Netgear GSM7328SNA 7000 Series Managed Switch Administration Guide for Softwar
Netgear GSM7328SNA - Prosafe 24 Port Gigabit L3 Managed Stackable Switch Manual
UPC - 606449042979
View all Netgear GSM7328SNA manuals
Add to My Manuals
Save this manual to your list of manuals |
Netgear GSM7328SNA manual content summary:
- Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 1
ProSafe 7000 Managed Switch Release 8.0.3 Software Administration Manual 350 East Plumeria Drive San Jose, CA 95134 USA November 2010 202-10515-04 v1.0 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 2
your product, get the latest product updates, or get support online, visit us at http://support.netgear.com. Phone (US & Canada only): 1-888-NETGEAR Phone (Other Countries): See Support information card. Trademarks NETGEAR, the NETGEAR logo, ReadyNAS, ProSafe, Smart Wizard, Auto Uplink, X-RAID2, and - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 3
VLANs: Create an IP Subnet-Based VLAN 21 Voice VLANs 24 Chapter 3 LAGs Create Two LAGs 35 Add Ports to LAGs 36 Enable Both LAGs 38 Chapter 4 Port Routing Port Routing Configuration 40 Enable Routing for the Switch 41 Enable Routing for Ports on the Switch 41 Add a Default Route 44 Add - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 4
ProSafe 7000 Managed Switch Release 8.0.3 Inter-area Router 65 OSPF on a Border Router 70 Stub Areas 75 nssa Areas 84 VLAN Routing OSPF 93 OSPFv3 98 Chapter 8 ARP Proxy ARP Examples 103 Chapter 9 VRRP VRRP on a Master Router 106 VRRP on a Backup Router 108 Chapter 10 ACLs Set Up an IP ACL - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 5
ProSafe 7000 Managed Switch Release 8.0.3 External Multicast Router 219 Multicast Router Using VLAN 220 IGMP Querier 221 Enable IGMP Querier 222 Show IGMP Querier Status 225 Chapter 14 Security Management Port Security 226 Set the Dynamic and Static Limit on Port 1/0/1 227 Convert the Dynamic - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 6
ProSafe 7000 Managed Switch Release 8.0.3 The Stack Master and Stack Members 303 Install and Power-up a Stack 305 Switch Firmware 306 Configure a Stacking Port as an Ethernet Port 308 Stack Switches Using 10G Fiber 311 Add, Remove, or Replace a Stack Member 314 Switch Stack Configuration Files - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 7
ProSafe 7000 Managed Switch Release 8.0.3 Chapter 26 PIM PIM-DM 373 PIM-SM 397 Chapter 27 DHCP L2 Relay and L3 Relay DHCP L2 Relay 424 DHCP L3 Relay 430 Confige a DHCP L3 Relay 434 Chapter 28 MLD Configure MLD 439 MLD Snooping 452 Chapter 29 DVMRP CLI: Configure DVMRP 458 Web Interface: - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 8
of the switching, routing, SNMP, configuration, management, and other packages. In addition, see the following publications: • The NETGEAR installation guide for your switch • Hardware Installation Guide • Software Setup Guide • NETGEAR CLI Reference for the Prosafe 7X00 Series Managed Switch. Refer - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 9
13 • Assign VLAN3 as the Default VLAN for Port 1/0/2 on page 15 • Create a MAC-Based VLAN on page 16 • Create a Protocol-Based VLAN on page 19 • Virtual VLANs: Create an IP Subnet-Based VLAN on page 21 • Voice VLANs on page 24 Adding virtual LAN (VLAN) support to a Layer 2 switch offers some of the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 10
ProSafe 7000 Managed Switch Release 8.0.3 and ports 1/0/3 and 1/0/4 are members of VLAN 3 only. The script following the diagram shows the commands you would use to configure the switch as shown in the diagram. Layer 3 switch Port 1/0/2 VLAN Router Port 1/3/1 192.150.3.1 Port 1/0/3 VLAN Router - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 11
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Switching > VLAN > Basic > VLAN Configuration. A screen similar to the following displays. b. Enter the following information: • In the VLAN ID field, enter 2. • In the VLAN Name field, enter VLAN2. • In the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 12
ProSafe 7000 Managed Switch Release 8.0.3 Assign Ports to VLAN2 This sequence shows how to assign ports to VLAN2, and to specify that frames will always be transmitted tagged from all member ports and that untagged frames will be rejected on receipt. CLI: Assign Ports to VLAN2 (Netgear Switch) # - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 13
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Switching > VLAN > Advanced > Port PVID Configuration. A screen similar to the following displays. b. Under PVID Configuration, scroll down and select the check box for Interface 1/0/1. Then scroll down and select the Interface 1/0/2 check box. c. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 14
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Assign Ports to VLAN3 1. Assign ports to VLAN3. a. Select Switching > VLAN > Advanced > VLAN Membership. A screen similar to the following displays. b. In the VLAN ID list, select 3. c. Click Unit 1. The ports display. d. Click the gray boxes - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 15
ProSafe 7000 Managed Switch Release 8.0.3 Assign VLAN3 as the Default VLAN for Port 1/0/2 This example shows how to assign VLAN 3 as the default VLAN for port 1/0/2. CLI: Assign VLAN3 as the Default VLAN for Port 1/0/2 (Netgear Switch) #config (Netgear Switch) (Config)#interface 1/0/2 (Netgear - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 16
ProSafe 7000 Managed Switch Release 8.0.3 Create a MAC-Based VLAN The MAC-based VLAN feature allows incoming untagged packets to be assigned to a VLAN and thus classify traffic based on the source MAC address of the packet. You define a MAC to VLAN mapping by configuring an entry in the MAC to VLAN - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 17
ProSafe 7000 Managed Switch Release 8.0.3 3. Map MAC 00:00:0A:00:00:02 to VLAN3. (Netgear Switch)(Config)#exit (Netgear Switch)#vlan data (Netgear Switch)(Vlan)#vlan association mac 00:00:00A:00:00:02 3 (Netgear Switch)(Vlan)#exit 4. Add all the ports to VLAN3. (Netgear Switch)#config (Netgear - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 18
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Switching > VLAN > Advanced > VLAN Membership. A screen similar to the following displays. b. In the VLAN ID list, select 3. c. Click Unit 1. The ports VPID3 to port 1/0/23. a. Select Switching > VLAN > Advanced > Port PVID Configuration. A screen - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 19
ProSafe 7000 Managed Switch Release 8.0.3 b. Enter the following information: • In the MAC Address field, enter 00:00:0A:00:00:02. • In the PVID (1 to 4093) field, enter 3. c. Click Add. Create a Protocol-Based VLAN Create two protocol VLAN groups. One is for IPX, and the other is for IP/ARP. The - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 20
ProSafe 7000 Managed Switch Release 8.0.3 5. Enable protocol VLAN group 1 and 2 on the interface. (Netgear Switch)(Vlan)#exit (Netgear Switch)#config (Netgear Switch)(Config)#interface 1/0/11 (Netgear Switch)(Interface 1/0/11)#protocol vlan group 1 (Netgear Switch)(Interface 1/0/11)#protocol vlan - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 21
ProSafe 7000 Managed Switch Release 8.0.3 • In the VLAN field, enter 5. c. Click Add. 3. Add port 11 to the group vlan_ipx. a. Select Switching > VLAN > Advanced > Protocol Based VLAN Group Membership. A screen similar to the following displays. b. In the Group ID list, select 1. c. Click the gray - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 22
802.1Q VLAN configuration must exist in order for the packet to be switched. 1/0/1 Switch 1/0/24 PC 1 10.100.5.1 Figure 2. IP subnet-based VLAN CLI: Create an IP Subnet-Based VLAN PC 2 10.100.5.30 (Netgear Switch) #vlan database (Netgear Switch) (Vlan)#vlan 2000 (Netgear Switch) (Vlan)#vlan - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 23
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Create an IP Subnet-Based VLAN 1. Create VLAN 2000. a. Select Switching > VLAN > Basic > VLAN Configuration. A screen similar to the following displays. b. Enter the following information: • In the VLAN ID field, enter 2000. • In the VLAN Type - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 24
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Switching > VLAN > Advanced > IP Subnet Based VLAN. A screen similar to the following displays. b. Enter the following information: • In the IP Address field, enter 10.100.0.0. • In the Subnet Mask field, enter 255.255.0.0. • In the VLAN (1 to 4093 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 25
ProSafe 7000 Managed Switch Release 8.0.3 management control and that clients attached to the network cannot initiate a direct attack on voice components. PBX 1/0/1 GSM73xxS 1/0/2 1/0/3 VoIP phone VoIP phone PC PC Voice traffic - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 26
ProSafe 7000 Managed Switch Release 8.0.3 2. Include the ports 1/0/1 and 1/0/2 in VLAN 10. (Netgear Switch) (Config)#interface range 1/0/1-1/0/2 (Netgear Switch) (conf-if-range-1/0/1-1/0/2)#vlan participation include 10 (Netgear Switch) (conf-if-range-1/0/1-1/0/2)#vlan tagging 10 (Netgear Switch) ( - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 27
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Configure Voice VLAN and Prioritize Voice Traffic 1. Create VLAN 10. a. Select Switching > VLAN > Basic > VLAN Configuration. A screen similar to the following displays. b. In the VLAN ID field, enter 10. c. In the VLAN Name field, enter Voice - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 28
ProSafe 7000 Managed Switch Release 8.0.3 c. Select Port 1 and Port 2 as tagged. A screen similar to the following displays. d. Click Apply. 3. Configure Voice VLAN globally. a. Select Switching > VLAN > Advanced > Voice VLAN Configuration. A screen similar to the following displays. b. For Admin - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 29
ProSafe 7000 Managed Switch Release 8.0.3 c. Click Apply. A screen similar to the following displays. 4. Configure Voice VLAN mode in interface 1/0/2. a. Select Switching > VLAN > Advanced > Voice VLAN Configuration. b. Select the 1/0/2 check box. c. In the Interface Mode list, select VLAN ID. d. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 30
ProSafe 7000 Managed Switch Release 8.0.3 c. In the Class Type list, select All. A screen similar to the following displays. d. Click Add. The Class Name screen displays, as shown in the next step in this procedure. 6. Configure matching criteria for the class as VLAN 10. a. Select QoS > DiffServ > - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 31
ProSafe 7000 Managed Switch Release 8.0.3 e. Click Apply. A screen similar to the following displays. 7. Create the DiffServ policy PolicyVoiceVLAN. a. Select QoS > DiffServ > Advanced > Policy Configuration. A screen similar to the following displays. b. In the Policy Name field, enter - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 32
ProSafe 7000 Managed Switch Release 8.0.3 a. Select QoS > DiffServ > Advanced > Policy Configuration. A screen similar to the following displays. b. Click the Policy PolicyVoiceVLAN. A screen similar to the following displays. c. In the field next to the Assign Queue radio - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 33
ProSafe 7000 Managed Switch Release 8.0.3 a. Select QoS > DiffServ > Advanced > Service Interface Configuration. A screen similar to the following displays. b. Select the check boxes for Interfaces 1/0/1 and 1/0/2. c. Set the Policy Name field as PolicyVoiceVLAN. A screen similar to the following - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 34
network. Management functions treat a LAG as if it were a single physical port. You can include a LAG in a VLAN. You can configure more than one LAG for a given switch. Port 1/0/3 LAG_10 Subnet 3 Port 1/0/2 Server LAG_10 Layer 3 Switch Port 1/0/8 LAG 20 Port 1/0/9 LAG_20 Layer 2 Switch Subnet - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 35
ProSafe 7000 Managed Switch Release 8.0.3 • Better use of physical resources. Traffic can be Create Two LAGs (Netgear Switch) #config (Netgear Switch) (Config)#port-channel lag_10 (Netgear Switch) (Config)#port-channel lag_20 (Netgear Switch) (Config)#exit Use the show port-channel all command to - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 36
ProSafe 7000 Managed Switch Release 8.0.3 b. In the Lag Name field, enter lag_10. c. Click Add. 2. Create LAG lag_20. a. Select Switching > LAG > LAG Configuration. A screen similar to the following displays. b. In the Lag Name field, enter lag_20. c. Click Add. Add Ports to LAGs The example is - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 37
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Add Ports to LAGs 1. Add ports to lag_10. a. Select Switching > LAG > LAG Membership. A screen similar to the following displays. b. In the LAG ID list, select LAG 1. c. Click Unit 1. The ports display. d. Click the gray boxes under port 2 and - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 38
ProSafe 7000 Managed Switch Release 8.0.3 Enable Both LAGs The example is shown as CLI commands and as a Web interface procedure. CLI: Enable Both LAGs By default, the system enables link trap notification. (Console) #config (Console) (Config)#port-channel adminmode all (Console) (Config)#exit At - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 39
3 address in its address table to determine the outbound port. • Update the Layer 3 header. • Re-create the Layer 2 header. The router's IP address is often statically configured in the end station, although the 7000 Series Managed Switch supports protocols such as DHCP that allow the address to be - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 40
ProSafe 7000 Managed Switch Release 8.0.3 Port Routing Configuration The 7000 Series Managed Switch always supports Layer 2 bridging, but Layer 3 routing must be explicitly enabled, first for the 7000 Series Managed Switch as a whole, and then for each port that is to be part of the routed network. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 41
Managed Switch to provide the port routing support shown in Figure 5, Layer 3 switch configured for port routing on page 40. Use the following command to enable routing for the switch. Execution of the command enables IP forwarding by default. (Netgear Switch) #config (Netgear Switch) (Config)#ip - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 42
ProSafe 7000 Managed Switch Release 8.0.3 CLI: Enable Routing for Ports on the Switch (Netgear Switch) #config (Netgear Switch) (Config)#interface 1/0/2 (Netgear Switch) (Interface 1/0/2)#routing (Netgear Switch) (Interface 1/0/2)#ip address 192.150.2.1 255.255.255.0 (Netgear Switch) (Interface - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 43
ProSafe 7000 Managed Switch Release 8.0.3 2. Assign IP address 192.150.3.1/24 to interface 1/0/3. a. Select Routing > IP> Advanced > IP Interface Configuration information: • In the IP Address field, enter 192.150.5.1. • In the Subnet Mask field, enter 255.255.255.0. Chapter 4. Port Routing | 43 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 44
ProSafe 7000 Managed Switch Release 8.0.3 • In the Routing Mode field, select Enable. d. Click Apply to save the settings. Add a Default Route When IP routing takes place on a switch, a routing table is needed for the switch to forward the packet based on the destination IP address. The route entry - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 45
a Static Route The following commands assume the switch already has a defined a routing interface with a network address of 10.10.10.0, and is configured so that all packets destined for network 10.10.100.0 take the path of routing port. (FSM7328S) #show ip route Total Number of Routes 1 Network - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 46
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Add a Static Route 1. Select Routing > Routing Table > Basic > Route Configuration to display the Route Configuration screen. 2. In the Route Type list, select Static. 3. Fill in the Network Address field. Note that this field ishould have a - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 47
on page 52 You can configure the 7000 Series Managed Switch with some ports supporting VLANs and some supporting routing. You can also configure it to allow traffic on a VLAN to be treated as if the VLAN were a router port. When a port is enabled for bridging (the default) rather than routing, all - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 48
ProSafe 7000 Managed Switch Release 8.0.3 shows the commands you would use to configure a 7000 Series Managed Switch to provide the VLAN routing support shown in the diagram. Layer 3 switch Port 1/0/2 VLAN Router port 1/3/1 192.150.3.1 Port 1/0/3 VLAN Router port 1/3/2 192.150.4.1 Port 1/0/1 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 49
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Create Two VLANs 1. Create VLAN 10 and VLAN20. a. Select Switching > VLAN > Advanced > VLAN Configuration , select Static. e. Click Add. f. Select Switching > VLAN > Advanced > VLAN Configuration. A screen similar to the following displays. g. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 50
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Switching > VLAN > Advanced > VLAN Membership. A screen similar to the following displays. b. In the VLAN ID field, select 10. c. Click the Unit 1. The ports display. d. Click the gray boxes under ports 1 and 2 until T displays. The T specifies - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 51
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Switching > VLAN > Advanced > Port PVID Configuraton. A screen similar to the following displays. b. Scroll down and select 1/0/1 and 1/0/2 check boxes. c. In the PVID (1 to 4093) field, enter 10. d. Click Apply - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 52
for the switch. (Netgear Switch) #config (Netgear Switch) (Config)#ip routing (Netgear Switch) (Config)#exit 3. The next sequence shows an example of configuring the IP addresses and subnet masks for the virtual router ports. (Netgear Switch) (Config)#interface vlan 10 (Netgear Switch) (Interface - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 53
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Set Up VLAN Routing for the VLANs and the Switch 1. Select Routing > VLAN> VLAN Routing. A screen similar to the following displays. 2. Enter the following information: • In the VLAN ID (1 to 4093) list, select 10. • In the IP Address field, - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 54
versions of RIP (the managed switch supports both): • RIPv1 defined in RFC 1058. - Routes are specified by IP destination network and hop count reducing network traffic. - Authentication is used for security. You can configure a given port to do the following: • Receive packets in either or both - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 55
ProSafe 7000 Managed Switch Release 8.0.3 Layer 3 sIwitch acting as a router Port 1/0/2 192.150.2.2 Port 1/0/5 192.64.4.1 Port 1/0/3 192.130.3.1 Subnet 2 Subnet 3 Figure 7. Network with RIP on ports 1/0/2 and 1/0/3 Subnet 5 Routing for the Switch The example is shown as CLI commands and as - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 56
ProSafe 7000 Managed Switch Release 8.0.3 Routing for Ports The example is shown as CLI commands and as a Web interface procedure. CLI: Enable Routing and Assigning IP Addresses for Ports 1/0/2 and 1/0/3 (Netgear Switch) #config (Netgear Switch) (Config)#interface 1/0/2 (Netgear Switch) (Interface - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 57
ProSafe 7000 Managed Switch Release 8.0.3 2. Assign IP address 192.150.3.1/24 to interface 1/0/3. a. Select Routing > Advanced >IP Interface Configuration. A screen similar to the following displays. b. Scroll down and select the interface 1/0/3 check box. Now 1/0/3 appears in the Interface field at - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 58
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Enableg RIP on the Switch 1. Select Routing > RIP > Basic > RIP Configuration. A screen similar to the following displays. 2. For RIP Admin Mode, select Enable radio button. 3. Click Apply to save the setting. RIP for Ports 1/0/2 and 1/0/3 The - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 59
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Enable RIP for Ports 1/0/2 and 1/0/3 1. Select Routing > RIP > Advanced > RIP Configuration. A screen similar to the following displays. 2. Enter the following information: • In the Interface field, select 1/0/2. • For RIP Admin Mode, select - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 60
