EasyManua.ls Logo

Cisco SG 300-20 User Manual

Cisco SG 300-20
326 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Page #1 background imageLoading...
Page #1 background image
Cisco Small Business 300 Series Managed Switch
Administration Guide
10/100 Switches SF 300-08, SF 302-08, SF 302-08MP, SF 302-08P, SF 300-24,
SF 300-24P, SF 300-48, SF 300-48P
Gigabit Switches SG 300-10, SG 300-10MP, SG 300-10P, SG 300-20, SG 300-28, SG 300-
28P, SG 300-52
ADMINISTRATION
GUIDE

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the Cisco SG 300-20 and is the answer not in the manual?

Cisco SG 300-20 Specifications

General IconGeneral
ModelSG 300-20
TypeManaged Switch
Ports20
Power over Ethernet (PoE)No
Rack MountableYes
Power SupplyInternal
VLAN SupportYes
MAC Address Table Size8K entries
Jumbo Frame SupportYes
Dimensions (W x D x H)440 x 250 x 44 mm (17.32 x 9.84 x 1.73 in)

Summary

Managing System Files

Upgrade/Backup Firmware/Language

Process for upgrading or backing up firmware, boot code, or importing language files via HTTP or TFTP.

Selecting the Active Image

Configures which firmware image will be active after the switch reboots.

Downloading or Backing-up a Configuration or Log

Enables backup of configuration files or flash log to another device, and restoration from another device.

General Administrative Information and Operations

Rebooting the Switch

Provides instructions on how to reboot the switch, including saving configurations and factory resets.

Managing Device Diagnostics

Testing Copper Ports

Performs integrated cable tests on copper cables for fault detection using TDR or DSP-based methods.

Port Management

Setting the Basic Port Configuration

Configures global and per-port settings like speed, duplex, auto-negotiation, and port status.

Managing Power-over-Ethernet Devices

Configuring PoE Properties

Sets PoE mode (Port Limit/Class Limit) and configures PoE traps for power usage monitoring.

Configuring the PoE Power, Priority, and Class

Manages per-port PoE settings, including power limits, priority, and class assignment.

VLAN Management

Creating VLANs

Explains how to create new VLANs, specifying VLAN ID, name, and type (Dynamic, Static, Default).

Configuring VLAN Interface Settings

Configures VLAN parameters for interfaces, including port mode (General, Access, Trunk) and PVID.

Defining VLAN Membership

Manages port membership to VLANs, covering untagged/tagged frames and port registration.

Configuring the Spanning Tree Protocol

Configuring STP Status and Global Settings

Enables STP, RSTP, or MSTP globally and configures BPDU handling and bridge priority.

Defining Spanning Tree Interface Settings

Configures STP settings per port, including edge port, path cost, priority, and port state.

Configuring Multicast Forwarding

IGMP Snooping

Supports selective multicast forwarding (IPv4) by monitoring IGMP packets and enabling IGMP Querier functionality.

MLD Snooping

Supports selective multicast forwarding (IPv6) by building Multicast membership lists.

Configuring IP Information

Management and IP Interfaces

Covers IP addressing modes (Layer 2/3), IP address assignment rules, and IPv6 concepts.

Defining IPv6 Addresses

Assigns Link Local or Global IPv6 addresses to an IPv6 interface, managing prefix length and EUI-64.

Defining IPv4 Static Routing

Configures static IPv4 routes on the switch for Layer 3 routing decisions.

DHCP Relay

Acts as a DHCP Relay agent, listening for and relaying DHCP messages between servers and clients.

Defining DHCP Relay Properties

Configures DHCP Relay status and IP addresses of DHCP servers for relaying messages.

Configuring Security

Defining Users

Manages user accounts, including adding new users, setting passwords, and defining complexity rules.

Setting Password Complexity Rules

Defines password complexity rules: minimum length, character classes, and password aging.

TACACS+ Configuration

Configures TACACS+ client for centralized security, authentication, and authorization via a TACACS+ server.

Adding a TACACS+ Server

Adds TACACS+ servers individually, configuring IP address, priority, key string, and authentication port.

Configuring RADIUS Parameters

Sets default and individual RADIUS server parameters for centralized authentication and authorization.

