Page 2
Reproduction in any manner whatsoever without the written permission of D-Link Computer Corporation is strictly forbidden. Trademarks used in this text: D-Link and the D-Link logo are trademarks of D-Link Computer Corporation; Microsoft and Windows are registered trademarks of Microsoft Corporation.
DGS-3024 Gigabit Ethernet Switch Manual Table of Contents Preface ....................................ix Intended Readers................................ix Notes, Notices, and Cautions ............................ix Safety Instructions.................................xi Introduction..................................... 1 Features ....................................1 Ports ....................................1 Performance Features................................ 1 Management..................................1 Unpacking and Setup................................3 Packing List ..................................3 Installation ....................................
Page 4
DGS-3024 Gigabit Ethernet Switch Manual Traps ....................................16 MIBs ....................................16 IP Address Assignment ............................... 16 Connecting Devices to the Switch ............................18 Web-Based Network Management............................19 Introduction................................... 19 Login to Web Manager................................. 19 Web-based User Interface..............................20 Areas of the User Interface ..............................20 Configuration ..................................
Page 5
Multicast Forwarding ................................. 48 VLANs....................................49 Understanding IEEE 802.1p Priority ..........................49 VLAN Description................................50 Notes About VLANs on the DGS-3024 ......................... 50 IEEE 802.1Q VLANs ..............................50 802.1Q VLAN Tags................................ 52 Port VLAN ID................................. 53 Tagging and Untagging..............................54 Ingress Filtering ................................
Appendix C, “Glossary” – Lists definitions for terms and acronyms used in this document. Intended Readers The DGS-3024 Manual contains information for setup and management and of the DGS-3024 Switch. This guide is intended for network managers familiar with network management concepts and terminology.
Page 10
DGS-3024 Gigabit Ethernet Switch Manual CAUTION: A CAUTION indicates a potential for property damage, personal injury, or death.
DGS-3024 Gigabit Ethernet Switch Manual Safety Instructions Use the following safety guidelines to ensure your own personal safety and to help protect your system from potential damage. Throughout this safety section, the caution icon ( ) is used to indicate cautions and precautions that you need to review and follow.
Page 12
DGS-3024 Gigabit Ethernet Switch Manual Safety Instructions (continued) • To help prevent an electric shock, plug the system and peripheral power cables into properly grounded electrical outlets. These cables are equipped with three-prong plugs to help ensure proper grounding. Do not use adapter plugs or remove the grounding prong from a cable.
Page 13
DGS-3024 Gigabit Ethernet Switch Manual Safety Instructions (continued) Always load the rack from the bottom up, and load the heaviest item in the rack first. Make sure that the rack is level and stable before extending a component from the rack.
DGS-3024 Gigabit Ethernet Switch Manual Protecting Against Electrostatic Discharge Static electricity can harm delicate components inside your system. To prevent static damage, discharge static electricity from your body before you touch any of the electronic components, such as the microprocessor. You can do so by periodically touching an unpainted metal surface on the chassis.
This section describes the features of the DGS-3024. Features The DGS-3024 was designed for departmental and enterprise connections. As an all-gigabit-port Switch, it is ideal for backbone and server connection. Powerful and versatile, the Switch eliminates network bottlenecks while giving users the...
Page 16
Ethernet-like MIB (RFC 1643) Private MIB Mini-RMON MIB (RFC 1757) – four groups. The RMON specification defines the counters for the receive functions only. However, the DGS-3024 provides counters for both receive and transmit functions. • Supports Web-based management. •...
D-View 5.1 demo CD-ROM • This Manual with Registration Card on CD-ROM If any item is found missing or damaged, please contact your local D-Link reseller for replacement. Installation Use the following guidelines when choosing a place to install the Switch: •...
Rack Installation The DGS-3024 can be mounted in an EIA standard-sized, 19-inch rack, which can be placed in a wiring closet with other equipment. To install, attach the mounting brackets on the Switch’s side panels (one on each side) and secure them with the screws provided.
DGS-3024 Gigabit Ethernet Switch Manual Figure 2- 2B. Installing in an equipment rack Power on The Switch can be used with AC power supply 100-240 VAC, 50 - 60 Hz. The Switch’s power supply will adjust to the local power source automatically and may be powered on without having any or all LAN segment cables connected.
Page 20
DGS-3024 Gigabit Ethernet Switch Manual Figure 2-3. DPS-300 in DPS-900 case with DGS-3024 Figure 2-4. DPS-300 in DPS-800 case with DGS-3024 See the DPS-300 documentation for more information. NOTE: Do not use the Switch with any redundant power system other than CAUTION: the DPS-300.
Figure 3-2. Rear panel view • The external Redundant Power Supply connector is used to connect the DGS-3024 to a DPS-300. An auto-Switch circuit automatically Switches to an external RPS once the internal power supply fails. Transition from internal to external supply shall not disturb normal operation.
DGS-3024 Gigabit Ethernet Switch Manual Figure 3-3. Side panel views of the Switch • The system fans are used to dissipate heat. The sides of the system also provide heat vents to serve the same purpose. Do not block these openings, and leave at least 6 inches of space at the rear and sides of the Switch for proper ventilation.
DGS-3024 Gigabit Ethernet Switch Manual Connecting the Switch This chapter describes how to connect the DGS-3024 to your Gigabit Ethernet network. Switch to End Node End nodes include PCs outfitted with a 10, 100, or 1000 Mbps RJ-45 Ethernet/Fast Ethernet/Gigabit Ethernet Network Interface Card (NIC) and most routers.
DGS-3024 Gigabit Ethernet Switch Manual Switch to Hub or Switch These connections can be accomplished in a number of ways using a normal cable. • A 10BASE-T hub or Switch can be connected to the Switch via a two-pair Category 3, 4, 5, or 5e UTP/STP cable.
Page 25
DGS-3024 Gigabit Ethernet Switch Manual Figure 4- 3. Switch connected by optical fiber cable to a Core Router Switch, with a server connected by crossover cable and a PC connected by a Category 3, 4, 5, or 5e UTP/STP cable...
