EasyManua.ls Logo

Cisco SG550XG-8F8T User Manual

Cisco SG550XG-8F8T
725 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #250 background imageLoading...
Page #250 background image
Smartport
Built-in Smartport Macros
Cisco Sx350, SG350X, SG350XG, Sx550X & SG550XG Series Managed Switches, Firmware Release 2.2.5.x 190
10
•printer
guest
server
•host
ip_camera
ip_phone
ip_phone_desktop
switch
•router
•ap
desktop
[desktop]
#interface configuration, for increased network security and reliability when
connecting a desktop device, such as a PC, to a switch port.
#macro description Desktop
#macro keywords $native_vlan $max_hosts
#
#macro key description: $native_vlan: The untag VLAN which will be
configured on the port
# $max_hosts: The maximum number of allowed devices on
the port
#Default Values are
#$native_vlan = Default VLAN
#$max_hosts = 10
#
#the port type cannot be detected automatically
#
#the default mode is trunk
smartport switchport trunk native vlan $native_vlan
#
port security max $max_hosts
port security mode max-addresses
port security discard trap 60
#
smartport storm-control broadcast level 10
smartport storm-control include-multicast
smartport storm-control broadcast enable
#
spanning-tree portfast
#
@

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the Cisco SG550XG-8F8T and is the answer not in the manual?

Cisco SG550XG-8F8T Specifications

General IconGeneral
ModelSG550XG-8F8T
LayerLayer 3
Power over Ethernet (PoE)No
Rack MountableYes
Power SupplyInternal
Operating Humidity10% to 90% non-condensing
Storage Humidity5% to 95% non-condensing
Device TypeSwitch
Ports8 x 10G SFP+ and 8 x 10GBase-T
Jumbo Frame SupportYes, up to 9216 bytes
Routing ProtocolOSPF
Operating Temperature0 - 40 °C
Storage Temperature-40°F to 158°F
VLANs4094

Summary

Getting Started

Dashboard

Configuration Wizards

Getting Started Wizard

Assisting in initial device configuration, including system location, contact, and host name.

VLAN Configuration Wizard

Assisting in configuring VLANs, including trunk and access port modes for ports.

ACL Wizard

Creating new Access Control Lists (ACLs) by defining name, type, and action on match criteria.

Status and Statistics

Administration

Administration: File Management

Firmware Operations

Updating or backing up firmware images and swapping active images using various transfer methods.

DHCP Auto Configuration/Image Update

Automatically configuring switches and upgrading firmware using remote TFTP/SCP servers.

Administration: Stack Management

Unit Failure in Stack

Handling master unit failure, backup unit switchover, and slave unit behavior during failures.

Stack Management

Selecting stack ports for devices and configuring unit IDs after reset.

Administration: Time Settings

Administration: Discovery

Port Management

Port Settings

Displaying global and per-port settings, including link flap prevention, jumbo frames, and port types.

Error Recovery Settings

Enabling automatic port reactivation after shutdown due to error conditions.

Link Aggregation

Configuring Link Aggregation Groups (LAGs) to bundle physical ports into a single logical channel.

PoE

Using the Power over Ethernet (PoE) feature to deliver electrical power to connected devices over copper cables.

VLAN Management

Regular VLANs

Configuring various types of VLANs, including creating VLANs, setting interface modes, and managing port membership.

Voice VLAN

Configuring voice VLANs for IP phones, VoIP endpoints, and voice systems.

Spanning Tree

STP Status and Global Settings

Setting parameters for enabling STP, RSTP, or MSTP, including BPDU handling and path cost.

STP Interface Settings

Configuring STP on a per-port basis and viewing information learned by the protocol.

Managing MAC Address Tables

Static Addresses

Assigning static MAC addresses to specific physical interfaces and VLANs, which do not expire.

Dynamic Addresses

Acquiring MAC addresses by monitoring source addresses of frames and deleting them after aging time.

Multicast

IPv4 Multicast Configuration

Configuring IPv4 Multicast, including IGMP snooping, interface settings, VLAN settings, and proxy.

IPv6 Multicast Configuration

Configuring IPv6 Multicast, including MLD snooping, interface settings, VLAN settings, and proxy.

