN, wit h Their Port Numbers. ...

  • IronPort Systems 4108GL - page 401

    17- 17 Monit oring an d Anal yzing Swi tch Oper ation Status an d Counter s Data Mon itor ing an d An alyzi ng Switch Op eration Spanning T ree Protocol (STP) Informati on Menu Access to STP Data Fro m the Mai n Me nu, se lect: 1. Statu s and Coun ters . . . 8. Span ning T ree Infor mati on STP must be en abled on the switch to disp lay the followi ...

  • IronPort Systems 4108GL - page 402

    17- 18 Monit oring and An alyzin g Sw itch Opera tio n Stat us and Co unter s Data Monito ring and Analyz ing Sw itch O perat ion Figure 17-12.Exam ple of STP Port Information CLI Access to STP Data This option lists the STP config uratio n, root data, and per -port da ta (cost, priority , state, an d designated br idge). Synta x: show spann ing-tr ...

  • IronPort Systems 4108GL - page 403

    17- 19 Monit oring an d Anal yzing Swi tch Oper ation Status an d Counter s Data Mon itor ing an d An alyzi ng Switch Op eration Internet Group Ma nagement Protocol (IGMP) Status The switch use s the CLI to display the followin g IGMP status on a per -VLAN basis: For exam ple, su ppose t hat show ip igmp listed an IGMP gr oup address of 224.0.1 .22 ...

  • IronPort Systems 4108GL - page 404

    17- 20 Monit oring and An alyzin g Sw itch Opera tio n Stat us and Co unter s Data Monito ring and Analyz ing Sw itch O perat ion VLAN Information The switch uses the CLI to disp lay the fol lowing VLAN status: For examp le, suppose that your switch ha s the follow ing VLANs: Ports VLAN VID 1 - 12 DEF AUL T_VLAN 1 1, 2 V LAN-33 33 3, 4 V LAN-44 44 ...

  • IronPort Systems 4108GL - page 405

    17- 21 Monit oring an d Anal yzing Swi tch Oper ation Status an d Counter s Data Mon itor ing an d An alyzi ng Switch Op eration Listing th e VLAN ID ( VID) and S tatus fo r Speci fic Ports. Figure 17-15. Example of VLAN Listing for Spec ific Ports Listing Indiv idual VL AN St atus. Figure 17-16. Example of Por t Listing for an Ind ividual VLA N Be ...

  • IronPort Systems 4108GL - page 406

    17- 22 Monit oring and An alyzin g Sw itch Opera tio n Stat us and Co unter s Data Monito ring and Analyz ing Sw itch O perat ion W e b Browser Interface Stat us Information The “ home ” scre en for the web b rowser inter face is the St atus Ove rview screen, as shown be low . As the title implie s, it provides an overview of the status of the ...

  • IronPort Systems 4108GL - page 407

    17- 23 Monit oring an d Anal yzing Swi tch Oper ation Port M onitor ing F eatu res Mon itor ing an d An alyzi ng Switch Op eration Port Monitoring Features Port Mo nitor ing Fea tures Y ou can designat e a po rt for monito ring in coming tr affic of one or more ot her ports on the switc h. The switch monit ors the network a ctivity by copyin g all ...

  • IronPort Systems 4108GL - page 408

    17- 24 Monit oring and An alyzin g Sw itch Opera tio n Port Monit oring Fea tures Monito ring and Analyz ing Sw itch O perat ion Menu: Configuring Port Monitoring This proced ure descr ibes conf iguring t he switch for monitoring when mon i- toring is disabled . (If monitoring has alre ady been enabled, t he screens will appear differently t han sh ...

  • IronPort Systems 4108GL - page 409

    17- 25 Monit oring an d Anal yzing Swi tch Oper ation Port M onitor ing F eatu res Mon itor ing an d An alyzi ng Switch Op eration Figure 17-19. How T o Select a Monitoring Port 5. Use the Spa ce bar to select th e port to use for monitorin g. 6. U se t he do wnar row key to m ove th e cu rsor to t he Action colum n for the individua l ports and po ...

  • IronPort Systems 4108GL - page 410

    17- 26 Monit oring and An alyzin g Sw itch Opera tio n Port Monit oring Fea tures Monito ring and Analyz ing Sw itch O perat ion Y ou must use th e follow ing conf iguration se quenc e to configur e port monitor - ing in the CLI: 1. Ass ign a mon itorin g (mirror ) port. 2. D esign ate th e port (s) to m onito r . Displaying th e Port Monito ring C ...