DGS-3024 Gigabit Ethernet Switch Manual Introduction to Switch Management Management Options This system may be managed out-of-band through the console port on the front panel or in-band using Telnet. The user may also choose the web-based management, accessible through a web browser.
Page 27
12. Enter the commands to complete your desired tasks. Many commands require administrator-level access privileges. Read the next section for more information on setting up user accounts. See the DGS-3024 Command Line Interface Reference Manual on the documentation CD for a list of all commands and additional information on using the CLI.
Password Protection The DGS-3024 does not have a default user name and password. One of the first tasks when settings up the Switch is to create user accounts. If you log in using a predefined administrator-level user name, you have privileged access to the Switch's management software.
The DGS-3024 supports SNMP versions 1, 2c, and 3. You can specify which version of SNMP you want to use to monitor and control the Switch. The three versions of SNMP vary in the level of security provided between the management station...
DGS-3024 Gigabit Ethernet Switch Manual In SNMP v.1 and v.2, user authentication is accomplished using 'community strings', which function like passwords. The remote user SNMP application and the Switch SNMP must use the same community string. SNMP packets from any station that has not been authenticated are ignored (dropped).
Page 31
DGS-3024 Gigabit Ethernet Switch Manual Figure 5- 3. Show Switch command The Switch's MAC address can also be found from the Web management program on the Switch Information (Basic Settings) window on the Configuration menu. The IP address for the Switch must be set before it can be managed with the Web-based manager. The Switch IP address can be automatically set using BOOTP or DHCP protocols, in which case the actual address assigned to the Switch must be known.
DGS-3024 Gigabit Ethernet Switch Manual Figure 5- 4. Assigning the Switch an IP Address In the above example, the Switch was assigned an IP address of 10.24.22.8 with a subnet mask of 255.0.0.0. The system message Success indicates that the command was executed successfully. Please remember to save your new settings before you logout or they will be lost.
Web-Based Network Management Introduction The DGS-3024 offers an embedded Web-based (HTML) interface allowing users to manage the Switch from anywhere on the network through a standard browser, such as Opera, Netscape Navigator/Communicator, or Microsoft Internet Explorer. The Web browser acts as a universal access tool and can communicate directly with the Switch using the HTTP protocol.
DGS-3024 Gigabit Ethernet Switch Manual Figure 6- 2. Enter Network Password dialog box Leave both the User Name field and the Password field blank and click OK. This will open the Web-based user interface. The Switch management features available in the Web-based manager are explained below.
Page 35
DGS-3024 Gigabit Ethernet Switch Manual mode, or flow control, depending on the specified mode. Various areas of the graphic can be selected for performing management functions, including port configuration. Presents Switch information based on your selection and the entry of configuration Area 3 data.
DGS-3024 Gigabit Ethernet Switch Manual Configuration The first Web Manager main folder is Configuration and includes the following windows and sub-folders: IP Address, Switch Information, Advanced Settings, Port Configuration, Port Mirroring, Link Aggregation, IGMP Snooping, Spanning Tree, Forwarding & Filtering, VLANs, SNTP Settings, QoS, MAC Notification, System Log Server, Port Access Entity, and Static ARP Settings, as well as secondary windows.
DGS-3024 Gigabit Ethernet Switch Manual Switch Information Figure 7- 2. Switch Information (Basic Settings) window This window is used to enter name, location, and contact information. Click Apply to activate the new settings. The information is described as follows: Parameter Description A description of the Switch type.
DGS-3024 Gigabit Ethernet Switch Manual Advanced Settings Figure 7- 3. Switch Information (Advanced Settings) window The following fields can be set: Parameter Description This setting for the restart of the console is 2 Minutes, 5 Minutes, 10 Minutes, 15 Serial Port Auto Minutes, or Never.
Page 39
DGS-3024 Gigabit Ethernet Switch Manual IP router. The default is Disabled. This indicates if a Telnet connection is currently enabled on the Switch. The default is Telnet Status Enabled. The TCP port number. TCP ports are numbered between 1 and 65535. The "well- Telnet TCP Port known"...
DGS-3024 Gigabit Ethernet Switch Manual Port Configuration Figure 7- 4. Port Configuration window To configure Switch ports: 1. Choose the port or sequential range of ports using the From and To pull-down menus. 2. Use the remaining pull-down menus to configure the parameters described below:...
Page 41
DGS-3024 Gigabit Ethernet Switch Manual then to use those settings. The other options are 10M/Half, 10M/Full, 100M/Half and 100M/Full, 1000M/Full_M and 1000M/Full_S. There is no automatic adjustment of port settings with any option other than Auto. The Switch allows the user to configure two types of gigabit connections;...
DGS-3024 Gigabit Ethernet Switch Manual Port Mirroring Figure 7- 5. Setup Port Mirroring window To configure a mirror port: 1. Select the Source Port from where you want to copy frames and the Target Port, which receives the copies from the source port.
“Link Aggregation” and “Port Trunking” will be used synonymously. The DGS-3024 supports up to four port trunk groups with 2 to 8 ports in each group. A potential bit rate of 8000 Mbps can be achieved. Figure 7- 6. Example of Port Trunk Group The Switch treats all ports in a trunk group as a single port.
Page 44
DGS-3024 Gigabit Ethernet Switch Manual The Switch allows the creation of up to four port trunking groups, each group consisting of 2 to 8 links (ports). The aggregated links must be contiguous (they must have sequential port numbers) except the two (optional) Gigabit ports, which can only belong to a single port trunking group.
DGS-3024 Gigabit Ethernet Switch Manual IGMP Snooping Use the Current IGMP Snooping Group Entries window to view IGMP Snooping settings. To modify the settings, click the Modify button of the VLAN ID you want to change. Figure 7- 9. Current IGMP Snooping Group Entries window Clicking the Modify button will open the IGMP Snooping Settings window, shown below: Figure 7- 10.
DGS-3024 Gigabit Ethernet Switch Manual A value between 1 and 25 seconds can be entered, with a default of 10 seconds. A tuning variable to allow for subnetworks that are expected to lose a large number of Robustness Value packets. A value between 2 and 255 can be entered, with larger values being specified for subnetworks that are expected to lose larger numbers of packets.