Management Access Authentication

Assigns authentication methods (Local, RADIUS, TACACS+) to management access methods like SSH, Telnet, HTTP.

Access Profiles

Limits management access via profiles, defining rules for access methods, interfaces, and source IP addresses.

Defining Profile Rules

Creates rules within access profiles to permit or deny access based on criteria like management method and interface.

Defining Storm Control

Limits the number of frames entering the switch and defines frame types counted for storm protection.

Configuring Port Security

Increases security by limiting port access to specific MAC addresses, using Classic Lock or Limited Dynamic Lock.

802.1X

Provides port-based access control, enabling authentication for hosts via 802.1x or MAC-based methods.

802.1X Parameters Workflow

Defines 802.1X parameters, including unauthenticated VLANs, port authentication, and host authentication.

Defining 802.1X Properties

Globally enables 802.1X and sets user authentication methods like RADIUS or None for ports.

Defining 802.1X Port Authentication

Configures port authentication parameters, including port control, authentication method, and guest VLAN settings.

Defining Host and Session Authentication

Defines 802.1X operation modes on ports: Single, Multiple Host, or Multiple Sessions.

Denial of Service Prevention

Protects the network from malicious attacks by preventing packets with specific IP address parameters.

Denial of Service Security Suite Settings

Activates security suite with predefined rules to protect against malicious attacks like SYN floods.

Defining Martian Addresses

Configures reserved IP addresses indicating attacks, discarded by the switch for DoS prevention.

Define SYN Filtering

Filters TCP packets with SYN flags destined for specific IP addresses/ports to mitigate SYN flood attacks.

Define SYN Rate Protection

Limits the number of incoming SYN packets to mitigate SYN flood attacks against servers.

Define ICMP Filtering

Blocks ICMP packets from specific sources to reduce network load during ICMP flood DoS attacks.

Define IP Fragmented Blocking

Blocks fragmented IP packets to prevent potential DoS attacks.

Access Control

Access Control Lists

Ordered lists of classification filters and actions (ACEs) to permit or deny traffic based on patterns.

Defining MAC-based ACLs

Creates ACLs to filter traffic based on Layer 2 fields, checking MAC addresses for frame matches.

IPv4-based ACLs

Creates ACLs to check IPv4 packets, matching IP protocol, ports, addresses, and flags.

IPv6-based ACLs

Creates ACLs to check pure IPv6-based traffic, matching IPv6 protocol, ports, and addresses.

Defining ACL Binding

Binds ACLs to interfaces, applying ACE rules to incoming packets and matching them to a default drop rule.

Adding Rules to a MAC-based ACL

Adds ACEs to MAC-based ACLs, defining priority, action (Permit/Deny), and criteria.

Adding Rules (ACEs) to an IPv4-Based ACL

Adds ACEs to IPv4 ACLs, specifying priority, action, protocol, IP addresses, and ports.

Defining a Rule (ACE) for an IPv6-based ACL

Adds ACEs to IPv6 ACLs, specifying priority, action, protocol, IPv6 addresses, and ports.

Configuring Quality of Service

Configuring QoS

Sets the QoS mode (Disable, Basic, Advanced) and defines default CoS priority for interfaces.

QoS Advanced Mode

Uses policies to support per-flow QoS, consisting of class maps, policers, and bindings to ports.

Workflow to Configure Advanced QoS Mode

Steps to configure Advanced QoS: select mode, map DSCP, create ACLs, class maps, policies, and bind them.

Defining Class Mapping

Defines traffic flows with ACLs, creating class maps that match packet criteria for QoS application.

QoS Policers

Measures traffic rates matching rules and enforces limits (CIR, CBS) using single or aggregate policers.

Configuring a Policy

Creates and manages advanced QoS policies, consisting of class maps and aggregates, bound to interfaces.

Policy Class Maps

Adds class maps to policies, defining packet types and selecting actions for ingress CoS/802.1p/DSCP values.

Configuring Bandwidth

Defines ingress rate limits and egress shaping values (CIR, CBS) to manage traffic rates.

Configuring SNMP

Creating SNMP Groups

Creates SNMP groups with security models and associates them with users/communities for access.

Managing SNMP Users

Defines SNMPv3 users with login credentials, context, scope, and associates them with groups.

Related product manuals