TP-Link TL-SG3210 TL-SG3210 V1 User Guide

TP-Link TL-SG3210 Manual

TP-Link TL-SG3210 manual content summary:

  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 1
    TL-SG3210 JetStream L2 Lite Managed Switch Rev: 1.0.0 1910010508
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 2
    TP-LINK TECHNOLOGIES CO., LTD. Copyright © 2011 TP-LINK TECHNOLOGIES CO., LTD. All rights reserved. http://www.tp-link.com FCC STATEMENT This equipment has been tested if not installed and used in accordance with the instruction manual, may cause harmful interference to radio communications.
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 3
    Tools ...18 4.3.1 Config Restore 18 4.3.2 Config Backup 18 4.3.3 Firmware Upgrade 19 4.3.4 System Reboot 20 4.3.5 System Reset 20 4.4 Access Security ...20 4.4.1 Access Control 20 4.4.2 SSL Config...22 4.4.3 SSH Config ...23 Chapter 5 Switching...29 5.1 Port ...29 5.1.1 Port Config ...29 IV
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 4
    LACP Config ...37 5.3 Traffic Monitor ...39 5.3.1 Traffic Summary 39 5.3.2 Traffic Statistics 40 5.4 MAC Address...41 5.4.1 Address Table 42 5.4.2 Static Address 44 5.4.3 Dynamic Address 45 5.4.4 Filtering Address 47 Chapter 6 VLAN...49 6.1 802.1Q VLAN...50 6.1.1 VLAN Config ...52 6.1.2 Port
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 5
    Snooping ...93 8.1.1 Snooping Config 94 8.1.2 Port Config ...95 8.1.3 VLAN Config ...96 8.1.4 Multicast VLAN 98 8.2 Multicast IP ...101 8.2.1 Multicast IP Table 102 8.2.2 Static Multicast IP 102 8.3 Multicast Filter...103 8.3.1 IP-Range...104 8.3.2 Port Filter ...105 8.4 Packet Statistics...106
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 6
    .4 Policy Binding ...132 10.4.1 Binding Table 132 10.4.2 Port Binding 133 10.4.3 VLAN Binding 133 10.5 Application Example for ACL 134 Chapter 11 Network Security ...137 11.1 IP-MAC Binding ...137 11.1.1 Binding Table 137 11.1.2 Manual Binding 138 11.1.3 ARP Scanning 140 11.1.4 DHCP Snooping
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 7
    198 14.2.4 Backup Log ...199 14.3 Device Diagnose...200 14.3.1 Cable Test ...200 14.3.2 Loopback ...201 14.4 Network Diagnose ...201 14.4.1 Ping...201 14.4.2 Tracert...202 Appendix A: Specifications ...204 Appendix B: Configuring the PCs 205 Appendix C: Load Software Using FTP 208 Appendix D: 802
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 8
    items should be found in your box: ¾ One JetStream L2 Lite Managed Switch ¾ One power cord ¾ One console cable ¾ Two mounting brackets and other fittings ¾ Installation Guide ¾ Resource CD for TL-SG3210 switch, including: • This User Guide • Other Helpful Information Note: Make sure that the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 9
    managers familiar with IT concepts and network terminologies. 1.2 Conventions In this Guide the following conventions are used: ¾ The switch or TL-SG3210 mentioned in this Guide stands for TL-SG3210 JetStream L2 Lite Managed Switch without any explanation. ¾ Menu Name→Submenu Name→Tab page indicates
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 10
    other switches, without having to individually configure each VLAN. This module is used to configure spanning tree function of the switch. Here mainly introduces: z STP Config: Configure and view the global settings of spanning tree function. z Port Config: Configure CIST parameters of ports. z MSTP
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 11
    access control mechanism for LAN ports to solve mainly authentication and security problems. This module is used to configure SNMP function to provide a management frame to monitor and maintain the network devices. Here mainly introduces: z SNMP Config: Configure global settings of SNMP function
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 12
    introduces: z System Monitor: Monitor the memory and CPU of the switch. z Log: View configuration parameters on the switch. z Device Diagnose: Test the connection status of the cable connected to the switch, test if the port of the switch and the connected device are available. z Network Diagnose
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 13
    choosing the TL-SG3210 JetStream L2 Lite Managed Switch! 2.1 Overview of the Switch Designed for workgroups and departments, TL-SG3210 from TP-LINK provides wire-speed performance and abundant layer 2 management features. It provides a variety of service features and multiple powerful functions with
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 14
    . Each has a corresponding 1000Mbps LED. ¾ SFP Ports: Designed to install the SFP module. ¾ Console Port: Designed to connect with the serial port of a computer or terminal for monitoring and configuring the Switch. ¾ LEDs Name Power System 1000Mbps Link/Act Status On Flashing Off On Flashing Off
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 15
    2-2 Rear Panel ¾ Grounding Terminal: TL-SG3210 already comes with Lightning Protection Mechanism. You can also ground the Switch through the PE (Protecting Earth) cable of AC cord or with Ground Cable. For detail information, please refer to Installation Guide. ¾ AC Power Socket: Connect the female
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 16
    configuration utility, open a web-browser and type in the default address http://192.168.0.1 in the address field of the browser, then press the Enter key. Figure 3-1 Web-browser Tips: To log in to the Switch, the IP address of your PC should be set in the same subnet addresses of the Switch. The IP
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 17
    can only make the new configurations effective before the switch is rebooted. If you want to keep the configurations effective even the switch is rebooted, please click Saving Config. You are suggested to click Saving Config before cutting off the power or rebooting the switch to avoid losing the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 18
    System Info, mainly for basic properties configuration, can be implemented on System Summary, Device Description, System Time and System IP pages. 4.1.1 System Summary On this page you can view the port connection status and the system information. The port status diagram shows the working status
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 19
    the speed of 100Mbps. When the cursor moves on the port, the detailed information of the port will be displayed. ¾ Port Info Figure 4-2 Port Information Port: Type: Rate: Status: Displays the port number of the switch. Displays the type of the port. Displays the maximum transmission rate of the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 20
    packets on this port. 4.1.2 Device Description On this page you can configure the description of the switch, including device name switch is running. On this page you can configure the system time and the settings here will be used for other time-based functions like ACL. You can manually set
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 21
    : Get GMT: Synchronize with PC'S Clock: When this option is selected, you can set the date and time manually. When this option is selected, you can configure the time zone and the IP Address for the NTP Server. The switch will get GMT automatically if it has connected to a NTP Server. z Time Zone
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 22
    can access the switch via any port on the switch. However, if another VLAN is created and set to be the Management VLAN, you may have to reconnect the management station to a port that is a member of the Management VLAN. IP Address: Enter the system IP of the switch. The default system IP is 192
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 23
    and default gateway can not be configured. 5. By default, the default IP address is 192.168.0.1. 4.2 User Manage User Manage functions to configure the user name and password for users to log on to the Web management page with a certain access level so as to protect the settings of the switch from
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 24
    of different functions. z Guest: Guest only can view the settings without the right to edit and modify. Select Enable/Disable the user configuration. Password: Type a password for users' login. Confirm Password: Retype the password. ¾ User Table Select: Select the desired entry to delete
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 25
    any damage, please don't power down the switch while being restored. 3. After being restored, the current settings of the switch will be lost. Wrong uploaded configuration file may cause the switch unmanaged. 4.3.2 Config Backup On this page you can download the current configuration and save it as