port routing rather than VLAN routing, has been added to the network. CLI: Configure VLAN Routing with RIP Support 1. Configure VLAN routing with RIP support on a 7000 Series Managed Switch. (Netgear Switch) #vlan data (Netgear Switch) (Vlan)#vlan 10 (Netgear Switch) (Vlan)#vlan 20 (Netgear Switch - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 61
ProSafe 7000 Managed Switch Release 8.0.3 (Netgear Switch) (Config)#ip routing (Netgear Switch) (Config)#vlan port tagging all 10 (Netgear Switch) (Config)#vlan port tagging all 20 (Netgear Switch) (Config)#interface 1/0/2 (Netgear Switch) (Interface 1/0/2)#vlan participation include 10 (Netgear - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 62
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Configure VLAN Routing with RIP Support 1. Configure a VLAN and include ports 1/0/2 in IP Address field, enter 192.150.3.1. • In the Network Mask field, enter 255.255.255.0. c. Click Unit 1. The ports display: d. Click the gray box under port - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 63
ProSafe 7000 Managed Switch Release 8.0.3 d. Click the gray box under port 3 until T displays. The T specifies that the egress packet is tagged for the port. e. Click Apply to save the VLAN that includes port 3. 3. Enable RIP on the switch (you can skip this step since the RIP is enabled by default - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 64
table which has changed is sent. - Updates are sent to a multicast, not a broadcast, address. • Hierarchical management, allowing the network to be subdivided. . The 7000 Series Managed Switch operating as a router and running OSPF determines the best route using the assigned cost and the type of - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 65
.2.1 Port 1/0/3 192.150.3.1 Border Router Border Router Area 2 Area 3 Figure 9. Network segment with an inter-area router connecting areas 0.0.0.2 and 0.0.0.3 CLI: Configure an Inter-area Router 1. Enable routing for the switch. (Netgear Switch) #config (Netgear Switch) (Config)#ip routing - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 66
ProSafe 7000 Managed Switch Release 8.0.3 2. Assign IP addresses to ports. (Netgear Switch) #config (Netgear Switch) (Config)#interface 1/0/2 (Netgear Switch) (Interface 1/0/2)#routing (Netgear Switch) (Interface 1/0/2)#ip address 192.150.2.1 255.255.255.0 (Netgear Switch) (Interface 1/0/2)#exit ( - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 67
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Configure an Inter-area Router 1. Enable IP routing on the switch. a. Select Routing > IP > Basic > IP Configuration . 2. Assign IP address 192.150.2.1 to port 1/0/2. a. Select Routing > IP > Advanced > IP Interface Configuration. A screen - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 68
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following displays. b. Scroll down and select the interface 1/0/3 check box. Now 1/0/3 appears in the Interface field at the top. c. Enter the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 69
ProSafe 7000 Managed Switch Release 8.0.3 c. Click Apply to save the settings. 5. Enable OSPF on port 1/0/2. a. Select Routing > OSPF > Advanced > Interface Configuration. A screen similar to the following displays. b. Scroll downand select the interface 1/0/2 check box. Now 1/0/2 appears in the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 70
: Configure OSPF on a Border Router 1. Enable routing for the switch. (Netgear Switch) #config (Netgear Switch) (Config)#ip routing 2. Enable routing and assign IPs for ports 1/0/2, 1/0/3, and 1/0/4. (Netgear Switch) (Config)#interface 1/0/2 (Netgear Switch) (Interface 1/0/2)#routing (Netgear Switch - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 71
ProSafe 7000 Managed Switch Release 8.0.3 4. Enable OSPF for the ports, and set the OSPF priority and cost for the ports. (Netgear Switch) #config (Netgear Switch) (Config)#interface 1/0/2 (Netgear Switch) (Interface 1/0/2)#ip ospf (Netgear Switch) (Interface 1/0/2)#ip ospf areaid 0.0.0.2 (Netgear - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 72
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the save the settings. 3. Assign IP address 192.130.3.1 to port 1/0/3: a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 73
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following displays. b. Scroll down and select the interface 1/0/4 check box. Now 1/0/4 appears in the Interface field at the top. c. Enter the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 74
ProSafe 7000 Managed Switch Release 8.0.3 c. Click Apply to save the settings. 6. Enable OSPF on the port 1/0/2. a. Select Routing > OSPF > Advanced > Interface Configuration. A screen similar to the following displays. b. Under Interface Configuration, scroll down and select the interface 1/0/2 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 75
ProSafe 7000 Managed Switch Release 8.0.3 • In the Priority field, enter 255. • In the Metric Cost field, enter 64. c. Click Apply to save the settings. 8. Enable OSPF on port 1/0/4. a. Select Routing > OSPF > Advanced > Interface Configuration. A screen similar to the following displays. b. Under - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 76
ProSafe 7000 Managed Switch Release 8.0.3 CLI: Configure Area 1 as a Stub Area on A1 1. Enable routing on the switch. (Netgear Switch) #config (Netgear Switch) (Config)#ip routing 2. Set the router IDd to 1.1.1.1. (Netgear Switch) (Config)#router ospf (Netgear Switch) (Config-router)#router-id - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 77
ProSafe 7000 Managed Switch Release 8.0.3 (Netgear Switch) (Config)#ex (Netgear Switch) #show ip ospf neighbor interface all Router ID IP Address Neighbor Interface State 4.4.4.4 192.168.10.2 2/0/11 Full 2.2.2.2 192.168.20.2 2/0/19 Full (Netgear Switch) #show ip route Total Number - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 78
ProSafe 7000 Managed Switch Release 8.0.3 b. Scroll down and select the interface 2/0/11 check box. Now 2/0/11 appears in the Interface field at the top. c. Enter the following information: • In the IP Address field, enter 192.168.10.1. • In the Network Mask field, enter 255.255.255.0. • In the the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 79
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > OSPF > Advanced > Interface Configuration. A screen similar to the following displays. b. Under Interface Configuration, scroll down and select the interface 2/0/11 check box. Now 2/0/11 appears in the Interface field at the top. • In the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 80
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > OSPF > Advanced > Stub Area Configuration. A screen similar to the following displays. b. Enter the following information: • In the Area ID field, enter 0.0.0.1. • In the Import Summary LSAs field, select Disable. c. Click - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 81
ProSafe 7000 Managed Switch Release 8.0.3 4. Enable OSPF area 0.0.0.1 on the 1/0/15. (Netgear Switch) (Config-router)#exit (Netgear Switch) (Config-router)#exit (Netgear Switch) (Config)#interface 1/0/15 (Netgear Switch) (Interface 1/0/15)#routing (Netgear Switch) (Interface 1/0/15)#ip address 192 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 82
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following displays. b. Scroll down and select the interface 1/0/15 check box. Now 1/0/15 appears in the Interface field at the top. c. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 83
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > OSPF > Advanced > Interface Configuration. A screen similar to the following displays. b. Under Interface Configuration, scroll down and select the interface 1/0/15 check box. Now 1/0/15 appears in the Interface field at the top. • In the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 84
ProSafe 7000 Managed Switch Release 8.0.3 nssa Areas Port 2/0/11 Layer 3 switch Port 2/0/191 Port 1/0/151 Layer 3 Switch Area 0 Area 1 Figure 11. nssa Area The example is shown as CLI commands and as a Web interface procedure. CLI: Configure Area 1 as an nssa Area 1. Enable routing on the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 85
ProSafe 7000 Managed Switch Release 8.0.3 4. Enable area 0.0.0.1 on port 2/0/19. (Netgear Switch) (Config-router)#exit (Netgear Switch) (Config)#interface 2/0/11 (Netgear Switch) (Interface 2/0/11)#routing (Netgear Switch) (Interface 2/0/11)#ip address 192.168.10.1 255.255.255.0 (Netgear Switch) ( - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 86
ProSafe 7000 Managed Switch Release 8.0.3 2. Assign IP address 192.168.10.1 to port 2/0/11. a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following displays. b. Scroll down and select the interface 2/0/11 check box. Now 2/0/11 appears in the Interface field - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 87
ProSafe 7000 Managed Switch Release 8.0.3 4. Specify the router ID, and enable OSPF for the switch. a. Select Routing > OSPF > Basic > OSPF Configuration. A screen similar to the following displays. b. Under OSPF Configuration port 2/0/11. a. Select Routing > OSPF > Advanced > Interface Configuration - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 88
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > OSPF > Advanced > Interface Configuration. A screen similar to the . CLI: Configure Area 1 as an nssa Area on A2 1. Enable routing on the switch. (Netgear Switch) #config (Netgear Switch) (Config)#ip routing (Netgear Switch) (Config)# - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 89
ProSafe 7000 Managed Switch Release 8.0.3 2. Set the router ID to 2.2.2.2. (Netgear Switch) (Config-router)#router-id 2.2.2.2 3. Configure the area 0.0.0.1 as an nssa area. (Netgear Switch) (Config-router)# area 0.0.0.1 nssa 4. Redistribute the RIP routes into the OSPF. (Netgear Switch) ( - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 90
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Configure Area 1 as an nssa Area on A2 1. Enable IP routing on the switch. a. Select Routing > IP > Basic > IP Configuration 2. Assign IP address 192.168.30.1 to port 1/0/11. a. Select Routing > IP > Advanced > IP Interface Configuration. A - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 91
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following displays. b. Under Configuration, scroll down and select the interface 1/0/15 check box. Now 1/0/15 appears in the Interface field at the top. c. Enter the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 92
7000 Managed Switch Release 8.0.3 b. Enter the following information: • In the Interface field, select 1/0/11. • For RIP Admin Mode, select the Enable radio button. c. Click Apply to save the settings. 6. Enable OSPF on port 1/0/15. a. Select Routing > OSPF > Advanced > Interface Configuration - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 93
ProSafe 7000 Managed Switch Release 8.0.3 a. has changed is sent - Updates are sent to a multicast, not a broadcast, address • Hierarchical management, allowing the network to 7000 Series Managed Switch operating as a router and running OSPF will determine the best route using the assigned cost and - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 94
in Figure 6, Layer 3 switch configured for port routing on page 48. 1. Configure the 7000 Series Managed Switch as an inter-area router. (Netgear Switch) #vlan data (Netgear Switch) (Vlan)#vlan 10 (Netgear Switch) (Vlan)#vlan 20 (Netgear Switch) (Vlan)#vlan routing 10 (Netgear Switch) (Vlan)#vlan - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 95
ProSafe 7000 Managed Switch Release 8.0.3 3. Enable OSPF for the VLAN and physical router ports. (Netgear Switch) (Config)#interface vlan 10 (Netgear Switch) (Interface vlan 10)#ip ospf areaid 0.0.0.2 (Netgear Switch) (Interface vlan 10)#ip ospf (Netgear Switch) (Interface vlan 10)#exit (Netgear - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 96
ProSafe 7000 Managed Switch Release 8.0.3 Click the gray box under port 2 until T displays. The T specifies that the egress packet is tagged for the port. d. Click Apply to save the VLAN that includes ports 2. 2. Configure a VLAN, and include port 1/0/3 in the VLAN. a. Select Routing > VLAN > VLAN - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 97
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > OSPF > Advanced > Interface Configuration. A screen similar to the following displays. b. Under Interface Configuration In the Priority field, enter 128. • In the Metric Cost field, enter 32. e. Click Apply to save the settings. 5. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 98
ProSafe 7000 Managed Switch field, enter 255. • In the Metric Cost field, enter 64. e. Click Apply to configure OSPFv3 on a IPv6 network. Switch A1 Switch A2 Area 0 Figure 12. OSPFv3 Protocol for IPv6 CLI: Configure OSPFv3 1. On A1, enable IPv6 unitcast routing on the switch. (Netgear Switch - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 99
ProSafe 7000 Managed Switch Release 8.0.3 2. Enable OSPFv3, and assign 1.1.1.1 to router ID. (Netgear Switch) (Config)#ipv6 router ospf (Netgear Switch) (Config-rtr)#enable (Netgear Switch) (Config-rtr)#router-id 1.1.1.1 (Netgear Switch) (Config-rtr)#exit 3. Enable routing mode on the interface - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 100
ProSafe 7000 Managed Switch Release 8.0.3 8. Enable OSPFv3 on interface 1/0/13, and set the OSPF network mode to broadcast. (Netgear Switch) (Interface 1/0/13)#ipv6 ospf (Netgear Switch) (Interface 1/0/13)#ipv6 ospf network broadcast (Netgear Switch) #show ipv6 ospf neighbor Router ID Priority - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 101
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IPv6 > Advanced > IP Interface Configuration. A screen similar to the following save the settings. 4. Assign the IP address 2001::1 to port 1/0/1. a. Select Routing > IPv6 > Advanced > IP Interface Configuration. A screen similar to the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 102
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > OSPFv3 > Advanced > Interface Configuration. A screen similar to the following displays. b. Under IP Interface Configuration, scroll down and select the interface 1/0/1 check box. Now 1/0/1 appears in the Interface field at the top. • In - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 103
ARP feature. CLI: show ip interface (Netgear Switch) #show ip interface ? brief Enter an interface in slot/port format. Display summary information about IP configuration settings for all ports. (Netgear Switch) #show ip interface 0/24 Routing Mode Disable Administrative Mode - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 104
ProSafe 7000 Managed Switch Release 8.0.3 CLI: ip proxy-arp (Netgear Switch) (Interface 0/24)#ip proxy-arp ? Press Enter to execute the command. (Netgear Switch) (Interface 0/24)#ip proxy-arp Web Interface: Configure Proxy ARP on a Port 1. Select Routing > IP > Advanced > IP Interface - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 105
router is the master router at any given time. A given port could appear as more than one virtual router to the network. Also, more than one port on a 7000 Series Managed Switch can be configured as a virtual router. Either a physical port or a routed VLAN can participate. Chapter 9. VRRP | 105 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 106
7000 Series Managed Switch to support VRRP. Router 1 is the default master router for the virtual route, and Router 2 is the backup router. CLI: Configure VRRP on a Master Router 1. Enable routing for the switch. IP forwarding will then be enabled by default. (Netgear Switch) #config (Netgear Switch - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 107
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Configure VRRP on a Master Router 1. Enable IP routing on the switch. a. Select Routing > IP > Basic > IP Configuration Assign the IP address 192.150.2.1 to port 1/0/2: a. Select Routing > IP > Advanced > IP Interface Configuration. A screen - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 108
by default. (Netgear Switch) #config (Netgear Switch) (Config)#ip routing 2. Configure the IP addresses and subnet masks for the port that will participate in the protocol. (Netgear Switch) (Config)#interface 1/0/4 (Netgear Switch) (Interface 1/0/4)#routing (Netgear Switch) (Interface 1/0/4)#ip - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 109
the priority for the port. The default priority is 100. (Netgear Switch) (Interface 1/0/4)#ip vrrp 20 priority 254 7. Enable VRRP on the port. (Netgear Switch) (Interface 1/0/4)#ip vrrp 20 mode (Netgear Switch) (Interface 1/0/4)#exit (Netgear Switch) (Config)#exit Web Interface: Configure VRRP on - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 110
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following VRRP on port 1/0/4. a. Select Routing > VRRP > Basic > VRRP Configuration. A screen similar to the following displays. b. Under Global Configuration, for - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 111
platform dependent. • The maximum of number of ACLs is 100. • The maximum number of rules per ACL is 8-10. • Stacking systems do not support redirection. • The system does not support MAC ACLs and IP ACLs on the same interface. • The system supports ACLs set up for inbound traffic only. Chapter 10 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 112
ProSafe 7000 Managed Switch Release 8.0.3 MAC ACLs MAC ACLs are Layer 2 ACLs. You can configure the rules to inspect the following fields of a packet (limited by platform): • Source MAC address with mask. • Destination MAC address with mask. • VLAN ID (or range of IDs). • Class of Service (CoS) (802 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 113
accepted. Dest. IP in range. Port 1/0/2 ACL 1 192.168.77.1 192.168.77.4 192.168.77.9 192.168.77.2 Figure 14. IP ACL with rules for TCP rraffic and UDP rraffic CLI: Set Up an IP ACL with Two Rules The following is an example of configuring ACL support on a 7000 Series Managed Switch. Create ACL - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 114
ProSafe 7000 Managed Switch Release 8.0.3 2. Define the second rule for ACL 101 to set conditions for UDP traffic similar to those for TCP traffic. (Netgear Switch) (Config)#access-list 101 permit udp 192.168.77.0 0.0.0.255 192.178.77.0 0.0.0.255 3. Apply the rule to inbound traffic on port 1/0/2. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 115
ProSafe 7000 Managed Switch Release 8.0.3 c. Click Add to create a new rule. 3. Create a new ACL rule and add it to ACL 101. a. After you click the Add button in step 2, A screen similar to the following displays. a. In the Extended ACL Rule Configuration, enter the following information: • In the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 116
ProSafe 7000 Managed Switch Release 8.0.3 a. After you click the Add button in step 3, a screen similar to the following displays. b. Under Extended ACL Rule Configuration, enter the following information: • In the Rule ID (1 to 23) field, enter 22. • For Action, select the Permit radio button. • In - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 117
2 can access only FTP server 2. Port 0/13 192.168.100.2 Port 1/0/24 192.168.40.2 FTP server 1 Layer 2 switch Port 1/0/48 Port 0/44 FTP server 2 Layer 3 switch Port 0/35 Port 1/0/25 PC 1 PC 2 Figure 15. One-Way Web access using a TCP flag in an ACL CLI:Configure One-Way Access Using a TCP - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 118
ProSafe 7000 Managed Switch Release 8.0.3 1. Create VLAN 30 with port 0/35 and assign IP address 192.168.30.1/24. (Netgear Switch) #vlan database (Netgear Switch) (Vlan)#vlan 30 (Netgear Switch) (Vlan)#vlan routing 30 (Netgear Switch) (Vlan)#exit (Netgear Switch) #config (Netgear Switch) (Config)# - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 119
ProSafe 7000 Managed Switch Release 8.0.3 3. Create VLAN 200 with port 0/44 and assign IP address 192.168.200.1/24. (Netgear Switch) #vlan database (Netgear Switch) (Vlan)#vlan 200 (Netgear Switch) (Vlan)#vlan routing 200 (Netgear Switch) (Vlan)#exit (Netgear Switch) #configure (Netgear Switch) ( - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 120
ProSafe 7000 Managed Switch Release 8.0.3 2. Create VLAN 40 with port 1/0/24 and assign IP address 192.168.40.1/24. (Netgear Switch) #vlan database (Netgear Switch) (Vlan)#vlan 40 (Netgear Switch) (Vlan)#vlan routing 40 (Netgear Switch) #configure (Netgear Switch) (Config)#interface 1/0/24 (Netgear - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 121
ProSafe 7000 Managed Switch Release 8.0.3 4. Create VLAN 200 with port 1/0/48 and assign IP address 192.168.200.1/24. (Netgear Switch) #vlan database (Netgear Switch) (Vlan)#vlan 200 (Netgear Switch) (Vlan)#vlan routing 200 (Netgear Switch) (Config)#interface 1/0/48 (Netgear Switch) (Interface 1/0/ - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 122
