Recommended Configuration of Switches in Campus Networks Best Practice Document
|
|
|
- Horace Goodwin
- 10 years ago
- Views:
Transcription
1 Recommended Configuration of Switches in Campus Networks Best Practice Document Produced by UNINETT led working group on LAN infrastructure (No UFS105) Authors: Børge Brunes, Vidar Faltinsen, Einar Lillebrygfjeld, Knut-Helge Vindheim May 2010
2 Original version UNINETT English translation TERENA All rights reserved. Document No: GN3-NA3-T4-UFS105 Version / date: May 2010 Original language : Norwegian Original title: UFS 105: Anbefalt konfigurasjon for svitsjer i campusnett Original version / date: Revision 1 of 20 December 2007 Contact: [email protected] UNINETT bears responsibility for the content of this document. The work has been carried out by a UNINETT led working group on LAN infraatructure as part of a joint-venture project within the HE sector in Norway. This translated version is based on the Norwegian counterpart approved by the Norwegian HE sector on 20 December 2007 after an open consultation period of four weeks. Parts of the report may be freely copied, unaltered, provided that the original source is acknowledged and copyright preserved. The translation of this report has received funding from the European Community's Seventh Framework Programme (FP7/ ) under grant agreement n , rel ating to the project 'Multi-Gigabit European Research and Education Network and Associated Services (GN3)'. 2
3 Table of Contents Executive Summary 5 1 Introduction 6 2 Definitions 7 3 Physical Requirements Assembly Power supply Flash 8 4 Software 9 5 Naming 9 6 Switch Administration Management address Remote login (with banner) Authentication in connection with remote login Saving a configuration SNMP access Neighbour Discovery Protocol LLDP, CDP etc Syslogging NTP Other server functions in a switch Stacking Remote console, console log 12 7 VLAN Configuration Trunk configuration (VLAN tagging) Management configuration for VLAN (GVRP, VTP, etc.) VLAN on unused ports / VLAN Spanning Tree Configuration Rapid spanning tree / MSTP Spanning tree root 14 3
4 8.3 PortFast BPDU guard 14 9 Traffic Properties Speed, duplex, autocrossing Jumbo frames Bundling of ports (ether channel) /load balancing Traffic management / Quality of Service (QoS) Power over Ethernet Protection of the control plane Physical link monitoring Multicast snooping Security Functions Port security IEEE 802.1X Traffic storm control DHCP snooping IP source guard / dynamic IP lockdown Dynamic ARP inspection Port unicast and multicast flood blocking MAC address notification Useful functions for day-to-day operations Port mirroring Blocking a MAC address Static binding of a MAC address to a port 20 4
5 Executive Summary This document presents a recommendation regarding the configuration of switches in campus networks. Layer 2 and Layer 2+ functions are covered, but not Layer 3 (routing). The recommendation is generic. A number of configurations intended for supplier-specific layouts will support the recommendation. The document does not deal with the design of campus networks, but focuses on the individual components and their configuration. 5
6 1 Introduction This document provides specification of the Norwegian HE sector s recommended configuration of switches in campus networks. This translated version is based on the document approved by the Norwegian HE sector on 20 December 2007 after an open consultation period of four weeks. The target group comprises IT managers and IT operations personnel in the HE sector. A number of things must be taken into consideration when configuring switches in campus networks. Depending on its location, a switch may have various functions. Here we classify switches in three classes: core, branch and edge switches, as defined below. In each class, different switches with different port density and port composition (different speeds) are used. We do not discuss here the types of units which should be used, but provide a generic requirement list for layout and configuration. 6
7 2 Definitions Layer 2: Layer 2 of the OSI stack. Switches on Layer 2 cannot interpret IP addresses, but operate with MAC addresses. Layer 2+: Some switches have the ability to interpret the various characteristics of IP headers and higher levels. DHCP snooping is an example of such functionality, which is designated Layer 2+. Layer 3: This is the network layer which is capable of interpreting IP addresses. Some switches can perform routing. This document does not deal with such functions. Edge switch: A switch located in the periphery of the network, closest to the users. Branch switch: A switch which handles aggregate traffic from a number of edge switches and connects it to core switches. Core switch: A switch which is located in the core of the network and to which users are generally not directly connected; primarily a high-capacity connection to other switches and servers. Client port: A port on a switch which is connected to client machines in the network. This also includes servers, printers and other terminal equipment. Such ports have a number of properties which differ from those of network ports, in other words ports which are connected to other network components (routers, switches or base stations). 7
8 3 Physical Requirements 3.1 Assembly Switches shall be assembled on racks and marked with easily legible names. Patching shall be achieved in a tidy manner, with emphasis on facilitating the replacement of switches if they fail. Light-emitting diodes shall be clearly visible. 3.2 Power supply While there are no requirements for the provision of UPS or duplicated power supply to edge switches and branch switches, both are recommended for core switches. Typically, the primary power supply should be via a UPS, while the secondary supply should be from the public supply grid. 3.3 Flash Core switches should have flash settings enabling the storage of at least two software versions. This makes it possible to configure the switch so as to revert to the previous version if new software fails at start-up. 8
9 4 Software Software shall at all times be updated to the currently recommended version. UNINETT maintains an up to date list which should be followed. Software should be downloaded from a local TFTP, FTP or SCP server. 5 Naming Every switch shall be given a unique name, using a carefully considered naming convention. It is an advantage if the names provide information regarding the location and application of the switches. The name should be configured into a switch as its sysname. It should also be recorded in the DNS. The switch should also be physically labelled with the same name. Switch ports should be named in the same way, also using a carefully considered convention. It may be natural to assign names using the jack or room number to which a port is patched, or if necessary the server name or name of another switch or router, if this is what the port applies to. One may consider omitting port naming in connection with end users if some other method of documentation is used, for example using a management application. 9