802.1d STP will be familiar to most networking professionals. However, since 802.1w RSTP and 802.1s MSTP has been recently introduced to D-Link managed Ethernet Switches, a brief introduction to the technology is provided below followed by a description of how to set up 802.1d STP, 802.1w RSTP and 802.1s MSTP.
DGS-3024 Gigabit Ethernet Switch Manual 1. A configuration name defined by an alphanumeric string of up to 32 characters (defined in the Current MST Configuration Identification window in the Configuration Name field). 2. A configuration revision number (named here as a Revision Level (0-65535) and found in the Current MST Configuration Identification window) and;...
DGS-3024 Gigabit Ethernet Switch Manual Edge Port The edge port is a configurable designation used for a port that is directly connected to a segment where a loop cannot be created. An example would be a port connected directly to a single workstation. Ports that are designated as edge ports transition to a forwarding state immediately, without going through the listening and learning states.
Page 51
DGS-3024 Gigabit Ethernet Switch Manual Figure 7- 14. STP Bridge Global Settings window - RSTP (default) Figure 7- 15. STP Bridge Global Settings window - MSTP The following parameters can be set: Parameter Description Use the pull-down menu to enable or disable STP globally on the Switch. The STP Status default is Disabled.
DGS-3024 Gigabit Ethernet Switch Manual that it is indeed the Root Bridge. This field will only appear here when STP or RSTP is selected for the STP Version. For MSTP, the Hello Time must be set on a port per port basis. See the STP Port Settings section for further details.
Page 53
DGS-3024 Gigabit Ethernet Switch Manual Figure 7- 16. Current MST Configuration Identification window The window above contains the following information: Parameter Description A previously configured name set on the Switch to uniquely identify the MSTI (Multiple Configuration Name Spanning Tree Instance). If a configuration name is not set, this field will show the MAC address to the device running MSTP.
Page 54
DGS-3024 Gigabit Ethernet Switch Manual Parameter Description Enter a number between 1 and 15 to set a new MSTI on the Switch. MSTI ID Create is selected to create a new MSTI. No other choices are available for this field Type when creating a new MSTI.
DGS-3024 Gigabit Ethernet Switch Manual Figure 7- 19. Instance ID Settings window - Modify The user may configure the following parameters for a MSTI on the Switch. Parameter Description Displays the MSTI ID previously set by the user. MSTI ID This field allows the user to choose a desired method for altering the MSTI settings.
Page 56
DGS-3024 Gigabit Ethernet Switch Manual Figure 7- 20. MSTI Port Information window To view the MSTI settings for a particular port, select the Port number, located in the top left hand corner of the window and click Apply. To modify the settings for a particular MSTI Instance, click on its hyperlinked MSTI ID, which will reveal the following window.
DGS-3024 Gigabit Ethernet Switch Manual STP Instance Settings The following window displays MSTIs currently set on the Switch. To view the following table, click Configuration > Spanning Tree > STP Instance Settings: Figure 7- 22. STP Instance Settings window The following information is displayed:...
Page 58
DGS-3024 Gigabit Ethernet Switch Manual Figure 7- 24. STP Instance Operational Status window – Previously Configured MSTI The following parameters may be viewed in the STP Instance Operational Status windows: Parameter Description This field will show the priority and MAC address of the Root Bridge.
Page 59
DGS-3024 Gigabit Ethernet Switch Manual The Max Age may be set to ensure that old information does not endlessly circulate Max Age through redundant paths in the network, preventing the effective propagation of the new information. Set by the Root Bridge, this value will aid in determining that the Switch has spanning tree configuration values consistent with other devices on the bridged LAN.
DGS-3024 Gigabit Ethernet Switch Manual STP Port Settings STP can be set up on a port per port basis. To view the following window click Configuration > Spanning Tree > STP Port Settings: Figure 7- 25. STP Port Settings window...
Page 61
DGS-3024 Gigabit Ethernet Switch Manual In addition to setting Spanning Tree parameters for use on the Switch level, the Switch allows for the configuration of groups of ports, each port-group of which will have its own spanning tree, and will require some of its own configuration settings.
DGS-3024 Gigabit Ethernet Switch Manual True. This drop-down menu allows you to enable or disable STP for the selected group of State ports. The default is Enabled. Click Apply to implement changes made. Forwarding Unicast Forwarding Open the Forwarding folder in the Configuration menu and click on the Unicast Forwarding link. This will open the Setup Static Unicast Forwarding Table window, as shown below: Figure 7- 26.
DGS-3024 Gigabit Ethernet Switch Manual Figure 7- 27. Static Multicast Forwarding Settings window The Static Multicast Forwarding Settings window displays all of the entries made into the Switch's static multicast forwarding table. Click the Add button to open the Setup Static Multicast Forwarding Table window, as shown below: Figure 7- 28.
VLANs without a network device performing a routing function between the VLANs. The DGS-3024 supports IEEE 802.1Q VLANs. The port untagging function can be used to remove the 802.1Q tag from packet headers to maintain compatibility with devices that are tag-unaware.
Page 65
DGS-3024 Gigabit Ethernet Switch Manual Ingress port – A port on a Switch where packets are flowing into the Switch and VLAN decisions must be made. Egress port – A port on a Switch where packets are flowing out of the Switch, either to another Switch or to an end station, and tagging decisions must be made.
DGS-3024 Gigabit Ethernet Switch Manual Figure 7- 29. IEEE 802.1Q Packet Forwarding 802.1Q VLAN Tags The figure below shows the 802.1Q VLAN tag. There are four additional octets inserted after the source MAC address. Their presence is indicated by a value of 0x8100 in the EtherType field. When a packet's EtherType field is equal to 0x8100, the packet carries the IEEE 802.1Q/802.1p tag.
DGS-3024 Gigabit Ethernet Switch Manual Figure 7- 30. IEEE 802.1Q Tag The EtherType and VLAN ID are inserted after the MAC source address, but before the original EtherType/Length or Logical Link Control. Because the packet is now a bit longer than it was originally, the Cyclic Redundancy Check (CRC) must be recalculated.