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > VLAN > VLAN Routing Wizard. A screen similar to the following displays.n the VLAN Routing Wizard, b. In the VLAN Routing Wizard, enter the following information: • In the Vlan ID field, enter 30. • In the IP Address field, enter 192.168. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 123
ProSafe 7000 Managed Switch Release 8.0.3 • In the IP Address field, enter 192.168.100.1. • In the Network Mask field, enter 255.255.255.0. c. Click Unit 1. The ports display. d. Click the gray box under port 13 twice until U displays. The U specifies that the egress packet is untagged for the port. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 124
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Basic > IP Configuration. A screen similar to the following displays. b. Under IP Configuration, make the following selections: • For Routing Mode, select the Enable radio button. • For IP Forwarding Mode, select the Enable radio - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 125
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Routing Table > Basic > Route Configuration. A screen similar to the following displays. b. Under Configure Routes, make the following selection and enter the following information: • In the Route Type list, select Static. • In the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 126
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Security > ACL > Advanced > IP ACL. A screen similar to the following displays. b. In the IP ACL Table, in the IP ACL ID field, enter 102. c. Click Add. 9. Add and configure an IP extended rule that is associated with ACL 101. a. Select Security > - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 127
ProSafe 7000 Managed Switch Release 8.0.3 c. Click Add. The Extended ACL Rule Configuration screen displays. d. Under Extended ACL Rule Configuration (100-199), enter the following information and make the following selections: • In the Rule ID field, enter 1. • For Action mode, select the Deny - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 128
ProSafe 7000 Managed Switch Release 8.0.3 c. Click Add. The Extended ACL Rule Configuration screen displays. d. Under Extended ACL Rule Configuration (100-199), enter the following information and make the following selections: • In the Rule ID field, enter 1. • For Action, select the Permit radio - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 129
ProSafe 7000 Managed Switch Release 8.0.3 c. Click Unit 1. The ports display. d. Click the gray box under port 44. A check mark displays in the box. e. Click Apply to save the settings. 12. Apply ACL 102 to port 44. a. Select Security > ACL > Advanced > IP Binding Configuration. A screen similar to - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 130
ProSafe 7000 Managed Switch Release 8.0.3 • In the IP Address field, enter 192.168.40.1. • In the Network Mask field, enter 255.255.255.0. c. Click Unit 1. The ports display. d. Click the gray box under port 24 twice until U displays. The U specifies that the egress packet is untagged for the port. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 131
egress packet is untagged for the port. e. Click Apply to save VLAN 200. 4. Create a static route with IP address 192.168.100.0/24: a. Select Routing > Routing Table > Basic > Route Configuration. A screen similar to the following displays. b. Under Configure Routes, make the following selections - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 132
ProSafe 7000 Managed Switch Release 8.0.3 c. Click Add. 5. Create a static route with IP address 192.168.30.0/24: a. Select Routing > Routing Table > Basic > Route Configuration. A screen similar to the following displays. b. Under Configure Routes, make the following selection and enter the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 133
ProSafe 7000 Managed Switch Release 8.0.3 PC 2 are isolated by an ACL but can both access the server. The example is shown as CLI commands and as a Web interface procedure. Server Port 11/0/38 10.100.5.34 10.100.5.252 Layer 3 switch Port 1/0/24 192.148.24.1 Port 1/0/48 192.148.48.1 PC1 PC2 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 134
ProSafe 7000 Managed Switch Release 8.0.3 2. Create VLAN 48, add port 1/0/48 to it, and assign IP address 192.168.48.1 to it. (Netgear Switch) #vlan database (Netgear Switch) (Vlan)#vlan 48 (Netgear Switch) (Vlan)#vlan routing 48 (Netgear Switch) (Vlan)#exit (Netgear Switch) #config (Netgear Switch) - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 135
ProSafe 7000 Managed Switch Release 8.0.3 6. Create ACL 101 to deny all traffic that has the destination IP address 192.168.24.0/24. (Netgear Switch) (Config)#access-list 101 deny ip any 192.168.24.0 0.0.0.255 7. Create ACL 102 to deny all traffic that has the destination IP address 192.168.48.0/24. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 136
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > VLAN > VLAN Routing Wizard. A screen similar to the following displays. b. Enter the following information: • In the Vlan ID field, enter 24. • In the IP Address field, enter 192.168.24.1. • In the Network Mask field, enter 255.255.255.0. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 137
ProSafe 7000 Managed Switch Release 8.0.3 c. Click Unit 1. The ports display. d. Click the gray box under port 48 twice until U displays. The U specifies that the egress packet is untagged for the port. e. Click Apply to save VLAN 48. 3. Create VLAN 38 with IP address 10.100.5.34. a. Select Routing - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 138
ProSafe 7000 Managed Switch Release 8.0.3 c. Click Apply to enable IP routing. 5. Create an ACL with ID 101. a. Select Security > ACL > Advanced > IP ACL. A screen similar to the following displays. b. In the IP ACL Table, in the IP ACL ID field, enter 101. c. Click Add. 6. Create an ACL with ID 102 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 139
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Security > ACL > Advanced > IP ACL. A screen similar to the following displays. b. In the IP ACL ID field of the IP ACL Table, enter 103. c. Click Add. 8. Add and configure an IP extended rule that is associated with ACL 101: a. Select Security > - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 140
ProSafe 7000 Managed Switch Release 8.0.3 c. Click Add. The Extended ACL Rule Configuration screen displays. d. Under Extended ACL Rule Configuration (100-199), enter the following information and make the following selections: • In the Rule ID field, enter 1. • For Action, select the Deny radio - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 141
ProSafe 7000 Managed Switch Release 8.0.3 c. Click Add. The Extended ACL Rule Configuration screen displays. d. Under Extended ACL Rule Configuration (100-199), enter the following information and make the following selections: • In the Rule ID field, enter 1. • For Action mode, select the Deny - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 142
ProSafe 7000 Managed Switch Release 8.0.3 c. Click Add. The Extended ACL Rule Configuration screen displays. d. Under Extended ACL Rule Configuration (100-199), enter the following information and make the following selections: • In the Rule ID field, enter 1. • For Action mode, select the Permit - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 143
ProSafe 7000 Managed Switch Release 8.0.3 • In the Sequence Number field, enter 1. c. Click Unit 1. The ports display. d. Click the gray box under port 24. A check mark displays in the box. e. Click Apply to save the settings. 12. Apply ACL 101 to port 48: a. Select Security > ACL > Advanced > IP - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 144
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Security > ACL > Advanced > IP Binding Configuration. A screen similar to the following displays. b. Under Binding Configuration, make the following selection and enter the following information: • In the ACL ID field, select 103. • In the Sequence - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 145
ProSafe 7000 Managed Switch Release 8.0.3 3. Permit all the other traffic. (Netgear Switch) (Config-mac-access-list)#permit any (Netgear Switch) (Config-mac-access-list)#exit 4. Apply the MAC ACL acl_bpdu to port 1/0/2. (Netgear Switch) (Config)#interface 1/0/2 (Netgear Switch) (Interface 1/0/2)#mac - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 146
ProSafe 7000 Managed Switch Release 8.0.3 c. Enter the following information in the Rule Table . c. Click the Add button. 4. Apply the ACL acl_bpdu to port 2. a. Select Security > ACL > MAC ACL > MAC Binding Configuration. A screen similar to the following displays. b. Enter the following information - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 147
ProSafe 7000 Managed Switch Release 8.0.3 • In the Sequence Number field, enter 1. c. Click the Unit 1. The ports display. d. Click the gray box under port 2. A check mark displays in the box. e. Click Apply to save the settings. ACL Mirroring This feature extends the existing port CLI: Configure ACL - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 148
ProSafe 7000 Managed Switch Release 8.0.3 1. Create an IP access control list with the name monitorHost. (Netgear Switch) (Config)# ip access-list monitorHost 2. Define the rules to match host 10.0.0.1 and to permit all others. (Netgear Switch) (Config-ipv4-acl)# permit ip 10.0.0.1 0.0.0.0 any - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 149
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Security > ACL > Advanced > IP ACL. A screen similar to the following displays. b. In the IP ACL ID field, enter monitorHost. c. Click Add to create ACL monitorHost, and the following screen displays: 2. Create a rule to match host 10.0.0.1 in the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 150
ProSafe 7000 Managed Switch Release 8.0.3 b. Click Add, and the Extended ACL Rule Configuration screen displays. c. In the Rule ID field, enter 1. d. For Action, select the Permit radio button. e. In the Mirror Interface list, select 1/0/19. f. In the Src IP Address field, enter 10.0.0.1. g. In the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 151
ProSafe 7000 Managed Switch Release 8.0.3 b. Click Add, and a screen similar to the following displays. c. In the Rule ID field, enter 2. d. Select the Permit radio button. e. In the Match Every field, select True. f. Click Apply. At the end of this configuration a screen similar to the following - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 152
ProSafe 7000 Managed Switch Release 8.0.3 e. Click Apply. A screen similar to the following displays. ACL Redirect This feature redirects a specified traffic to the specified interface. This example redirects the HTTP traffic stream received in port 1/0/1 to port 1/0/19. 152 | Chapter 10. ACLs - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 153
ProSafe 7000 Managed Switch Release 8.0.3 1. Create an IP access control list with the name redirectHTTP. (Netgear Switch) (Config)#ip access-list redirectHTTP 2. Define a rule to match the HTTP stream and define a rule to permit all others. (Netgear Switch) (Config-ipv4-acl)# permit tcp any any - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 154
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Security > ACL > Advanced > IP ACL. A screen similar to the following displays. b. In the IP ACL field, enter redirectHTTP. c. Click Add to create the IP ACL redirectHTTP. A screen similar to the following displays. 2. Create a rule to redirect - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 155
ProSafe 7000 Managed Switch Release 8.0.3 b. Click Add, and the Extended ACL Rule Configuration screen displays. c. In the Rule ID field, enter 1. d. For Action, select the Permit radio button. e. In the Redirect Interface list, select 1/0/19. f. In the Dst L4 Port list, select http. g. Click Apply. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 156
ProSafe 7000 Managed Switch Release 8.0.3 b. Click Add, and the Extended ACL Rule Configuration screen displays. c. In the Rule ID the ACL with interface 1/0/1. a. Select Security > ACL > Advanced > IP Binding Configuration. A screen similar to the following displays. b. In the Sequence Number field - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 157
ProSafe 7000 Managed Switch Release 8.0.3 d. Select the check box below Port 1. e. Click Apply. At the end of this configuration a screen similar to the following displays. Configure IPv6 ACLs This feature extends the existing IPv4 ACL by providing support for IPv6 packet classification. Each ACL is - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 158
ProSafe 7000 Managed Switch Release 8.0.3 Note that the order of the rules is important: When a packet matches multiple rules, the first rule takes precedence. Also, once you define an ACL for a given port, all traffic not specifically permitted by the ACL is denied access. Interface 1/0/1 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 159
ProSafe 7000 Managed Switch Release 8.0.3 • Permit IPv6 Telnet traffic to the destination network 2001:DB8:C0AB:AC13::/64 from the source network 2001:DB8:C0AB:AC11::/64. • Permit IPv6 HTTP traffic to any destination network from the source network 2001:DB8:C0AB:AC11::/64. (Netgear Switch) (Config- - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 160
ProSafe 7000 Managed Switch Release 8.0.3 Rule Number: 3 Action permit Protocol 6(tcp) Source IP Address 2001:DB8:C0AB:AC11::/64 Destination L4 Port Keyword 80(www/http) Web Interface: Configure an IPv6 ACL 1. Create the access control list with the name ipv6-acl a. Select Security > ACL > - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 161
ProSafe 7000 Managed Switch Release 8.0.3 c. Click Add. d. In the Rule ID field, enter 1. e. For Action, select the Permit radio button. f. In the Source Prefix field, enter 2001:DB8:C0AB: - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 162
ProSafe 7000 Managed Switch Release 8.0.3 h. In the Destination L4 Port list, select telnet. A screen similar to the following displays. i. Click Apply. 4. Add Rule 3. a. In the Rule ID field, enter 3. b. For Action, select the Permit radio - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 163
ProSafe 7000 Managed Switch Release 8.0.3 b. In the ACL ID list, select ipv6-acl. c. In the Sequence Number list, select 1. d. Click Unit 1. e. Select Port 1. A screen similar to the following displays. f. Click Apply. A screen similar to the following displays. 6. View the binding table. Select - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 164
an Interface on page 170 • Configure Traffic Shaping on page 171 Each port has one or more queues for packet transmission. During configuration, you can determine the mapping and configuration of these queues. Based on the service rate and other criteria you configure, queues provide preference to - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 165
. • There can be only one trust field at a time - per port. - 802.1p user priority (This is the default trust mode and is managed through switching configuration.) - IP precedence - IP DiffServ Code Point (DSCP) The system can assign the service level based upon the 802.1p priority field of the L2 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 166
ProSafe 7000 Managed Switch Release 8.0.3 CoS Queue Configuration CoS queue configuration involves port egress queue configuration and drop precedence configuration (per queue). The design of these on a per-queue, pe- drop precedence basis allows you to create the service characteristics that you - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 167
classofservice Trust Mode (Netgear Switch) (Config)#classofservice? dot1p-mapping Configure dot1p priority mapping. ip-dscp-mapping Maps an IP DSCP value to an internal traffic class. trust Sets the Class of Service Trust Mode of an Interface. (Netgear Switch) (Config)#classofservice trust - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 168
ProSafe 7000 Managed Switch Release 8.0.3 2. Select the Global radio button. 3. In the Global Trust Mode list, select trust dot1p. 4. Click Apply to save the settings. Show classofservice IP-Precedence Mapping The example is shown as CLI commands and as a Web interface procedure. CLI: Show - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 169
ProSafe 7000 Managed Switch Release 8.0.3 The IP precedence to queue mapping of the interface is displayed. Configure Cos-queue Min-bandwidth and Strict Priority Scheduler Mode The example is shown as CLI commands and as a Web interface procedure. CLI: Configure Cos-queue Min-bandwidth and Strict - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 170
ProSafe 7000 Managed Switch Release 8.0.3 c. Under Interface Queue Configuration, scroll down and select the interface 1/0/2 scheduler type to strict. a. Select QoS > CoS > Advanced > Interface Queue Configuration. A screen similar to the following displays. b. In the Queue ID list, select - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 171
ProSafe 7000 Managed Switch Release 8.0.3 CLI: Set CoS Trust Mode for an Interface (Netgear Switch) (Interface 1/0/3)#classofservice trust? dot1p Sets the Class of Service Trust Mode of an Interface to 802.1p. ip-dscp Sets the Class of Service Trust Mode of an Interface to IP DSCP. (Netgear - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 172
ProSafe 7000 Managed Switch Release 8.0.3 command to enable traffic shaping by specifying the maximum transmission bandwidth limit for all interfaces (Global Config) or for a single interface (Interface Config). The value is a percentage that ranges from 0 to 100 in increments of 5. The - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 173
and is recorded in the Differentiated Services Code Point (DSCP) added to a packet's IP header. • Interior node. A switch in the core of the network and forwarding services using the appropriate queue management algorithms. Before configuring DiffServ on a particular 7000 Series Managed Switch, you - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 174
ProSafe 7000 Managed Switch The 7000 Series Managed Switch supports a traffic conditions Port 1/0/5 Outbound Layer 3 Switch Port 1/0/1 Port 1/0/2 Port 1/0/4 Port 1/0/3 VLAN 10: Finance VLAN 20: Marketing VLAN 30: Test VLAN 40: Development Figure 20. Class B subnet with differentiated services - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 175
ProSafe 7000 Managed Switch Release 8.0.3 CLI: Configure DiffServ 1. Ensure that the DiffServ operation is enabled for the switch. (Netgear Switch) #config (Netgear Switch) (Config)#diffserv 2. Create a DiffServ class of type all for each of the departments, and name them. Define the match criteria - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 176
ProSafe 7000 Managed Switch Release 8.0.3 This policy uses the assign-queue attribute to put each department's traffic on a different egress queue. This is how the DiffServ inbound policy connects to the CoS queue settings established in the following example. (Netgear Switch) (Config)#policy-map - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 177
ProSafe 7000 Managed Switch Release 8.0.3 assign-queue attribute. It is presumed that the switch will forward this traffic to interface 1/0/5 based on a normal destination address lookup for Internet traffic. (Netgear Switch) (Config)#interface 1/0/5 (Netgear Switch) (Interface 1/0/5)#cos-queue min- - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 178
ProSafe 7000 Managed Switch Release 8.0.3 d. Click the finance_dept to configure this class. e. Under Diffserv Class Configuration, enter the following information: • In the Source IP Address field, enter 172.16.10.0. • In the Source Mask field, enter 255.255.255.0. f. Click Apply. 3. Create the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 179
ProSafe 7000 Managed Switch Release 8.0.3 d. Click marketing_dept to configure this class. e. Under Diffserv Class Configuration, enter the following information: • In the Source IP Address field, enter 172.16.20.0. • In the Source Mask field, enter 255.255.255.0. f. Click Apply. 4. Create the class - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 180
ProSafe 7000 Managed Switch Release 8.0.3 d. Click test_dept to configure this class. e. Under Diffserv Class Configuration, enter the following information: • In the Source IP Address field, enter 172.16.30.0. • In the Source Mask field, enter 255.255.255.0. f. Click Apply. 5. Create class - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 181
ProSafe 7000 Managed Switch Release 8.0.3 d. Click development_dept to configure this class. e. Under Diffserv Class Configuration, enter the following information: • In the Source IP Address field, enter 172.16.40.0. • In the Source Mask field, enter 255.255.255.0. f. Click Apply. 6. Create a - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 182