10 6 Switch Administration It must be possible to configure switches by means of remote login and to monitor them using SNMP. One should also consider using SNMP for configuration, at least for certain properties. While a web interface to a switch may be considered, experience shows that such an interface is in most cases unsuitable. Only the access essential to operation should be open, and any other access should be blocked, cf. Section Management address The management IP address of a switch should be located in a dedicated network for switches and network electronics. This network should also be well protected by means of an access list which permits access to operations personnel only. 6.2 Remote login (with banner) Remote login should be performed using SSH. If Telnet is used, this should be via a secure transport route, cf. Section 6.1. A banner should be created indicating that unauthorised personnel do not have access. 6.3 Authentication in connection with remote login Login to a switch should be user-based. This has several advantages, among others that it is easy to deny access to personnel who are no longer employed. Personal passwords are also preferable to shared passwords. Last, but not least, the configuration archive clearly indicates who has performed which changes. User-based login should be based on RADIUS, TACACS+ or similar protocols. This facilitates the provision of different authorisations to different users. This configuration mode often calls for an additional login following user-based login. Here the password is a shared secret, but one must be an authorised user to be able to use it. In any eventuality, routines must be in place for changing a password at pre-defined intervals. It is extremely important that the supplier s standard password is not used once a switch is accessible via the network. The password must be changed in connection with the initial configuration. 10
11 6.4 Saving a configuration The newest version of a configuration should at all times be saved in the NVRAM of a switch. It shall also at all times be saved in a TFTP server, which should support version control (RCS or similar), so that a historical archive is maintained of all changes made. 6.5 SNMP access SNMPv2c is the most commonly used protocol, and must be supported. Since this has a low level of security, system security must be based on filters which govern who is to be granted SNMP access to the unit. This can often be configured directly in a switch, which is recommended. Alternatively, access may be governed using a Layer 3 filter in the management network (cf. Section 6.1). SNMP read must be supported. SNMP write may be considered, as it may, for example be practical for allowing shut down of the port via a management application, automated upgrades or other automated configuration. One should be aware of the risks involved in permitting SNMP write. Good protection of SNMP access is therefore very important. 6.6 Neighbour Discovery Protocol LLDP, CDP etc. For some time, Cisco has provided a proprietary solution for neighbour discovery, the Cisco Discovery Protocol (CDP). A standard now exists for this: IEEE 802.1AB or LLDP (Link Layer Discovery Protocol). For administrative purposes, this function should be activated. It provides considerable advantages during day-today operations and can also provide information which improves the management system s ability to discover topology. While it can be argued that in this way end users will receive unnecessary information, if a switch is otherwise well protected, this is considered acceptable. If a switch supports LLDP, this should be used: alternatively a proprietary solution such as CDP should be used. 6.7 Syslogging A switch should log error messages in its own buffer and also in an external syslog server. Syslogging must be set to use a real-time clock, not a clock which refers to the elapsed time since the switch was last re-started. 6.8 NTP A switch should be configured as an NTP client and will thus have a reliable clock. This is particularly important for precise logging. It can be an advantage to configure several NTP servers for improved robustness. It is recommended that the primary NTP source be the closest core router or, alternatively, a server within the campus network. These should in turn obtain the time from a number of reliable sources, including UNINETT. 11
12 6.9 Other server functions in a switch For general, important security reasons, all services which are not used in connection with a switch should be de-activated. These include finger, BOOTP, UDP Echo and HTTP (if not used) Stacking Some switches can be stacked to produce a virtual chassis with the stacking cable forming the backplane. This may call for a certain amount of configuration. Switches may also be stacked virtually, but only for the purpose of simplifying administration, in other words by providing a single IP address to administer a number of switches. This also calls for special configuration Remote console, console log A facility for logging in to the console port of a switch is beneficial. This is not very realistic for edge switches and branch switches, but such an arrangement is recommended for core switches, i.e. especially those switches which also perform routing. This can also be achieved by connecting a serial port to a terminal server in the room, or a modem, or if necessary by connecting via an AUX port on another unit. An even better solution is to provide a console server which logs everything which happens at the console. Again, this is only relevant in connection with the most critical equipment. 12
13 7 VLAN Configuration 7.1 Trunk configuration (VLAN tagging) Trunk configuration (VLAN tagging) should use IEEE 802.1q (not ISL or other proprietary variants). Trunk configuration shall not be based on autoconfiguration. Auto setup should be de-activated at all ports. For trunk ports, trunk configuration should be performed manually, as this enables a greater degree of control. It is considered extremely important from a security point of view that it should not be possible to change a random client port to a trunk port if the client attempts to do so. One should consider whether to configure so as to restrict which VLANs are permitted to traverse a given trunk. Some products require this, while others do not. Although for reasons of simplicity of management it may be tempting to omit it, it should be pointed out that such a configuration provides an even greater degree of control. 7.2 Management configuration for VLAN (GVRP, VTP, etc.) GVRP (GARP, Generic Attribute Registration Protocol, VLAN Registration Protocol) is a standard management configuration for VLAN using IEEE 802.1q trunks. Several suppliers support this protocol, though at present Cisco only supports it under CatOS. GVRP should be preferred over proprietary products such as Cisco s Virtual Trunking Protocol (VTP). In any event, it is safest not to use such administration methods but instead to manually define the necessary VLAN for each switch. Supplier-specific properties connected with configuration may make this rather cumbersome. If a VLAN administration method is used, this should be set up to be as secure as possible. This involves having full control over which ports are trunk ports, cf. Section 7.1, as well as using shared secrets, passwords, etc. 7.3 VLAN on unused ports / VLAN 1 The use of VLAN 1 is not recommended. It is recommended that a dummy VLAN be used for unused ports, so that incorrect connection or random connection does not result in a user obtaining access to a network for which he is not authorised. Similarly, all non-trunk ports shall during the initial configuration be set to a VLAN value, either the VLAN which is to be used or to a dummy VLAN. 13
