EasyManua.ls Logo

ZyXEL Communications MES3500 Series User Manual

ZyXEL Communications MES3500 Series
370 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Page #1 background imageLoading...
Page #1 background image
Quick Start Guide
www.zyxel.com
MES3500 Series
Layer 2 Management Switch
Version 4.00
Edition 2, 01/2016
Copyright © 2016 ZyXEL Communications Corporation
User’s Guide
Default Login Details
LAN IP Address http://192.168.1.1
User Name admin
Password 1234

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the ZyXEL Communications MES3500 Series and is the answer not in the manual?

ZyXEL Communications MES3500 Series Specifications

General IconGeneral
Product SeriesMES3500 Series
Device TypeManaged Ethernet Switch
LayerLayer 2
Power over Ethernet (PoE)Yes (on select models)
Quality of Service (QoS)8 priority queues
Security FeaturesACLs
ManagementWeb GUI, CLI, SNMP
Jumbo Frame SupportUp to 9KB
Power SupplyInternal AC power supply
Operating Temperature0°C to 40°C
Storage Temperature-40°C to 70°C

Summary

Getting to Know Your Switch

Introduction

Introduces the main features and applications of the Switch, covering models, management methods, and network environments.

Ways to Manage the Switch

Outlines various methods for managing the Switch, including Web Configurator, Command Line Interface, FTP, and SNMP.

Good Habits for Managing the Switch

Provides essential practices for maintaining Switch security and efficient management, such as password policies and configuration backups.

Hardware Installation and Connection

Installation Scenarios

Describes the different placement options for the Switch: desktop, rack, or wall mounting, including ventilation requirements.

Desktop Installation

Provides step-by-step instructions for installing the Switch on a desktop surface, emphasizing stability and clearance.

Rack Mounting

Details the process for mounting the Switch into a standard EIA 19-inch rack, including necessary hardware and precautions.

Wall Mounting

Explains how to mount the Switch on a wall, including selecting a suitable location and marking screw positions.

Hardware Overview

Front Panel

Describes the components and ports found on the front panel of the Switch, including LEDs, Ethernet ports, and console port.

LEDs

Details the function and status indication of each LED on the Switch for operational monitoring and troubleshooting.

The Web Configurator

Introduction

Introduces the HTML-based Web Configurator for Switch setup and management via a web browser.

System Login

Guides users on how to access the Web Configurator by entering the Switch's IP address and logging in.

The Web Configurator Layout

Explains the navigation panel and key components of the Web Configurator interface for managing the Switch.

Saving Your Configuration

Details how to save configuration changes to the Switch's nonvolatile memory to ensure persistence after reboot.

Switch Lockout

Describes methods to prevent unauthorized access to the Switch via in-band management, potentially locking oneself out.

Resetting the Switch

Provides instructions on how to reload the factory-default configuration file or reset the Switch to its factory defaults.

Logging Out of the Web Configurator

Recommends logging out after a management session for security reasons and explains the process.

Help

Explains how to access the web configurator's online help for descriptions of screens and supplementary information.

Initial Setup Example

Overview

Lists the configuration steps for initial setup: creating a VLAN, setting port VLAN ID, and configuring the Switch IP address.

Configuring Switch Management IP Address

Demonstrates how to configure the Switch's management IP address, possibly in a different subnet for management purposes.

Tutorials

How to Use DHCP Snooping on the Switch

Provides a step-by-step guide on configuring DHCP snooping to manage IP address assignments and enhance network security.

How to Use DHCP Relay on the Switch

Explains how to configure the Switch to forward DHCP client requests to a specific DHCP server for IP address assignment.

How to Use PPPoE IA on the Switch

Details the configuration of PPPoE Intermediate Agent to pass subscriber information to a PPPoE server for identification and authentication.

How to Use Error Disable and Recovery on the Switch

Illustrates how to configure the Switch to shut down a port upon detecting errors like loops or excessive ARP requests.