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 26
    to backup the configuration. Please wait without any operation. 4.3.3 Firmware Upgrade The switch system can be upgraded via the Web management page. To upgrade the system is to get more functions and better performance. Go to http://www.tp-link.com to download the updated firmware. Choose the menu
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 27
    page. Figure 4-13 System Reset Note: After the system is reset, the switch will be reset to the default and all the settings will be cleared. 4.4 Access Security Access Security provides different security measures for the remote login so as to enhance the configuration management security. It can
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 28
    to limit the MAC Address of the users for login. z Port-based: Select this option to limit the ports for login. These fields can be available for configuration only when IP-based mode is selected. Only the users within the IP-range you set here are allowed for login. MAC Address: The field can be
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 29
    ecommerce and online banking. SSL mainly provides the following services: 1. Authenticate the users and the servers based on default the switch has a certificate (self-signed certificate) and a corresponding private key. The Certificate/Key Download function enables the user to replace the default
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 30
    old telnet remote management method is not safe, because the password and data transmitted with plain-text can be easily intercepted. SSH can provide information security and powerful authentication when you log on to the switch remotely through an insecure network environment. It can encrypt all
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 31
    with each other after successful authentication. This switch supports SSH server and you can log on to the switch via SSH connection using SSH client software. SSH key can be downloaded into the switch. If the key is successfully downloaded, the certificate authentication will be preferred for
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 32
    the IP address of the switch into Host Name field; keep the default value 22 in the Port field; select SSH as the Connection type. 2. Click the Open button in the above figure to log on to the switch. Enter the login user name and password, and then you can continue to configure the switch. 25
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 33
    Application Example 2 for SSH: ¾ Network Requirements 1. Log on to the switch via password authentication using SSH and the SSH function is enabled on the switch. 2. PuTTY client software is recommended. ¾ Configuration Procedure 1. Select the key type and key length, and generate SSH key. Note: 1.
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 34
    3. On the Web management page of the switch, download the public key file saved in the computer to the switch. Note: 1. The key type should accord with the type of the key file. 2. The SSH key downloading can not be interrupted. 4. Download the private key file to SSH client software. 27
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 35
    After the public key and private key are downloaded, please log on to the interface of PuTTY and enter the IP address for login. After successful authentication, please enter the login user name. If you log on to the switch without entering password, it indicates that the key has been successfully
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 36
    for a long time can reduce the power consumption effectively. And you can enable the port when it is in need. The parameters will affect the working mode of the port, please set the parameters appropriate to your needs. Choose the menu Switching→Port→Port Config to load the following page. Figure
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 37
    diagnose device, which is used to analyze the mirrored packets for monitoring and troubleshooting the network. Choose the menu Switching→Port→Port Mirror to load the following page. Figure 5-2 Mirroring Port The following entries are displayed on this screen. ¾ Mirror Group List Group: Mirroring
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 38
    LAG member can not be selected as the mirrored port or mirroring port. 2. A port can not be set as the mirrored port and the mirroring port simultaneously. 3. The Port Mirror function can take effect span the multiple VLANs. 5.1.3 Port Security MAC Address Table maintains the mapping relationship
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 39
    this port. Choose the menu Switching→Port→Port Security to load the following page. Figure 5-4 Port Security The following entries are displayed on this screen: ¾ Port Security Select: Select the desired port for Port Security configuration. It is multi-optional. Port: Displays the port number
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 40
    port to forward packets to the ports that are not on its forward portlist. Choose the menu "Switching→Port→Port Isolation" to load the following page. Figure 5-5 Port Isolation Config The following entries are displayed on this screen: ¾ Port Isolation Config Port: Select the port number to set
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 41
    . The basic configuration includes STP, QoS, GVRP, VLAN, port attributes, MAC Address Learning mode and other associated settings. The further explains are following: z If the ports, which are enabled for the GVRP, 802.1Q VLAN, Voice VLAN, STP, QoS, DHCP Snooping and Port Configuration (Speed and
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 42
    Aggregate Arithmetic, which results in choosing a port to transfer the packets. • SRC MAC IP + DST IP: When this option is selected, the Aggregate Arithmetic will apply to the source and destination IP for each LAG. • Edit: Click to modify the settings of the LAG. • Detail: Click to get the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 43
    5.2.2 Static LAG On this page, you can manually configure the LAG. The LACP feature is disabled for the member ports of the manually added Static LAG. Choose the menu Switching→LAG→Static LAG to load the following page. Figure 5-8 Manually Config The following entries are displayed on this screen
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 44
    Control Protocol) is defined in IEEE802.3ad and enables the dynamic link aggregation and disaggregation by exchanging LACP packets with its partner. The switch can dynamically group similarly configured ports into a single logical link, which will highly extend the bandwidth and flexibly balance the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 45
    priority adds the proper links to the ling aggregation according to the selection of its partner. ¾ LACP Config Port Select: Click the Select button to quick-select the corresponding port based on the port number you entered. Select: Select the desired port for LACP configuration. It is multi
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 46
    LACP feature for your selected port. Displays the LAG number which the port belongs to. 5.3 Traffic Monitor The Traffic Monitor function, monitoring the traffic of each port each port, which facilitates you to monitor the traffic and analyze the network abnormity. Choose the menu Switching→Traffic
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 47
    5.3.2 Traffic Statistics Traffic Statistics screen displays the detailed traffic information of each port, which facilitates you to monitor the traffic and locate faults promptly. Choose the menu Switching→Traffic Monitor→Traffic Statistics to load the following page. Figure 5-11 Traffic Statistics
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 48
    port. The error frames are not counted in. Displays the number of the received packets that have a bad Frame Check port-based MAC address information, which is the base for the switch to forward packets quickly. The entries in the Address Table can be updated by auto-learning or configured manually
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 49
    No The bound MAC address can be learned by the other ports in the same VLAN. Filtering Manually configuring No Yes - Address Table Table 5-1 Types and features of view all the information of the Address Table. Choose the menu Switching→MAC Address→Address Table to load the following page. 42
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 50