14 8 Spanning Tree Configuration The spanning tree protocol must be run on the switches so that any physical loops are either consciously or unconsciously broken. Note that some switches support more VLANs than the number of spanning tree instances, and that this must be borne in mind during configuration. 8.1 Rapid spanning tree / MSTP Standard spanning tree protocol has an unfavourably long convergence time. Note that this may also have a detrimental effect in situations where the design is loop-free, in other words in a pure tree structure. If one inadvertently creates loops, this will hinder traffic for an unnecessarily long time when standard spanning tree is implemented. One should therefore consider methods which provide more rapid convergence. IEEE 802.1w, also known as RSTP (Rapid Spanning Tree), is a standard which addresses this. If all the switches in a broadcast domain support RSTP, it should be used. MSTP should also be considered. MSTP enables multiple VLANs to be handled by the same spanning tree instance. MSTP also includes support for load sharing and more rapid convergence because redundant routes are theoretically operational, but since MSTP increases complexity one should weigh up the advantages and disadvantages. 8.2 Spanning tree root The spanning tree root should be located on a core switch, as close to the router port as possible. If possible, the root should be protected by a root guard. 8.3 PortFast End-user ports should be configured with PortFast, so that a link is established before the full re-calculation of the spanning tree has been completed. 8.4 BPDU guard If a switch supports this, it should be configured, and on all client ports in other words those ports which are not configured with PortFast. The objective is to stop traffic if a switch is found to be present behind a client port. 14
15 9 Traffic Properties 9.1 Speed, duplex, autocrossing All ports should be set to automatic. All clients should also be set to automatic, as this simplifies administration and leads to less likelihood of duplex conflicts. If a given client does not support auto mode, the speed and duplex mode should be set manually. Routines must exist for tidying up when the machine in question is no longer behind the port. One should be particularly careful in cases of auto-configuration where the duplex mode ends at half duplex. This often indicates a duplex conflict because of a non-auto configuration on the client side. Some ports support autocrossing, and in some cases this must be configured explicitly. 9.2 Jumbo frames Ports which support jumbo frames should be configured to use them. Jumbo frames result in an increase in MTU from 1500 bytes to 9000 bytes, which improves the transmission capacity of gigabit Ethernet, especially over long distances. 9.3 Bundling of ports (ether channel) /load balancing In certain cases, it may be useful to double or multiply the capacity of a link by combining multiple fast Ethernet or gigabit Ethernet ports. Cisco s proprietary system is known as EtherChannel. IEEE 803.ad is a standard for such link aggregation. 9.4 Traffic management / Quality of Service (QoS) Quality of service functions may be configured according to needs, including support for different service classes, policing and shaping. 15
16 9.5 Power over Ethernet If a switch port is to be connected to an IP telephone, a base station or some other unit based on power supply over the network cable, this must be configured. Conversely it will be appropriate to de-activate this if it is not wanted. 9.6 Protection of the control plane To protect the CPU (as is particularly relevant on core switches), measures should be adopted to control and safeguard resource utilisation and access to it. 9.7 Physical link monitoring If a switch supports mechanisms for monitoring the physical cable to which a given port is connected, such functions should be activated. 16
17 10 Multicast snooping Switches must have support for IGMP snooping, both Version 2 and Version 3. Version 3 is important for handling SSM (single source multicast), which is becoming increasingly widespread. IGMP snooping should be activated on all ports. 17
18 11 Security Functions 11.1 Port security The port security functions can be used to enable better access control to a given switch port. This allows only a certain number of machines (MAC addresses) behind a given port. The configuration should be such that authorised machines still have network access after any additional machines are connected. Only the additional machines are blocked. The function is recommended especially in connection with printers in open areas, so that these switch ports are not misused. As a minimum requirement, all client ports should be configured with a high value which exceeds practical usage, so as to prevent flooding of the CAM table. Note that network ports (ports connecting to other network equipment) must not have this type of configuration IEEE 802.1X IEEE 802.1X provides better control over who accesses the network. The disadvantage of this is that it requires more of the client, which must have configured support. Moreover, the user must log in each time the network is accessed. IEEE 802.1X is recommended especially for wireless networks, but can also be used effectively on a fixed network. One can choose to implement it for individual user groups, such as student villages Traffic storm control The port should be configured so that broadcast traffic is blocked when its volume exceeds a pre-defined acceptable threshold (e.g. 10 %) DHCP snooping DHCP snooping should be configured for edge switches (provided it is supported by the switch). The objective is to prevent incorrectly configured clients from behaving as DHCP servers and hence assigning false IP addresses to other clients. This has become a problem and can be avoided by implementing DHCP snooping with its associated blocking function. It is important that this function is only implemented in client ports and not on trunk or network ports. 18
19 11.5 IP source guard / dynamic IP lockdown This is a mechanism which prevents forgery of IP addresses from the client machine. Only the IP address assigned to the client by DHCP or any statically registered address can be used behind the port. If a switch supports this function, it is recommended that it be actuated on client ports. The function may require that DHCP snooping is also being used Dynamic ARP inspection This mechanism protects against man-in-the-middle attacks which send false ARP packets pretending to behave as a router. If the switch knows which IP addresses should belong behind which ports it can effectively block attempts at pretending to be somebody else by way of ARP. This function should definitely be considered, but may require that DHCP snooping is also in use Port unicast and multicast flood blocking If packets are sent to new, false MAC addresses, these will always be sent out to all the ports on a switch. A deliberate attack may hence degrade performance for the entire environment behind the port. This may be prevented by configuring this function. If a switch supports this property, one should consider actuating it on all client ports MAC address notification This is a mechanism which sends an SNMP trap when a new MAC address is discovered or aged out on a switch. If the SNMP trap receiver is capable of interpreting it, an accurate picture of the client machines in the network can be obtained. Such mapping may also be achieved by performing regular SNMP polling of the switches, although this provides a somewhat cruder picture. If a switch supports this function, it should be activated. 19
20 12 Useful functions for day-to-day operations 12.1 Port mirroring It is useful to configure port mirroring when needed. This function sends a copy of all traffic from one port out to another port. On the monitoring port one can analyse the traffic using, for example, a sniffer or tcpdump Blocking a MAC address A MAC address can be effectively blocked by configuration of a switch. An alternative approximation is to use a network management system with support for machine blocking. It is also possible to block an IP address with a Layer 3 filter Static binding of a MAC address to a port The same function can be activated using port security, but it is possible to define static bridge table entries if desired. 20
21
22 More Best Practice Documents are available at
Management Software. Web Browser User s Guide AT-S106. For the AT-GS950/48 Gigabit Ethernet Smart Switch. Version 1.0.0. 613-001339 Rev.