  • IronPort Systems 4108GL - page 411

    17- 27 Monit oring an d Anal yzing Swi tch Oper ation Port M onitor ing F eatu res Mon itor ing an d An alyzi ng Switch Op eration Selecting o r Removing Ports A s Monitoring Sourc es. Afte r you conf ig- ure a moni tor port you can use either the globa l configur ation level or the interfac e context le vel to selec t ports as mo nitoring sources. ...

  • IronPort Systems 4108GL - page 412

    17- 28 Monit oring and An alyzin g Sw itch Opera tio n Port Monit oring Fea tures Monito ring and Analyz ing Sw itch O perat ion T o remove por t monitoring : 1. Cl ick o n the Monito ring Of f radi o button . 2. Cli ck on [Apply Changes] . For web-ba sed Help on how to u se the web brow ser interfa ce screen, clic k on the [?] button provid ed on ...

  • IronPort Systems 4108GL - page 413

    18-1 Trouble shootin g 18 T rou bleshoo ting Contents Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-2 Troubleshooting Approaches . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-3 Browser or Telnet Acc ess Problems . . . . . . . . . . . . . . . . . . . ...

  • IronPort Systems 4108GL - page 414

    18- 2 Trou blesh ooting Overv iew Trouble shooting Overview This chapt er ad dress es pe rforman ce-rel ated network probl ems th at ca n be caused by top ology , switch configur ation , and t he effect s of o ther dev ices or their config uration s on switch operatio n. (For switch-spe cific inform ation on hardware problems in dicated by LED beha ...

  • IronPort Systems 4108GL - page 415

    18-3 Trou blesh ooting Troub lesho oting Approa ches Trouble shootin g T roubl eshooting App roaches Use th ese appr oaches t o diagnose switch p roblem s: ■ Check the HP Proc urve w ebsite f or soft ware updates t hat m ay ha ve solve d your p roblem: http://www.hp.com/go/hppro curve ■ Check the switch LEDs for in dicatio ns of proper sw itch ...

  • IronPort Systems 4108GL - page 416

    18- 4 Trou blesh ooting Brows er or Teln et Access Proble ms Trouble shooting Browser or T elnet Access Problems Cannot a ccess the we b browser i nterface: ■ Access ma y be disabled by the W eb Ag ent Enabl ed parameter in the swi tch console. Ch eck the setting on t his paramet er by selectin g: 2. Switch Con figuratio n . . . 1. Sy stem Inform ...

  • IronPort Systems 4108GL - page 417

    18-5 Trou blesh ooting Brow ser or Teln et Acce ss Prob lems Trouble shootin g Cannot T elnet into the switch console from a stati on on the network : ■ T elnet ac cess may be dis abled by the Inbou nd T e lnet Enabl ed parameter in the System Informa tion scre en of the men u inter face: 2. Switch Config uration 1. Sy stem Information ■ The sw ...

  • IronPort Systems 4108GL - page 418

    18- 6 Trou blesh ooting Unusua l Netw ork Acti vity Trouble shooting Unusual Network Activity Netw ork act ivity that fails t o meet accept ed nor ms may in dica te a har dwar e problem w ith one or more of the networ k compo nents, possibly inc luding th e switch. Such problems can a lso be caused by a net work loo p or simply too much tr affic fo ...

  • IronPort Systems 4108GL - page 419

    18-7 Trou blesh ooting Unus ual Net work Activi ty Trouble shootin g This can also happen, for e xample, if the serve r is first config ured to i ssue IP addresse s with an unlimited du ration, then is subse quently conf igured to issue IP addresses that will exp ire after a limited duration. One solut ion is to config ure “ reservat ions ” in ...

  • IronPort Systems 4108GL - page 420

    18- 8 Trou blesh ooting Unusua l Netw ork Acti vity Trouble shooting One or more C DP neighbors appear intermitte ntly or not at all in the switch ’ s CDP Neighbors tab le. T h is m a y b e c a u se d b y mo r e th an 6 0 ne i g h - boring d evices sendin g CDP packe ts to the switch. E xceedin g the 60-neig h bor limi t can occu r , f or ex ampl ...

  • IronPort Systems 4108GL - page 421

    18-9 Trou blesh ooting Unus ual Net work Activi ty Trouble shootin g Problems Relat ed to Sp anning-T ree Protocol (STP) Caut ion If you e nable ST P , it is recom mended that y ou leav e the remaind er of th e STP paramet er settings at th eir defaul t values unt il you have had an opport unity to evalua te STP pe rformanc e in your ne twork. Bec ...