DGS-3024 Gigabit Ethernet Switch Manual table). If the PVID of the port that received the packet is different from the PVID of the port that is to transmit the packet, the Switch will drop the packet. Within the Switch, different PVIDs mean different VLANs (remember that two VLANs cannot communicate without an external router).
DGS-3024 Gigabit Ethernet Switch Manual Default VLANs The Switch initially configures one VLAN, VID = 1, called "default." The factory default setting assigns all ports on the Switch to the "default." Packets cannot cross VLANs. If a member of one VLAN wants to connect to another VLAN, the link must be through an external router.
Page 70
DGS-3024 Gigabit Ethernet Switch Manual Figure 7- 32. first 802.1Q Static VLANs window The first 802.1Q Static VLANs window lists all previously configured VLANs by VLAN ID and VLAN Name. To delete an existing 802.1Q VLAN, click the corresponding button under the Delete heading.
DGS-3024 Gigabit Ethernet Switch Manual Figure 7- 34. second 802.1Q Static VLANs window (Modify) The following fields can then be set in either the Add or Modify 802.1Q Static VLANs windows: Parameter Description Allows the entry of a VLAN ID in the Add window, or displays the VLAN ID of an existing VID (VLAN ID) VLAN in the Modify window.
Page 72
DGS-3024 Gigabit Ethernet Switch Manual Figure 7- 35. GVRP Settings window The following fields can be set: Parameter Description These two fields allow you to specify the range of ports that will be included in the From/To VLAN that you are creating using the GVRP Settings window.
DGS-3024 Gigabit Ethernet Switch Manual This field denotes the type of frame that will be accepted by the port. The user may Frame Type choose between Tagged Only, which means only VLAN tagged frames will be accepted, and Admit_All, which means both tagged and untagged frames will be accepted.
Page 74
DGS-3024 Gigabit Ethernet Switch Manual Figure 7- 36. Current Time: Status window The following parameters can be set or are displayed: Parameter Description Current Time: Status Displays the time when the Switch was initially started for this session. Current Time Displays the time source for the system.
DGS-3024 Gigabit Ethernet Switch Manual Enter the current month, if you would like to update the system clock. Month Enter the current day, if you would like to update the system clock. Enter the current time in hours and minutes, if you would like to update the system Time in HH MM SS clock.
Click Apply to implement changes made to the Time Zone and DST Settings window. The DGS-3024 supports 802.1p priority queuing Quality of Service. The following section discusses the implementation of QoS (Quality of Service) and benefits of using 802.1p priority queuing.
The Switch has separate hardware queues on every physical port to which packets from various applications can be mapped to, and, in turn prioritized. View the following map to see how the DGS-3024 implements 802.1P priority queuing. Figure 7- 38. Mapping QoS on the Switch The picture above shows the default priority setting for the Switch.
Page 78
CoS until there are no more packets for this CoS. The other CoS queues that have been given a nonzero value, and depending upon the weight, will follow a common weighted round-robin scheme. Remember that the DGS-3024 has four priority queues (and four Classes of Service) for each port on the Switch.
DGS-3024 Gigabit Ethernet Switch Manual Traffic Control Use the Traffic Control window to enable or disable storm control and adjust the threshold for multicast/broadcast/DLF (Destination Look Up Failure) storms. Traffic control settings are applied to individual Switch modules. To view the following window, click Configuration >...
DGS-3024 Gigabit Ethernet Switch Manual trigger the storm traffic control measures. The Threshold value can be set from 10 to 15000 packets per second. The default setting is 15000. The settings of each port may be viewed in the Traffic Control Information Table in the same window.
0, the lowest priority, to 7, the highest priority. Click Apply to implement your settings. 802.1p User Priority The DGS-3024 allows the assignment of a user priority to each of the 802.1p priorities. In the Configuration folder open the QoS folder and click 802.1p User Priority, to view the window shown below.
DGS-3024 Gigabit Ethernet Switch Manual The highest class of service is the first to process traffic. That is, the highest class of Strict service will finish before other queues empty. Use the weighted round-robin (WRR) algorithm to handle packets in an even RoundRobin distribution in priority classes of service.
DGS-3024 Gigabit Ethernet Switch Manual Figure 7- 44. MAC Notification Global Settings window The following parameters may be modified: Parameter Description Enable or disable MAC notification globally on the Switch State The time in seconds between notifications. Interval (sec) [1~2147483647] The maximum number of entries listed in the history log used for notification.
Page 84
DGS-3024 Gigabit Ethernet Switch Manual Figure 7- 45. MAC Notification Port Settings window The following parameters may be set: Parameter Description Select a port or group of ports to enable for MAC notification using the pull- From and To down menus.
DGS-3024 Gigabit Ethernet Switch Manual System Log Server The Switch can send Syslog messages to up to four designated servers using the System Log Server. In the Configuration folder, click System Log Server, to view the window shown below. Figure 7- 46. System Log Servers window The parameters configured for adding and editing System Log Server settings are the same.
Page 86
DGS-3024 Gigabit Ethernet Switch Manual Numerical Facility Code kernel messages user-level messages mail system system daemons security/authorization messages messages generated internally by Syslog line printer subsystem network news subsystem UUCP subsystem clock daemon security/authorization messages FTP daemon NTP subsystem log audit...
DGS-3024 Gigabit Ethernet Switch Manual Port Access Entity 802.1x Port-Based Access Control The IEEE 802.1x standard is a security measure for authorizing and authenticating users to gain access to various wired or wireless devices on a specified Local Area Network by using a Client and Server based access control model. This is accomplished by using a RADIUS server to authenticate users trying to access a network by relaying Extensible Authentication Protocol over LAN (EAPOL) packets between the Client and the Server.
DGS-3024 Gigabit Ethernet Switch Manual network by exchanging secure information between the RADIUS server and the Client through EAPOL packets and, in turn, informs the Switch whether or not the Client is granted access to the LAN and/or Switch services.
DGS-3024 Gigabit Ethernet Switch Manual Client The Client is simply the workstation that wishes to gain access to the LAN or Switch services. All workstation must be running software that is compliant with the 802.1x protocol. For users running Windows XP, the software is included within the operating system.