Management Software AT-S106 Web Browser User s Guide For the AT-GS950/48 Gigabit Ethernet Smart Switch Version 1.0.0 613-001339 Rev. A Copyright 2010 Allied Telesis, Inc. All rights reserved. No part of
20 GE + 4 GE Combo SFP + 2 10G Slots L3 Managed Stackable Switch
GTL-2691 Version: 1 Modules are to be ordered separately. 20 GE + 4 GE Combo SFP + 2 10G Slots L3 Managed Stackable Switch The LevelOne GEL-2691 is a Layer 3 Managed switch with 24 x 1000Base-T ports associated
AT-S63 and AT-S63 NE Version 1.0.0 Management Software for the AT-9400 Series Layer 2+ Gigabit Ethernet Switches Software Release Notes
AT-S63 and AT-S63 NE Version 1.0.0 Management Software for the AT-9400 Series Layer 2+ Gigabit Ethernet Switches Software Release Notes Supported Platforms Please read this document before you begin to
TP-LINK L2 Managed Switch
NEW TP-LINK L2 Managed Switch TM NEW TL-SL3428/TL-SL3452 Overview TP-LINK JetStream TM L2 managed switch TL-SL3428/TL-SL3452 provides 24/48 10/100Mbps ports, the switch provide high performance, enterprise-level
INDIAN INSTITUTE OF TECHNOLOGY BOMBAY MATERIALS MANAGEMENT DIVISION : (+91 22) 2576 8800 (DR)
Item CORE SWITCH: 24 Ports Item Description 1)General requirements: Switch- modular operating system, non-blocking wire speed performance. Switch solution-capable of providing complete redundancy by using
TP-LINK. 24-Port 10/100Mbps + 4-Port Gigabit L2 Managed Switch. Overview. Datasheet TL-SL3428. www.tp-link.com
TP-LINK TM 24-Port 10/100Mbps + 4-Port Gigabit L2 Managed Switch Overview TP-LINK JetStream TM gigabit L2 managed switch provides 24 10/100Mbps ports. The switch provides high performance, enterprise-level
TP-LINK. 24-Port 10/100Mbps + 4-Port Gigabit L2 Managed Switch. Overview. Datasheet TL-SL5428E. www.tp-link.com
TP-LINK 24-Port 10/100Mbps + 4-Port Gigabit L2 Managed Switch Overview TP-LINK JetStream L2 managed switch provides high performance, enterprise-level QoS, advanced security strategies and rich layer 2
EX 3500 ETHERNET SWITCH
PRODUCT SPEC SHEET EX 3500 ETHERNET SWITCH EX 3500 ETHERNET SWITCH EQUIPPED THE WIRED ETHERNET SWITCH FOR UNIFIED WIRED-WIRELESS NETWORKS GET ALL THE WIRED NETWORKING FEATURES YOU NEED, PLUS THE SIMPLICITY
IMPLEMENTING CISCO SWITCHED NETWORKS V2.0 (SWITCH)
IMPLEMENTING CISCO SWITCHED NETWORKS V2.0 (SWITCH) COURSE OVERVIEW: Implementing Cisco Switched Networks (SWITCH) v2.0 is a five-day instructor-led training course developed to help students prepare for
How To Install An At-S100 (Geo) On A Network Card (Geoswitch)
AT-S100 Version 1.0.3 Patch 1 Management Software for the AT-9000/28 Managed Layer 2 GE ecoswitch and AT-9000/28SP Managed Layer 2 GE ecoswitch Software Release Notes Please read this document before you
Objectives. The Role of Redundancy in a Switched Network. Layer 2 Loops. Broadcast Storms. More problems with Layer 2 loops
ITE I Chapter 6 2006 Cisco Systems, Inc. All rights reserved. Cisco Public 1 Objectives Implement Spanning Tree Protocols LAN Switching and Wireless Chapter 5 Explain the role of redundancy in a converged
Juniper / Cisco Interoperability Tests. August 2014
Juniper / Cisco Interoperability Tests August 2014 Executive Summary Juniper Networks commissioned Network Test to assess interoperability, with an emphasis on data center connectivity, between Juniper
TP-LINK. JetStream 28-Port Gigabit Stackable L3 Managed Switch. Overview. Datasheet T3700G-28TQ. www.tp-link.com
TP-LINK JetStream 28-Port Gigabit Stackable L3 Managed Switch Overview TP-LINK s is an L3 managed switch designed to build a highly accessible, scalable, and robust network. The switch is equipped with
HARTING Ha-VIS Management Software
HARTING Ha-VIS Management Software People Power Partnership HARTING Management Software Network Management Automation IT - with mcon Switches from HARTING With the Ha-VIS mcon families, HARTING has expanded
TP-LINK. 24-Port Gigabit L2 Managed Switch with 4 SFP Slots. Overview. Datasheet TL-SG5428. www.tp-link.com
TP-LINK TM 24-Port Gigabit L2 Managed Switch with 4 SFP Slots Overview Designed for workgroups and departments, from TP-LINK provides full set of layer 2 management features. It delivers maximum throughput
TP-LINK. Gigabit L2 Managed Switch. Overview. Datasheet TL-SG3216 / TL-SG3424. www.tp-link.com
TP-LINK TM Gigabit L2 Managed Switch TL-SG3216 / TL-SG3424 Overview TP-LINK JetStream TM gigabit L2 managed switch 3 series family consists of two switches: TL-SG3216 with 16 10/100/1000Mbps ports and
JetNet 5428Gv2. Features. Industrial 24FE+4G Gigabit Managed Ethernet Switch INDUSTRIAL ETHERNET RACKMOUNT SWITCH
INDUSTRIAL ETHERNET RACKMOUNT SWITCH Industrial 24FE+4G Gigabit Managed Ethernet Switch JetNet 5428Gv2 The JetNet 5428G is a 19-inch Gigabit Layer 2+ Industrial switch, equipped with 24 100 Base-TX ports
Recommendations for a redundant campus network Best Practice Document