IP Configuration

IPv4 Management and Interfaces

Configuring IPv4 interface addresses, routes, RIPv2, access lists, VRRP, ARP, and DHCP.

IPv6 Management and Interfaces

Configuring IPv6 global parameters, interfaces, tunnels, addresses, router configuration, and neighbors.

Policy-Based Routing

Routing selected packets to a next hop address based on packet fields using ACLs for classification.

Security

Configuring TACACS+

Establishing a TACACS+ server for centralized security, authentication, authorization, and accounting.

RADIUS

Using RADIUS servers for centralized 802.1X or MAC-based network access control.

Management Access Method

Defining access rules for various management methods like Telnet, SSH, HTTP, and SNMP.

Management Access Authentication

Assigning authentication methods for management access, locally or via TACACS+/RADIUS servers.

Secure Sensitive Data Management

Protecting sensitive data like passwords and keys using encryption, access control, and user authentication.

SSH Server

Establishing secure SSH sessions for remote users, supporting password or public key authentication.

SSH Client

Using the device as an SSH client to securely transfer files and manage network devices.

Storm Control

Limiting the number of frames entering the device to prevent traffic storms.

Port Security

Limiting access on ports to users with specific MAC addresses for network security.

802.1X Authentication

Restricting unauthorized clients from connecting to a LAN via publicity-accessible ports.

IP Source Guard

Preventing traffic attacks by validating client IP traffic against the DHCP Snooping Binding database.

ARP Inspection

Enabling IP communication within a Layer 2 domain by mapping IP addresses to MAC addresses and preventing cache poisoning.

First Hop Security

Securing link operations in an IPv6-enabled network using Neighbor Discovery and DHCPv6 messages.

Security: Secure Sensitive Data Management

SSD Rules

Defining read permissions and default read modes for user sessions on management channels.

SSD Properties

Configuring parameters for handling and security of sensitive data, including encryption and passphrase control.

Security: SSH Server

Security: SSH Client

SSH User Authentication

Selecting SSH user authentication methods (password, public key) and setting credentials.

SSH Server Authentication

Enabling SSH server authentication and defining trusted servers by their IP address or name.

Security: IPv6 First Hop Security

IPv6 First Hop Security Overview

Describing IPv6 FHS features for securing link operations based on Neighbor Discovery and DHCPv6 messages.

Router Advertisement Guard

Guarding against RA messages by filtering and validating received RA, CPA, and ICMPv6 redirect messages.

Neighbor Discovery Inspection

Validating received Neighbor Discovery protocol messages and performing egress filtering.

DHCPv6 Guard

Treating trapped DHCPv6 messages, filtering received messages, and validating them.

Neighbor Binding Integrity

Establishing binding of neighbors by learning IPv6 addresses from NDP and DHCPv6 messages.

IPv6 Source Guard

Validating source IPv6 addresses of NDP and DHCPv6 messages using the Neighbor Binding table.

Attack Protection

Protecting against IPv6 router spoofing, address resolution spoofing, and DHCPv6 server spoofing.

Access Control

Overview

Defining traffic flows using ACLs for traffic filtering and actions, enabling traffic classification.

MAC-Based ACLs Creation

Creating MAC-based ACLs to filter traffic based on Layer 2 fields.

IPv4-based ACL Creation

Creating IPv4-based ACLs to check IPv4 packets based on IP protocol, ports, and addresses.

IPv6-Based ACL Creation

Creating IPv6-based ACLs to check pure IPv6 traffic based on protocol, addresses, and ports.

ACL Binding

Binding ACLs to interfaces (ports, LAGs, VLANs) to apply ACE rules for packet filtering.

Quality of Service

QoS Features and Components

Optimizing network performance by classifying traffic, assigning to queues, and managing bandwidth.

QoS Basic Mode

Defining trusted domains and marking packets with 802.1p priority or DSCP for QoS treatment.

QoS Advanced Mode

Applying per-flow QoS using policies, class maps, and policers for granular traffic control.

SNMP

Smart Network Application (SNA)

Device Authorization Control (DAC)

Configuring a list of authorized client devices and activating 802.1x features using MAC authentication.

Related product manuals