ProSafe 7000 Managed Switch Release 8.0.3 a. Select QoS > DiffServ > Advanced > Policy Configuration. A screen similar to the following displays. b. Under Policy Configuration, scroll down and select the internet_access check box. internet_access now appears in the Policy Selector field at the top. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 183
ProSafe 7000 Managed Switch Release 8.0.3 a. Select QoS > DiffServ > Advanced > Policy Configuration. A screen similar to the following displays. b. Under Policy Configuration, scroll down and select the internet_access check box. Now internet_access appears in the Policy Selector field at the top. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 184
Managed Switch Release 8.0.3 b. Click the internet_access check box for the member class finance_dept. A screen similar to the following displays. c. In the Assign Queue list, select 1. d. Click Apply. 11. Assign queue 2 to marketing_dept. a. Select QoS > DiffServ > Advanced > Policy Configuration - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 185
ProSafe 7000 Managed Switch Release 8.0.3 b. Click the internet_access check box for marketing_dept. A screen similar to the following displays. c. In the Assign Queue list, select 2. d. Click Apply. 12. Assign queue 3 to test_dept. a. Select QoS > DiffServ > Advanced > Policy Configuration. A - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 186
ProSafe 7000 Managed Switch Release 8.0.3 b. Click the internet_access check mark for test_dept. A screen similar to the following displays. c. In the Assign Queue list, select 3. d. Click Apply. 13. Assign queue 4 to development_dept. a. Select QoS > DiffServ > Advanced > Policy Configuration. A - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 187
ProSafe 7000 Managed Switch Release 8.0.3 b. Click the internet_access check mark for development_dept. A screen similar through 1/0/4 in the inbound direction. a. Select QoS > DiffServ > Advanced > Service Configuration. A screen similar to the following displays. b. Scroll down and select the check - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 188
ProSafe 7000 Managed Switch Release 8.0.3 a. Select QoS > CoS > Advanced > Interface Queue Configuration. A screen similar to the following displays. b. Scroll down and select the Interface 1/0/5 check box. Now 1/0/5 appears in the Interface field at the top. c. In the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 189
ProSafe 7000 Managed Switch Release 8.0.3 a. Select QoS > CoS > Advanced > Interface Queue Configuration. A screen similar to the following displays. b. Under Interface Queue Configuration, scroll down and select the interface 1/0/5 check box. Now 1/0/5 appears in the Interface field at the top. c. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 190
ProSafe 7000 Managed Switch Release 8.0.3 DiffServ for VoIP One of the most valuable uses of DiffServ is to support Voice over IP (VoIP). VoIP traffic is inherently time sensitive: For a network to provide acceptable service, a guaranteed transmission rate is vital. This example shows one way to - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 191
map)#mark ip-dscp ef (Netgear Switch) (Config policy-class-map)#assign-queue 5 (Netgear Switch) (Config policy-class-map)#exit (Netgear Switch) (Config policy-map)#exit 5. Attach the defined policy to an inbound service interface. (Netgear Switch) (Config)#interface 1/0/2 (Netgear Switch) (Interface - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 192
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Diffserv for VoIP 1. Set queue 5 on all interfaces to use strict mode. a. Select QoS > CoS > Advanced > CoS Interface Configuration. A screen similar to the following displays. b. Under Interface Queue Configuration, select all the interfaces. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 193
ProSafe 7000 Managed Switch Release 8.0.3 a. Select QoS > DiffServ > Advanced > DiffServ Configuration. A screen similar to the following displays. b. In the Class Name field, enter class_voip. c. In the Class Type list, select All. d. Click Add to create a new - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 194
ProSafe 7000 Managed Switch Release 8.0.3 a. Select QoS > DiffServ > Advanced > DiffServ Configuration. A screen similar to the following displays. b. In the Class Name field, enter class_ef. c. In the Class Type list, select All. d. Click Add to create a new - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 195
ProSafe 7000 Managed Switch Release 8.0.3 a. Select QoS > DiffServ > Advanced > Policy Configuration. A screen similar to the following displays. f. In the Assign Queue list, select 5. g. For Policy Attribute, select the Mark IP DSCP radio button, and select ef. h. Click Apply to create a new policy. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 196
ProSafe 7000 Managed Switch Release 8.0.3 a. Select QoS > DiffServ > Advanced > Policy Configuration. A screen similar to the following displays. b. Under Policy Configuration, scroll down and select the pol_voip check box. Pol_voip now appears in the Policy Selector field at the top. c. In the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 197
ProSafe 7000 Managed Switch Release 8.0.3 a. Select QoS > DiffServ > Advanced > Service Configuration. A screen similar to the VoIP for IP phones on a switch. This functionality copies VoIP signaling packets to the CPU to get the source and destination IP address and Layer 4 port of the current - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 198
ProSafe 7000 Managed Switch Release 8.0.3 installed to assign the highest priority to VOIP data packets 22. Auto VoIP The example is shown as CLI commands and as a Web interface procedure. CLI: Configure Auto VoIP This script in this section shows how to set up auto VoIP system-wide. 1. Enable - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 199
ProSafe 7000 Managed Switch Release 8.0.3 2. View the auto VoIP information: (Netgear Switch) # show auto-voip interface all Interface --------1/0/1 1/0/2 1/0/3 6 --More-- or (q)uit Interface --------1/0/21 1/0/22 1/0/23 1/0/24 1/0/25 1/0/26 1/0/27 1/0/28 Auto VoIP Mode Traffic Class - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 200
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Configure Auto-VoIP 1. Enable auto VoIP for all the interfaces in the device. a. Select QoS > DiffServ > Auto VoIP. A screen similar to the following displays. b. Select the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 201
ProSafe 7000 Managed Switch Release 8.0.3 DiffServ for IPv6 This feature extends the existing QoS ACL and DiffServ functionality by providing support for IPv6 packet classification. Internet Interface 1/0/1 GSM73xxS Interface 1/0/2 Interface 1/0/3 IPv6 Workstation IPv6 Workstation IPv6 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 202
ProSafe 7000 Managed Switch Release 8.0.3 2. Define matching criteria as protocol ICMPv6. (Netgear Switch) (Config-classmap) # match protocol 58 (Netgear Switch) (Config-classmap) # exit 3. Create the policy policyicmpv6. (Netgear Switch) (Config)# policy-map policyicmpv6 in 4. Associate the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 203
ProSafe 7000 Managed Switch Release 8.0.3 a. Select QoS > DiffServ > Advanced > IPv6 Class Configuration. A screen similar to the following displays. b. In the Class Name field, enter classicmpv6. c. In the Class Type list, select All. A screen similar to the following - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 204
ProSafe 7000 Managed Switch Release 8.0.3 b. Click the class classicmpv6. A screen similar to the following displays. c. Select the Protocol Type radio button, select Other, and enter 58. A screen similar to - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 205
ProSafe 7000 Managed Switch Release 8.0.3 a. Select QoS > DiffServ > Advanced > Policy Configuration. A screen similar to the following displays. b. In the Policy Name field, enter policyicmpv6. c. In the Policy Type list, select In. d. In the Member Class list, - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 206
ProSafe 7000 Managed Switch Release 8.0.3 b. Click the policy policyicmpv6. A screen similar to the following displays. c. In the Assign Queue list, select 6. d. Click Apply. 5. Attach the policy policyicmpv6 to interfaces 1/0/1,1/0/2 and 1/0/3. 206 | Chapter 12. DiffServ - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 207
ProSafe 7000 Managed Switch Release 8.0.3 a. Select QoS > DiffServ > Advanced > Service Interface Configuration. A screen similar to the following displays. b. In the Policy Name list, select policyicmpv6. c. Select the Interface 1/0/1, 1/0/2, and 1/0/3 check boxes. A screen similar to the following - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 208
service is enabled by default. (Netgear Switch) (Config)#class-map match-all class_vlan (Netgear Switch) (Config-classmap)#match vlan 5 (Netgear Switch) (Config-classmap)#exit (Netgear Switch) (Config)#class-map match-all class_color (Netgear Switch) (Config-classmap)#match ip precedence 7 (Netgear - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 209
-policy-map)#exit 4. Apply this policy to port 1/0/13. (Netgear Switch) (Config)#interface 1/0/13 (Netgear Switch) (Interface 1/0/13)#service-policy in policy_vlan (Netgear Switch) (Interface 1/0/13)#exit (Netgear Switch) (Config)#exit Web Interface: Configure a Color Conform Policy 1. Create a VLAN - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 210
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Switching > VLAN > Advanced > VLAN Membership. A screen similar to the following displays. b. In the VLAN ID list, select 5. c. Click Unit 1. The ports display. d. Click the gray boxes under ports 13 and 25 until T displays. The T specifies that - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 211
ProSafe 7000 Managed Switch Release 8.0.3 c. Click Add to create a new class class_vlan. d. Click class_vlan to configure this class. A screen similar to the following displays: e. Under Diffserv Class Configuration, in the VLAN field, enter 5. f. Click Apply. 4. Create a class class_color. a. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 212
ProSafe 7000 Managed Switch Release 8.0.3 b. Enter the following information: • In the Class Name field, enter class_color. • In the Class Type list, select All. c. Click Add to create a new class class_color. d. Click class_color to configure this class. A screen similar to the following displays: - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 213
ProSafe 7000 Managed Switch Release 8.0.3 a. Select QoS > DiffServ > Advanced > Policy Configuration. A screen similar to the following displays. b. In the Policy Name field, enter policy_vlan. c. In the Policy Type list, select In. d. Click Add. 6. Associate policy_vlan with - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 214
ProSafe 7000 Managed Switch Release 8.0.3 a. Select QoS > DiffServ > Advanced > Policy Configuration. Click policy_vlan. A screen similar to the following displays. b. Select the Simple Policy radio button. c. In the Color Mode list, select Color Aware. d. In the Color - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 215
ProSafe 7000 Managed Switch Release 8.0.3 a. Select QoS > DiffServ > Advanced > Service Interface Configuration. A screen similar to the following displays. b. Under Service Interface Configuration, scroll down and select the Interface 1/0/13 check box. c. In the Policy Name list, select policy_vlan - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 216
in the IGMP snooping feature. CLI: Enable IGMP Snooping The following example shows how to enable IGMP snooping. (Netgear Switch) #config (Netgear Switch) (Config)#set ip igmp (Netgear Switch) (Config)#set igmp interfacemode (Netgear Switch) (Config)#exit Chapter 13. IGMP Snooping and Querier | 216 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 217
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Enable IGMP Snooping 1. Configure IGMP snooping: a. Select Switching > Multicast > IGMP Snooping Configuration. A screen similar to the following displays. b. For Admin Mode select the Enable radio button. c. Click Apply. Show igmpsnooping The - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 218
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Show igmpsnooping Select Switching > Multicast > IGMP Snooping Configuration. mac-address-table igmpsnooping (Netgear Switch) #show mac-address-table igmpsnooping ? Press Enter to execute the command. (Netgear Switch) #show mac-address - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 219
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Show mac-address-table igmpsnooping Select Switching > Multicast > IGMP Snooping Table. A screen similar to the following displays. External Multicast Router The example is shown as CLI commands and as a Web interface procedure. CLI: Configure - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 220
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Configure the Switch with an External Multicast Router 1. Select Switching > Multicast > Multicast Router Configuration. A screen similar to the following displays. 2. Under Multicast Router Configuration, scroll down and select the Interface - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 221
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Configure the Switch with a Multicast Router Using VLAN 1. Select Switching > Multicast > Multicast Router VLAN Configuration. A screen similar to the following displays. 2. Under Multicast Router VLAN Configuration, scroll down and select the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 222
ProSafe 7000 Managed Switch Release 8.0.3 respond. With the built-in IGMP querier feature inside the switch, such an external device is no longer needed. Figure 24 set up the switch to generate an IGMP querier packet for a designated VLAN. The IGMP packet will be transmitted to every port on the VLAN - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 223
ProSafe 7000 Managed Switch Release 8.0.3 address in querier packets. See the Command Line Reference for more details about other IGMP querier command options. (Netgear switch) #vlan database (Netgear switch) (vlan)#set igmp 1 (Netgear switch) (vlan)#set igmp querier 1 (Netgear switch) (vlan)#exit ( - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 224
ProSafe 7000 Managed Switch Release 8.0.3 c. Click Add. 3. Enable the IGMP snooping querier globally. a. Select Switching > Multicast > IGMP Snooping > IGMP VLAN Configuration. A screen similar to the following displays. b. Enter the following information: • For Querier Admin Mode, select the Enable - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 225
ProSafe 7000 Managed Switch Release 8.0.3 Show IGMP Querier Status The example is shown as CLI commands and as a Web interface procedure. CLI: Show IGMP Querier Status To see the IGMP querier status, use the following command. (Netgear Switch Switching > Multicast > IGMP Snooping Configuration. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 226
on page 262 • Enter Static Binding into the Binding Database on page 265 • Maximum Rate of DHCP Messages on page 266 • IP Source Guard on page 268 Port Security Port Security helps secure the network by preventing unknown devices from forwarding packets. When a link goes down, all dynamically locked - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 227
ProSafe 7000 Managed Switch Release 8.0.3 given in the software Release Notes. After the limit is reached, additional MAC addresses are not learned. Only frames with an allowable source MAC addresses are forwarded. Note: If you want to set a specific MAC address for a port, set the dynamic entries - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 228
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Set the Dynamic and Static Limit on Port 1/0/1 1. Select Security > Traffic Control > Port Security >Port Administrator. A screen similar to the following displays. c. Under Port Security Configuration, next to Port Security Mode, select the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 229
ProSafe 7000 Managed Switch Release 8.0.3 Convert the Dynamic Address Learned from 1/0/1 to a Static Address The example is shown as CLI commands and as a Web interface procedure. CLI: Convert the Dynamic Address Learned from 1/0/1 to the Static Address (Netgear Switch)(Interface 1/0/1)#port- - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 230
ProSafe 7000 Managed Switch Release 8.0.3 Create a Static Address The example is shown as CLI commands and as a Web interface procedure. CLI: Create a Static Address (Netgear Switch) (Interface 1/0/1)#port-security mac-address 00:13:00:01:02:03 Web Interface: Create a Static Address 1. Select - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 231
10.100.5.34 Layer 2 switch 192.168.1.252 192.168.1.252 PC 1 PC 2 192.168.1. Figure 25. Protected ports 192.168.1. CLI: Configure a Protected Port to Isolate Ports on the Switch 1. Create one VLAN 192 including PC 1 and PC 2. (Netgear Switch) #vlan database (Netgear Switch) #vlan 192 (Netgear - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 232
(Netgear Switch) (Config-dhcp-pool)#exit 4. Enable IP routing and configure a default route. (Netgear Switch)(config)#ip routing (Netgear Switch)(config)#ip route 0.0.0.0 0.0.0.0 10.100.5.252 5. Enable a protected port on 1/0/23 and 1/0/24. (Netgear Switch) (Config)#interface 1/0/23 (Netgear Switch - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 233
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Configure a Protected Port to Isolate Ports on the Switch 1. Create a DHCP pool: Note: This example assumes that the DHCP service is enabled. For information about how to enable the DHCP service, see the Web interface procedure in Configure a - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 234
ProSafe 7000 Managed Switch Release 8.0.3 • In the Network Number field, enter 192.168.1.0. • In the Network Mask field, enter 255.255.255.0. • In the Days field, enter 1. • Click Default .7.210.170. c. Click Add. 2. Configure a VLAN and include ports 1/0/23 and 1/0/24 in the VLAN: a. Select Routing - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 235
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > VLAN > VLAN Routing Wizard. A screen similar to the following displays. b. Enter the following information: • In the Vlan ID field, enter 202. • In the IP Address field, enter 10.100.5.34. • In the Network Mask field, enter 255.255.255.0. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 236
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Routing Table > Basic > Route Configuration. A screen similar to the following displays. b. Under Configure Routes, in the Route Type list, select Default Route. c. In the Next Hop IP Address field, enter 10.100.5.252. d. Click Add to add - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 237
to a VLAN. It can be configured on a per-port basis. RADIUS server Layer 2 switch PC 1 PC 2 Figure 26. Using 802.1x port security The following example shows how to authenticate the dot1x users by a RADIUS server. The management IP address is 10.100.5.33/24. The example is shown as CLI - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 238
ProSafe 7000 Managed Switch Release 8.0.3 2. Use RADIUS to authenticate the dot1x users. (Netgear Switch) (Config)#aaa authentication dot1x default radius 3. Configure a RADIUS authentication server. (Netgear Switch) (Config)#radius server host auth 10.100.5.17 4. Configure the shared secret between - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 239
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Basic > IP Configuration. A screen similar to the following displays. b. For Routing Mode, select the Enable radio button. c. Click Apply to save the settings. 2. Assign IP address 192.168.1.1/24 to the interface 1/0/1. a. Select Routing - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 240
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Advanced > IP Interface Configuration. A screen similar to the following displays. b. Scroll down and select the interface 1/0/19 check box. Now 1/0/19 appears in the Interface field at the top. c. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 241
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Security > Port Authentication > Advanced > Port Configure the RADIUS authentication server. a. Select Security > Management Security > Server Configuration. A screen similar to the following displays. b. In the Server Address field, enter 10.100 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 242
ProSafe 7000 Managed Switch Release 8.0.3 c. In the Secret Configured field, select Yes. d. In the Secret field, enter 123456. e. In the Primary Server field, select Yes. f. In the Message Authenticator field, select Enable. g. Click Add. 8. Enable accounting. a. Select Security > Management - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 243