Recommendations for a redundant campus network Best Practice Document Produced by UNINETT led working group on campus networking (UFS114) Authors: Gunnar Bøe, Vidar Faltinsen, Einar Lillebrygfjeld December
TP-LINK 24-Port Gigabit L2 Managed Switch with 4 SFP Slots
NEW TP-LINK 24-Port Gigabit L2 Managed Switch with 4 SFP Slots TM NEW Overview Designed for workgroups and departments, from TP-LINK provides full set of layer 2 management features. It delivers maximum
DCS-3950-52C Fast Ethernet Intelligent Access Switch Datasheet
DCS-3950-52C Fast Ethernet Intelligent Access Switch Datasheet DCS-3950-52C Product Overview DCS-3950-52C switch is Fast Ethernet intelligent security access switch for carrier and MAN networks. It supports
Juniper Networks EX Series/ Cisco Catalyst Interoperability Test Results. May 1, 2009
Juniper Networks EX Series/ Cisco Catalyst Interoperability Test Results May 1, 2009 Executive Summary Juniper Networks commissioned Network Test to assess interoperability between its EX4200 and EX8208
AT-S60 Version 1.1.4 Management Software for the AT-8400 Series Switch. Software Release Notes
AT-S60 Version 1.1.4 Management Software for the AT-8400 Series Switch Supported Platforms Software Release Notes Please read this document before you begin to use the AT-S60 management software. The AT-S60
48 GE PoE-Plus + 2 GE SFP L2 Managed Switch, 375W
GEP-5070 Version: 1 48 GE PoE-Plus + 2 GE SFP L2 Managed Switch, 375W The LevelOne GEP-5070 is an intelligent L2 Managed Switch with 48 x 1000Base-T PoE-Plus ports and 2 x 100/1000BASE-X SFP (Small Form
20 GE PoE-Plus + 4 GE PoE-Plus Combo SFP + 2 GE SFP L2 Managed Switch, 370W
GEP-2672 Version: 1 20 GE PoE-Plus + 4 GE PoE-Plus Combo SFP + 2 GE SFP L2 Managed Switch, 370W The LevelOne GEP-2672 is a Layer 2 Managed switch with 24 x 1000Base-T PoE-Plus ports associated with 4 x
DCS-3950-28CT-POE fully loaded AT PoE Switch Datasheet
DCS-3950-28CT-POE fully loaded AT PoE Switch Datasheet DCS-3950-28CT-POE Product Overview DCS-3950-28CT-POE is fully loaded PoE switch for carrier and enterprises. It supports comprehensive QoS, enhanced
Cisco Certified Network Associate Exam. Operation of IP Data Networks. LAN Switching Technologies. IP addressing (IPv4 / IPv6)
Cisco Certified Network Associate Exam Exam Number 200-120 CCNA Associated Certifications CCNA Routing and Switching Operation of IP Data Networks Operation of IP Data Networks Recognize the purpose and
Management Software. User s Guide AT-S84. For the AT-9000/24 Layer 2 Gigabit Ethernet Switch. Version 1.1. 613-000368 Rev. B
Management Software AT-S84 User s Guide For the AT-9000/24 Layer 2 Gigabit Ethernet Switch Version 1.1 613-000368 Rev. B Copyright 2006 Allied Telesyn, Inc. All rights reserved. No part of this publication
Switching in an Enterprise Network
Switching in an Enterprise Network Introducing Routing and Switching in the Enterprise Chapter 3 Version 4.0 2006 Cisco Systems, Inc. All rights reserved. Cisco Public 1 Objectives Compare the types of
Layer 3 Network + Dedicated Internet Connectivity
Layer 3 Network + Dedicated Internet Connectivity Client: One of the IT Departments in a Northern State Customer's requirement: The customer wanted to establish CAN connectivity (Campus Area Network) for
TP-LINK. 24-Port Gigabit L2 Managed PoE Switch with 4 Combo SFP Slots. Overview. Datasheet TL-SG3424P. www.tp-link.com
TP-LINK TM 24-Port Gigabit L2 Managed PoE Switch with 4 Combo SFP Slots Overview The provides 24 10/100/1000Mbps ports that supports 802.3at/af-compliant PoE, with a total PoE power supply up to 320W,
ALLNET ALL-SG8926PM Layer 2 FULL Management 24 Port Giga PoE Current Sharing Switch IEEE802.3at/af
ALLNET ALL-SG8926PM Layer 2 FULL Management 24 Port Giga PoE Current Sharing Switch IEEE802.3at/af 24-Port Giga PoE Current Sharing 500W PoE Budget IPv6 and IPv4 Dual Protocol SNMP v1/v2c/v3 SSH version
24-Port 10/100Mbps + 4-Port Gigabit L2 Managed Switch TL-SL5428E
ACL, 802.1X Authentication, Port Security, IP Filtering, Storm control, DHCP Snooping, IP Source Guard and DoS Defend provide you robust security strategy Single-IP-Management supports virtual stack of
AT-S41 Version 1.1.4 Management Software for the AT-8326 and AT-8350 Series Fast Ethernet Switches. Software Release Notes
AT-S41 Version 1.1.4 Management Software for the AT-8326 and AT-8350 Series Fast Ethernet Switches Software Release Notes Please read this document before you begin to use the AT-S41 management software.
Web Browser Interface User s Guide
Management Software AT-S62 Web Browser Interface User s Guide AT-8516F/SC, AT-8524M, AT-8524POE, AT-8550GB and AT-8550SP LAYER 2+ FAST ETHERNET SWITCHES VERSION 1.3.0 PN 613-000127 Rev A Copyright 2005
RESILIENT NETWORK DESIGN
Matěj Grégr RESILIENT NETWORK DESIGN 1/36 2011 Brno University of Technology, Faculty of Information Technology, Matěj Grégr, [email protected] Campus Best Practices - Resilient network design Campus
"Charting the Course...