How to Set Up a Guest VLAN

Guides on setting up a guest VLAN for unauthenticated clients, providing limited network access like internet surfing.

How to Do Port Isolation in a VLAN

Explains how to prevent inter-port communication within a VLAN using private VLANs while allowing uplink access.

System Status and Port Statistics

Overview

Describes how the web configurator's home screen displays port statistics and links to detailed port information.

Port Status Summary

Explains how to view port statistics by accessing the Status screen, providing a summary of link status and traffic.

Basic Setting

System Information

Allows checking firmware version, monitoring Switch temperature, and voltage, and viewing system hardware information.

General Setup

Guides on configuring general settings like system name, location, contact person, and time server synchronization.

Introduction to VLANs

Explains Virtual Local Area Networks (VLANs), their benefits for network segmentation, isolation, and performance.

Switch Setup

Covers configuring global switch parameters including VLAN type (802.1Q or Port Based), MAC learning, and smart isolation.

IP Setup

Details configuring the Switch IP address, default gateway, DNS server, and management VLAN ID for network access.

Port Setup

Explains how to configure individual Switch port settings such as speed, duplex mode, flow control, and 802.1p priority.

VLAN

Introduction to IEEE 802.1Q Tagged VLANs

Introduces IEEE 802.1Q tagged VLANs, explaining VLAN membership, tagging, and frame format for network segmentation.

Automatic VLAN Registration

Describes automatic VLAN registration using GARP and GVRP protocols for dynamic VLAN membership across switches.

Port VLAN Trunking

Explains how to enable VLAN Trunking to allow frames belonging to unknown VLAN groups to pass through intermediary devices.

Select the VLAN Type

Instructs on selecting the VLAN type (802.1Q or Port Based) in the Switch Setup screen for VLAN configuration.

Static VLAN

Details how to configure static VLANs to control frame forwarding based on VLAN tags, group membership, or blocking.

Subnet Based VLANs

Explains how to group traffic into logical VLANs based on source IP subnet for traffic prioritization and management.

Protocol Based VLANs

Describes grouping traffic into logical VLANs based on specified protocols like ARP or AppleTalk for traffic prioritization.

MAC Based VLAN

Explains how to assign incoming untagged packets to a VLAN based on the source MAC address for port-based traffic classification.

VLAN MAC Learning

Details how to set MAC address learning limits on a per-port and per-VLAN basis for controlling dynamic MAC entries.

Port-based VLAN Setup

Guides on setting up port-based VLANs where forwarding decisions are based on destination MAC address and associated port.

Static MAC Forward Setup

Overview

Introduces configuring forwarding rules based on MAC addresses of devices on the network for static MAC address forwarding.

Configuring Static MAC Forwarding

Explains how to manually enter static MAC addresses into the MAC address table for port-specific forwarding rules.

Static Multicast Forward Setup

Static Multicast Forwarding Overview

Provides an overview of static multicast forwarding, allowing administrators to forward multicast frames to specific ports.

Configuring Static Multicast Forwarding

Details how to configure rules to forward specific multicast frames, such as streaming or control frames, to specific ports.

Filtering

Configure a Filtering Rule

Explains how to configure the Switch to filter traffic based on source, destination MAC addresses, or VLAN group (ID).

Spanning Tree Protocol

STP/RSTP Overview

Provides an overview of Spanning Tree Protocol (STP), Rapid Spanning Tree Protocol (RSTP), and Multiple Spanning Tree Protocol (MSTP).

Spanning Tree Protocol Status Screen

Describes the Spanning Tree Protocol status screen, which displays information based on the chosen STP standard.

Spanning Tree Configuration

Explains how to activate one of the STP modes (RSTP, MRSTP, MSTP) on the Switch via the Spanning Tree Configuration screen.

Configure Rapid Spanning Tree Protocol

Guides on configuring RSTP settings, including bridge priority, hello time, and port configurations.