  • IronPort Systems 4108GL - page 422

    18- 10 Trou blesh ooting Unusua l Netw ork Acti vity Trouble shooting ■ If the ab ove method does not w ork, try el iminating configura tion changes in the switch that have not been save d to flash (boot-up config uration) by causing the switch to reboo t from the boot-up config uration (wh ich includ es only the configura tion chang es made prio ...

  • IronPort Systems 4108GL - page 423

    18- 11 Trou blesh ooting Unus ual Net work Activi ty Trouble shootin g ■ The time quot a for the account ha s been exh austed. ■ The time cre dit for the ac count has e xpired. ■ The acc ess attempt i s outside o f the time frame allo wed for th e accoun t. ■ The allowe d num ber of conc urrent lo gins for t he ac count has be en exceed ed ...

  • IronPort Systems 4108GL - page 424

    18- 12 Trou blesh ooting Unusua l Netw ork Acti vity Trouble shooting ■ If the mon itor port i s not a membe r of the same VLAN as the traf fic from the monitor ed ports, tr affic from the monitored por ts does not go ou t the moni tor por t. None of the devi ces a ssigned to one or more VLANs o n an 802.1Q- compliant switch are being reco gnized ...

  • IronPort Systems 4108GL - page 425

    18- 13 Trou blesh ooting Unus ual Net work Activi ty Trouble shootin g redunda nt links to anoth er switch. If the other devic e sends traf fic over multiple VLA Ns, its MAC ad dress will co nsistently appe ar in mul tiple VLANs on the switch port to which it is linked. Note that attem pting to creat e redundant paths through t he use of VLANs will ...

  • IronPort Systems 4108GL - page 426

    18- 14 Trou blesh ooting Unusua l Netw ork Acti vity Trouble shooting ■ If the ab ove method does not w ork, try el iminating configura tion changes in the switch that have not been save d to flash (boot-up config uration) by causing the switch to reboo t from the boot-up config uration (wh ich includ es only the configura tion chang es made prio ...

  • IronPort Systems 4108GL - page 427

    18- 15 Trou blesh ooting Unus ual Net work Activi ty Trouble shootin g ■ The time quot a for the account ha s been exh austed. ■ The time cre dit for the ac count has e xpired. ■ The acc ess attempt i s outside o f the time frame allo wed for th e accoun t. ■ The allowe d num ber of conc urrent lo gins for t he ac count has be en exceed ed ...

  • IronPort Systems 4108GL - page 428

    18- 16 Trou blesh ooting Using t he Even t Log T o Iden tify P roble m Sour ces Trouble shooting Using the Event Log T o Identify Problem Sources The Event Log records op erating even ts as single-l ine entries listed in chrono - logical order , and serv es as a tool for isola ting proble ms. Each Event Log entry is co mpo sed o f f ive f iel ds: S ...

  • IronPort Systems 4108GL - page 429

    18- 17 Trou blesh ooting Using the Event Log To Identify Problem So urces Trouble shootin g T able 18-1. Event Log Sy stem Modules Menu: Entering and Navigating in the Event Log Fro m the Mai n Me nu, se lect Event Lo g . Figure 18-3. Example of an Event Log Display Modu le Even t Description Modu le Event Descri ption addrMg r Addr ess tab le mgr ...

  • IronPort Systems 4108GL - page 430

    18- 18 Trou blesh ooting Using t he Even t Log T o Iden tify P roble m Sour ces Trouble shooting The log status line at the bo ttom of th e display id entifies where in the sequen ce of event messag es the display is curr ently posi tioned. T o displa y va rious p ortio ns of the E vent L og, eith er prec eding or f ollow ing th e curren tly visibl ...

  • IronPort Systems 4108GL - page 431

    18- 19 Trou blesh ooting Diagno sti c Tools Trouble shootin g Diagnostic T o ols Diagnostic Feature s Port Auto -Negotiati on When a link LED doe s not light (ind icating loss of link betwe en two device s), the m ost co mmon reas on is a failu re of po rt au to-ne gotiat ion bet ween the conne cting ports. If a link LE D fails to ligh t whe n you ...

  • IronPort Systems 4108GL - page 432

    18- 20 Trou blesh ooting Diagno stic Tools Trouble shooting Note T o re spond to a Ping test or a Link test, th e device y ou are try ing to rea ch must be IEE E 802.3- compli ant. Ping T est. This is a test of the pat h between t he switch and a nother devic e on the same or a nother IP network th at can re spond to IP pa ckets (I CMP Echo Request ...

  • IronPort Systems 4108GL - page 433

    18- 21 Trou blesh ooting Diagno sti c Tools Trouble shootin g W eb: Execu ting Ping or Link T ests Figure 18-4. Link and Ping T est Screen on the W eb Browser Interface Successes indicates the number o f Ping or Link packe ts that successfully compl eted th e mos t rece nt tes t. Failures indica tes the numbe r of Ping or Link packets that were uns ...