Description "Charting the Course... Course Summary Interconnecting Cisco Networking Devices: Accelerated (CCNAX), is a course consisting of ICND1 and ICND2 content in its entirety, but with the content
AT-GS950/8. AT-GS950/8 Web Users Guide AT-S107 [1.00.043] Gigabit Ethernet Smart Switch. 613-001484 Rev A
AT-GS950/8 Gigabit Ethernet Smart Switch AT-GS950/8 Web Users Guide AT-S107 [1.00.043] 613-001484 Rev A Copyright 2011 Allied Telesis, Inc. All rights reserved. No part of this publication may be reproduced
24-port 10/100 + 4-port Gigabit
24-port 10/100 + 4-port Gigabit Managed Switch IP Clustering supports virtual stack of 32 units L2/L3/L4 QoS, Voice VLAN, and IGMP snooping/filtering optimize voice and video application ACL, 802.1x, IP
ADMINISTRATION GUIDE Cisco Small Business 300 Series Managed Switch Administration Guide
ADMINISTRATION GUIDE Cisco Small Business 300 Series Managed Switch Administration Guide 10/100 Switches SF 300-08, SF 302-08, SF 302-08MP, SF 302-08P, SF 300-24, SF 300-24P, SF 300-48, SF 300-48P Gigabit
How To Learn Cisco Cisco Ios And Cisco Vlan
Interconnecting Cisco Networking Devices: Accelerated Course CCNAX v2.0; 5 Days, Instructor-led Course Description Interconnecting Cisco Networking Devices: Accelerated (CCNAX) v2.0 is a 60-hour instructor-led
TP-LINK. 48-Port Gigabit Smart Switch with 4 SFP Slots. Overview. Datasheet T1600G-52TS (TL-SG2452) www.tp-link.com
TP-LINK 48-Port Gigabit Smart Switch with 4 SFP Slots Overview TP-LINK JetStream Gigabit Smart Switch T1600G-52TS is a cost-effective product solution for small and medium-sized business which provides
High Performance 10Gigabit Ethernet Switch
BDCOM S3900 Switch High Performance 10Gigabit Ethernet Switch BDCOM S3900 is a standard L3 congestion-less switch series, which are capable of multi-layer switching and wire-speed route forwarding. Its
AT-S63 Version 3.1.0 Management Software for the AT-9400 Basic Layer 3 Gigabit Ethernet Switches Software Release Notes
AT-S63 Version 3.1.0 Management Software for the AT-9400 Basic Layer 3 Gigabit Ethernet Switches Software Release Notes Please read this document before you begin to use the management software. Supported
TP-LINK. 24-Port Gigabit Smart Switch with 4 SFP Slots. Overview. Datasheet T1600G-28TS (TL-SG2424) www.tp-link.com
TP-LINK 24-Port Gigabit Smart Switch with 4 SFP Slots Overview TP-LINK JetStream Gigabit Smart Switch T1600G-28TS is a cost-effective product solution for small and medium-sized business which provides
ADMINISTRATION GUIDE Cisco Small Business
ADMINISTRATION GUIDE Cisco Small Business SFE/SGE Managed Switches 2009 Cisco Systems, Inc. All rights reserved. OL-20139-01 Contents Contents Chapter 1: Getting Started 1 Starting the Application 1 Understanding
Datasheet. Managed PoE+ Gigabit Switches with SFP. Models: ES-24-250W, ES-24-500W, ES-48-500W, ES-48-750W
Managed PoE+ Gigabit Switches with SFP Models: ES-24-250W, ES-24-500W, ES-48-500W, ES-48-750W Non-Blocking Throughput Switching Performance Gigabit Ethernet RJ45 and SFP+/SFP Ports Auto-Sensing IEEE 802.3af/at
CHAPTER 10 LAN REDUNDANCY. Scaling Networks
CHAPTER 10 LAN REDUNDANCY Scaling Networks CHAPTER 10 10.0 Introduction 10.1 Spanning Tree Concepts 10.2 Varieties of Spanning Tree Protocols 10.3 Spanning Tree Configuration 10.4 First-Hop Redundancy
AT-S62 and AT-S62 NE Version 1.2.1 Management Software for AT-8500 Series Switches Software Release Notes
Supported Platforms AT-S62 and AT-S62 NE Version 1.2.1 Software Release Notes AT-S62 and AT-S62 NE Version 1.2.1 Management Software for AT-8500 Series Switches Software Release Notes Please read this
Troubleshooting an Enterprise Network
Troubleshooting an Enterprise Network Introducing Routing and Switching in the Enterprise Chapter 9 Released under Creative Commons License 3.0 By-Sa Cisco name, logo and materials are Copyright Cisco
TP-LINK. L2 Managed Switch. Overview. Datasheet TL-SL3428/TL-SL3452. www.tp-link.com
TP-LINK TM L2 Managed Switch TL-SL3428/TL-SL3452 Overview TP-LINK JetStreamTM L2 managed switch TL-SL3428/TL-SL3452 provides 24/48 10/100Mbps ports, the switch provide high performance, enterprise-level
DCRS-5650 Dual Stack Ethernet Switch Datasheet
DCRS-5650 Dual Stack Ethernet Switch Datasheet DCRS-5650-28C Product Overview DCRS-5650 series switch is L3 Fast Ethernet switch which meets the requirements of security and intelligent networks for education
ENTERASYS WEBVIEW WEB-BASED MANAGEMENT FOR THE VH-2402S/VH-2402S2 WEB MANAGEMENT GUIDE
ENTERASYS WEBVIEW WEB-BASED MANAGEMENT FOR THE VH-2402S/VH-2402S2 WEB MANAGEMENT GUIDE 9033821 Notice NOTICE Enterasys Networks reserves the right to make changes in specifications and other information
RuggedCom Solutions for
RuggedCom Solutions for NERC CIP Compliance Rev 20080401 Copyright RuggedCom Inc. 1 RuggedCom Solutions Hardware Ethernet Switches Routers Serial Server Media Converters Wireless Embedded Software Application
The Cisco IOS Firewall feature set is supported on the following platforms: Cisco 2600 series Cisco 3600 series
Cisco IOS Firewall Feature Set Feature Summary The Cisco IOS Firewall feature set is available in Cisco IOS Release 12.0. This document includes information that is new in Cisco IOS Release 12.0(1)T, including
CCT vs. CCENT Skill Set Comparison
Operation of IP Data Networks Recognize the purpose and functions of various network devices such as Routers, Switches, Bridges and Hubs Select the components required to meet a given network specification
Data Networking and Architecture. Delegates should have some basic knowledge of Internet Protocol and Data Networking principles.
Data Networking and Architecture The course focuses on theoretical principles and practical implementation of selected Data Networking protocols and standards. Physical network architecture is described
24 GE + 2 GE SFP L2 Managed Switch
GEL-2670 Version: 1 24 GE + 2 GE SFP L2 Managed Switch The LevelOne GEL-2670 is an intelligent L2 Managed Switch with 24 x 1000Base-T ports and 2 x 100/1000BASE-X SFP (Small Form Factor Pluggable) slots.