ProSafe 7000 Managed Switch Release 8.0.3 Create a Guest VLAN The guest VLAN feature allows a switch to provide a distinguished service 24 1/0/6 1/0/12 Switch Figure 27. Guest VLAN If a port is in port-based mode, and a client that does not support 802.1X is connected to an unauthorized port - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 244
ProSafe 7000 Managed Switch Release 8.0.3 CLI: Create a Guest VLAN 1. Enter the following commands: (Netgear Switch) #vlan database (Netgear Switch) (Vlan)#vlan 2000 (Netgear Switch) (Vlan)#exit (Netgear Switch) (Config)#interface 1/0/1 (Netgear Switch) (Interface 1/0/1)#vlan participation include - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 245
ProSafe 7000 Managed Switch Release 8.0.3 4. Enable the guest VLAN on ports 1/0/1 and 1/0/24. (Netgear Switch) #show dot1x detail 0 Session Termination Action Default Web Interface: Create a Guest VLAN 1. Create VLAN 2000. a. Select Switching > VLAN > Basic > VLAN Configuration. A screen similar to - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 246
ProSafe 7000 Managed Switch Release 8.0.3 c. In the VLAN Type field, select Static. d. Click Add. 2. Add ports to VLAN 2000. a. Select Switching > VLAN > Advanced > VLAN Membership. A screen similar to the following displays. b. In the VLAN ID list, select 2000 . c. Click Unit 1. The ports display. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 247
ProSafe 7000 Managed Switch Release 8.0.3 Make sure that 1/0/12 and 1/0/6 are configured as force authorized before you do this step; otherwise you cannot access the switch through the Web Interface. a. Select Security > Port Authentication > Basic > 802.1x Configuration. A screen similar to the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 248
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Security > Management Security > Radius > Server Configuration. A screen similar to the following displays. b. In the Radius Server IP Address field, enter 192.168.0.1. c. In the Secret Configured field, select Yes. d. In the Secret field, enter - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 249
protocol none Changing protocol mode will reset ip configuration. Are you sure you want to continue? (y/n) y (Netgear Switch) #network parms 192.168.0.5 255.255.255.0 (Netgear Switch) #vlan database (Netgear Switch) (Vlan)#vlan 2000 (Netgear Switch) #exit Chapter 14. Security Management | 249 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 250
ProSafe 7000 Managed Switch Release 8.0.3 2. Enable dot1x authentication on the switch (Netgear Switch) (Config)#dot1x system-auth-control 3. Use the RADIUS as the authenticator. (Netgear Switch) (Config)#aaa authentication dot1x default radius 4. Enable the switch to accept VLAN assignment by the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 251
ProSafe 7000 Managed Switch Release 8.0.3 8. Show the dot1x detail for 1/0/5. (Netgear Switch) #show dot1x detail 1/0/5 Port 1/0/5 Protocol Version 1 PAE Capabilities Authenticator Control Mode auto Authenticator PAE State Authenticated Backend Authentication State Idle Quiet Period (secs 60 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 252
ProSafe 7000 Managed Switch Release 8.0.3 b. For Current Network Configuration Protocol, select the None radio button. c. In the IP Address field, enter 192.168.0.5. d. In the Subnet Mask field, enter 255.255.255.0. e. Click Apply. 2. Create VLAN 2000. a. Select Switching > VLAN > Basic > VLAN - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 253
ProSafe 7000 Managed Switch Release 8.0.3 4. Enable dot1x on the switch. Make sure that 1/0/12 and 1/0/6 are configured as force authorized before you do this step; otherwise, you cannot access the switch through the Web Management Interface. a. Select Security > Port Authentication > Basic > 802.1x - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 254
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Security > Management Security > Radius > Server Configuration. A screen similar to the following displays. b. In the Radius Server IP Address field, enter 192.168.0.1. c. In the Secret Configured field, select Yes. d. In the Secret field, enter - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 255
DHCP snooping in a VLAN. (Netgear Switch) (Config)# ip dhcp snooping vlan 1 3. Configure the port through which the DHCP server is reached as trusted. (Netgear Switch) (Config)# interface 1/0/1 (Netgear Switch) (Interface 1/0/1)# ip dhcp snooping trust Chapter 14. Security Management | 255 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 256
them as trusted in the next step. ARP packets received on trusted ports are not copied to the CPU. 6. Configure port 1/0/1 as trusted. (Netgear Switch) (Config)# interface 1/0/1 (Netgear Switch) (Interface 1/0/1)# ip arp inspection trust Now ARP packets from the DHCP client go through because - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 257
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Security > Control > DHCP Snooping Global Configuration. A screen similar to the following displays. b. In the VLAN ID field, enter 1. c. In the the DHCP Snooping Mode field, select Enable. A screen similar to the following displays. 3. Configure - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 258
ProSafe 7000 Managed Switch Release 8.0.3 d. Click Apply. A screen similar to the following displays. 4. View the DHCP Snooping Binding table. a. Select Security > Control > DHCP Snooping Binding Configuration. A screen similar to the following displays. 5. Enable ARP Inspection in VLAN 1. a. Select - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 259
ProSafe 7000 Managed Switch Release 8.0.3 c. In the Dynamic ARP Inspection field, select Enable. A screen similar to the following displays. d. Click Apply. A screen similar to the following displays. Now all the ARP packets received on the ports that are member of the VLAN are copied to the CPU for - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 260
ProSafe 7000 Managed Switch Release 8.0.3 d. Click Apply. A screen similar to the following displays. Now ARP packets from the DHCP client will go through; however ARP packets from the static client are dropped, since it does have a DHCP snooping entry. It can be overcome by static configuration as - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 261
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Configure Static Mapping 1. Create an ARP ACL. a. Select Security > Control > Dynamic ARP Inspection > DAI ACL Configuration. b. In the Name field, enter ArpFilter. c. Click Add. A screen similar to the following displays. 2. Configure a rule - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 262
GSM73xxS Interface 1/0/1 DHCP server DHCP client Figure 30. DHCP Snooping The example is shown as CLI commands and as a Web interface procedure. CLI: Configure DHCP Snooping 1. Enable DHCP snooping globally. (Netgear Switch) (Config)# ip dhcp snooping 262 | Chapter 14. Security Management - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 263
ProSafe 7000 Managed Switch Release 8.0.3 2. Enable DHCP snooping in a VLAN. (Netgear Switch) (Config)# ip dhcp snooping vlan 1 3. Configure the port through which the DHCP server is reached as trusted. (Netgear Switch) (Config)# interface 1/0/1 (Netgear Switch) (Interface 1/0/1)# ip dhcp - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 264
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Security > Control > DHCP Snooping Global Configuration. A screen similar to the following . A screen similar to the following displays. d. Click Apply. 3. Configure the port through which DHCP server is reached as trusted. a. Select Security > - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 265
ProSafe 7000 Managed Switch Release 8.0.3 d. Click Apply. A screen similar to the following displays. 4. View the DHCP Snooping Binding configuration. Select Security > Control > DHCP Snooping Binding Configuration. A screen similar to the following displays. Enter Static Binding into the Binding - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 266
ProSafe 7000 Managed Switch Release 8.0.3 2. Check to make sure the binding database has the static entry. (GSM7328S) #show ip dhcp snooping binding Total number of bindings: 2 MAC Address IP in the Static Binding Configuration table. Maximum Rate rate exceeds the configured limit, DHCP snooping - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 267
ProSafe 7000 Managed Switch Release 8.0.3 CLI: Configure the Maximum Rate of DHCP Messages 1. Control the maximum rate of DHCP messages. (Netgear Switch) (Interface 1/0/2)# ip dhcp snooping limit rate 5 2. View the rate configured. (GSM7328S) #show ip dhcp snooping interfaces 1/0/2 Interface - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 268
ProSafe 7000 Managed Switch Release 8.0.3 IP Source Guard IP Source Guard uses the DHCP snooping bindings database. When IP Source Guard is enabled, the switch drops incoming packets that do not match a binding in the bindings database. IP Source Guard can be configured to enforce just the source IP - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 269
ProSafe 7000 Managed Switch Release 8.0.3 2. Enable DHCP snooping in a VLAN. (Netgear Switch) (Config)# ip dhcp snooping vlan 1 3. Configure the port through which the DHCP server is reached as trusted. (Netgear Switch) (Config)# interface 1/0/1 (Netgear Switch) (Interface 1/0/1)# ip dhcp - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 270
ProSafe 7000 Managed Switch Release 8.0.3 b. For DHCP Snooping Mode, select the Enable radio button. c. Click Apply. 2. Enable DHCP snooping in a VLAN. a. Select Security > Control > DHCP Snooping Global Configuration. A screen similar to the following displays. b. In the VLAN Configuration table, - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 271
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Security > Control > DHCP Snooping Interface Configuration. A screen similar to the following displays. b. Select Interface 1/0/1 check box. c. For interface 1/0/1, in the Trust Mode field, select Enable. d. Click Apply. A screen similar to the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 272
ProSafe 7000 Managed Switch Release 8.0.3 d. Click Apply. A screen similar to the following displays. 6. Set up IP source guard static binding. a. Select Security > Control > IP Source Guard > Binding Configuration. b. Select the Interface 1/0/2 check box. c. In the MAC Address field, enter 00:05:05 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 273
. • It can be used in broadcast or unicast mode. • It supports SNTP client implemented over UDP, which listens on port 123. Show SNTP (CLI Only) The following are examples of the commands used in the SNTP feature. show sntp (Netgear Switch Routing) #show sntp? client server Press Enter to - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 274
ProSafe 7000 Managed Switch Release 8.0.3 show sntp client (Netgear Switch Routing) #show sntp client Client Supported Modes: SNTP Version: Port: Client Mode: Unicast Poll Interval: Poll Timeout (seconds): Poll Retry: unicast broadcast 4 123 unicast 6 5 1 show sntp server (Netgear Switch - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 275
ProSafe 7000 Managed Switch Release 8.0.3 Configure SNTP The example is shown as CLI commands and as a Web interface procedure. CLI: Configure SNTP NETGEAR switches servers. The following steps configure SNTP on the switch: 1. Configure the SNTP server IP address. The IP address can be either from - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 276
ProSafe 7000 Managed Switch Release 8.0.3 command to confirm that the time has been received. The time will be used in all logging messages. (Netgear Switch) #show sntp server Server IP Address: 208.14.208.19 Server Type: ipv4 Server Stratum: 4 Server Reference Id: NTP Srv: 208.14.208.3 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 277
ProSafe 7000 Managed Switch Release 8.0.3 • Iin the Server Type field, select IPV4 . • In the Address field, enter 208.14.208.19. • In the Port field, enter 123. • In the Priority field, enter 1. • In the Version field, enter 4. c. Click Add. 2. Configure SNTP globally. a. Select System > Management - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 278
ProSafe 7000 Managed Switch Release 8.0.3 CLI: Set the Named SNTP Server NETGEAR provides SNTP servers accessible by NETGEAR devices. Because NETGEAR might change IP addresses assigned to its time servers, it is best to access an SNTP server by DNS name instead of using a hard-coded IP address. The - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 279
ProSafe 7000 Managed Switch Release 8.0.3 a. Select System > Management > DNS > DNS Configuration. A screen similar to the following displays. b. Enter the following information: • For DNS Status, select the Enable radio button • In the DNS Server field, enter 192. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 280
the following examples: • Traceroute • Configuration Scripting on page 282 • Pre-Login Banner on page 285 • Port Mirroring on page 286 • Dual on the network . • Tracerout tracks up to 20 hops. • The default UPD port is used 33343 unless you specify otherwise in the traceroute command. The following - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 281
ProSafe 7000 Managed Switch Release 8.0.3 CLI: Traceroute (Netgear Switch) #traceroute? Enter IP address. (Netgear Switch) #traceroute 216.109.118.74 ? Press Enter to execute the command. Enter port no. (Netgear Switch) #traceroute 216.109.118.74 racing route over a - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 282
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Traceroute 1. Select Maintenance > Troubleshooting > Traceroute. A screen similar to the following displays. Use this screen to tell the switch to discover the routes that packets actually take when traveling to their destination through the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 283
ProSafe 7000 Managed Switch Release 8.0.3 Netgear Switch) #script ? apply delete list show validate Applies configuration script to the switch. Deletes a configuration script file from the switch. Lists all configuration script files present on the switch. Displays the contents of configuration - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 284
ProSafe 7000 Managed Switch Release 8.0.3 script apply running-config.scr (Netgear Switch) #script apply running-config.scr Are you sure you want to apply the configuration script? (y/n) y The system has unsaved changes. Would you like to save them now? (y/n) y Configuration Saved! Create a - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 285
ProSafe 7000 Managed Switch Release 8.0.3 Pre-Login Banner Pre-login banner: • Allows you to create message screens that display when a user logs in to the CLI. • By default switch using TFTP. (Netgear Switch Routing) #copy tftp://192.168.77.52/banner.txt nvram:clibanner Mode TFTP Set TFTP Server IP - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 286
ProSafe 7000 Managed Switch Release 8.0.3 Port Mirroring The port ,irroring feature: • Allows you to monitor network traffic with an external network analyzer. • Forwards a copy of each incoming and outgoing packet to a specific port. • Is used as a diagnostic tool, debugging feature, or means of - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 287
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Specify the Source (Mirrored) Ports and Destination (Probe) 1. Select Monitoring > Mirroring > Port Mirroring. A screen similar to the following displays. 2. Scroll down and select the Source Port for the switches, when the firmware is being - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 288
the problem, by using appropriate stacking commands. CLI: Download a Backup Image and Make It Active (Netgear Switch) #copy tftp://192.168.0.1/gsm73xxseps.stk image2 Mode TFTP Set Server IP 192.168.0.1 Path Filename gsm73xxseps.stk Data Type Code Destination Filename image2 Management access - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 289
ProSafe 7000 Managed Switch Release 8.0.3 unit image1 image2 current-active next-active 1 5.11.2.51 8.0.0.2 image1 image1 (Netgear Switch) #boot system image2 Activating image image2 .. (Netgear Switch) #show bootvar Image Descriptions image1 : default .100.5.17(tftp server IP - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 290
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Maintenance > File Management > Dual Image Configuration. A screen similar to the following displays. b. Under Dual Image Configuration, scroll down and select and terminal handling conventions. • Must use a valid IP address. 290 | Chapter 16. Tools - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 291
ProSafe 7000 Managed Switch Release 8.0.3 CLI: show network (Netgear Switch Routing) >telnet 192.168.77.151 Trying 192.168.77.151... (Netgear Switch Routing) User:admin Password: (Netgear Switch Routing) >en Password: (Netgear Switch Routing) #show network IP Address 192.168.77.151 Subnet Mask 255 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 292
ProSafe 7000 Managed Switch Release 8.0.3 CLI: transport output telnet (Netgear Switch Routing) (Config)#lineconfig ? Press Enter to execute the command. (Netgear Switch Routing) (Config)#lineconfig (Netgear Switch Routing) (Line)#transport ? input output Displays the protocols to use - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 293
ProSafe 7000 Managed Switch Release 8.0.3 2. Under Outbound Telnet, for Admin Mode, select the Enable radio button. 3. Click Apply. CLI: Configure the session-limit and session-timeout (Netgear Switch Routing) (Line)#session-limit ? Configure the maximum number of outbound telnet sessions - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 294
Show Logging Traplogs on page 298 • Show Logging Hosts on page 299 • Configure Logging for a Port on page 300 The syslog feature: • Allows you to store system messages and errors. • Can store to local files on the switch or - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 295
ProSafe 7000 Managed Switch Release 8.0.3 Show Logging The example is shown as CLI commands and as a Web interface procedure. CLI: Show Logging (Netgear Switch Routing) #show logging Logging Client Local Port : CLI Command Logging : Console Logging : Console Logging Severity Filter : - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 296
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Monitoring > Logs > Command Log. b. Under Command Log, for Admin Status, select the Disable radio button. c. Click Apply. 3. Configure the console log. a. Select Monitoring > Logs > Console Log. b. Under Console Log Configuration, for Admin Status, - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 297
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Monitoring > Logs > Buffer Logs. A screen similar to the procedure. CLI: Show Logging Buffered (Netgear Switch Routing) #show logging buffered ? Press Enter to execute the command. (Netgear Switch Routing) #show logging buffered Buffered - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 298
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Show Logging Buffered Select Monitoring > Logs > Buffer Logs. A screen similar to the following displays. Show Logging Traplogs The example is shown as CLI commands and as a Web interface procedure. CLI: Show Logging Traplogs (Netgear Switch - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 299
ProSafe 7000 Managed Switch Release 8.0.3 Select Monitoring > Logs > Trap Logs. A screen similar to the following displays. Show Logging Hosts The example is shown as CLI commands and as a Web interface procedure. CLI: Show Logging Hosts (Netgear Switch Routing) #show logging hosts ? Press - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 300
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Show Logging Hosts Select Monitoring > Logs > Sys Log Configuration. A screen similar to the following displays. Configure Logging for a Port The example is shown as CLI commands and as a Web interface procedure. CLI: Configure Logging for - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 301
host 192.168.21.253 4 1 (Netgear Switch Routing) #show logging hosts Index ----1 IP Address 192.168.21.253 Severity ---------alert Port ---4 Status Active Web Interface: Configure Logging for the Port 1. Select Monitoring > Logs > Sys Log Configuration. A screen similar to the following - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 302
to manage NETGEAR stackable managed switches running release 4.x.x.x or newer. This chapter includes the following topics: • Switch Stack Management and Connectivity • The Stack Master and Stack Members on page 303 • Install and Power-up a Stack on page 305 • Switch Firmware on page 306 • Configure - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 303