  • IronPort Systems 4108GL - page 434

    18- 22 Trou blesh ooting Diagno stic Tools Trouble shooting Numb er of Pac kets t o Send is the n umber of tim es you w ant th e sw itch to attempt to test a co nnection. T imeo ut in Sec onds is the n umb er of se cond s to all ow pe r at temp t t o te st a connect ion befor e determ ining th at the cu rrent attempt ha s failed. T o halt a Link or ...

  • IronPort Systems 4108GL - page 435

    18- 23 Trou blesh ooting Diagno sti c Tools Trouble shootin g Link T ests. Y ou can issue single or multiple link tests with varyi ng repititions and time out perio ds. The default s are: ■ Repetitions: 1 (1 - 99 9) ■ T imeout: 5 seconds ( 1 - 256 seconds) Synta x: link < mac-addr ess > [repetitions <1 - 999>] [timeout <1 - 256&g ...

  • IronPort Systems 4108GL - page 436

    18- 24 Trou blesh ooting Diagno stic Tools Trouble shooting Displaying th e Configuratio n File The complet e switch config uration is co ntained in a fi le that you c an browse from ei ther the w eb browser i nterface o r the CLI . It may b e useful in some troubleshoo ting scenar ios to view t he switch conf iguration . CLI: Vi ewing the Configur ...

  • IronPort Systems 4108GL - page 437

    18- 25 Trou blesh ooting Diagno sti c Tools Trouble shootin g CLI Administ rative and T roubleshooting Comman ds These comm ands pr ovide inform atio n or perform a ctions tha t you may fi nd helpful in tr oubleshoot ing oper ating pr oblems with t he switch. Note For more on the CLI, ref er to chap ter 3, "Using the Com mand Line Referenc e ( ...

  • IronPort Systems 4108GL - page 438

    18- 26 Trou blesh ooting Restor ing t he Fa ctory- Defa ult C onfig ura tion Trouble shooting Restoring the Factory-Default Configuration As part of your troublesh ooting pr ocess, it may bec ome necessa ry to return the switch configur ation to th e factory d efault setti ngs. This pr ocess momen- tarily interr upts the swi tch operat ion, clears ...

  • IronPort Systems 4108GL - page 439

    18- 27 Trou blesh ooting Res toring a Fl ash Im age Trouble shootin g Restoring a Flash Image The sw itch can lo se its oper ating syste m if ei ther the pr ima ry or se cond ary flash ima ge locatio n is empty or conta ins a corrup ted OS file an d an opera tor uses the eras e flas h command t o erase a good OS im age f ile fro m the op posite fla ...

  • IronPort Systems 4108GL - page 440

    18- 28 Trou blesh ooting Resto ring a Flash Imag e Trouble shooting 4. Since th e OS file is larage, you can inc rease the speed of the download by changi ng the sw itch con sole and term inal em ulator baud rates to a hi gh speed . Fo r ex ampl e: a. Ch ange the s witc h baud r ate to 1 15, 200 Bp s. => sp 115200 b. Chan ge the te rminal em ula ...

  • IronPort Systems 4108GL - page 441

    18- 29 Trou blesh ooting Res toring a Fl ash Im age Trouble shootin g Figure 18-7. Example of Xmodem Download in Progress 8. When the download co mpletes, the switch reb oots from pri mary fla sh using the O S image you do wnloade d in the preced ing steps, plus the most recent st artup-con fig file. ...

  • IronPort Systems 4108GL - page 442

    18- 30 Trou blesh ooting Resto ring a Flash Imag e Trouble shooting ...

  • IronPort Systems 4108GL - page 443

    A-1 File Transfe rs A File T ransfers Contents Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A-2 Down load ing an Op erat ing Sy ste m (OS) . . . . . . . . . . . . . . . . . . . . . . . A-2 General OS Download Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A ...

  • IronPort Systems 4108GL - page 444

    A-2 File T ransfer s Overv iew File Transfers Overview Y ou can downlo ad new switc h software (o perating system — OS) a nd upload or dow nload sw itch c onfigur ation files. Th ese featu res a re usefu l for acquir ing periodic switch softw are upgr ades and f or storing or retrievi ng a switch config uration. This appendi x includes t he follo ...

  • IronPort Systems 4108GL - page 445

    A-3 File T ransfer s Downlo ading an O perating Syste m (OS) File Transfe rs Note Downloading a ne w OS does not c hange the current swi tch configur ation. The switch con figuration is c ontained i n separa te files that can al so be transfer red. See “ T ra nsferri ng Switc h Config uration s ” on page A-13 . In most ca ses, if a p ower fai l ...