Top-Down Network Design
Top-Down Network Design Chapter Five Designing a Network Topology Copyright 2010 Cisco Press & Priscilla Oppenheimer Topology A map of an internetwork that indicates network segments, interconnection points,
ZyXEL GS2210-8HP V4.10(AASQ.1)C0 Release Note/Manual Supplement
ZyXEL GS2210-8HP V4.10(AASQ.1)C0 Release Note/Manual Supplement Date: May. 5, 2015 This document describes the features in the GS2210-8HP product for its 4.10(AASQ.1)C0 release. Support Platforms: ZyXEL
How To Switch In Sonicos Enhanced 5.7.7 (Sonicwall) On A 2400Mmi 2400Mm2 (Solarwall Nametra) (Soulwall 2400Mm1) (Network) (
You can read the recommendations in the user, the technical or the installation for SONICWALL SWITCHING NSA 2400MX IN SONICOS ENHANCED 5.7. You'll find the answers to all your questions on the SONICWALL
ADMINISTRATION GUIDE Cisco Small Business
ADMINISTRATION GUIDE Cisco Small Business 200 Series Smart Switch Administration Guide Contents Chapter 1: Getting Started 1 Starting the Web-based Switch Configuration Utility 1 Launching the Configuration
ANNEX III BUDGET PROPOSAL AS PER LOTS LOT 1
ANNEX III BUDGET PROPOSAL AS PER LOTS Item no. UNIT COSTS WITH DELIVERY Comment Technical Specification Quantity Specification Offered INCLUDING INSTALLATION AND PUTTING INTO OPERATION Technical Specification
Supports O-Ring (recovery time < 30ms over 250 units of connection) and MSTP(RSTP/STP compatible) for Ethernet
IGS-9812GP Series Industrial 20-port managed Gigabit Ethernet switch with 8x10/100/1000Base-T(X) ports and 12x100/1000Base-X, SFP socket Features Supports O-Ring (recovery time < 30ms over 250 units of
Datasheet. Managed Gigabit Switches with SFP. Models: ES-24-Lite, ES-48-Lite. Non-Blocking Throughput Switching Performance
Managed Gigabit Switches with SFP Models: ES-24-Lite, ES-48-Lite Non-Blocking Throughput Switching Performance Gigabit Ethernet RJ45 Ports SFP+/SFP Fiber Connectivity Options Deployment Examples VLAN 80
AT-S95 Version 1.0.0.35 AT-8000GS Layer 2 Stackable Gigabit Ethernet Switch Software Release Notes
AT-S95 Version 1.0.0.35 AT-8000GS Layer 2 Stackable Gigabit Ethernet Switch Software Release Notes Please read this document before you begin to use the management software. Supported Platforms The following
IT-AD08: ADD ON DIPLOMA IN COMPUTER NETWORK DESIGN AND INSTALLATION
IT-AD08: ADD ON DIPLOMA IN COMPUTER NETWORK DESIGN AND INSTALLATION Objective of the course: This course is designed to impart professional training to the students of computer Science, computer applications,
Securing end devices
Securing end devices Securing the network edge is already covered. Infrastructure devices in the LAN Workstations Servers IP phones Access points Storage area networking (SAN) devices. Endpoint Security
Configure IOS Catalyst Switches to Connect Cisco IP Phones Configuration Example
Configure IOS Catalyst Switches to Connect Cisco IP Phones Configuration Example Document ID: 69632 Introduction Prerequisites Requirements Components Used Conventions Background Information Configure
SSVP SIP School VoIP Professional Certification
SSVP SIP School VoIP Professional Certification Exam Objectives The SSVP exam is designed to test your skills and knowledge on the basics of Networking and Voice over IP. Everything that you need to cover
24 Port Gigabit Ethernet Web Smart Switch. Users Manual
24 Port Gigabit Ethernet Web Smart Switch Users Manual Content Web Smart Switch Configure login -------------------------------- 2 Configuration System Configuration ---------------------------------------------------
ALLNET ALL8944WMP Layer 2 Management 24 Port Giga PoE Current Sharing Switch
ALLNET ALL8944WMP Layer 2 Management 24 Port Giga PoE Current Sharing Switch 24-Port Giga PoE Current Sharing Pv6 and IPv4 Dual Protocol SNMP v1/v2c/v3 SSH version 2.0 Authentication TACACS+ Jumbo Frames
Note: This case study utilizes Packet Tracer. Please see the Chapter 5 Packet Tracer file located in Supplemental Materials.
Note: This case study utilizes Packet Tracer. Please see the Chapter 5 Packet Tracer file located in Supplemental Materials. CHAPTER 5 OBJECTIVES Configure a router with an initial configuration. Use the
100-101: Interconnecting Cisco Networking Devices Part 1 v2.0 (ICND1)
100-101: Interconnecting Cisco Networking Devices Part 1 v2.0 (ICND1) Course Overview This course provides students with the knowledge and skills to implement and support a small switched and routed network.
P330-ML Version 4.5 Release Notes
Avaya P330-ML Version 4.5 Release Notes 1. Introduction This document contains information related to the Avaya P332G-ML, P332GT-ML and P334T-ML stackable switches that was not included in the User's Guide.
16-PORT POWER OVER ETHERNET WEB SMART SWITCH
16-PORT POWER OVER ETHERNET WEB SMART SWITCH User s Manual (DN-95312) - 0 - Content Web Smart Switch Configure login ---------------------------------- 2 Administrator Authentication Configuration ---------------------------------------------
Network security includes the detection and prevention of unauthorized access to both the network elements and those devices attached to the network.
By: Ziad Zubidah CCNP Security IT Security Officer National Information Technology Center Network security includes the detection and prevention of unauthorized access to both the network elements and
Command Line User s Guide
Management Software AT-S63 Command Line User s Guide For AT-9400 Switch Stacks AT-S63 Version 3.2.0 for AT-9400 Basic Layer 3 Switches 613-001027 Rev. A Copyright 2008 Allied Telesis, Inc. All rights reserved.