DGS-3024 Gigabit Ethernet Switch Manual RADIUS Server Ethernet Switch … 802.1X 802.1X 802.1X 802.1X 802.1X 802.1X 802.1X 802.1X 802.1X Client Client Client Client Client Client Client Client Client Network access controlled port Network access uncontrolled port Figure 7- 53. Example of Typical Port-Based Configuration Once the connected Client has successfully been authenticated, the Port then becomes Authorized, and all subsequent traffic on the Port is not subject to access control restriction until an event occurs that causes the Port to become Unauthorized.
Page 91
DGS-3024 Gigabit Ethernet Switch Manual Figure 7- 54. First 802.1x Authenticator Settings window To configure the settings by port, click on the hyperlinked port number under the Port heading, which will display the following table to configure:...
Page 92
DGS-3024 Gigabit Ethernet Switch Manual Figure 7- 55. Second 802.1x Authenticator Settings window This window allows you to set the following features: Parameter Description Enter the port or ports to be set. From and To Sets the administrative-controlled direction to either in or both.
DGS-3024 Gigabit Ethernet Switch Manual This sets the TxPeriod of time for the authenticator PAE state machine. This value TxPeriod determines the period of an EAP Request/Identity packet transmitted to the client. The default setting is 30 seconds. This allows you to set the number of seconds that the Switch remains in the quiet QuietPeriod state following a failed authentication exchange with the client.
Page 94
DGS-3024 Gigabit Ethernet Switch Manual Figure 7- 57. 802.1x Capability Settings window To set up the Switch's 802.1x port-based authentication, select which ports are to be configured in the From and To fields. Next, enable the ports by selecting Authenticator from the drop-down menu under Capability. Click Apply to make your change take effect.
DGS-3024 Gigabit Ethernet Switch Manual network. None - The port is not controlled by the 802.1x functions. Initialize Port(s) To initialize ports for the port-based side of 802.1x, the user must first enable 802.1x by Port Base under Switch 802.1x in the Switch Information (Advanced Settings) window.
DGS-3024 Gigabit Ethernet Switch Manual Reauthenticate Port(s) This window allows you to reauthenticate a port or group of ports by choosing a port or group of ports by using the pull down menus From and To and clicking Apply. The Reauthenticate Port Table displays the current status of the reauthenticated port(s) once you have clicked Apply.
DGS-3024 Gigabit Ethernet Switch Manual RADIUS Server The RADIUS feature of the Switch allows you to facilitate centralized user administration as well as providing protection against a sniffing, active hacker. Click Port Access Entity > RADIUS Server to open the Authentic RADIUS Server Setting window shown below: Figure 7- 60.
DGS-3024 Gigabit Ethernet Switch Manual Static ARP Settings The Address Resolution Protocol (ARP) is a TCP/IP protocol that converts IP addresses into physical addresses. This table allows network managers to view, define, modify and delete ARP information for specific devices.
DGS-3024 Gigabit Ethernet Switch Manual Security The second Web Manager main folder is Security and includes the following windows and sub-folders: Trusted Host, Secure Socket Layer (SSL), Secure Shell (SSH), and Access Authentication Control, as well as secondary windows. Trusted Host Go to the Security folder and click on the Trusted Host link;...
DGS-3024 Gigabit Ethernet Switch Manual 3. Hash Algorithm: This part of the ciphersuite allows the user to choose a message digest function which will determine a Message Authentication Code. This Message Authentication Code will be encrypted with a sent message to provide integrity and prevent against replay attacks. The Switch supports two hash algorithms, MD5 (Message Digest 5) and SHA (Secure Hash Algorithm).
Page 101
SSL are not available on the web-based management of this Switch and need to be configured using the command line interface. For more information on SSL and its functions, see the DGS-3024 Command Line Interface Reference Manual, located on the documentation CD of this...
DGS-3024 Gigabit Ethernet Switch Manual NOTE: Enabling the SSL command will disable the web-based Switch management. To log on to the Switch again, the header of the URL must begin with https://. Entering anything else into the address field of the web browser will result in an error and no authentication will be granted.
Page 103
DGS-3024 Gigabit Ethernet Switch Manual Figure 8- 4. Current SSH Configuration Settings window To configure the SSH server on the Switch, modify the following parameters and click Apply: Parameter Description Use the pull-down menu to enable or disable SSH on the Switch. The default is SSH Server Status Disabled.
DGS-3024 Gigabit Ethernet Switch Manual SSH Algorithm This window allows the configuration of the desired types of SSH algorithms used for authentication encryption. There are three categories of algorithms listed and specific algorithms of each may be enabled or disabled by using their corresponding pull-down menus.
Page 105
DGS-3024 Gigabit Ethernet Switch Manual Use the pull-down to enable or disable the Advanced Encryption Standard AES128 AES128-CBC encryption algorithm with Cipher Block Chaining. The default is Enabled. Use the pull-down to enable or disable the Advanced Encryption Standard AES192 AES192-CBC encryption algorithm with Cipher Block Chaining.
DGS-3024 Gigabit Ethernet Switch Manual SSH User Authentication The following windows are used to configure parameters for users attempting to access the Switch through SSH. To access the following window, click Security Management > Secure Shell > SSH User Authentication Mode.
DGS-3024 Gigabit Ethernet Switch Manual publickey on a SSH server for authentication. Enter an alphanumeric string of no more than 32 characters to identify the remote Host Name SSH user. This parameter is only used in conjunction with the Host Based choice in the Auth.
DGS-3024 Gigabit Ethernet Switch Manual authentication is made, the second server host in the list will be queried, and so on. The built-in Authentication Server Groups can only have hosts that are running the specified protocol. For example, the TACACS Authentication Server Groups can only have TACACS Authentication Server Hosts.
DGS-3024 Gigabit Ethernet Switch Manual Click Apply to implement changes made. Application Authentication Settings This window is used to configure Switch configuration applications (console, Telnet, SSH, web) for login at the user level and at the administration level (Enable Admin) utilizing a previously configured method list. To view the following window, click Security >...
Page 110
DGS-3024 Gigabit Ethernet Switch Manual Figure 8- 10. Authentication Server Group Settings window This window displays the Authentication Server Groups on the Switch. The Switch has four built-in Authentication Server Groups that cannot be removed but can be modified. To modify a particular group, click its hyperlinked Group Name, which will then display the following window.