    MAC Address: Enter the MAC address of your desired entry. VLAN ID: Enter the VLAN ID of your desired entry. Port: Select the corresponding port number of your desired entry. Type: Select the type of your ¾ Address Table MAC Address: Displays the MAC address learned by the switch. 43
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 51
    menu Switching→MAC Address→Static Address to load the following page. Figure 5-13 Static Address The following entries are displayed on this screen: ¾ Create Static Address MAC Address: Enter the static MAC Address to be bound. VLAN ID: Enter the corresponding VLAN ID of the MAC address. Port
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 52
    your desired entry. • VLAN ID: Enter the VLAN ID number of your desired entry. • Port: Enter the Port number of your desired entry port number of the MAC address is not correct, or the connected port (or the device) has been changed, the switch can not be forward the packets correctly. Please reset
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 53
    list and click the Search button to find your desired entry in the Dynamic Address Table. • MAC: Enter the MAC address of your desired entry. • VLAN ID: Enter the VLAN ID number of your desired entry. • Port: Enter the Port number of your desired entry. ¾ Dynamic Address Table 46
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 54
    switch. It is recommended to keep the default value. 5.4.4 Filtering Address The filtering address is to forbid the undesired packets to be forwarded. The filtering address can be added or removed manually on all the ports in the corresponding VLAN. Choose the menu Switching→MAC Address→Filtering
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 55
    corresponding filtering address. It is multi-optional. MAC Address: Displays the filtering MAC Address. VLAN ID: Displays the corresponding VLAN ID. Port: Here the symbol "__" indicates no specified port. Type: Displays the Type of the MAC address. Aging Status: Displays the Aging Status
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 56
    its network configuration. A VLAN can span across multiple switches, or even routers. This enables hosts in a VLAN to be dispersed in a looser way. That is, hosts in a VLAN can belong to different physical network segments. This switch supports three ways, namely, 802.1Q VLAN, MAC VLAN and Protocol
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 57
    a packet belongs. When the switch receives an un-VLAN-tagged packet, it will encapsulate a VLAN tag with the default VLAN ID of the inbound port for the packet, and the packet will be assigned to the default VLAN of the inbound port for transmission. In this User Guide, the tagged packet refers to
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 58
    according to the different VLANs. The default egress rule is UNTAG. The PVID can be set as the VID number of any VLAN the port belongs to. ¾ PVID PVID (Port Vlan ID) is the default VID of the port. When the switch receives an un-VLAN-tagged packet, it will add a VLAN tag to the packet according
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 59
    the current created 802.1Q VLAN. Choose the menu VLAN→802.1Q VLAN→VLAN Config to load the following page. Figure 6-3 VLAN Table To ensure the normal communication of the factory switch, the default VLAN of all ports is set to VLAN1. The Web Management Page of switch can only be accessed through
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 60
    number you entered. Select the desired port to be a member of VLAN or leave it blank. It's multi-optional. Displays the port number. Displays the Link Type of the port. It can be reset on Port Config screen. Select the Egress Rule for the VLAN port member. The default egress rule is UNTAG. • TAG
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 61
    port number. Link Type: PVID: Select the Link Type from the pull-down list for the port. • ACCESS: The ACCESS port can be added in a single VLAN, and the egress rule of the port is UNTAG. The PVID is same as the current VLAN ID. If the current VLAN is deleted, the PVID will be set to 1 by default
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 62
    the port from the current VLAN. Configuration Procedure: Step Operation Description 1 Set the link type for Required. On the VLAN→802.1Q VLAN→Port Config page, set port. the link type for the port based on its connected device. 2 Create VLAN. Required. On the VLAN→802.1Q VLAN→VLAN Config
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 63
    port in this VLAN and still takes its member role effect without changing the configuration of VLAN members. The packet in MAC VLAN is processed in the following way: 1. When receiving an untagged packet, the switch VLAN, please set its connected port of switch to be a member of this 802.1Q VLAN so
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 64
    to apply your settings. Configuration Procedure: Step Operation Description 1 Set the link type for Required. On the VLAN→802.1Q VLAN→Port Config page, set port. the link type for the port based on its connected device. 2 Create VLAN. Required. On the VLAN→802.1Q VLAN→VLAN Config page, click
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 65
    802.2LLC (Logic Link Control) encapsulation The Length field, DSAP (Destination Service Access Point) field, SSAP (Source Service Access Point) encapsulation formats are supported in IP protocol, ARP protocol and RARP protocol, but not supported in all protocols. The switch identifies the protocol
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 66
    has been preset in the switch, you can create protocol VLAN according to the corresponding protocol template. Encapsulation Protocol IP(0x0800) Ethernet II Supported IPX(0x8137) AppleTalk(0x809B) Supported Supported 802.3 raw Not supported Supported Not supported 802.2 LLC 802.2 SNAP Not
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 67
    packet, the switch will process it based on the 802.1Q VLAN. If the received port is the member of the VLAN to which the tagged packet belongs, the packet will be forwarded normally. Otherwise, the packet will be discarded. 3. If the Protocol VLAN is created, please set its enabled port to be the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 68
    VLAN. This VLAN should be one of the 802.1Q VLANs the ingress port belongs to. ¾ Protocol Group Member Select your desired port for Protocol VLAN Group. 6.3.3 Protocol Template The Protocol Template should be created before configuring the Protocol VLAN. By default, the switch has defined the IP
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 69
    field in the protocol template. Frame Type Displays the Frame type field for the protocol template. Note: The Protocol Template bound to VLAN can not be deleted. Configuration Procedure: Step Operation 1 Set the link type for port. 2 Create VLAN. 3 Create Protocol Template. 4 Create Protocol
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 70
    . On VLAN→802.1Q VLAN→VLAN Config page, create a VLAN with its VLANID as 20, owning Port 3 and Port 4. z Configure Switch B Step 1 2 3 Operation Description Configure the Required. On VLAN→802.1Q VLAN→Port Config page, configure Link Type of the the link type of Port 7, Port 6 and Port 8 as
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 71
    ¾ Configuration Procedure z Configure Switch A Step Operation Description 1 Configure the Required. On VLAN→802.1Q VLAN→Port Config page, configure the Link Type of the link type of Port 11 and Port 12 as GENERAL and TRUNK respectively. ports 2 Create VLAN10 Required. On VLAN→802.1Q VLAN→VLAN
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 72
    19-56-82-3B-70. z Configure Switch C Step Operation Description 1 Configure the Required. On VLAN→802.1Q VLAN→Port Config page, configure the Link Type of the link type of Port 2 and Port 3 as GENERAL, and configure the link type ports of Port 4 and Port 5 as ACCESS. 2 Create VLAN10 Required
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 73
    Configure Switch A Step Operation Description 1 Configure the Required. On VLAN→802.1Q VLAN→Port Config page, configure the Link Type of the link type of Port 11 and Port 13 as ACCESS, and configure the link type ports of Port 12 as GENERAL. 2 Create VLAN10 Required. On VLAN→802.1Q VLAN→VLAN
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 74
    registration protocol). GVRP allows the switch to automatically add or remove the VLANs via the dynamic VLAN registration information and propagate the local VLAN registration information to other switches, without having to individually configure each VLAN. ¾ GARP GARP provides the mechanism