TP-LINK. 24-Port Gigabit Smart PoE Switch with 4 Combo SFP Slots. Overview. Datasheet TL-SG2424P. www.tp-link.com
Power Budget TP-LINK 24-Port Gigabit Smart PoE Switch with 4 Combo SFP Slots Overview The provides 24 10/100/1000Mbps ports that supports 802.3at/af-compliant PoE, with a total PoE power supply up to 180W,
AT-S45 Version 1.0.7 Management Software for the AT-9410GB Gigabit Ethernet Switches. Software Release Notes
AT-S45 Version 1.0.7 Management Software for the AT-9410GB Gigabit Ethernet Switches Product Documentation Software Release Notes Please read this document before you begin to use the AT-S45 management
Aruba Mobility Access Switch and Arista 7050S INTEROPERABILITY TEST RESULTS:
Aruba and INTEROPERABILITY TEST RESULTS: Aruba and Aruba and Table of Contents Executive summary 3 Scope and methodology 3 Interface connectivity 4 Port channels and link aggregation control protocol (LACP)
Objectives. Explain the Role of Redundancy in a Converged Switched Network. Explain the Role of Redundancy in a Converged Switched Network
Implement Spanning Tree Protocols LAN Switching and Wireless Chapter 5 Objectives Explain the role of redundancy in a converged network Summarize how STP works to eliminate Layer 2 loops in a converged
CCNP v2 Eğitimi İçeriği
Öngereksinimler: CCNA http://www.cliguru.com/ccna Kurs Tanımı: CCNP v2 Eğitimi İçeriği Giriş seviyesi network bilgilerine sahip katılımcıları network'ün temeli olan Routing Switching alanında orta üst
Cisco SRW2024P 24-Port Gigabit Switch: WebView/PoE Cisco Small Business Managed Switches
Cisco SRW2024P 24-Port Gigabit Switch: WebView/PoE Cisco Small Business Managed Switches Reliable, Intelligent Switching for Growing Businesses Highlights 24 high-speed ports optimized for the network
SSVVP SIP School VVoIP Professional Certification
SSVVP SIP School VVoIP Professional Certification Exam Objectives The SSVVP exam is designed to test your skills and knowledge on the basics of Networking, Voice over IP and Video over IP. Everything that
LANs and VLANs A Simplified Tutorial
Application Note LANs and VLANs A Simplified Tutorial Version 3.0 May 2002 COMPAS ID 90947 Avaya Labs 1 Companion document IP Addressing: A Simplified Tutorial COMPAS ID 92962 2 Introduction As the name
ADMINISTRATION GUIDE Cisco Small Business Pro
ADMINISTRATION GUIDE Cisco Small Business Pro ESW 500 Series Switches 2009 Cisco Systems, Inc. All rights reserved. OL-19128-01 Contents Chapter : Getting Started 12 Introduction 12 Typical Installation
Ha-VIS FTS 3000 Introduction and features
Ha-VIS Introduction and features Ethernet Switch Ha-VIS FTS 3100s-A 10-port Ethernet Switch with Fast Track Technology configurable via USB General Description Features The Fast Ethernet Switches of the
Interconnecting Cisco Network Devices 1 Course, Class Outline
www.etidaho.com (208) 327-0768 Interconnecting Cisco Network Devices 1 Course, Class Outline 5 Days Interconnecting Cisco Networking Devices, Part 1 (ICND1) v2.0 is a five-day, instructorled training course
Easy Smart Configuration Utility
Easy Smart Configuration Utility REV1.1.0 1910010977 CONTENTS Chapter 1 About this Guide...1 1.1 Intended Readers... 1 1.2 Conventions... 1 1.3 Overview of This Guide... 1 Chapter 2 Getting Started...4
Extreme Networks EAS 100-24t Switch Software Release Notes, Version 1.00
Extreme Networks EAS 100-24t Switch Software Release Notes, Version 1.00 This release note for the EAS 100-24t switch software describes: s on page 1 Supported MIBs on page 7 Known Issues on page 8 Fixed
EGS7228P. Business Class EGS7228P. 24-port Gigabit AT PoE + 4SFP Smart Switch PRODUCT OVERVIEW
24-port Gigabit AT PoE + 4SFP Smart Switch PRODUCT OVERVIEW EnGenius Smart PoE Switch family is special tailored for Access Points and IP surveillance applications., one of the members from EnGenius Smart
Datasheet. Managed Gigabit Fiber Switch. Model: ES-12F. Non-Blocking Throughput Switching. High Performance and Low Latency
Managed Gigabit Fiber Switch Model: ES-12F Non-Blocking Throughput Switching High Performance and Low Latency Gigabit Ethernet SFP and RJ45 Ports Deployment Examples Advanced Switching Technology for the
Cisco Small Business Managed Switches
Cisco SRW208MP 8-Port 10/100 Ethernet Switch: WebView/Max PoE Cisco Small Business Managed Switches Secure, Reliable, Intelligent Switch with PoE for Your Growing Small Business Highlights Connects up
AlliedWare Plus Version 2.1.2 AT-9000 Layer 2-4 Gigabit Ethernet EcoSwitches Software Release Notes
4 AlliedWare Plus Version 2.1.2 AT-9000 Layer 2-4 Gigabit Ethernet EcoSwitches Software Release Notes Please read this document before you begin to use the management software. The document has the following
Local Area Networks. LAN Security and local attacks. TDC 363 Winter 2008 John Kristoff - DePaul University 1
Local Area Networks LAN Security and local attacks TDC 363 Winter 2008 John Kristoff - DePaul University 1 Overview Local network attacks target an internal network Some attacks can be launched remotely
Interconnecting Cisco Networking Devices, Part 1 (ICND1) v3.0
Interconnecting Cisco Networking Devices, Part 1 (ICND1) v3.0 COURSE OVERVIEW: Interconnecting Cisco Networking Devices, Part 1 (ICND1) v3.0 is a five-day, instructor-led training course that teaches learners
AT-S105 Version 1.2.0 Management Software Release Notes AT-FS750/24POE and AT-FS750/48 Fast Ethernet WebSmart Switches
AT-S105 Version 1.2.0 Management Software Release Notes AT-FS750/24POE and AT-FS750/48 Fast Ethernet WebSmart Switches Please read this document before you begin to use the management software. NOTE This
48 GE PoE-Plus + 2 GE SFP L2 Managed Switch, 375 W
GEP-5070 Version: 1 48 GE PoE-Plus + 2 GE SFP L2 Managed Switch, 375 W The LevelOne GEP-5070 is an intelligent L2 Managed Switch with 48 x 1000Base-T PoE-Plus ports and 2 x 100/1000BASE-X SFP (Small Form
Redundant Rugged Switches OVERVIEW Rugged Switch with following features: Managed switch with 8 ports 10/100/1000 + 2 Combo mini-gbic slots Based on Cisco 300 Series Box 1U rugged standard rack Ethercon
Cisco SFE1000P 8-Port 10/100 Ethernet Switch: PoE/Fanless Cisco Small Business Managed Switches
Cisco SFE1000P 8-Port 10/100 Ethernet Switch: PoE/Fanless Cisco Small Business Managed Switches Secure, Reliable, Managed Ethernet Switching with PoE Highlights Power over Ethernet easily and cost-effectively