ProSafe 7000 Managed Switch Release 8.0.3 The Stack Master and Stack Members A switch stack is a set of up to 8 switches connected through their stacking ports. The switch that controls the operation of the stack is the stack master. The stack master and the other switches in the stack are stack - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 304
ProSafe 7000 Managed Switch Release 8.0.3 1. The switch that is currently the stack master. 2. The switch with the highest stack member priority value. Note: NETGEAR recommends assigning the highest priority value to the switch that you prefer to be the stack master. This ensures that the switch is - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 305
Installation Guide that includes additional information about rack mounting and stack cabling. Compatible Switch Models NETGEAR stackable managed switches include the following models: • FSM7226RS • FSM7250RS • FSM7328S • FSM7328PS • FSM7352S • FSM7352PS • GSM7328S • GSM7352S • GSM7328FS • GSM7228PS - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 306
ProSafe 7000 Managed Switch Release 8.0.3 Install a Switch Stack Note: Many models of switches have a Hardware Installation Guide that includes additional information about rack mounting and switch stack cabling. 1. Install the switches in a rack. 2. Install all stacking cables, including the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 307
Once code is loaded to all members of the stack, reset all the switches so that the new firmware starts running. Migrate Configuration with a Firmware Upgrade In some cases, a configuration might not be carried forward in a code update. For updates where this issue is to be expected, the following - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 308
ProSafe 7000 Managed Switch Release 8.0.3 4. Continue with the boot of operational code. 5. Once the stack is up, download the saved configuration back to the master. This configuration should then be automatically propagated to all members of the stack. Copy Master Firmware to a Stack Member (Web - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 309
ProSafe 7000 Managed Switch Release 8.0.3 CLI: Configure a Stacking Port as an Ethernet Port 1. On Switch A, Configure the Stack Port and Reboot (Netgear Switch) #show stack-port Configured Running Link Stack Stack Link Speed Unit Intf SlotId Type XFP Adapter Mode Mode Status (Gb/s) - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 310
Managed Switch Release 8.0.3 After Switch B reboots: (Netgear Switch) #show port 2/0/28 Admin Physical Physical Intf Type Mode Mode Status 1/0/51 Enable 10G Full 10G Full Up Link Status -----Enable Link LACP Trap Mode Enable long Actor Timeout ------ Web Interface: Configure - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 311
ProSafe 7000 Managed Switch Release 8.0.3 a. Select System > Stacking > Advanced > Stack Port Configuration. A screen similar to the following displays. b. Under Stack Port Configuration, scroll down and select the 1/0/51 check box. c. In the Configured Stack Mode list, select Ethernet. d. Click - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 312
ProSafe 7000 Managed Switch Release 8.0.3 CLI: Stack Switches Using 10G Fiber 1. On Switch A, show the port information. (Netgear Switch) #show stack-port Configured Stack Unit Intf SlotId Type XFP Adapter Mode 1 0/51 None Ethernet 1 0/52 AX741 Stack Running Stack Mode ------- - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 313
ProSafe 7000 Managed Switch Release 8.0.3 On Switch A, you see the following: (Netgear Switch) #show switch Management SW Switch 1 Mgmt Sw 2 Stack Mbr Standby Status -------- Oper Stby Preconfig Model ID ----------GSM7352Sv2 GSM7328Sv2 Plugged-in Model ID ----------GSM7352Sv2 GSM7328Sv2 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 314
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Maintenance > Reset > Device Reboot. A screen similar to the following displays. b. In the Reboot Unit No. list, select 2. c. Click Apply. Add, Remove, or Replace a Stack Member Add Switches to an Operating Stack 1. Make sure the redundant stack - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 315
ProSafe 7000 Managed Switch Release 8.0.3 6. Connect this cable to the new switch, following the established order of stack-up to stack-down connections. 7. Power up the new switches one by one. Verify, by monitoring the master switch console port, that the new switch joins the stack by issuing the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 316
code version of the newly added member is not the same as the existing stack, update the code as described in Upgrade the Firmware on page 307. Switch Stack Configuration Files The configuration files record settings for all global and interface-specific settings that define the operation of the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 317
ProSafe 7000 Managed Switch Release 8.0.3 Table 1. Switch Stack Master Scenarios (Continued) Scenario Action Result Stack master election specifically determined by the MAC address. Assuming that both stack members have the same priority value and firmware image, restart both stack members at - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 318
When issuing a command (such as move management, or renumber), NETGEAR recommends that you wait until the command has fully executed before issuing the next command. For example, if a reset is issued to a stack member, use the show port command to verify that the switch has re-merged with the stack - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 319
ProSafe 7000 Managed Switch Release 8.0.3 • If you need to reassign multiple existing stack unit numbers, the configuration could become mismatched. To avoid this situation, NETGEAR recommends that you power down all switches except the master, and then add them back one at a time using the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 320
ProSafe 7000 Managed Switch switch command to verify that all units rejoined the stack. 3. NETGEAR recommends that you rest the stack with the reload command after moving the master. Web Interface: Move the Stack Master to a Different Unit 1. Select System > Management > Basic > Stack Configuration - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 321
Counters with sFlow on page 329 Add a New Community The example is shown as CLI commands and as a Web interface procedure. CLI: Add a New Community (Netgear switch) #config (Netgear switch) (Config)#snmp-server community rw public@4 Chapter 19. SNMP | 321 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 322
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Add a New Community 1. Select System > SNMP > SNMP V1/V2 > Community Configuration. A screen similar to the following displays. 2. In the Community Name field, enter public@4. 3. In the Client Address field, enter 0.0.0.0. 4. In the Client IP - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 323
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Enable SNMP Trap 1. Enable SNMP trap for the server 10.100.5.17. a. Select System > SNMP > SNMP V1/V2 > Trap Configuration. A screen similar to the following displays. b. In the Community Name field, enter public. c. In the Version list, - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 324
ProSafe 7000 Managed Switch Release 8.0.3 CLI: Configure SNMP V3 (Netgear Switch) #config (Netgear Switch) (Config)#users passwd admin Enter old password: Enter new password:12345678 Confirm new password:12345678 Password Changed! change the password to "12345678" (Netgear Switch) (Config)#users - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 325
ProSafe 7000 Managed Switch Release 8.0.3 a. Select System > Management > User Configuration. A screen similar to the following displays. b. In the User Name field, select the admin. c. For Authentication Protocol, select the MD5 radio button. d. For Encryption Protocol, - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 326
ProSafe 7000 Managed Switch Release 8.0.3 The sFlow agent uses two forms of sampling: statistical packet-based sampling of switched or routed packet flows, and time-based sampling of counters. PC Interface 1/0/2 Interface 1/0/1 GSM73xxS Interface 1/0/3 Uplink interface PC 1/0/24 Sflow - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 327
ProSafe 7000 Managed Switch Release 8.0.3 3. Here the default maxiumum satagram size is 1400. It can be modified to a value between 200 and 9116 using the command sflow receiver 1 maxdatagram . (GSM7328S) #show sflow receivers Receiver Owner Time out Max Datagram Port IP Address Index - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 328
ProSafe 7000 Managed Switch Release 8.0.3 e. In the Receiver Address field, enter 192.168.10.2. A screen similar to the following displays. f. Click Apply. A screen similar to the following displays. 2. Configure the sampling ports sFlow receiver index, sampling rate, and sampling maximum header - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 329
ProSafe 7000 Managed Switch Release 8.0.3 Time-Based Sampling of Counters with sFlow CLI: Configure Time-Based Sampling of Counters with sFlow 1. Configure the sampling port sFlow receiver index, and polling interval. You need to repeat this for all the ports to be polled. (Netgear Switch) ( - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 330
Web interface procedure. CLI: Specify Two DNS Servers (Netgear Switch)#config (Netgear Switch) (Config)#ip name-server 12.7.210.170 219.141.140.10 (Netgear Switch) (Config)#ip domain-lookup (Netgear Switch) (Config)#exit (Netgear Switch)#ping www.netgear.com Send count=3, Receive count=3 from 206.82 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 331
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Specify Two DNS Servers 1. Select System > Management > DNS > DNS Configuration. A screen similar to the following displays. 2. Under DNS Server Configuration, in the DNS Server field, enter 12.7.210.170. 3. Click Add. 4. In the DNS Server - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 332
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Manually Add a Host Name and an IP Address 1. Select System > Management > DNS > Host Configuration. A screen similar to the following displays. 2. Under DNS Host Configuration, enter the following information: • In the Host Name field, enter - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 333
(Netgear Switch) (Interface 1/0/1)#exit (Netgear Switch) (Config)#interface vlan 200 (Netgear Switch) (Interface-vlan 200)#routing (Netgear Switch) (Interface-vlan 200)#ip address 192.168.100.1 255.255.255.0 (Netgear Switch) #config (Netgear Switch) (Config)#service dhcp (Netgear Switch) (Config)#ip - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 334
ProSafe 7000 Managed Switch Release 8.0.3 Note: If there is no DHCP L3 relay between client PC and DHCP server, there must be an active route whose subnet is the same as the DHCP dynamic pool's subnet. Web Interface: Configure a DHCP Server in Dynamic Mode 1. Create VLAN 200. a. Select Switching > - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 335
ProSafe 7000 Managed Switch Release 8.0.3 d. Click the gray boxes under ports 1 and 24 until U displays. The U specifies that the egress packet is untagged for the port. e. Click Apply. 3. Assign PVID to the VLAN 200. a. Select Switching > VLAN> Advanced > Port PVID Configuration. A screen similar - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 336
ProSafe 7000 Managed Switch Release 8.0.3 d. Select System > Services > DHCP Server > DHCP Pool Configuration. A screen similar to the following displays. e. Under DHCP Pool Configuration 192.168.100.0. • In the Network Mask field, enter 255.255.255.0. As an alternate, you can enter 24 in the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 337
ProSafe 7000 Managed Switch Release 8.0.3 CLI: Configure a DHCP Reservation (Netgear Switch)#config (Netgear Switch) (Config)#service dhcp (Netgear Switch) (Config)#ip dhcp pool pool_manual (Netgear Switch) (Config)#client-name dhcpclient (Netgear Switch) (Config)#hardware-address 00:01:02:03:04:05 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 338
ProSafe 7000 Managed Switch Release 8.0.3 4. Select System > Services > DHCP Server > DHCP Pool Configuration. A screen similar to the following displays. 5. Under DHCP Pool Configuration, enter the following information: • In the Pool Name list, select Create. • In the Pool Name field, enter - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 339
in a simple and cost-effective manner. You can use VLANs to specify customer ports and a service provider port. In this example, the switches have the same configuration. Internet Port 1/0/48 Port 1/0/48 Layer 2 switch Port 1/0/24 Port 1/0/24 Layer 2 switch Customer domain Figure 1. Double - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 340
ProSafe 7000 Managed Switch Release 8.0.3 The following example shows how to configure the NETGEAR switch shown in the preceding figure to add a double VLAN tag for traffic going from the subnet domain connected to port 1/0/24. This example assumes there is a Layer 2 switch connecting all these - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 341
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Switching > VLAN > Basic > VLAN Configuration. A screen similar to the following displays. b. Under VLAN Configuration, enter the following information: • In the VLAN ID field, enter 200. • In the VLAN Name field, enter vlan200. • In the VLAN Type - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 342
ProSafe 7000 Managed Switch Release 8.0.3 • Click the gray box under port 48 once until T displays. The T specifies that the egress packet is tagged for the port. d. Click Apply to save the settings. 3. Change the port VLAN ID (PVID) of port 24 to 200: a. Select Switching > VLAN > Advanced > Port - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 343
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Switching > VLAN > Advanced > Port DVLAN Configuration. A screen similar to the following to any other members in the same group. the default mode is community, in which each member port can forward traffic to other members in the same group - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 344
ProSafe 7000 Managed Switch Release 8.0.3 The following example creates two groups. Group 1 is in community mode, and Group 2 is in isolated mode. Internet Port 1/0/13 Layer 2 Switch Port 1/0/6 Port 1/0/7 Port 1/0/17 Port 1/0/16 Group 1 Group 2 Figure 2. Private VLAN groups in community mode - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 345
ProSafe 7000 Managed Switch Release 8.0.3 CLI: Create a Private VLAN Group 1. Enter the following commands. (Netgear Switch) # (Netgear Switch) #vlan data (Netgear Switch) (Vlan)#vlan 200 (Netgear Switch) (Vlan)#exit (Netgear Switch) #config (Netgear Switch) (Config)#interface 1/0/6 (Netgear Switch) - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 346
ProSafe 7000 Managed Switch Release 8.0.3 5. Add 1/0/16 and 1/0/7 to the private group 1. (Netgear Switch) (Config)#interface range 1/0/16-1/0/17 (Netgear Switch) (conf-if-range-1/0/16-1/0/17)#switchport private-group 2 6. Add 1/0/16 and 1/0/7 to the private group 2. (Netgear Switch) (conf-if-range - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 347
ProSafe 7000 Managed Switch Release 8.0.3 b. Under VLAN Membership, in the VLAN ID list, select 200. c. Click Unit 1. The ports display. d. Click the gray boxes under ports 6, 7, 16 and 17 until U displays. The U specifies that the egress packet is untagged for the port Private Group Configuration. A - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 348
ProSafe 7000 Managed Switch Release 8.0.3 e. Click Add. 5. Add port 6 and 7 to group1. a. Select Security > Traffic Control > Private Group VLAN >Private Group Membership. A screen similar to the following displays. b. In the Group ID list, select 1. c. Click Unit 1. The ports display. d. Click the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 349
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Security > Traffic Control > Private Group VLAN > Private Group VLAN > Private Group Membership. A screen similar to the following displays. b. In the Group ID list, select 2. c. Click Unit 2. The ports display. d. Click the gray boxes under ports - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 350
is shown as CLI commands and as a Web interface procedure. CLI: Configure Classic STP (802.1d) (Netgear Switch) (Config)# spanning-tree (Netgear Switch) (Config)# spanning-tree forceversion 802.1d (Netgear switch) (Interface 1/0/3)# spanning-tree port mode Chapter 23. Spanning Tree Protocol | 350 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 351
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Configure Classic STP (802.1d) 1. Enable 802.1d on the switch. a. Select Switching > STP > STP Configuration. A screen similar to the following displays. b. Enter the following information: • For Spanning Tree Admin Mode, select the Enable - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 352
ProSafe 7000 Managed Switch Release 8.0.3 Configure Rapid STP (802.1w) The example is shown as CLI commands and as a Web interface procedure. CLI: Configure Rapid STP (802.1w) (Netgear switch) (Config)# spanning-tree (Netgear switch) (Config)# spanning-tree forceversion 802.1w (Netgear switch) ( - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 353
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Switching > STP > CST Port Configuration. A screen similar to the following displays. b. Under CST Port Configuration, scroll down and select the Interface 1/0/3 check box. Now 1/0/3 appears in the Interface field at the top. c. In the Port Mode - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 354
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Configure Multiple STP (802.1s) 1. Enable 802.1s on the switch. a. Select Switching > STP > STP Configuration. A screen similar to the following displays. b. Enter the following information: • For Spanning Tree Admin Mode, select the Enable - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 355
ProSafe 7000 Managed Switch Release 8.0.3 • In the VLAN Id field, enter 2. • Click Add. • In the VLAN Id field, enter 3. • Click Apply. c. Configure MST ID 2. • In the MST ID field, enter 2. • In the Priority field, enter 4096. • In the VLAN Id field, enter 11. • Click Add. • In the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 356
24. Tunnel 24 There are two methods for Pv6 sites to communicate with each other over the IPv4 network: 6in4 tunnel and 6to4 tunnel. The 6in4 tunnel encapsulates IPv6 traffic over an explicitly configured IPv4 destination or end port of the tunnel with the IP two switches Chapter 24. Tunnel | 356 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 357
ProSafe 7000 Managed Switch Release 8.0.3 CLI: Create a Tunnel Configure Switch GSM7328S_1 (Netgear Switch) #config (Netgear Switch) (Config)#ip routing (Netgear Switch) (Config)#ipv6 forwarding (Netgear Switch) (Config)#ipv6 unicast-routing (Netgear Switch) (Config)#interface 1/0/1 (Netgear Switch) - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 358
ProSafe 7000 Managed Switch Release 8.0.3 Configure Switch GSM7328S_2 (Netgear Switch) #show interfacet tunnel 0 Interface Link Status Up IPv6 is enabled IPv6 Prefix is FE80::C0A8:101/128 2000::1/64 MTU size 1280 bytes #show interface - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 359
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Create a Tunnel Configure Switch GSM7328S_1 1. Enable IP routing on the switch. a. Select Routing > IP > Basic > IP Configuration. A screen similar to the following displays. b. For Routing Mode, select the Enable radio button. c. Click Apply. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 360
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following displays. b. Under IP Interface Configuration, scroll down and select the Port 1/0/1 check box. Now 1/0/1 appears in the Interface field at the top. • In the IP - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 361
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IPv6 > Advanced > Prefix Configuration. A screen similar to the following displays. b. In the Interface list, select 0/7/1. c. In the IPv6 Prefix field, enter 2000::1. d. In the Length field, enter 64. e. In - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 362
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IPv6 > Basic > Global Configuration. A screen similar to the following displays. b. For IPv6 Unicast Routing, select the Enable radio button. c. For IPv6 Forwarding, select the Enable radio button. d. Click Apply. 3. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 363