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 75
    have the same VLAN information. The VLAN registration information includes not only the static registration information configured locally, but also the dynamic registration information, which is received from other switches. In this switch, only the port with TRUNK link type can be set as the GVRP
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 76
    -select the corresponding entry based on the port number you entered. Select: Select the desired port for configuration. It is multi-optional. Port: Displays the port number. Status: Enable/Disable the GVRP feature for the port. The port type should be set to TRUNK before enabling the GVRP
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 77
    . Note: LeaveAll Timer >= 10* Leave Timer, Leave Timer >= 2*Join Timer Configuration Procedure: Step Operation Description 1 Set the link type for port. Required. On the VLAN→802.1Q VLAN→Port Config page, set the link type of the port to be TRUNK. 2 Enable GVRP function. Required. On the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 78
    network segment or switch. Port Priority: The port priority can be set to a value in the range of 0~255. The lower value priority has the higher priority. The port with the higher priority has more chance to be chosen as the root port. Path Cost: Indicates the parameter for choosing the link path by
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 79
    It is used to test the links. Max. Age: Max. Age ranges from 6 to 40 seconds. It specifies the maximum time the switch can wait without receiving a BPDU before attempting to reconfigure. Forward Delay: Forward Delay ranges from 4 to 30 seconds. It specifies the time for the port to transit its state
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 80
    the ID of the designated bridge being that of the switch, and the designated port being itself. z Comparing BPDUs Each switch sends out configuration BPDUs and receives a configuration BPDU on one of its ports from another switch. The following table shows the comparing operations. Step Operation
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 81
    is compatible with both STP and RSTP. ¾ MSTP Elements MST Region (Multiple Spanning Tree Region): An MST Region comprises switches with the same region configuration and VLAN-to-Instances mapping relationship. IST (Internal Spanning Tree): An IST is a spanning tree in an MST. CST (Common Spanning
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 82
    spanning tree. The only difference is that the BPDU for MSTP carry the MSTP configuration information on the switches. ¾ Port States In an MSTP, ports can be in the following four states: z Forwarding: In this status the port can receive/forward data, receive/send BPDU packets as well as learn MAC
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 83
    Spanning Tree module is mainly for spanning tree configuration of the switch, including four submenus: STP Config, Port Config, MSTP Instance and STP Security. 7.1 STP Config The STP Config function, for global configuration of spanning trees on the switch, can be implemented on STP Config and STP
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 84
    packets drop occurred in the links, which in turn result in spanning tree being regenerated. A too small hello time parameter may result in duplicated configuration being sent frequently, which increases the network load of the switches and wastes network resources. The default value is recommended
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 85
    hello time may be increased with occupying too much network resources. The default value is recommended. 7.1.2 STP Summary On this page you can view STP Summary 7.2 Port Config On this page you can configure the parameters of the ports for CIST Choose the menu Spanning Tree→Port Config to load the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 86
    : IntPath: Edge Port: P2P Link: MCheck: STP Version: Port Role: Click the Select button to quick-select the corresponding port based on the port number you entered. Select the desired port for STP configuration. It is multi-optional. Displays the port number of the switch. Select Enable /Disable
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 87
    owning this port are configured as point-to-point links. If the physical link of a port is not a point-to-point link and you forcibly configure the link as a point-to-point link, temporary loops may be incurred. 7.3 MSTP Instance MSTP combines VLANs and spanning tree together via VLAN-to-instance
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 88
    Config Instance Configuration, a property of MST region, is used to describe the VLAN to Instance mapping configuration. You can assign VLAN to different the desired Instance ID for configuration. It is multi-optional. Displays Instance ID of the switch. Select Enable/Disable the instance. 81
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 89
    through GVRP, please be sure to map the VLAN to the CIST when configuring the MSTP VLAN-instance mapping table. For detailed introduction of GVRP, please refer to GVRP function page. 7.3.3 Instance Port Config A port can play different roles in different spanning tree instance. On this page you can
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 90
    desired instance ID for its port configuration. Click the Select button to quick-select the corresponding port based on the port number you entered. Select the desired port to specify its priority and path cost. It is multi-optional. Displays the port number of the switch. Enter the priority of the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 91
    always set to blocking state, when the port does not receive BPDU packets from the upstream switch and spanning trees are regenerated, and thereby loops can be prevented. ¾ Root Protect A CIST and its secondary root bridges are usually located in the high-bandwidth core region. Wrong configuration
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 92
    you set in the TC threshold field, the switch will not performs the removing operation in the TC protect cycle. Such a mechanism prevents the switch from frequently removing MAC address entries. ¾ BPDU Protect Ports of the switch directly connected to PCs or servers are configured as edge ports to
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 93
    you entered. Select the desired port for port protect configuration. It is multi-optional. Displays the port number of the switch. Loop Protect is to prevent the loops in the network brought by recalculating STP because of link failures and network congestions. Root Protect is to prevent wrong
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 94
    . The default value is 5. 7.5 Application Example for STP Function ¾ Network Requirements z Switch A, B, C, D and E all support MSTP function. z A is the central switch. z B and C are switches in the convergence layer. D, E and F are switches in the access layer. z There are 6 VLANs labeled as
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 95
    page, enable MSTP function for the port. 3 Configure the region name and On Spanning Tree→MSTP Instance→Region Config the revision of MST region page, configure the region as TP-LINK and keep the default revision setting. 4 Configure VLAN-to-Instance On Spanning Tree→MSTP Instance→Instance
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 96
    page, enable MSTP function for the port. 3 Configure the region name and On Spanning Tree→MSTP Instance→Region Config the revision of MST region page, configure the region as TP-LINK and keep the default revision setting. 4 Configure VLAN-to-Instance On Spanning Tree→MSTP Instance→Instance
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 97
    z For Instance 2 (VLAN 102, 104 and 106), the blue paths in the following figure are connected links; the gray paths are the blocked links. ¾ Suggestion for Configuration z Enable TC Protect function for all the ports of switches. z Enable Root Protect function for all the ports of root bridges. z
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 98
    users requiring this information is not certain, unicast and broadcast deliver a low efficiency. Multicast solves this problem. It can deliver a high efficiency to send data in the point to multi-point service, which can save large bandwidth and reduce the network load. In multicast, the packets are
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 99