  • IronPort Systems 4108GL - page 446

    A-4 File T ransfer s Downl oading an Operatin g System (OS) File Transfers Menu: TF TP Download from a S erver to Primary Flash Note th at the me nu interface accesses only t he prim ary flas h. 1. In th e console Main Menu, selec t Downlo ad OS to d ispl ay this scr een: Figure A-1. Example of the Down load OS Screen (Defaul t V alues) 2. Press [E ...

  • IronPort Systems 4108GL - page 447

    A-5 File T ransfer s Downlo ading an O perating Syste m (OS) File Transfe rs A “ pr ogress ” bar i ndicates t he progre ss of the dow nload . When the e ntire OS file has been r eceived, all activit y on the switch halt s and you will see V a lidating and writing sy stem software to FLASH... 7. Af ter th e prima ry f lash mem ory ha s been u pd ...

  • IronPort Systems 4108GL - page 448

    A-6 File T ransfer s Downl oading an Operatin g System (OS) File Transfers 1. Ex ecut e copy as shown belo w: Figur e A- 3. Ex amp le of the Comma nd to D ownl oad an OS 2. When the switch fini shes download ing the OS fi le from the serv er , it displays this pr ogress message: V a lidating an d Writing Sy stem Software to FLASH . . . 3. When the ...

  • IronPort Systems 4108GL - page 449

    A-7 File T ransfer s Downlo ading an O perating Syste m (OS) File Transfe rs ■ The term inal emul ator you are using includ es the X modem binary tra nsfer feature. (For example, in the HyperT erminal app lication included with W indows NT , you would use the Se nd File option in the T rans fer dropdown menu.) Menu: Xmodem Download to Primary Fla ...

  • IronPort Systems 4108GL - page 450

    A-8 File T ransfer s Downl oading an Operatin g System (OS) File Transfers CLI: Xmodem Download fro m a PC or Unix W orkstation to Primary or Secondary Flash Using Xmode m and a ter minal emul ator , yo u can downloa d an OS imag e to eith er prim ary o r sec ond ary fl ash. Synta x: copy xmodem flash [<prim ary | secondary>] Note that if you ...

  • IronPort Systems 4108GL - page 451

    A-9 File T ransfer s Downlo ading an O perating Syste m (OS) File Transfe rs If you need inf ormat ion on prima ry/secon dary flash me mory an d the boot comm ands, see “ Using Primar y and Sec ondar y Flash Im age Op tions ” on pa ge 5-11 . Switch-to-Switch D ownload Y ou can use TF TP to tr ansfer a n OS im age bet ween tw o Switc h 4108 GLs. ...

  • IronPort Systems 4108GL - page 452

    A-10 File T ransfer s Downl oading an Operatin g System (OS) File Transfers a. F rom th e M ain Men u, s elec t Status an d Counter s General Sy stem Information b. Chec k the Fi rmware re vision line . CLI: Switch-T o-Switch Dow nloads Y ou can download an OS image be tween two Swi tch 4108GLs conne cted o n your LAN by initiating a copy tftp comm ...

  • IronPort Systems 4108GL - page 453

    A-11 File T ransfer s Downlo ading an O perating Syste m (OS) File Transfe rs If you do not specify ei ther a prima ry or seconda ry flash location fo r the destinat ion, the downl oad auto matica lly goes t o pri mary flash . For exa mple, to downloa d an OS fi le from se condar y flas h in a Sw itch 410 8GL with an IP ad dres s of 10 .28.2 27.10 ...

  • IronPort Systems 4108GL - page 454

    A-12 File T ransfer s Trou blesh ootin g TFTP D ownlo ads File Transfers T roubl eshooti ng TF TP Down loads When using the menu interfa ce, if a TF TP download fails, t he Download OS screen indicates the fa ilure. Figure A-6. Example of Message fo r Download Failure T o find more inf ormatio n on the ca use of a do wnload fa ilure, exam ine the m ...

  • IronPort Systems 4108GL - page 455

    A-13 File T ransfer s Tran sferri ng Sw itch Confi gurati ons File Transfe rs ■ For a Unix TF TP serv er , the file permi ssions for the OS file do no t allow the fil e to be co pied. ■ Anothe r console session (thr ough eit her a di rect c onnect ion to a t ermina l device or throug h T elnet) was al read y running w hen you st arted th e sess ...