DGS-3024 Gigabit Ethernet Switch Manual NOTE: The user must configure Authentication Server Hosts using the Authentication Server Hosts window before adding hosts to the list. Authentication Server Hosts must be configured for their specific protocol on a remote centralized server before this function can work properly.
DGS-3024 Gigabit Ethernet Switch Manual The IP address of the remote server host the user wishes to add. IP Address The protocol used by the server host. The user may choose one of the following: Protocol TACACS - Enter this parameter if the server host utilizes the TACACS protocol.
Page 113
DGS-3024 Gigabit Ethernet Switch Manual Figure 8- 15. Login Method List Settings window The Switch contains one Method List that is set and cannot be removed, yet can be modified. To delete a Login Method List defined by the user, click the under the Delete heading corresponding to the entry desired to be deleted.
DGS-3024 Gigabit Ethernet Switch Manual methods to this method list: tacacs - Adding this parameter will require the user to be authenticated using the TACACS protocol from a remote TACACS server. xtacacs - Adding this parameter will require the user to be authenticated using the XTACACS protocol from a remote XTACACS server.
Page 115
DGS-3024 Gigabit Ethernet Switch Manual To delete an Enable Method List defined by the user, click the under the Delete heading corresponding to the entry desired to be deleted. To modify an Enable Method List, click on its hyperlinked Method List Name. To configure a Method List, click the Add button.
DGS-3024 Gigabit Ethernet Switch Manual tacacs - Adding this parameter will require the user to be authenticated using the TACACS protocol from a remote TACACS server. xtacacs - Adding this parameter will require the user to be authenticated using the XTACACS protocol from a remote XTACACS server.
Page 117
DGS-3024 Gigabit Ethernet Switch Manual a password configured by the administrator that will support the "enable" function. This function becomes inoperable when the authentication policy is disabled. To view the following window, click Security > Access Authentication Control > Enable Admin: Figure 8- 22.
DGS-3024 Gigabit Ethernet Switch Manual Management The third Web Manager main folder is Management and includes the following windows and sub-folders: User Accounts and SNMPV3, as well as secondary windows. User Accounts The Switch allows you to set up and manage user accounts in the following windows.
DGS-3024 Gigabit Ethernet Switch Manual The information on the window is described as follows: Parameter Description Enter a user name in this field. User Name Enter the desired new password in this field. New Password Enter the new password a second time.
DGS-3024 Gigabit Ethernet Switch Manual Management Admin User Configuration Read Only Network Monitoring Read Only Community Strings and Trap Read Only Stations Update Firmware and Configuration Files System Utilities Factory Reset User Account Management Add/Update/Delete User Accounts View User Accounts Table 9- 1.
DGS-3024 Gigabit Ethernet Switch Manual Using SNMPv3 individual users or groups of SNMP managers can be allowed to perform or be restricted from performing specific SNMP management functions. The functions allowed or restricted are defined using the Object Identifier (OID) associated with a specific MIB.
DGS-3024 Gigabit Ethernet Switch Manual SHA - Specifies that the HMAC-SHA authentication protocol will be used. This field is only operable when the Encryption field has been checked. This field will require the user to enter a password. None - Specifies that no authorization protocol is in use.
DGS-3024 Gigabit Ethernet Switch Manual Figure 9- 7. SNMP View Table Configuration window The SNMP Group created with this table maps SNMP users (identified in the SNMP User Table) to the views created in the previous window. The following parameters can be set:...
Page 124
DGS-3024 Gigabit Ethernet Switch Manual To delete an existing SNMP Group Table entry, click the corresponding under the Delete heading. To display the current settings for an existing SNMP Group Table entry, click the hyperlink for the entry under the Group Name.
DGS-3024 Gigabit Ethernet Switch Manual SNMPv1 – Specifies that SNMP version 1 will be used. Security Model SNMPv2 – Specifies that SNMP version 2c will be used. The SNMPv2 supports both centralized and distributed network management strategies. It includes improvements in the Structure of Management Information (SMI) and adds some security features.
DGS-3024 Gigabit Ethernet Switch Manual Figure 9- 11. SNMP Community Table Configuration window The following parameters can be set: Parameter Description Type an alphanumeric string of up to 32 characters that is used to identify members Community Name of an SNMP community. This string is used like a password to give remote SNMP managers access to MIB objects in the Switch's SNMP agent.
DGS-3024 Gigabit Ethernet Switch Manual Figure 9- 12. SNMP Host Table window To add a new entry to the Switch's SNMP Host Table, click the Add button in the upper left-hand corner of the window. This will open the SNMP Host Table Configuration window, as shown below.
Page 128
DGS-3024 Gigabit Ethernet Switch Manual To display the Switch's SNMP Engine ID, open the SNMP Manager folder, located in the Management folder and click on the SNMP Engine ID link. This will open the SNMP Engine ID Configuration window, as shown below.
DGS-3024 Gigabit Ethernet Switch Manual Monitoring The fourth Web Manager main folder is Monitoring and includes the following windows and sub-folders: Port Utilization, Packets, Errors, Size, MAC Address, Switch History Log, IGMP Snooping Group, IGMP Snooping Forwarding, VLAN Status, Router Port, Session Table, and Port Access Control, as well as secondary windows.
DGS-3024 Gigabit Ethernet Switch Manual Parameter Description Select the desired setting between 1s and 60s, where "s" stands for seconds. The Time Interval default value is one second. Select the number of times the Switch will be polled between 20 and 200. The default Record Number value is 200.
Page 131
DGS-3024 Gigabit Ethernet Switch Manual To view the Received Packets Table, click the link View Table, which will show the following table: Figure 10- 3. Rx Packets Analysis window (table for Bytes and Packets) The following fields may be set or viewed:...
DGS-3024 Gigabit Ethernet Switch Manual UMB Cast (RX) Click the UMB Cast (RX) link in the Packets folder of the Monitoring menu to view the following graph of UMB cast packets received on the Switch. Figure 10- 4. Rx Packets Analysis window (line graph for Unicast, Multicast, and Broadcast Packets)
Page 133
DGS-3024 Gigabit Ethernet Switch Manual Figure 10- 5. Rx Packets Analysis window (table for Unicast, Multicast, and Broadcast Packets) The following fields may be set or viewed: Parameter Description Select the desired setting between 1s and 60s, where "s" stands for seconds. The Time Interval default value is one second.