    that the destination address should be a group port list, so the switch will duplicate this multicast data and deliver each port one copy. The general format of the multicast address table is described as Figure 8-3 below. VLAN ID Multicast IP Port Figure 8-3 Multicast Address Table 92
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 100
    mainly for multicast management configuration of the switch, including four submenus: IGMP Snooping, Multicast IP, Multicast Filter and the router. When receiving IGMP report message, the switch will send the report message via the router port in the VLAN as well as analyze the message to get the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 101
    groups. The default value is 1 second. The IGMP Snooping function can be implemented on Snooping Config, Port Config, VLAN Config and Multicast VLAN pages. 8.1.1 Snooping Config To configure the IGMP Snooping on the switch, please firstly configure IGMP global configuration and related parameters
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 102
    IGMP Snooping Status Description: Member: Displays IGMP Snooping status. Displays the member of the corresponding status. 8.1.2 Port Config On this page you can configure the IGMP feature for ports of the switch. Choose the menu Multicast→IGMP Snooping→Port Config to load the following page. 95
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 103
    Snooping: Fast Leave: LAG: Click the Select button to quick-select the corresponding port based on the port number you entered. Select the desired port for IGMP Snooping feature configuration. It is multi-optional. Displays the port of the Switch. Select Enable/Disable IGMP Snooping for the desired
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 104
    Select the static router port which is mainly used in the network with stable topology. ¾ VLAN Table VLAN ID Select: Click the Select button to quick-select the corresponding VLAN ID based on the ID number you entered. Select: Select the desired VLAN ID for configuration. It is multi-optional
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 105
    . This mode wastes a lot of bandwidth. The problem above can be solved by configuring a multicast VLAN. By adding switch ports to the multicast VLAN and enabling IGMP Snooping, you can make users in different VLANs share the same multicast VLAN. This saves the bandwidth since multicast streams are
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 106
    unless you first complete the configuration for the corresponding VLAN owning the port on the 802.1Q VLAN page. 3. The link type of the member ports in the multicast VLAN can only be GENERAL. 4. Configure the link type of the router port in the multicast VLAN as TRUNK or configure the egress rule as
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 107
    globally on the switch function and for the port on Multicast→IGMP Snooping→Snooping Config and Port Config page. 2 Create a multicast VLAN Required. Create a multicast VLAN and add all the member ports and router ports to the VLAN on the VLAN→802.1Q VLAN page. z Configure the link type of
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 108
    the description of VLAN3 as Multicast VLAN on VLAN→802.1Q VLAN page. 2 Configure ports On VLAN→802.1Q VLAN function pages. For port 3, configure its link type as GENERAL and its egress rule as TAG, and add it to VLAN3, VLAN4 and VLAN5. For port 4, configure its link type as GENERAL and its egress
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 109
    IP Displays multicast IP address. VLAN ID: Displays the VLAN ID of the multicast group. Forward Port Displays the forward port of the multicast group. Type: Displays the type of the multicast IP. Note: If the configuration on VLAN Config page and multicast VLAN page is changed, the switch
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 110
    Table The following entries are displayed on this screen: ¾ Create Static Multicast Multicast IP: VLAN ID: Forward Port: Enter static multicast IP address. Enter the VLAN ID of the multicast IP. Enter the forward port of the multicast group. ¾ Search Option Search Option: Select the rules for
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 111
    applying for a multicast group, the host will send IGMP report message. After receiving the report message, the switch will firstly check the multicast filter rules configured for the receiving port. If the port can be added to the multicast group, it will be added to the multicast address table; if
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 112
    On this page you can configure the multicast filter rules for port. Take the configuration on this page and the configuration on IP-Range page together to function to implement multicast filter function on the switch. Choose the menu Multicast→Multicast Filter→Port Filter to load the following
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 113
    can only have effect on the VLAN with IGMP Snooping enabled. 2. Multicast Filter feature has no effect on static multicast IP. 3. Up to 5 IP-Ranges can be bound to one port. Configuration Procedure: Step Operation Description 1 Configure IP-Range Required. Configure IP-Range to be filtered on
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 114
    Select: Click the Select button to quick-select the corresponding port based on the port number you entered. Port: Displays the port number of the switch. Query Packet: Displays the number of query packets the port received. Report Packet (V1): Displays the number of IGMPv1 report packets
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 115
    congested, the problem that many packets complete for resources must be solved, usually in the way of queue scheduling. The switch supports four schedule modes: SP, WRR, SP+WRR and Equ. ¾ Priority Mode This switch implements three priority modes based on port, on 802.1P and on DSCP. By default, the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 116
    , you can configure different priority tags mapping to the corresponding priority levels, and then the switch determine which packet is sent preferentially when forwarding packets. The switch processes untagged packets based on the default priority mode. 3. DSCP Priority Figure 9-3 IP datagram As
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 117
    each queue and every queue can be assured of a certain service time. The weight value indicates the occupied proportion of the default weight value ratio of TC0, TC1, TC2 and TC3 is 1:2:4:8. Figure 9-5 WRR-Mode 3. SP+WRR-Mode: Strict-Priority + Weight Round Robin Mode. In this mode, this switch
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 118
    The following entries are displayed on this screen: ¾ Port Priority Config Select: Port: Priority: LAG: Select the desired port to configure its priority. It is multi-optional. Displays the physical port number of the switch. Specify the priority for the port. Displays the LAG number which the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 119
    network is congested, the problem that many packets complete for resources must be solved, usually in the way of queue scheduling. The switch will control the forwarding sequence of the packets according to the priority queues and scheduling algorithms you set. On this switch, the priority levels
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 120
    mode. The untagged packets are mapped based on port priority mode. Choose the menu QoS→DiffServ→802.1P configure DSCP priority. DSCP (DiffServ Code Point) is a new definition to IP ToS field given by IEEE. This field is used to divide IP datagram into 64 priorities. When DSCP Priority is enabled, IP
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 121
    ¾ Priority Level DSCP: Indicates the priority determined by the DS region of IP datagram. It ranges from 0 to 63. Priority: Indicates the 802.1P priorities are labeled as CoS0 ~ CoS7. Configuration Procedure: Step Operation Description 1 Configure the mapping Required. On QoS→DiffServ→DSCP
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 122
    : Select the desired port for Rate configuration. It is multi-optional. Port: Displays the port number of the Switch. Ingress Rate (Kbps): Configure the bandwidth for receiving packets on the port. You can select a rate from the dropdown list or select "Manual" to set Ingress rate, the system
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 123
    Egress Rate(Kbps): LAG: Configure the bandwidth for sending packets on the port. You can select a rate from the dropdown list or select "Manual" to set Ingress/Egress rate, the system will automatically select integral multiple of 64Kbps that closest to the rate you entered as the real Egress rate.