Rapid Spanning Tree Protocol Status

Details the RSTP status screen, showing bridge information, hello time, max age, and forwarding delay settings.

Configure Multiple Rapid Spanning Tree Protocol

Explains how to configure MRSTP, including activating STP trees and assigning ports to specific spanning trees.

Multiple Rapid Spanning Tree Protocol Status

Describes the MRSTP status screen, providing information on bridge IDs, hello times, and maximum age settings.

Configure Multiple Spanning Tree Protocol

Guides on configuring MSTP, including settings for MST regions, instances, and port configurations.

Bandwidth Control

Bandwidth Control Overview

Defines bandwidth control as setting maximum allowable bandwidth for incoming and outgoing traffic flows on a port.

Bandwidth Control Setup

Details how to configure bandwidth control settings via the Bandwidth Control screen, including CIR and PIR.

Broadcast Storm Control

Broadcast Storm Control Setup

Explains how to configure broadcast storm control to limit broadcast, multicast, and DLF packets per second on ports.

Mirroring

Port Mirroring Overview

Introduces port mirroring for copying traffic flows to a monitor port for examination without interfering with network traffic.

Local Port Mirroring Screen

Describes the screen for configuring local port mirroring, allowing selection of monitor ports and traffic direction.

RMirror-Source Screen

Explains how to set the RMirror VLAN ID and mirroring port for remote port mirroring when the Switch is the source device.

RMirror-Destination Screen

Details specifying the RMirror VLAN ID and monitor port for remote port mirroring when the Switch is the destination device.

Link Aggregation

Link Aggregation Overview

Explains link aggregation (trunking) as grouping physical ports into a single logical, higher-bandwidth link.

Dynamic Link Aggregation

Describes dynamic link aggregation using LACP, allowing automatic negotiation and management of trunk groups.

Link Aggregation Status

Explains how to view the status of link aggregation, including group ID, enabled ports, and synchronized ports.

Link Aggregation Setting

Guides on configuring static link aggregation, including group ID, active status, and traffic distribution criteria.

Link Aggregation Control Protocol

Details the configuration of LACP for dynamic link aggregation, including system priority and LACP active settings.

Static Trunking Example

Provides an example of creating a static port trunk group for ports 2-5, including physical connections and configuration.

Port Authentication

Port Authentication Overview

Introduces port authentication for validating client access based on external servers using IEEE 802.1x and MAC authentication.

Port Authentication Configuration

Guides on activating port authentication methods and configuring RADIUS server settings in the AAA section.

Port Security

About Port Security

Explains port security allowing only packets with learned or static MAC addresses to pass through a port.

Port Security Setup

Details how to set up port security, including enabling the feature, disabling MAC learning, and configuring static MAC addresses.

Range Profile

Range Profile Overview

Defines a profile as saved settings for ranges of ports, IP addresses, VLANs, or socket ports, usable across multiple screens.

Range Profile Screen

Describes accessing and configuring profiles for VLANs, IP addresses, ports, and socket ports via the Range Profile screen.

VLAN Range Profile

Explains how to view, manage, and create VLAN range profiles, specifying ranges of VLAN IDs for identification purposes.

Port Range Profile

Guides on viewing, managing, and creating port range profiles, specifying ranges of port numbers for configuration.

IP Address Range Profile

Details viewing, managing, and creating IP address range profiles, specifying ranges of IP addresses for configuration.

Socket-Port Range Profile

Explains how to view, manage, and create socket port range profiles, specifying ranges of socket port numbers.

Classifier

About the Classifier and QoS

Introduces Classifiers and Quality of Service (QoS) for prioritizing traffic and fine-tuning network performance.

Configuring the Classifier

Details how to define classifiers to specify actions (policy) on traffic matching specific rules.

Viewing and Editing Classifier Configuration

Explains how to view a summary of classifier configurations and edit existing rules for traffic classification.