DGS-3024 Gigabit Ethernet Switch Manual Transmitted (TX) Click the Transmitted (TX) link in the Packets folder of the Monitoring menu to view the following graph of packets transmitted from the Switch. Figure 10- 6. Tx Packets Analysis window (line graph for Bytes and Packets)
DGS-3024 Gigabit Ethernet Switch Manual Figure 10- 7. Tx Packets Analysis window (table for Bytes and Packets) The following fields may be set or viewed: Parameter Description Select the desired setting between 1s and 60s, where "s" stands for seconds. The Time Interval default value is one second.
DGS-3024 Gigabit Ethernet Switch Manual Received (RX) Click the Received (RX) link in the Errors folder of the Monitoring menu to view the following graph of error packets received on the Switch. Figure 10- 8. Rx Error Analysis window (line graph)
Page 137
DGS-3024 Gigabit Ethernet Switch Manual Figure 10- 9. Rx Error Analysis window (table) The following fields can be set: Parameter Description Select the desired setting between 1s and 60s, where "s" stands for seconds. The Time Interval default value is one second.
DGS-3024 Gigabit Ethernet Switch Manual Clicking this button clears all statistics counters on this window. Clear View Table Clicking this button instructs the Switch to display a table rather than a line graph. View Line Chart Clicking this button instructs the Switch to display a line graph rather than a table.
Page 139
DGS-3024 Gigabit Ethernet Switch Manual Figure 10- 11. Tx Error Analysis window (table) The following fields may be set or viewed: Parameter Description Select the desired setting between 1s and 60s, where "s" stands for seconds. The Time Interval default value is one second.
DGS-3024 Gigabit Ethernet Switch Manual View Table Clicking this button instructs the Switch to display a table rather than a line graph. View Line Chart Clicking this button instructs the Switch to display a line graph rather than a table.
Page 141
DGS-3024 Gigabit Ethernet Switch Manual Figure 10- 13. Packet Size Analysis window (table) The following fields can be set or viewed: Parameter Description Select the desired setting between 1s and 60s, where "s" stands for seconds. The Time Interval default value is one second.
DGS-3024 Gigabit Ethernet Switch Manual Check whether or not to display 64, 65-127, 128-255, 256-511, 512-1023, and Show/Hide 1024-1518 packets received. Clicking this button clears all statistics counters on this window. Clear View Table Clicking this button instructs the Switch to display a table rather than a line graph.
Page 143
DGS-3024 Gigabit Ethernet Switch Manual Figure 10- 14. MAC Address Table window The following fields can be viewed or set: Parameter Description Enter a VLAN ID for the forwarding table to be browsed by. VLAN ID Enter a MAC address for the forwarding table to be browsed by.
DGS-3024 Gigabit Ethernet Switch Manual The MAC address entered into the address table. MAC Address The port that the MAC address above corresponds to. Port How the Switch discovered the MAC address. The possible entries are Dynamic, Self, Learned and Static.
Page 145
DGS-3024 Gigabit Ethernet Switch Manual Figure 10- 15. Switch History window The Switch can record event information in its own logs, to designated SNMP trap receiving stations, and to the PC connected to the console manager. Click Next to go to the next page of the Switch History Log. Clicking Clear will allow the user to clear the Switch History Log.
DGS-3024 Gigabit Ethernet Switch Manual Parameter Description A counter incremented whenever an entry to the Switch's history log is made. The Sequence table displays the last entry (highest sequence number) first. Displays the time in days, hours, and minutes since the Switch was last restarted.
DGS-3024 Gigabit Ethernet Switch Manual IGMP Snooping Forwarding This window will display the current IGMP snooping forwarding table entries currently configured on the Switch. To view the following screen, open the Monitoring folder and click the IGMP Snooping Forwarding link.
DGS-3024 Gigabit Ethernet Switch Manual Router Port This displays the Switch's ports that are currently configured as router ports. A router port configured by a user (using the console or Web-based management interfaces) is displayed as a static router port, designated by an S. A router port that is dynamically configured by the Switch is designated by D.
DGS-3024 Gigabit Ethernet Switch Manual Maintenance The fifth Web Manager main folder is Maintenance and includes the following windows and sub-folders: TFTP Services, Ping Test, Save Changes, Reboot Services, and Logout, as well as secondary windows. TFTP Services Trivial File Transfer Protocol (TFTP) services allow the Switch's firmware to be upgraded by transferring a new firmware file from a TFTP server to the Switch.
DGS-3024 Gigabit Ethernet Switch Manual Enter the IP address of the TFTP server and specify the location of the Switch settings file on the TFTP server. Click Start to record the IP address of the TFTP server and to initiate the file transfer.
DGS-3024 Gigabit Ethernet Switch Manual Figure 11- 5. Ping Test window The user may use the Infinite times radio button, in the Repeat Pinging for field, which will tell the ping program to keep sending ICMP Echo packets to the specified IP address until the program is stopped. The user may opt to choose a specific number of times to ping the Target IP Address by clicking its radio button and entering a number between 1 and 255.
DGS-3024 Gigabit Ethernet Switch Manual Figure 11- 7. Save Configuration Confirmation dialog box Click the OK button to continue. Once the Switch configuration settings have been saved to NV-RAM, they become the default settings for the Switch. These settings will be used every time the Switch is rebooted.
DGS-3024 Gigabit Ethernet Switch Manual Reset gives the option of retaining the Switch's User Accounts and History Log while resetting all other configuration parameters to their factory defaults. If the Switch is reset using this window, and Save Changes is not executed, the Switch will return to the last saved configuration when rebooted.
DGS-3024 Gigabit Ethernet Switch Manual Cable Lengths Use the following table to as a guide for the maximum cable lengths: Standard Media Type Maximum Distance DEM-310GT: SFP Transceiver 10km for 1000BASE-LX, Single-mode fiber module Mini GBIC DEM-311GT: SFP Transceiver 550m...