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 124
    . By configuring Voice VLANs and adding the ports with voice devices attached to voice VLANs, you can perform QoS-related configuration for voice data, ensuring the transmission priority of voice data stream and voice quality. ¾ OUI Address (Organizationally unique identifier address) The switch can
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 125
    within the aging time, the switch will remove this port from voice VLAN. Voice ports are automatically added into or removed from voice VLAN. Manual Mode: You need to manually add the port of IP phone to voice VLAN, and then the switch will assign ACL rules and configure the priority of the packets
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 126
    mode and voice stream processing mode ¾ Security Mode of Voice VLAN When voice VLAN is enabled for a port, you can configure its security mode to filter data stream. If security mode is enabled, the port just forwards voice packets, and discards other packets whose source MAC addresses do not match
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 127
    out. Priority: Select the priority of the port when sending voice data. 9.3.2 Port Config Before the voice VLAN function is enabled, the parameters of the ports in the voice VLAN should be configured on this page. Choose the menu QoS→Voice VLAN→Port Config to load the following page. Figure
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 128
    this mode, the switch automatically adds a port to the voice VLAN or removes a port from the voice VLAN by checking whether the port receives voice data or not z Manual: In this mode, you can manually add a port to the voice VLAN or remove a port from the voice VLAN. Configure the security mode for
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 129
    check address whether the switch is supporting the OUI template or not. If not, please add the OUI address. 4 Configure the Required. On QoS→Voice VLAN→Port Config page, configure the parameters of parameters of the ports in voice VLAN. the ports in voice VLAN. 5 Enable Voice Required. On
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 130
    of match conditions, which can be L2-L4 protocol key fields carried in the packets. A time-range based ACL enables you to implement ACL control over packets by differentiating the time-ranges. The ACL module is mainly for ACL configuration of the switch, including four submenus: Time-Range, ACL
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 131
    of the time-range for time identification. Holiday: Select Holiday you set as a time-range. The ACL rule based on this time-range takes effect only when the system time is within the holiday. Absolute: Select Absolute to configure absolute time-range. The ACL rule based on this time-range takes
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 132
    Range→Holiday Config to load the following page. Figure 10-3 Holiday Configuration The following entries are displayed on this screen: ¾ Create Holiday are matched in match order. Once a rule is matched, the switch processes the matched packets taking the operation specified in the rule without considering
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 133
    , The ACL Config function can be implemented on ACL Summary, ACL Create, MAC ACL, Standard-IP ACL and Extend-IP ACL pages. 10.2.1 ACL Summary On this page, you can view the current ACLs configured in the switch. Choose the menu ACL→ACL Config→ACL Summary to load the following page. Figure 10-4 ACL
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 134
    the desired MAC ACL for configuration. Rule ID: Enter the rule ID. Operation: S-MAC: Select the operation for the switch to process packets which match the MAC address mask. If it is set to 1, it must strictly match the address. VLAN ID: Enter the VLAN ID contained in the rule. EtherType:
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 135
    Rule The following entries are displayed on this screen: ¾ Create Standard-IP ACL ACL ID: Select the desired Standard-IP ACL for configuration. Rule ID: Enter the rule ID. Operation: S-IP: Select the operation for the switch to process packets which match the rules. z Permit: Forward packets
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 136
    rule. Mask: Enter IP address mask. If it is set to 1, it must strictly match the address. IP Protocol: TCP Flag: Select IP protocol contained in the rule. Configure TCP flag when TCP is selected from the pull-down list of IP Protocol. S-Port: Configure TCP/IP source port contained in the rule
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 137
    IP-ToS contained in the rule. Enter the IP Precedence contained in the rule. Select the time-range for the rule to take effect. 10.3 Policy Config A Policy is used to control the data packets those match the corresponding ACL rules by configuring Displays the source mirror port of the policy. S-
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 138
    10.3.2 Policy Create On this page you can create the policy. Choose the menu ACL→Policy Config→Policy Create to load the following page. Figure 10-10 Create Policy The following entries are displayed on this screen: ¾ Create Policy Policy Name: Enter the name of the policy. 10.3.3 Action Create
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 139
    Select the ACL for configuration in the policy. Select S-Mirror to mirror the data packets in the policy to the specific port. Select S-Condition to limit on a specific port/VLAN. The policy will take effect only when it is bound to a port/VLAN. In the same way, the port/VLAN will receive the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 140
    policy. Displays the name of the binding policy. Displays the port number or VLAN ID bound to the policy. Displays the binding direction. 10.4.2 Port Binding On this page you can bind a policy to a port. Choose the menu ACL→Policy Binding→Port Binding to load the following page. Figure 10-13 Bind
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 141
    ACL rules. 4 Bind the policy to the Required. On ACL→Policy Binding configuration pages, port/VLAN bind the policy to the port/VLAN to make the policy effective on the corresponding port/VLAN. 10.5 Application Example for ACL ¾ Network Requirements 1. The manager of the R&D department
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 142
    configure the week time from Monday to Friday. Add a time-slice 08:00~18:00. 2 Configure for On ACL→ACL Config→ACL Create page, create ACL 11. requirement 1 On ACL→ACL Config→MAC ACL page, select ACL 11, create Rule 1, configure the operation as Permit, configure and configure the time
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 143
    Binding page, select Policy limit1 to bind to port 3. 4 Configure for On ACL→ACL Config→ACL Create page, create ACL 101. requirement 3 On ACL→ACL Config→Standard-IP ACL page, select ACL 101, and 4 create Rule 1, configure operation as Deny, configure S-IP as 172.31.70.1 and mask as 255.255
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 144
    the Hosts matching the bound entries to access the network. The following three IP-MAC Binding methods are supported by the switch. (1) Manually: You can manually bind the IP address, MAC address, VLAN ID and the Port number together in the condition that you have got the related information of the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 145
    the conflicting entries with the same Source priority, only the last added or edited one will take effect. 11.1.2 Manual Binding You can manually bind the IP address, MAC address, VLAN ID and the Port number together in the condition that you have got the related information of the Hosts in the LAN
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 146
    entries are displayed on this screen: ¾ Manual Binding Option Host Name: Enter the Host Name. IP Address: Enter the IP Address of the Host. MAC Address: Enter the MAC Address of the Host. VLAN ID: Enter the VLAN ID. Port: Select the number of port connected to the Host. Protect Type
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 147
    link layer, is necessary for the packet to reach the very device. So the destination IP switch to send the ARP request packets of the specified IP field to the Hosts in the LAN or VLAN. Upon receiving the ARP reply packet, the switch can get the IP address, MAC address, VLAN and the connected port