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IPv6 > Advanced > Tunnel Configuration. A screen similar to the following displays. b. In the Tunnel Id list, select 0. c. In the Mode list, select 6-in-4-configured > IPv6 > Advanced > Prefix Configuration. A screen similar to the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 364
round trip time = 1.00 ms (Netgear Switch) #show ipv6 brief IPv6 Forwarding Mode Enable IPv6 Unicast Routing Mode Enable IPv6 Hop Limit 0 ICMPv6 Rate Limit Error Interval 1000 msec ICMPv6 Rate Limit Burst Size 100 messages Maximum Routes 12 Chapter 25. IPv6 Interface Configuration | 364 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 365
ProSafe 7000 Managed Switch Release 8.0.3 (Netgear Switch) #show ipv6 interface 1/0/1 IPv6 is enabled IPv6 Routing Interface 1. Enable IPv6 forwarding and unicast routing on the switch. a. Select Routing > IPv6 > Basic > Global Configuration. A screen similar to the following displays. b. For IPv6 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 366
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IPv6 > Advanced > Interface Configuration. A screen similar to the following displays. b. Under IPv6 Interface Configuration, scroll down and select the Interface 1/0/1 check box. Now 1/0/1 appears in the Interface field at the top. c. In - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 367
ProSafe 7000 Managed Switch Release 8.0.3 To access the switch over an IPv6 network you must first configure it with IPv6 information (IPv6 prefix, prefix length, and default gateway). CLI: Configure the IPv6 Network Interface (Netgear Switch) #network ipv6 enable (Netgear Switch) #network ipv6 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 368
ProSafe 7000 Managed Switch Release 8.0.3 d. In the EUI64 field, select False. e. Click Add. 2. Add an IPv6 gateway to the network interface. a. Select System > Management > Network Interface > IPv6 Network Configuration. A screen similar to the following displays. b. In the IPv6 Gateway field, - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 369
ProSafe 7000 Managed Switch Release 8.0.3 3. Assign IPv6 address 2000::1/64 to VLAN 500 and enable IPv6 routing. (Netgear Switch) (Config)#interface vlan 0/4/1 (Netgear Switch) (Interface 0/4/1)#routing (Netgear Switch) (Interface 0/4/1)#ipv6 enable (Netgear Switch) (Interface 0/4/1)#ipv6 address - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 370
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Create an IPv6 VLAN Routing Interface 1. Create VLAN 500. a. Select Switching > VLAN > Basic > VLAN Configuration. A screen similar to the following displays. b. In the VLAN ID field, enter 500. c. In the VLAN Type field, select Static. d. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 371
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Switching > VLAN > Advanced > Port PVID Configuration. A screen similar to the following displays. b. Under PVID Configuration, scroll down and select the Interface 1/0/1 check box. c. In the PVID (1 to 4093) field, enter 500. d. Click Apply to - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 372
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IPv6 > Advanced > Interface Configuration. A screen similar to the following displays. b. Click VLANS. The logical VLAN interface 0/4/2 displays. c. Select the 0/4/2 check box. d. Under IPv6 Interface Configuration, in the IPv6 Mode field - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 373
networks. Separate CLI commands are provided for IPv4 and IPv6 operation; however, most configuration options are common to both protocols. Therefore, this section describes only IPv4 configuration; IPv6 configuration is similar to IPv4. Multicast protocols are used to deliver multicast packets from - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 374
.1.1 ProSafe 7000 Managed Switch Release 8.0.3 Switch A Port 1/0/13 Port 1/0/1 Port 1/0/9 Port 1/0/10 Subnet 192.168.3.0/24 Port 1/0/11 Switch B Switch D Port 1/0/21 Port 1/0/24 Subnet 192.168.6.0/24 Port 1/0/22 Port 1/0/22 Port 1/0/21 Switch C Host IP 192.168.4.2 Figure 1. Configuring - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 375
ProSafe 7000 Managed Switch Release 8.0.3 Switch A 1. Enable IP routing on the switch. (Netgear Switch) #configure (Netgear Switch) (Config)#ip routing 2. Enable pimdm on the switch. (Netgear Switch) (Config)#ip pimdm 3. Enable IP multicast forwarding on the switch. (Netgear Switch) (Config)#ip - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 376
ProSafe 7000 Managed Switch Release 8.0.3 5. Enable PIM-DM on the interface. (Netgear Switch) (Interface 1/0/1)#ip pimdm (Netgear Switch) (Interface 1/0/1)#exit (Netgear Switch) (Config)#interface 1/0/9 (Netgear Switch) (Interface 1/0/9)#routing (Netgear Switch) (Interface 1/0/9)#ip address ( - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 377
ProSafe 7000 Managed Switch Release 8.0.3 PIM-DM on Switch C (Netgear Switch) #configure (Netgear Switch) (Config)#ip routing (Netgear Switch) (Config)#ip pimdm (Netgear Switch) (Config)#ip multicast (Netgear Switch) (Config)#interface 1/0/21 (Netgear Switch) (Interface 1/0/21)#routing (Netgear - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 378
ProSafe 7000 Managed Switch Release 8.0.3 2. Enable IGMP on 1/0/24. (Netgear Switch) (Config)#interface 1/0/24 (Netgear Switch) (Interface 1/0/24)#routing (Netgear Switch) (Interface 1/0/24)#ip pimdm (Netgear Switch) (Interface 1/0/24)#ip igmp (Netgear Switch) (Interface 1/0/24)#ip rip (Netgear - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 379
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Configure PIM-DM PIM-DM on Switch A 1. Enable IP routing on the switch. a. Select Routing > IP > Basic > IP Configuration. A screen similar to the following displays. b. For Routing Mode, select the Enable radio button. c. Click Apply. 2. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 380
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following displays. b. Scroll down and select the Port 1/0/9 check box. Now 1/0/9 appears in the Port field at the top. c. Enter the following information : • In the IP - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 381
ProSafe 7000 Managed Switch Release 8.0.3 • In the Routing Mode field, select Enable. d. Click Apply to save the settings. 5. Enable RIP on the interface 1/0/1. a. Select Routing > RIP > Advanced > Interface Configuration. A screen similar to the following displays. b. In the Interface list, select - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 382
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > RIP > Advanced > Interface Configuration. A screen similar to the following Apply. 8. Enable multicast globally. a. Select Routing > Multicast > Global Configuration. A screen similar to the following displays. b. For Admin Mode, select - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 383
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > PIM-DM > > Global Configuration. A screen similar to the following displays. b. For Admin Mode, select the Enable radio button. c. Click Apply. 10. Enable PIM-DM on interfaces 1/0/1,1/0/9, and 1/0/13. a. Select - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 384
ProSafe 7000 Managed Switch Release 8.0.3 PIM-SM on Switch B: 1. Enable IP routing on the switch. a. Select Routing > IP > Basic > IP Configuration. A screen similar to the following displays. b. For Routing Mode, select the Enable radio button. c. Click Apply. 2. Configure 1/0/10 as a routing port - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 385
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following displays. b. Under IP Interface Configuration, scroll down and select the Port 1/0/11 check box. Now 1/0/11 appears in the Port field at the top. c. Enter the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 386
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > RIP > Advanced > Interface Configuration. A screen similar to the following Apply. 6. Enable multicast globally. a. Select Routing > Multicast > Global Configuration. A screen similar to the following displays. b. For Admin Mode, select - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 387
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > PIM-DM > Global Configuration. A screen similar to the following 10 and 1/0/11. a. Select Routing > Multicast > PIM-SM > Interface Configuration. A screen similar to the following displays. b. Scroll down and select the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 388
ProSafe 7000 Managed Switch Release 8.0.3 PIM-SM on Switch C 1. Enable IP routing on the switch. a. Select Routing > IP > Basic > IP Configuration. A screen similar to the following displays. b. For Routing Mode, select the Enable radio button. c. Click Apply. 2. Configure 1/0/21 as a routing port - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 389
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following displays. b. Scroll down and select the Port 1/0/22 check box. Now 1/0/22 appears in the Port field at the top. c. Enter the following information: • In the IP - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 390
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > RIP > Advanced > Interface Configuration. A screen similar to the following Apply. 6. Enable mulicast globally. a. Select Routing > Multicast > Global Configuration. A screen similar to the following displays. b. For Admin Mode, select - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 391
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > PIM-DM > Global Configuration. A screen similar to the following 1/0/21 and 1/0/22. a. Select Routing > Multicast > PIM-DM > Interface Configuration. A screen similar to the following displays. b. Scroll down and select the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 392
ProSafe 7000 Managed Switch Release 8.0.3 PIM-DM on Switch D: 1. Enable IP routing on the switch. a. Select Routing > IP > Basic > IP Configuration. A screen similar to the following displays. b. For Routing Mode, select the Enable radio button. c. Click Apply. 2. Configure 1/0/21 as a routing port - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 393
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following displays. b. Scroll down and select the Port 1/0/22 check box. Now 1/0/22 appears in the Interface field at the top. c. Enter the following information: • In - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 394
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > RIP > Advanced > Interface Configuration. A screen similar to the following 1/0/24. a. Select Routing > RIP > Advanced > Interface Configuration. A screen similar to the following displays. b. In the Interface list, select 1/0/24. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 395
ProSafe 7000 Managed Switch Release 8.0.3 d. Click Apply. 8. Enable multicast globally. a. Select Routing > Multicast > Global Configuration. A PIM-DM globally. a. Select Routing > Multicast > PIM-DM > Global Configuration. A screen similar to the following displays. b. For Admin Mode, select the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 396
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > PIM-DM > Interface Configuration. A screen similar to the following displays. b. Scroll down and select the Interface 1/0/21, 1/0/22, and 1/0/24 check boxes. c. In the Admin Mode field, select Enable. d. Click Apply to save - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 397
.168.3.0/24 Port 1/0/11 Switch B Subnet 192.168.5.0/24 Subnet 192.168.2.0/24 Switch D Port 1/0/21 Port 1/0/24 Port 1/0/22 Port 1/0/22 Subnet 192.168.6.0/24 Port 1/0/21 Switch C Subnet 192.168.4.0/24 Host IP 192.168.4.2 Figure 2. PIM-SM PIM-SM uses shared trees by default and implements - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 398
ProSafe 7000 Managed Switch Release 8.0.3 Switch A 1. Enable IP routing on the switch. (Netgear Switch)#configure (Netgear Switch) (Config)#ip routing 2. Enable PIM-SM on the switch. (Netgear Switch) (Config)#ip pimsm 3. Enable IP multicast forwarding on the switch. (Netgear Switch) (Config)#ip - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 399
ProSafe 7000 Managed Switch Release 8.0.3 (Netgear Switch) (Interface 1/0/1)#ip pimsm (Netgear Switch) (Interface 1/0/1)#exit (Netgear Switch) (Config)#interface 1/0/9 (Netgear Switch) (Interface 1/0/9)#routing (Netgear Switch) (Interface 1/0/9)#ip address 192.168.3.1 (Netgear Switch) (Interface - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 400
ProSafe 7000 Managed Switch Release 8.0.3 PIM-SM on Switch C (Netgear Switch)#configure (Netgear Switch) (Config)#ip routing (Netgear Switch) (Config)#ip pimsm (Netgear Switch) (Config)#ip multicast (Netgear Switch) (Config)#ip pimsm rp-candidate interface 1/0/22 225.1.1.1 255.255.255.0 (Netgear - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 401
ProSafe 7000 Managed Switch Release 8.0.3 (Netgear Switch) (Config)#interface 1/0/24 (Netgear Switch) (Interface 1/0/24)#routing (Netgear Switch) (Interface 1/0/24)#ip address (Netgear Switch) (Interface 1/0/24)#ip rip (Netgear Switch) (Interface 1/0/24)#ip igmp (Netgear Switch) (Interface 1/0/24)# - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 402
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Configure PIM-SM PIM-SM on Switch A 1. Enable IP routing on the switch. a. Select Routing > IP > Basic > IP Configuration. A screen similar to the following displays. b. For Routing Mode, select the Enable radio button. c. Click Apply. 2. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 403
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the Click Apply. 4. Configure 1/0/13 as a routing port and assign an IP address to it. a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 404
ProSafe 7000 Managed Switch Release 8.0.3 • In the Subnet Mask field, enter 255.255.255.0. • In the Routing Mode field, select Enable. d. Click Apply to save the settings. 5. Enable RIP on interface 1/0/1. a. Select Routing > RIP > Advanced > Interface Configuration. A screen similar to the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 405
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > RIP > Advanced > Interface Configuration. A screen similar to the following Apply. 8. Enable multicast globally. a. Select Routing > Multicast > Global Configuration. A screen similar to the following displays. b. For Admin Mode, select - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 406
ProSafe 7000 Managed Switch Release 8.0.3 b. For Admin Mode, select the Enable radio button. c. Click Apply. 10. Enable PIM-SM on interfaces 1/0/1,1/0/9, and 1/0/13. a. Select Routing > Multicast > PIM-SM > Interface Configuration. A screen similar to the following displays. b. Scroll down and - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 407
ProSafe 7000 Managed Switch Release 8.0.3 PIM-SM on Switch B: 1. Enable IP routing on the switch. a. Select Routing > IP > Basic > IP Configuration. A screen similar to the following displays. b. For Routing Mode, select the Enable radio button. c. Click Apply. 2. Configure 1/0/10 as a routing port - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 408
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following displays. b. Scroll down and select the Port 1/0/11 check box. Now 1/0/11 appears in the Port field at the top. c. Enter the following information: • In the IP - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 409
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > RIP > Advanced > Interface Configuration. A screen similar to the following Apply. 6. Enable multicast globally. a. Select Routing > Multicast > Global Configuration. A screen similar to the following displays. b. For Admin Mode, select - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 410
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > PIM-SM > Global Configuration. A screen similar to the following 1/0/10 and 1/0/11. a. Select Routing > Multicast > PIM-SM > Interface Configuration. A screen similar to the following displays. b. Scroll down and select the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 411
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > PIM-SM > Candidate RP Configuration. A screen similar to the following displays. b. In the Interface list, select 1/0/11. c. In the Group IP field, enter 225.1.1.1. d. In the Group Mask field, enter 255.255.255.0. e. Click Add - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 412
ProSafe 7000 Managed Switch Release 8.0.3 PIM-SM on Switch C: 1. Enable IP routing on the switch. a. Select Routing > IP > Basic > IP Configuration. A screen similar to the following displays. b. For Routing Mode, select the Enable radio button. c. Click Apply. 2. Configure 1/0/21 as a routing port - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 413
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following displays. b. Scroll down and select the 1/0/22 check box. Now 1/0/22 appears in the Interface field at the top. c. Enter the following information: • In the IP - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 414
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > RIP > Advanced > Interface Configuration. A screen similar to the following Apply. 6. Enable multicast globally. a. Select Routing > Multicast > Global Configuration. A screen similar to the following displays. b. For Admin Mode, select - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 415
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > PIM-SM > Global Configuration. A screen similar to the following 1/0/21 and 1/0/22. a. Select Routing > Multicast > PIM-SM > Interface Configuration. A screen similar to the following displays. b. Scroll down and select the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 416
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > PIM-SM > Candidate RP Configuration. A screen similar to the following displays. b. In the Interface list, welect 1/0/22. c. In the Group IP field, enter 225.1.1.1. d. In the Group Mask field, enter 255.255.255.0. e. Click Add - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 417
ProSafe 7000 Managed Switch Release 8.0.3 e. Click Apply. PIM-SM on Switch D 1. Enable IP routing on the switch. a. Select Routing > IP > Basic > IP Configuration. A screen similar to the following displays. b. For Routing Mode, select the Enable radio button. c. Click Apply. 2. Configure 1/0/21 as - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 418
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following displays. b. Scroll down and select the Port 1/0/22 check box. Now 1/0/22 appears in the Port field at the top. c. Enter the following information: • In the IP - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 419
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > RIP > Advanced > Interface Configuration. A screen similar to the following 1/0/24. a. Select Routing > RIP > Advanced > Interface Configuration. A screen similar to the following displays. b. In the Interface list, select 1/0/24. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 420
ProSafe 7000 Managed Switch Release 8.0.3 d. Click Apply. 8. Enable multicast globally. a. Select Routing > Multicast > Global Configuration. A PIM-SM globally. a. Select Routing > Multicast > PIM-SM > Global Configuration. A screen similar to the following displays. b. For Admin Mode, select the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 421
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > PIM-SM > Interface Configuration. A screen similar to the following displays. b. Scroll down and select the Interface 1/0/21, 1/0/22, and 1/0/24 check boxes. c. In the Admin Mode field, select Enable. d. Click Apply to save - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 422
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > PIM-SM > BSR Candidate Configuration. A screen similar to the 13. Enable IGMP globally. a. Select Routing > Multicast > IGMP > Global Configuration. A screen similar to the following displays. b. For Admin Mode, select - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 423
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > IGMP > Interface Configuration. A screen similar to the following displays. b. Under IGMP Routing Interface Configuration, scroll down and select the Interface 1/0/24 check box. c. In the Admin Mode field, select Enable. d. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 424
are typically IP routing-aware devices and are referred to as Layer 3 relay agents. In some network configurations, there is a need for Layer 2 devices to append the relay agent Information option as they are closer to the end hosts. Host #1 1/0/5 1/0/6 1/0/4 Layer 2 Switch #1 DHCP Server - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 425
ProSafe 7000 Managed Switch Release 8.0.3 These Layer 2 devices port 1/0/4. (Netgear Switch) (Config)#interface 1/0/4 (Netgear Switch) (Interface 1/0/4)# dhcp l2relay (Netgear Switch) (Interface 1/0/4)# vlan pvid 200 (Netgear Switch) (Interface 1/0/4)# vlan participation include 200 (Netgear Switch - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 426