Classifier Example

Provides an example of configuring a classifier to identify traffic based on MAC address and port.

Policy Rule

Policy Rules Overview

Explains how classifiers distinguish traffic flows and policy rules ensure requested treatment within the network.

Configuring Policy Rules

Guides on configuring policy rules, which define actions for classified traffic flows, after setting up classifiers.

Viewing and Editing Policy Configuration

Describes how to view a summary of policy configurations and edit existing rules for traffic treatment.

Policy Example

Illustrates configuring a policy to limit bandwidth on a traffic flow classified using a specific example classifier.

Queuing Method

Queuing Method Overview

Introduces queuing methods used to solve performance degradation during network congestion and configure outgoing traffic.

Configuring Queuing

Details how to configure queuing methods like SPQ, WFQ, and WRR on the Switch for traffic management.

VLAN Stacking

VLAN Stacking Overview

Explains VLAN stacking for distinguishing multiple customer VLANs within a network by adding outer VLAN tags.

VLAN Stacking Port Roles

Describes the three VLAN stacking roles: Normal, Access Port, and Tunnel Port for frame switching and tag handling.

VLAN Tag Format

Details the format of a VLAN tag, including Type, Priority, and VID fields used in service provider VLAN stacking.

Configuring VLAN Stacking

Guides on configuring VLAN stacking settings, including port roles and tunnel TPID values for frame encapsulation.

Multicast

Multicast Overview

Introduces multicast transmission, IGMP, IP multicast addresses, and IGMP filtering features for efficient group communication.

Multicast Status

Explains how to view multicast group information and configure multicast settings via the Multicast Status screen.

MVR Overview

Describes Multicast VLAN Registration (MVR) for sharing a single multicast VLAN among different subscriber VLANs.

General MVR Configuration

Guides on creating multicast VLANs and configuring receiver and source ports for each multicast VLAN using the MVR screen.

AAA

Authentication, Authorization and Accounting (AAA)

Explains the AAA process: authentication, authorization, and accounting for user access and activity tracking on the Switch.

AAA Screens

Details the AAA screens for enabling authentication, authorization, and accounting, and configuring server settings.

Supported RADIUS Attributes

Lists RADIUS attributes used for defining authentication and accounting elements in user profiles on the RADIUS server.

IP Source Guard

IP Source Guard Overview

Explains IP Source Guard's use of a binding table to filter unauthorized DHCP and ARP packets, distinguishing authorized and unauthorized traffic.

IP Source Guard

Describes viewing current bindings for DHCP snooping and ARP inspection, which distinguish authorized and unauthorized packets.

IP Source Guard Static Binding

Guides on managing static bindings for DHCP snooping and ARP inspection, uniquely identified by MAC address and VLAN ID.

DHCP Snooping

Details how to view statistics about the DHCP snooping database, including agent URL and database file format.

DHCP Snooping Configure

Explains enabling DHCP snooping on the Switch and configuring the database location and update intervals.

ARP Inspection Status

Describes viewing statistics about ARP packets in each VLAN and MAC address filters created due to unauthorized ARP packets.

Loop Guard

Loop Guard Overview

Explains Loop Guard's function to shut down ports detecting looped-back packets, protecting the network edge.

Loop Guard Setup

Guides on enabling Loop Guard on the Switch, including port settings and generating syslog/SNMP traps on port shutdown.

VLAN Mapping

VLAN Mapping Overview

Explains VLAN mapping to map VLAN IDs and priorities from private networks to service provider networks.

Enabling VLAN Mapping

Instructs on enabling VLAN mapping on the Switch via the VLAN Mapping screen.

Configuring VLAN Mapping

Details how to enable and edit VLAN mapping rules, specifying port, VID, translated VID, priority, and direction.

Layer 2 Protocol Tunneling

Layer 2 Protocol Tunneling Overview

Introduces Layer-2 protocol tunneling (L2PT) for service provider edge devices to tunnel L2 protocols like STP and CDP.