  • IronPort Systems 4108GL - page 456

    A-14 File T ransfer s Tran sferr ing S witch Configu ratio ns File Transfers TF TP: Copying a Configuration File to a Remote Host. Synta x: copy <star tup-confi g | running-c onfig> tftp < ip-addr > < re mo te-f ile > This comma nd copies th e switch ’ s startup co nfigura tion (startup- conf ig file) to a remote TF TP host. For ...

  • IronPort Systems 4108GL - page 457

    A-15 File T ransfer s Tran sferri ng Sw itch Confi gurati ons File Transfe rs Xmodem: C opying a C onfigur ation Fi le from a Seri ally Con nected PC or Unix W orkstation. T o use this method , the switch mu st be connecte d via the ser ial por t to a PC or Unix w orkstation on which is stored the config uratio n file you want to co py . T o compl ...

  • IronPort Systems 4108GL - page 458

    A-16 File T ransfer s Copy ing Di agnost ic Da ta to a Re mote Host , PC, o r Unix W orks tatio n File Transfers Copying Diagnostic Data to a Remote Host, PC, or Unix W orkstation Y ou can use th e CLI to copy the fol lowing typ es of swi tch data to a text fil e in a ma nagemen t devi ce: ■ Command Output : Sends the outpu t of a switch CLI co m ...

  • IronPort Systems 4108GL - page 459

    A-17 File T ransfer s Copyin g Diagnost ic Data to a Remo te Host, PC, or Unix Works tation File Transfe rs Copying Event Log O utput to a Destination Device This co mmand uses TF TP or Xm odem to cop y the Ev ent Log co nten t to a PC or UNIX work station on th e network . Synta x: copy event -log tftp < ip-address > < fi lepath and filen ...

  • IronPort Systems 4108GL - page 460

    A-18 File T ransfer s Copy ing Di agnost ic Da ta to a Re mote Host , PC, o r Unix W orks tatio n File Transfers Copying Cr ash Log Data Content to a Destination Device This comma nd uses T F TP or Xm odem to cop y the Cras h Log cont ent to a PC or UNIX workst ation on the ne twork. Y ou can cop y individua l slot informa tion or the m aster swi t ...

  • IronPort Systems 4108GL - page 461

    B-1 MAC Address Man agement B MAC Address Management Contents Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . B -1 Determi ning MAC Addresse s . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . B-2 Menu: View ing the Switc h ’ s MAC Addresses . . . . . . . . . . . ...

  • IronPort Systems 4108GL - page 462

    B-2 MAC Ad dress Ma nage ment Determin ing MAC Addre sses MAC Address M anageme nt Determining MAC Addresses MAC A ddres s Viewin g Meth ods ■ Use the menu inte rface to view th e swi tch ’ s base MAC address and the MAC addr ess assigned to any non-default VLAN you hav e configure d on the switch . Note The swi tch ’ s base MAC addr ess is u ...

  • IronPort Systems 4108GL - page 463

    B-3 MAC Ad dress M anag ement Determin ing MAC Add resses MAC Address Man agement Menu: V i ewing the Switc h ’ s MAC Ad dresses The Management Address Inf ormation screen lists the MAC addresses for: ■ Base switch (default VLA N; VID = 1) ■ Any ad dit ional VLANs conf igur ed on the sw itch. Also, the Base MA C address appe ars on a label on ...

  • IronPort Systems 4108GL - page 464

    B-4 MAC Ad dress Ma nage ment Determin ing MAC Addre sses MAC Address M anageme nt CLI: Vi ewin g the Por t and VLAN MAC Addr esses The M AC ad dress assi gned to ea ch sw itch port is u sed int erna lly by s uch features as Flow Contr ol and the Spa nning T re e Protoco l. Using the walkmib command to de termine the MAC addre ss assignment s for i ...

  • IronPort Systems 4108GL - page 465

    B-5 MAC Ad dress M anag ement Determin ing MAC Add resses MAC Address Man agement Figure B-2. Example of Port MAC Address Assignments ifPh y sAddr ess. 226 & 237 MAC Addr esses for non-defau lt VLAN s. ifPhy sAddress.1 - 6: Ports A1 - A6 in Slot 1 (Addresses 7 - 24 in s lot 1 and 25 - 48 in slot 2 are unused .) ifPhy sAddress.49 - 51 : P orts C ...

  • IronPort Systems 4108GL - page 466

    B-6 MAC Ad dress Ma nage ment Determin ing MAC Addre sses MAC Address M anageme nt ...