DGS-3024 Gigabit Ethernet Switch Manual Glossary 1000BASE-T – A specification for Gigabit Ethernet over copper wire (IEEE Std. 802.3ab). The standard defines 1 Gb/s data transfer over distances of up to 100 meters using four pairs of CAT-5 balanced copper cabling and a 5-level coding scheme.
Page 160
DGS-3024 Gigabit Ethernet Switch Manual full duplex – A system that allows packets to be transmitted and received at the same time and, in effect, doubles the potential throughput of a link. GBIC – Gigabit interface converter, a transceiver that converts serial electric signals to serial optical signals and vice versa.
Page 161
DGS-3024 Gigabit Ethernet Switch Manual Switch – A device that filters, forwards and floods packets based on the packet’s destination address. The Switch learns the addresses associated with each Switch port and builds tables based on this information to be used for the Switching decision.
OR BY ACCIDENT, FIRE, LIGHTNING OR OTHER HAZARD. LIMITATION OF LIABILITY IN NO EVENT WILL D-LINK BE LIABLE FOR ANY DAMAGES, INCLUDING LOSS OF DATA, LOSS OF PROFITS, COST OF COVER OR OTHER INCIDENTAL, CONSEQUENTIAL OR INDIRECT DAMAGES ARISING OUT THE INSTALLATION, MAINTENANCE, USE, PERFORMANCE,...
Registration Card. If a Registration Card for the product in question has not been returned to a D-Link office, then a proof of purchase (such as a copy of the dated purchase invoice) must be provided when requesting warranty service.
Page 164
Any repair or replacement will be rendered by D-Link at an Authorized D-Link Service Office. The replacement hardware need not be new or have an identical make, model or part. D-Link may, at its option, replace the defective Hardware or any part thereof with any reconditioned product that D-Link reasonably determines is substantially equivalent (or superior) in all material respects to the defective Hardware.
Page 165
The customer is responsible for all in-bound shipping charges to D-Link. No Cash on Delivery (“COD”) is allowed. Products sent COD will either be rejected by D-Link or become the property of D-Link. Products shall be fully insured by the customer and shipped to D-Link Systems, Inc., 17595 Mt.
Page 166
This Limited Warranty provides specific legal rights and you may also have other rights which vary from state to state. Trademarks: D-Link is a registered trademark of D-Link Systems, Inc. Other trademarks or registered trademarks are the property of their respective owners.
Product Registration Register your D-Link product online at http://support.dlink.com/register/ Product registration is entirely voluntary and failure to complete or return this form will not diminish your warranty rights.
Page 168
The Limited Product Warranty set forth below is given by D-LINK (Europe) Ltd. (herein referred to as "D-LINK"). This Limited Product Warranty is only effective upon presentation of the proof of purchase. Upon further request by D-LINK, this warranty card has to be presented, too.
Page 169
The replacement part or product takes on the remaining limited warranty status of the removed part or product. The replacement product need not be new or of an identical make, model or part; D-LINK may in its discretion replace the defective product (or any part thereof) with any reconditioned equivalent (or superior) product in all material respects to the defective product.
Page 170
Laufzeit der eingeschränkten Garantie Die Laufzeit der eingeschränkten Garantie beginnt mit dem Zeitpunkt, zu dem das Produkt von D-LINK gekauft wurde. Als Nachweis für den Zeitpunkt des Kaufs gilt der datierte Kauf- oder Lieferbeleg. Es kann von Ihnen verlangt werden, dass Sie zur Inanspruchnahme von...
Page 171
Ein (1) Jahr Die oben aufgeführten Garantielaufzeiten gelten für alle D-LINK-Produkte, die in europäischen Staaten ab dem 1. Januar 2004 von D- LINK oder einem autorisierten Fachhändler oder Distributor verkauft werden. Alle vor dem 1. Januar 2004 von D-LINK oder einem autorisierten Vertragshändler oder Distributor verkauften Produkte haben eine Gewährleistung von 5 Jahren;...
Page 172
; ou (f) du feu, de l’eau, d’une catastrophe naturelle ou autre. La présente garantie ne s’applique pas non plus à un produit dont le numéro de série D-LINK aurait été retiré ou altéré de quelque manière que ce soit.
Page 173
Les périodes de garantie indiquées ci-dessus s’appliquent à tous les produits D-LINK vendus depuis le 1er janvier 2004 dans les pays européens par D-LINK ou l’un de ses revendeurs ou distributeurs agréés. Tous les produits vendus avant le 1er janvier 2004 dans les pays européens par D-LINK ou l’un de ses revendeurs ou distributeurs agréés bénéficient d’une garantie de 5 ans, excepté...
Page 174
(c) manejo incorrecto; (d) errores en artículos o servicios ajenos a D-LINK o no sujetos a una garantía o un contrato de mantenimiento vigentes de D-LINK;...
Page 175
El período de la garantía limitada del producto se inicia en la fecha en que se realizó la compra a D-LINK. Para el comprador, el comprobante de la fecha de la compra es el recibo de la venta o de la entrega, en el que figura la fecha de la compra del producto. Puede ser necesario tener que presentar el comprobante de la compra a fin de que se preste el servicio de garantía.
Page 176
(c) movimentazione impropria; (d) guasto di prodotti o servizi non forniti da D-LINK o non soggetti a una garanzia successiva di D-LINK o a un accordo di manutenzione;...
Page 177
1 (Un) anno Il periodo di garanzia sopra specificato relativamente a tutti i prodotti D-LINK venduti nei Paesi europei da D-LINK o da qualsiasi suo rivenditore o distributore autorizzato decorre dal 1° gennaio 2004. Tutti i prodotti venduti nei Paesi europei da D-LINK o da uno qualsiasi dei suoi rivenditori o distributori autorizzati prima del 1°...
8. What category best describes your company? Aerospace Engineering Education Finance Hospital Legal Insurance/Real Estate Manufacturing Retail/Chainstore/Wholesale Government Transportation/Utilities/Communication System house/company Other________________________________ 9. Would you recommend your D-Link product to a friend? Don't know yet 10.Your comments on this product? _______________________________________________________________________________...