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 148
    IP Address: VLAN ID: Scan: Specify the Start IP Address. Specify the End IP Address. Enter the VLAN ID. If blank, the switch will send the untagged packets for scanning. Click the Scan button to scan the Hosts in the LAN. ¾ Scanning Result Select: Host Name: IP Address: MAC Address: VLAN ID: Port
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 149
    on the BOOTP, functions to solve the above mentioned problems. ¾ DHCP Working Principle DHCP works via the "Client/Server" communication mode. The Client applies to the Server for configuration. The Server assigns the configuration information, such as the IP address, to the Client, so as to reach
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 150
    location of the DHCP Client. Upon receiving the DHCP-REQUEST packet, the switch adds the Option 82 to the packet and then transmits the packet to account management of Client. The Server supported Option 82 also can set the distribution policy of IP addresses and the other parameters according to
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 151
    the network, network confusion and security problem will happen. The common cases incurring the illegal DHCP servers are the following two: (1) It's common that the illegal DHCP server is manually configured by the user by mistake. (2) Hacker exhausted the IP addresses of the normal DHCP server and
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 152
    Choose the menu Network Security→IP-MAC Binding→Binding Table to load the following page. Figure 11-8 DHCP Snooping Note: If you want to enable the DHCP Snooping feature for the member port of LAG, please ensure the parameters of all the member ports are the same. The following entries are
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 153
    the switch defined one. • Drop: port based on the port number you entered. Select: Select your desired port for configuration. It is multi-optional. Port: Displays the port number. Trusted Port: Select Enable/Disable the port to be a Trusted Port. Only the Trusted Port
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 154
    this false destination MAC address for packets, which results in a breakdown of the normal communication. ¾ Cheating Gateway The attacker sends the wrong IP address-to-MAC address mapping entries of Hosts to the Gateway, which causes that the Gateway can not communicate with the legal terminal Hosts
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 155
    this false destination MAC address for packets, which results in a breakdown of the normal communication. ¾ Cheating Terminal Hosts The attacker sends the false IP address-to-MAC address mapping entries of terminal Host/Server to another terminal Host, which causes that the two terminal Hosts in the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 156
    Figure 11-11 ARP Attack - Cheating Terminal Hosts As the above figure shown, the attacker sends the fake ARP packets of Host A to Host B, and then Host B will automatically update its ARP table after receiving the ARP packets. When Host B tries to communicate with Host A, it will encapsulate this
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 157
    false entries and unable to learn the ARP entries of legal Hosts, which causes that the legal Hosts can not access the external network. The IP-MAC Binding function allows the switch to bind the IP address, MAC address, VLAN ID 150
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 158
    enables the switch to detect the ARP packets based on the bound entries in the IP-MAC Binding Table Port. The specific ports, such as up-linked port, routing port and LAG port, should be set as Trusted Port. To ensure the normal communication of the switch, please configure the ARP Trusted Port
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 159
    Configuration Procedure: Step Operation Description 1 Bind the IP address, MAC Required. On the IP-MAC Binding page, bind the IP address, VLAN ID and the address, MAC address, VLAN ID and the connected Port connected Port number of number of the Host together via Manual Binding, ARP the Host
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 160
    : Speed: Current Speed: Status: LAG: Operation: based on the port number you entered. Select your desired port for configuration. It is multi-optional. Displays the port number. Select Enable/Disable the ARP Defend feature for the port. Enter a value to specify the maximum amount of the received
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 161
    service requests to the Host, which incurs an abnormal service or even breakdown of the network. With DoS Defend function enabled, the switch can analyze the specific fields of the IP illegal packet with its source port and destination port on Layer 4 the same and its URG field set to 1. Similar to
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 162
    packets. Since the IP address is fake DoS Defend The following entries are displayed on this screen: ¾ Configure DoS Defend: Enable/Disable DoS Defend function. ¾ Defend Table Select the network and block the unnecessary network services. 3. Enhance the network security via the protection devices,
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 163
    -supported network device, such as this TP-LINK switch. It provides the physical or logical port for the supplicant system to access the LAN and authenticates the supplicant system. (3) Authentication Server System: The authentication server system is an entity that provides authentication service
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 164
    PAP (Password Authentication Protocol the controlled port according to the instructions (accept or EAPOL-Start packet to the switch, This TP-LINK switch can authenticate supplicant systems in support the two fields of EAP: the EAP-message field and the Message-authenticator field. This switch supports
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 165
    switch changes the state of the corresponding port to accepted state to allow the supplicant system access the network. And then the switch will monitor the status of supplicant by sending hand-shake packets periodically. By default, the switch switch and the RADIUS server. This switch supports the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 166
    function enabled and Guest VLAN configured, after the maximum number retries have been made to send the EAP-Request/Identity packets and there are still ports that have not sent any response back, the switch will then add these ports into the Guest VLAN according to their link types. Only when the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 167
    transmission of EAP packets is terminated at the switch and the EAP packets are converted to the other protocol (such as RADIUS) packets for transmission. Enable/Disable the Guest VLAN feature. Guest VLAN ID: Enter your desired VLAN ID to enable the Guest VLAN feature. The supplicants in the Guest
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 168
    1X Authentication, then the switch will not respond to port based on the port number you entered. Select: Select your desired port for configuration. It is multi-optional. Port: Displays the port number. Status: Select Enable/Disable the 802.1X authentication feature for the port. Guest VLAN
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 169
    Dial-In User Service) server provides the authentication service for the switch via the stored client information, such as the user name, password, etc, with the purpose to control the authentication and accounting status of the clients. On this page, you can configure the parameters of
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 170
    . Enable/Disable the accounting feature. Enter the IP address of the accounting server. Enter the IP address of the alternate accounting server. Set the UDP port of accounting server(s). The default port is 1813. Set the shared password for the switch and the accounting servers to exchange messages
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 171
    the UDP/IP networks. SNMP provides a management frame to monitor and detect the malfunctions and configure the network devices. restarting the device. MIB: MIB is the set of the managed objects. MIB defines a SNMP Network Elements ¾ SNMP Versions This switch supports SNMP v3, and is compatible with