  • IronPort Systems 4108GL - page 467

    C-1 Daylight Savings Time on HP Proc urve Swit ches C Daylight Savings T i me on HP Procur ve Switches This information a pplies to the followin g HP Procurve switch es: HP Proc urve swit ches pr ovide a way t o auto matically adjust the syst em cloc k for Daylig ht Savi ngs T i me (DS T) changes. T o us e this fea ture you d efine the month an d d ...

  • IronPort Systems 4108GL - page 468

    C-2 Daylig ht Savi ngs Time on HP Procu rve Switc hes Day light Sa vin gs Time on HP Procur ve Switches Middle Eu rope an d Portugal : • Begin DST a t 2am the f irst Sunda y on or af ter Marc h 25th. • End DST a t 2am the first Sunday on or after Septemb er 24th. Southern He misphere: • Begin DST a t 2am the f irst Sunda y on or aft er Octobe ...

  • IronPort Systems 4108GL - page 469

    C-3 Dayli ght Sa ving s Time on HP Procur ve Sw itche s Daylight Savings Time on HP Proc urve Swit ches Before conf iguring a "User defined" Daylight T im e Rule, it is importan t to understand how the switch treats th e entries. The switch knows whi ch dates are S unday s, and uses a n algo rithm to det ermin e on wh ich date to chang e ...

  • IronPort Systems 4108GL - page 470

    ...

  • IronPort Systems 4108GL - page 471

    Index – 1 Index Index Symbols => prompt … 18 -27 Numerics 802.1Q V LAN stan dard … 16 -3 802.3u auto neg otiati on stan dard … 11 -3 A A.09 .70 ro uter releas e … 14-29 aaa aut hentic atio n … 9-14 access mana ger … 12-5 oper ator … 12-5 access le vels, authorize d IP mana gers … 10-5 Actions lin e … 2-9 – 2-1 1 location on ...

  • IronPort Systems 4108GL - page 472

    2 – Index Index configu r ation, vie wing … 12-19 effect o f spanni ng tree … 12-23 general oper ation … 12 -13 hold time … 12-23 IP ad dress in outbound packet … 12-24 mib objec ts … 12-25 neighb or … 12-13 neighb or data … 12-25 neighb or max imum … 12-27 neighb or table … 12-17 neighb ors table … 12-19 neighb ors table , ...

  • IronPort Systems 4108GL - page 473

    Inde x – 3 Index SNMP -ba sed … A-11 switch-to- s witch … A-9 troubles hooting … A-12 Xmodem … A-6 downl oad O S … A-9 downlo ad, TFTP … A-3 – A-4 dupli cate IP addres s effect on auth orized IP manage rs … 10-13 dupli cate MAC ad dress See MAC addres s Dyn1 See LAC P E ending a co nsole s ession … 2-5 event log … 2-7, 18 -16 ...

  • IronPort Systems 4108GL - page 474

    4 – Index Index H Help … 2-11 , 4-14 Help line, about … 2-9 Help line , locatio n on screen s … 2-9 help, o nline inop erable … 4-14 HP ProCurve support UR L … 4-14 HP prop rietary MIB … 12 -3 HP Rou ter 44 0 … 14-2 9 HP Rou ter 47 0 … 14-2 9 HP Rou ter 48 0 … 14-2 9 HP Rou ter 65 0 … 14-2 9 HP TopTools See TopTools HP web br ...

  • IronPort Systems 4108GL - page 475

    Inde x – 5 Index STP … 11-28 VLANs … 11-28 LACP, with CDP … 12-2 7 learni ng bridge … 7-2 leave g roup See IGMP legacy VLAN … 14-6 limit, br oadcast … 11-9 link spee d, port trunk … 11-11 link test … 18-20 for troub leshooting … 18-19 link, s erial … 6-3 load ba lanci ng See po rt t runk loop, ne twork … 1 1-11, 16 -2, 16-9 ...

  • IronPort Systems 4108GL - page 476

    6 – Index Index if you lo se the password … 4-12, 9-6 incorrect … 9-5 length … 9- 5 lost … 4-12 mana ger … 4-9 oper ator … 4-9 set … 2-7 setting … 4-10, 9 -5 using to acce ss brow ser and console … 4-11 path c os t … 16-10 ping t est … 18 -20 for troub leshooting … 18-19 port addres s table … 17-13 auto nego tiation … ...

  • IronPort Systems 4108GL - page 477

    Inde x – 7 Index quick s tart … iii, 7-4 R reboo t … 2-8, 2- 10, 2 -12 , 14-36 reboot, a ctions c ausing … 5-3 reco nfigure … 2-10 redunda nt path … 16-2, 1 6-9 spanning tre e … 16-3 report See IGMP reset … 2- 12, 5- 9 Reset button rest orin g fact ory de faul t conf igurat ion … 18 -26 reset port counters … 17-9 resetting the s ...