Configuring Layer 2 Protocol Tunneling

Guides on configuring L2PT, including port modes (Access, Tunnel) and supported protocols like STP, LACP, VTP, CDP, UDLD, PAGP.

sFlow

sFlow Overview

Describes sFlow (RFC 3176) as a technology for monitoring switched networks by sampling traffic data.

sFlow Port Configuration

Details how to configure sFlow ports for traffic monitoring, specifying sample rate and poll interval to send datagrams to a collector.

PPPoE

PPPoE Intermediate Agent Overview

Introduces PPPoE Intermediate Agent (PPPoE IA) for adding subscriber information to PPPoE discovery packets.

PPPoE Screen

Explains how to configure the PPPoE Intermediate Agent on the Switch via the PPPoE screen.

PPPoE Intermediate Agent

Details configuring the Switch to provide subscriber information to a PPPoE server for client identification and authentication.

Error Disable

CPU Protection Overview

Explains CPU protection for limiting control packet rates (ARP, BPDU, IGMP) to prevent CPU overload and DoS attacks.

Error-Disable Recovery Overview

Describes error-disable recovery features that allow automatic port activation after an error condition is resolved.

Error Disable Screen

Guides on configuring error disable related settings, including CPU protection, errdisable detect, and recovery.

Error-Disable Status

Explains how to view the Switch's detected control packet rate limits and port status (disabled or forwarding).

CPU Protection Configuration

Details limiting control packet rates on ports for CPU protection and selecting actions when limits are exceeded.

Error-Disable Detect Configuration

Guides on configuring the Switch to detect exceeded rate limits for control packets and take corresponding actions.

Error-Disable Recovery Configuration

Explains how to configure the Switch to automatically undo actions after an error condition is gone, specifying time intervals.

Private VLAN

Private VLAN Overview

Introduces Private VLAN for port isolation within a VLAN, blocking traffic between isolated ports while allowing promiscuous port access.

Configuring Private VLAN

Guides on configuring and enabling private VLAN rules for VLANs to achieve port isolation within the network.

Static Route

Static Routing Overview

Explains how the Switch uses IP for communication and static routes for responding to unreachable management stations.

Configuring Static Routing

Details how to configure static routes in the IP Application > Static Routing screen for managing network traffic forwarding.

Differentiated Services

DiffServ Overview

Introduces DiffServ (Differentiated Services) as a CoS model for marking packets with DSCPs for specific per-hop treatment.

Two Rate Three Color Marker Traffic Policing

Explains traffic policing methods like TRTCM for limiting traffic rates based on CIR and PIR, marking packets with colors.

Activating DiffServ

Guides on activating DiffServ to apply marking rules or IEEE 802.1p priority mapping on selected ports.

DHCP

DHCP Overview

Introduces DHCP for obtaining TCP/IP configuration, allowing the Switch to act as a server or relay agent.

DHCP Configuration

Explains DHCP configuration options divided into Global and VLAN screens for offering DHCP services to clients.

DHCPv4 Status

Describes the DHCPv4 Status screen, showing configuration settings related to the Switch's DHCP relay mode.

DHCPv4 Relay

Guides on configuring DHCP relay to help forward network information between DHCP clients and servers not in the same domain.

DHCPv6 Relay

Explains DHCPv6 relay agent functionality for forwarding messages between DHCPv6 servers and clients, including option 82 information.

ARP Learning

ARP Overview

Introduces Address Resolution Protocol (ARP) for mapping IP addresses to MAC addresses and maintaining the ARP table.

ARP Learning

Details configuring each port's ARP learning mode (ARP-Reply, Gratuitous-ARP, ARP-Request) for updating the ARP table.

Maintenance

The Maintenance Screen

Explains how to manage firmware and configuration files, including upgrade, restore, backup, and factory default loading.

Load Factory Default

Provides instructions to reset the Switch back to its factory default configuration settings.