ProSafe 7000 Managed Switch Release 8.0.3 6. Enable DHCP L2 relay on port 1/0/5. (Netgear Switch) (Config)#interface 1/0/5 (Netgear Switch) (Interface 1/0/5)# dhcp l2relay (Netgear Switch) (Interface 1/0/5)# vlan pvid 200 (Netgear Switch) (Interface 1/0/5)# vlan participation include 200 (Netgear - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 427
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Switching > VLAN > Advanced > VLAN Membership. A screen similar to the following displays. b. In the VLAN ID field, select 200. c. Click Unit 1. The ports display. d. Click the gray boxes under ports 4, 5, and 6 until U displays. The U specifies - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 428
ProSafe 7000 Managed Switch Release 8.0.3 a. Select System > Services > DHCP L2 Relay > DHCP L2 Relay Configuration. A screen similar to the following displays. b. For Admin Mode, select the Enable radio button. c. Scroll down and select the VLAN ID 200 check box. d. Enter - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 429
ProSafe 7000 Managed Switch Release 8.0.3 a. Select System > Services > DHCP L2 Relay > DHCP L2 Relay Interface Configuration. A screen similar to the following displays. b. Under DHCP L2 Relay Configuration, scroll down and select the Interface 1/0/6 check box. c. In the 82 Option Trust Mode field, - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 430
ProSafe 7000 Managed Switch Release 8.0.3 DHCP L3 Relay This example shows how to configure a DHCP L3 relay on a NETGEAR switch and how to configure DHCP pool to assign IP addresses to DHCP clients using DHCP L3 relay. DHCP server DHCP L3 relay 1/0/10 1/0/15 1/0/14 PC Figure 2. DHCP L3 relay - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 431
Managed Switch Release 8.0.3 2. Create a routing interface and enable RIP on it so that the DHCP server learns the route 10.200.1.0/24 from the DHCP L3 relay. (Netgear Switch) (Config)#interface 1/0/3 (Netgear Switch) (Interface 1/0/3)#routing (Netgear Switch) (Interface 1/0/3)#ip address 10.100 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 432
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following displays. b. Scroll down and select the 1/0/3 check box. c. In the IP Address field, enter 10.100.1.1. d. In the Subnet Mask field, enter 255.255.255.0. e. In - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 433
ProSafe 7000 Managed Switch Release 8.0.3 a. Select System > Services > DHCP Server > DHCP Server Configuration. A screen similar to the following displays. b. For Admin Mode, select the Enable radio button. c. In the IP Range From field, enter 10.200.1.1. d. In the IP Range To field, enter 10.200 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 434
15)#routing (Netgear Switch) (Interface 1/0/15)#ip address 10.200.1.1 255.255.255.0 (Netgear Switch) (Interface 1/0/15)#exit 4. Configure the DHCP Server IP address and enable the DHCP L3 relay. (Netgear Switch) (Config)#ip helper-address 10.100.1.1 dhcp (Netgear Switch) (Config)#ip helper enable - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 435
ProSafe 7000 Managed Switch Release 8.0.3 5. Redistribute 10.200.1.0/24 to the RIP such that RIP adviertises this route to the DHCP server. (Netgear Switch) (Config)# (Netgear Switch) (Config)#router rip (Netgear Switch) (Config-router)#redistribute connected (Netgear Switch) (Config-router)#exit - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 436
ProSafe 7000 Managed Switch Release 8.0.3 f. Click Apply to save the settings. 3. Enable RIP on interface 1/0/4. a. Select Routing > RIP > Advanced > Interface Configuration. A screen similar to the following displays. b. In the Interface list, select 1/0/4. c. For RIP Admin Mode, select the Enable - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 437
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > RIP > Advanced > Route Redistribution. A Configure the DHCP server IP address. a. Select System > Services > UDP Relay. A screen similar to the following displays. b. In the Server Address field, enter 10.100.1.1. c. In the UDP Port - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 438
Snooping on page 452 Multicast Listener Discovery (MLD) protocol enables IPv6 routers to discover multicast listeners, the nodes that are configured to receive multicast data packets, on its directly attached interfaces. The protocol specifically discovers which multicast addresses are of interest - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 439
ProSafe 7000 Managed Switch Release 8.0.3 Configure MLD In this case, PIM-DM is enabled on Switch A and Switch B, and MLD is enabled on Switch B's port 1/0/24 to discover the multicast listeners. IPv6 multicast source 2001:2::/65 Switch A Port 1/0/13 Port 1/0/1 2001:1::/64 Switch B Port 1/0/ - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 440
ProSafe 7000 Managed Switch Release 8.0.3 (Netgear Switch) (Config)#ipv6 unicast-routing (Netgear Switch) (Config)#ipv6 pimdm (Netgear Switch) (Config)#ip routing (Netgear Switch) (Config)#ip multicast (Netgear Switch) (Config)#interface 1/0/1 (Netgear Switch) (Interface 1/0/1)#routing (Netgear - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 441
ProSafe 7000 Managed Switch Release 8.0.3 5. Enable IP multicast forwarding on the switch. (Netgear Switch) (Config)#ip routing (Netgear Switch) (Config)#ip multicast 6. Enable MLD on interface 1/0/24. (Netgear Switch) (Config)#interface 1/0/21 (Netgear Switch) (Interface 1/0/21)#routing ( - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 442
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Basic > IP Configuration. A screen similar to the following displays. b. For Routing Mode, select the Enable radio button. c. Click Apply. 2. Enable IPv6 unicast routing on the switch. a. Select Routing > IPv6 > Basic > Global - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 443
ProSafe 7000 Managed Switch Release 8.0.3 b. Scroll down and select the Interface 1/0/1 and 1/0/13 check boxes . 4. Assign an IPv6 address to 1/0/1. a. Select Routing > IPv6 > Advanced > Prefix Configuration. A screen similar to the following displays. b. In the Interface field, select 1/0/1. c. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 444
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IPv6 > Advanced > Prefix Configuration. A screen similar to the following displays. b. Select Interface 1/0/13. c. Enter the following information: • In the IPv6 Prefix field, enter 2001:2::1. • In the Prefix Length field, - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 445
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > OSPFv3 > Advanced > Interface Configuration. A screen similar to the settings. 8. Enable multicast globally. a. Select Routing > Multicast > Global Configuration. A screen similar to the following displays. b. For Admin Mode, select - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 446
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > PIM-DM > Global Configuration. A screen similar to the following 1/0/1 and 1/0/13. a. Select Routing > Multicast > PIM-DM > Interface Configuration. A screen similar to the following displays. b. Scroll down and select the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 447
ProSafe 7000 Managed Switch Release 8.0.3 d. Click Apply to save the settings. MLD on Switch B 1. Enable IP routing on the switch. a. Select Routing > IP > Basic > IP Configuration. A screen similar to the following displays. b. For Routing Mode, select the Enable radio button. c. Click Apply. 2. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 448
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IPv6 > Advanced > Interface Configuration. A screen similar to the following displays. b. Scroll down and select the Interface 1/0/21 and 1/0/24 check boxes. c. Enter the following information: • In the IPv6 Mode field, select Enable. • - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 449
ProSafe 7000 Managed Switch Release 8.0.3 5. Assign an IPv6 address to 1/0/24. a. Select Routing > IPv6 > Advanced > Prefix Configuration. A screen similar to the following displays. b. Under IPv6 Interface Selection, in the Interface field, select 1/0/24 . c. Enter the following information: • In - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 450
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > OSPFv3 > Advanced > Interface Configuration. A screen similar to the following displays. b. Under OSPFv3 Interface Configuration, scroll down and select the Interface 1/0/21 and 1/0/24 check boxes. c. In the OSPFv3 Interface Configuration - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 451
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > PIM-DM > Global Configuration. A screen similar to the following displays. b. For Admin Mode, select the Enable radio button. c. Click Apply. 10. Enable PIM-DM on interfaces 1/0/21 and 1/0/24. a. Select Routing > Multicast > - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 452
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > MLD > Global Configuration. A screen similar to the following displays. b. For Admin Mode, select the Enable radio button. c. Click Apply. 12. Enable MLD on interface 1/0/24. a. Select Routing > Multicast > MLD > Routing - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 453
ProSafe 7000 Managed Switch Release 8.0.3 MLD is a protocol used by IPv6 multicast routers to discover the presence of multicast listeners (nodes configured to receive IPv6 multicast packets) on its directly attached links and to discover which multicast packets are of interest to neighboring nodes. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 454
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Configure MLD Snooping 1. Create VLAN 300. a. Select Switching > VLAN > Basic > VLAN Configuration. A screen similar to the following displays. b. In the VLAN ID field, enter 300. c. Click Add. 2. Assign all of the ports to VLAN 300. a. Select - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 455
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Switching > VLAN > Advanced > Port PVID Configuration. A screen similar to the following displays. b. Scroll down and select the interface 1/0/1 and 1/0/24 check boxes. c. In the PVID (1 to 4093) field, enter 300. d. Click Apply to save the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 456
ProSafe 7000 Managed Switch Release 8.0.3 b. Enter the following information: • In the VLAN ID field, enter 300. • In the Admin Mode field, select Enable. 6. Click Add. 456 | Chapter 28. MLD - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 457
Protocol 29 The DVMRP is used for multicasting over IP networks without routing protocols to support multicast. The DVMRP is based on the RIP constructed. In this example, DVMRP is running on switches A, B, and C. IGMP is also running on Switch C, which is connected to the host directly. After the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 458
24 Figure 1. DVMRP CLI: Configure DVMRP DVRMP on Switch A 1. Create routing interfaces 1/0/1, 1/0/13, and 1/0/21. (Netgear Switch) #config (Netgear Switch) (Config)#ip routing (Netgear Switch) (Config)#interface 1/0/1 (Netgear Switch) (Interface 1/0/1)#routing (Netgear Switch) (Interface 1/0/1)#ip - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 459
ProSafe 7000 Managed Switch Release 8.0.3 3. Enable DVMRP protocol on the switch. (Netgear Switch) (Config)#ip dvmrp 4. Enable DVMRP mode on the interfaces 1/0/1, 1/0/13, and 1/0/21. (Netgear Switch) (Config)#interface 1/0/1 (Netgear Switch) (Interface 1/0/1)#ip dvmrp (Netgear Switch) (Interface - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 460
ProSafe 7000 Managed Switch Release 8.0.3 (Netgear Switch) #show ip mcast mroute summary Multicast Route Table Summary Incoming Source IP Group IP Protocol Interface 192.168.1.2 225.0.0.1 DVMRP 1/0/1 Outgoing Interface List 1/0/21 DVRMP on Switch B 1. Create routing ports 1/0/13 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 461
ProSafe 7000 Managed Switch Release 8.0.3 (Netgear Switch) #show ip dvmrp neighbor Interface 1/0/13 Neighbor IP Address 192.168.2.1 State Active Up Time (hh:mm:ss 00:02:26 Expiry Time (hh:mm:ss 00:00:20 Generation ID 88091 Major - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 462
ProSafe 7000 Managed Switch Release 8.0.3 DVRMP on Switch C: 1. Create routing interfaceS 1/0/11, 1/0/3, and 1/0/24. (Netgear Switch) #config (Netgear Switch) (Config)#ip routing (Netgear Switch) (Config)#ip interface 1/0/11 (Netgear Switch) (Interface 1/0/11)#ip routing (Netgear Switch) (Interface - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 463
ProSafe 7000 Managed Switch Release 8.0.3 6. Enable IGMP mode on the interface 1/0/24. (Netgear Switch) (Config)#interface 1/0/24 (Netgear Switch) (Interface 1/0/24)#ip igmp (Netgear Switch) (Interface 1/0/24)#exit (Netgear Switch) #show ip dvmrp neighbor Interface 1/0/11 Neighbor IP Address 192 - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 464
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Configure DVMRP DVMRP on Switch A 1. Enable IP routing on the switch. a. Select Routing > IP > Basic >IP Configuration. A screen similar to the following displays. b. For Routing Mode, select the Enable radio button. c. Click Apply. 2. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 465
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following displays. b. Scroll down and select the Port 1/0/13 check box. Now 1/0/13 appears in the Port field at the top. c. Enter the following information: • In the IP - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 466
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > Global Configuration. A screen similar to the following displays. b. For Admin Mode, select the Enable radio button. c. Click Apply. 6. Enable DVMRP on the switch. a. Select Routing > Multicast > DVMRP > Global Configuration. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 467
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > DVMRP > Interface Configuration. A screen similar to the following displays. b. Scroll down select the Interface 1/0/1, 1/0/13, and 1/0/21 check boxes. c. In the Interface Mode field, select 300. d. Click Apply - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 468
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following displays. b. Scroll down and select the Port 1/0/13 check box. Now 1/0/13 appears in the Port field at the top. c. Enter the following information in the IP - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 469
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > Global Configuration. A screen similar to the following displays. b. For Admin Mode, select the Enable radio button. c. Click Apply. 5. Enable DVMRP on the switch. a. Select Routing > Multicast > DVMRP> Global Configuration. A - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 470
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > DVMRP > Interface Configuration. A screen similar to the following displays. b. Scroll down and select the Interface 1/0/13 and 1/0/20 check boxes. c. In the Interface Mode field, select Enable. d. Click - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 471
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following displays. b. Scroll down and select the Port 1/0/11 check box. Now 1/0/11 appears in the Port field at the top. c. Enter the following information: • In the IP - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 472
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > IP > Advanced > IP Interface Configuration. A screen similar to the following displays. b. Scroll down and select the Port 1/0/24 check box. Now 1/0/24 appears in the Port field at the top. c. Enter the following information: • In the IP - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 473
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > DVMRP > Global Configuration. A screen similar to the following displays. > Interface Configuration. A screen similar to the following displays. b. Scroll down and select the Interface 1/0/3, 1/0/11, and 1/0/24 check boxes. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 474
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Routing > Multicast > IGMP > Global Configuration. A screen similar to the following Routing Interface Configuration. A screen similar to the following displays. b. Scroll down and select the Interface 1/0/24 check box. Now 1/0/24 appears in - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 475
Groups on page 479 • Remote Authorization (RADIUS) User Configuration on page 481 • SSL Certificates on page 483 The port from the unauthenticated clients is dropped except for the ARP, DHCP, DNS and NETBIOS packets. The switch forwards these packets so that unauthenticated clients can get an IP - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 476
ProSafe 7000 Managed Switch Release 8.0.3 You can enable captive portal on all the physical ports on the switch. It is not supported for VLAN interfaces, loopback interfaces or logical interfaces. The captive portal feature uses MAC-aaddress based authentication and not port-based authentication. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 477
ProSafe 7000 Managed Switch Release 8.0.3 2. Enable captive portal instance 1. (Netgear Switch) (Config-CP)#configuration 1 (Netgear Switch) (Config-CP 1)#enable 3. Enable captive portal instance 1 on port 1/0/1. (Netgear Switch) (Config-CP 1)#interface 1/0/1 Web Interface: Enable Captive Portal 1. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 478
ProSafe 7000 Managed Switch Release 8.0.3 a. Select Security > Control > Captive Portal > CP Configuration. A screen similar to the following displays. b. Scroll down and select the CP 1 check box. Now CP 1 appears in the CP ID field at the top. c. - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 479
ProSafe 7000 Managed Switch Release 8.0.3 captive portal instance is a temporary command executed by the administrator and not saved in the configuration. Block a Captive Portal Instance CLI: Block a Captive Portal Instance (Netgear Switch)(Config-CP 1)#block Web Interface: Block a Captive Portal - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 480
ProSafe 7000 Managed Switch Release 8.0.3 CLI: Create Users and Groups 1. Create a group whose group ID is 2. (Netgear Switch) #config (Netgear Switch) (config)#captive-portal (Netgear Switch)(Config-CP)# user group 2 2. Create a user whose name is user1. (Netgear Switch) (Config-CP)#user 2 name - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 481
ProSafe 7000 Managed Switch Release 8.0.3 c. Click Add. 2. Create a user. a. Select Security > Control > Captive Portal > CP User Configuration. A screen similar to the following displays. b. Enter the following information: • In the User ID Field, enter 2. • In the User Name field, enter user1. • - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 482
ProSafe 7000 Managed Switch Release 8.0.3 are used to configure captive portal. VSAs are denoted in the ID column and are comma delimited (vendor ID, attribute ID). Table 1. RADIUS Attributes for Configuring Captive Portal Users RADIUS Attribute No. Description Range Usage User-Name 1 User - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 483
ProSafe 7000 Managed Switch Release 8.0.3 Web Interface: Configure RADIUS as the Verification Mode 1. Select Security > Control > Captive Portal > CP Configuration. A RADIUS server name Default-RADIUS-Server. 4. Click Apply. SSL Certificates A captive portal instance can be configured to use the - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 484
routing protocol (DVMRP) 457 DNS 330 host name and IP address 331 documentation 8 dual image 287 DVMRP 457, 458, 464 E Ethernet configuration for stacking ports 308 F firmware upgrading stacked switches 307, 308 firmware for stacked switches 306 G gaming 221 guest VLAN 243, 244, 245 I Index - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 485
ProSafe 7000 Managed Switch Release 8.0.3 IGMP querier 221, 222 enable 222, 223 status 225 IGMP image 288 dual image 287 port routing adding a default route 44 adding a static route 45, 46 configuration 40 enabling routing for ports 41, 42 enabling routing for the switch 41 port security 802.1x 237, - Netgear GSM7328SNA | 7000 Series Managed Switch Administration Guide for Softwar - Page 486
STPs 350 switch FSM family of switches 305 GSM family of switches 305 switch priority 305 switch stack configuration files 316 member numbers 304 member priority values 305 membership 304 software compatibility 316 486 | Index ProSafe 7000 Managed Switch Release 8.0.3 upgrading firmware 307 Syslog
350 East Plumeria Drive
San Jose, CA 95134
USA
November 2010
202-10515-04
v1.0
ProSafe 7000 Managed
Switch Release 8.0.3
Software Administration Manual