  • IronPort Systems 4108GL - page 478

    8 – Index Index stacki ng benefits … 13-4 – 13-5 mini mum softwa re versio n, other HP switch es … 13-10 prim ary … 13-47 standa rd MIB … 12 -3 start ing a console session … 2- 4 stat ic VLAN, conv ert to … 14-30 statis tical samp ling … 12-2 statistics … 2-7, 17-3 stat istics, cle ar counte rs … 2-12, 5-9 status and cou nters ...

  • IronPort Systems 4108GL - page 479

    Inde x – 9 Index selec ting … 8-3 viewin g an d confi guring, menu … 8-1 4 viewi ng, CLI … 8- 16 times ync, disa blin g … 8-19 Time-To -Live … 7 -3, 7- 5 top talke r … 11-30 TopTools … 1-6 TopToo ls sys tem requi remen ts … 4-5 TopTools , main screen … 1- 6 traffic analysis … 12-2 traffic monito ring … 12-2, 12- 4 traffic, m ...

  • IronPort Systems 4108GL - page 480

    10 – I ndex Index maximu m, GVRP … 14 -42 monit ori ng … 17-2 multiple … 12-2 multiple VLANs on port … 14-25 notes on using … 14-10 number allow ed, in cluding d ynamic … 14-14 OS down load … A-3 port as signme nt … 14-1 4 port conf igur ation … 1 4-26, 18-12 port m onitoring … 14-28 port restriction … 14-29 port tru nk … ...

  • IronPort Systems 4108GL - page 481

    Index – 11 Index write memo ry, eff ect on me nu inte rface … 2-13 X Xmodem OS dow nload … A-6 ...

  • IronPort Systems 4108GL - page 482

    ...

  • IronPort Systems 4108GL - page 483

    T echnical inf orma tion in this doc ument is subj ect to c hange wit hout no tice . ©Cop yr ight Hew lett-P ac kar d Compan y 2001. All r ight r eserv ed. Rep r oductio n, ada ptatio n, or tr anslation with out pr ior wr it ten per mission is prohib ited ex cept as allo wed un der the cop yr ight law s. Pr oduct o f U .S .A. Apr il 2001 Manual P ...

Manufacturer IronPort Systems Category Switch

Documents that we receive from a manufacturer of a IronPort Systems 4108GL can be divided into several groups. They are, among others:
- IronPort Systems technical drawings
- 4108GL manuals
- IronPort Systems product data sheets
- information booklets
- or energy labels IronPort Systems 4108GL
All of them are important, but the most important information from the point of view of use of the device are in the user manual IronPort Systems 4108GL.

A group of documents referred to as user manuals is also divided into more specific types, such as: Installation manuals IronPort Systems 4108GL, service manual, brief instructions and user manuals IronPort Systems 4108GL. Depending on your needs, you should look for the document you need. In our website you can view the most popular manual of the product IronPort Systems 4108GL.

A complete manual for the device IronPort Systems 4108GL, how should it look like?
A manual, also referred to as a user manual, or simply "instructions" is a technical document designed to assist in the use IronPort Systems 4108GL by users. Manuals are usually written by a technical writer, but in a language understandable to all users of IronPort Systems 4108GL.

A complete IronPort Systems manual, should contain several basic components. Some of them are less important, such as: cover / title page or copyright page. However, the remaining part should provide us with information that is important from the point of view of the user.

1. Preface and tips on how to use the manual IronPort Systems 4108GL - At the beginning of each manual we should find clues about how to use the guidelines. It should include information about the location of the Contents of the IronPort Systems 4108GL, FAQ or common problems, i.e. places that are most often searched by users in each manual
2. Contents - index of all tips concerning the IronPort Systems 4108GL, that we can find in the current document
3. Tips how to use the basic functions of the device IronPort Systems 4108GL - which should help us in our first steps of using IronPort Systems 4108GL
4. Troubleshooting - systematic sequence of activities that will help us diagnose and subsequently solve the most important problems with IronPort Systems 4108GL
5. FAQ - Frequently Asked Questions
6. Contact detailsInformation about where to look for contact to the manufacturer/service of IronPort Systems 4108GL in a specific country, if it was not possible to solve the problem on our own.

Do you have a question concerning IronPort Systems 4108GL?

Use the form below

If you did not solve your problem by using a manual IronPort Systems 4108GL, ask a question using the form below. If a user had a similar problem with IronPort Systems 4108GL it is likely that he will want to share the way to solve it.

Copy the text from the picture

Comments (0)