Save Configuration

Details how to save current configuration settings permanently to Configuration 1 or Configuration 2 on the Switch.

Reboot System

Explains how to restart the Switch without physical power cycling, allowing loading of specific configurations upon reboot.

Firmware Upgrade

Guides on uploading the correct model firmware to the Switch, emphasizing the importance of using the right version.

Restore a Configuration File

Describes how to restore a previously saved configuration file from a computer to the Switch.

Backup a Configuration File

Explains how to create 'snap shots' of the Switch configuration to a computer for later restoration.

Tech-Support

Introduces the Tech-Support feature for logging useful information like CPU utilization and crash reports for issue analysis.

FTP Command Line

Provides examples of uploading or downloading files from the Switch using FTP commands, including filename conventions.

Access Control

Access Control Overview

Describes how to control access to the Switch via console port, Telnet, SSH, FTP, Web, and SNMP sessions.

The Access Control Main Screen

Shows the main Access Control screen where users can access SNMP, Logins, Service Access Control, and Remote Management.

About SNMP

Introduces Simple Network Management Protocol (SNMP) for managing and monitoring TCP/IP-based devices.

Setting Up Login Accounts

Guides on setting up login accounts for administrators and non-administrators to access the Switch via web configurator.

SSH Overview

Explains SSH (Secure Shell) as a secure protocol for encrypted communication, authentication, and file transfer.

How SSH works

Summarizes the process of establishing a secure connection between two remote hosts using SSH.

SSH Implementation on the Switch

Details the Switch's support for SSH version 2, including authentication methods and encryption algorithms.

Introduction to HTTPS

Explains HTTPS as a web protocol for secure web page encryption and decryption using SSL/TLS.

HTTPS Example

Provides examples of accessing the Switch via HTTPS, including handling browser security certificate warnings.

Service Port Access Control

Describes controlling access to the Switch by enabling/disabling services and configuring trusted computers for each service.

Remote Management

Explains configuring trusted computers for remote management services like Telnet, HTTP, and SSH.

Diagnostic

Diagnostic

Explains the Diagnostic screen for checking system logs, pinging IP addresses, and performing port tests to identify problems.

Syslog

Syslog Overview

Introduces the syslog protocol for sending event notification messages to syslog servers for collection and analysis.

Syslog Setup

Guides on configuring system logging settings to send logs to an external syslog server.

Syslog Server Setup

Details configuring a list of external syslog servers, specifying IP address, log level, and activation status.

Cluster Management

Cluster Management Status Overview

Introduces cluster management for managing multiple switches through one Switch (cluster manager).

Cluster Management Status

Explains how to view cluster management status, including manager details, member count, and member status (online, error, offline).

Clustering Management Configuration

Guides on configuring clustering management, including setting the cluster manager and managing cluster members.

MAC Table

MAC Table Overview

Introduces the MAC Table screen, showing how frames are forwarded or filtered based on MAC addresses and VLAN groups.

Viewing the MAC Table

Details how to view the MAC Table, specifying conditions and sort order for displaying MAC address entries.

ARP Table

ARP Table Overview

Introduces the ARP Table, which maps IP addresses to MAC addresses and maintains associations for local area network communication.

The ARP Table Screen

Guides on using the ARP table screen to view IP-to-MAC address mappings and remove specific dynamic ARP entries.

Configure Clone

Configure Clone

Explains how to copy basic and advanced settings from a source port to destination ports using the Configure Clone screen.

Troubleshooting

Power, Hardware Connections, and LEDs

Provides troubleshooting steps for issues related to power, hardware connections, and LED behavior.

Switch Access and Login

Offers solutions for problems related to forgetting IP addresses, usernames, passwords, or accessing the web configurator.

Switch Configuration

Addresses issues with losing configuration settings after restarting the Switch and ensures proper saving of configurations.

APPENDIX A Customer Support

APPENDIX B Common Services

APPENDIX C Legal Information

Related product manuals