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 172
    NMS, functioning as a password. SNMP v2c: SNMP v2c The user can configure the authentication and the MIB tree ¾ SNMP Configuration Outline 1. Create View The set to under or out of the management of SNMP Management Station by configuring be the same. You can configure SNMP Group to control the network
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 173
    are used for SNMP Management Station to access the SNMP Agent, functioning as the password. SNMP module is used to configure the SNMP function of the switch, including three submenus: SNMP Config, Notification and RMON. 12.1 SNMP Config The SNMP Config can be implemented on the Global Config
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 174
    even. 12.1.2 SNMP View The OID (Object Identifier) of the SNMP packets is used to describe the managed objects of the switch, and the MIB (Management Information Base) is the set of the OIDs. The SNMP View is created for the SNMP management station to manage MIB objects. Choose the menu SNMP
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 175
    for the SNMP Group. • v1: SNMPv1 is defined for the group. In this model, the Community Name is used for authentication. SNMP v1 can be configured on the SNMP Community page directly. • v2c: SNMPv2c is defined for the group. In this model, the Community Name is used for authentication. SNMP v2c
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 176
    Group should contain a Read View. The default Read View is viewDefault. 12.1.4 SNMP User The User in a SNMP Group can manage the switch via the management station software. The User and its Group have the same security level and access right. You can configure the SNMP User on this page. Choose
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 177
    Level for the SNMP v3 User. Auth Mode: Auth Password: Select the Authentication Mode for the SNMP v3 User. • None: No authentication method is used. • MD5: The port authentication is performed via HMAC-MD5 algorithm. • SHA: The port authentication is performed via SHA (Secure Hash Algorithm). This
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 178
    name can limit access to the SNMP agent from SNMP network management station, functioning as a password. If SNMP v1 or SNMP v2c is employed, you can directly configure the SNMP Community on this page without configuring SNMP Group and User. Choose the menu SNMP→SNMP Config→SNMP Community to load the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 179
    View page, create SNMP View of the management agent. The default View Name is viewDefault and the default OID is 1. Required. On the SNMP→SNMP Config→SNMP User page, create SNMP User in the Group and configure the auth/privacy mode and auth/privacy password for the User. z If SNMPv1 or SNMPv2c is
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 180
    default OID is 1. 3 Create SNMP Required alternatively. Community directly. z Create SNMP Community directly. On the SNMP→SNMP Config→SNMP Community page, create SNMP Community based on SNMP v1 and SNMP v2c. Configure and ask for the reply. The switch will resend the inform request if it
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 181
    IP Address: Enter the IP Address of the management Host. UDP Port: Enter the number of the UDP port used to send notifications. The UDP port functions with the IP address for the notification sending. The default amount of times the switch resends an inform request. The switch will resend the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 182
    station. Displays the IP Address of the management host. Displays the UDP port used to send managed agent. ¾ RMON Group This switch supports the following four RMON Groups defined on Group is set to monitor the statistic of alarm variables on the specific ports. Alarm Group is configured to monitor
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 183
    entries are displayed on this screen: ¾ History Control Table Select: Select the desired entry for configuration. Index: Displays the index number of the entry. Port: Specify the port from which the history samples were taken. Interval: Specify the interval to take samplings from the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 184
    Figure 12-10 Event Config The following entries are displayed on this screen: ¾ Event Table Select: Select the desired entry for configuration. Index: Displays the index number of the entry. User: Enter the name of the User or the community to which the event belongs. Description: Give a
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 185
    on this screen: ¾ Alarm Table Select: Select the desired entry for configuration. Index: Displays the index number of the entry. Variable: Select the alarm variables form the pull-sown list. Port: Select the port on which the Alarm entry acts. Sample Type: Rising Threshold: Specify the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 186
    Interval: Owner: Status: Enter the alarm interval time in seconds. Enter the name of the device or user that defined the entry. Select Enable/Disable the corresponding alarm entry. Note: When alarm variables exceed the Threshold on the same direction continuously for several times, an alarm event
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 187
    be respectively configured to meet the application requirements, manpower are needed. The Cluster Management function can solve the above problem. It the switches in the cluster via a management switch. The management switch is the commander of the cluster and the others are member switches. The
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 188
    , z After being removed from the cluster, the member switch becomes to be the candidate switch. z The commander switch becomes to be the candidate switch only when the cluster is deleted. Note: TL-SG3210 Switch cannot be configured as commander switch to manage the cluster. ¾ Introduction to Cluster
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 189
    of the neighbor switch. Firmware Version: Displays the firmware version of the neighbor switch. Aging Time: Displays the period for the switch s to keep the NDP packets from the neighbor switch. 13.1.2 NDP Summary On this page you can view the NDP configuration of the switch. Choose the menu
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 190
    (enabled or disabled) for the switch. Aging Time: Displays the period for the neighbor switch to keep the NDP packets from this switch. Hello Time: Displays the interval to send NDP packets. ¾ Port Status Port: Displays the port number of the switch. NDP: Displays the NDP status (enabled
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 191
    : Enter the period for the neighbor switch to keep the NDP packets from this switch. Hello Time: Enter the interval to send NDP packets. ¾ Port Config Select: Select the desired port to configure its NDP status. Port: Displays the port number of the switch. NDP: Displays NDP status of the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 192
    problem, two time parameters are designed to control the spread speed of NTDP request packets. z NTDP hop delay: Indicates the time between the switch receiving NTDP request packets and the switch forwarding NTDP request packets for the first time. z NTDP port manually that can configure and manage
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 193
    information of the switch so as to collect the latest network topology. Click the Detail button to view the complete information of this device and its neighbors. Figure 13-6 Information of the Current Device 13.2.2 NTDP Summary On this page you can view the NTDP configuration. Choose the menu
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 194
    NTDP request packets and its adjacent port forwarding NTDP request packets over. ¾ Port Status Port: Displays the port number of the switch. NTDP: Displays NTDP status (enabled or disabled) of the current port. 13.2.3 NTDP Config On this page you can configure NTDP globally. Choose the menu
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 195
    NTDP request packets and its adjacent port forwarding NTDP request packets over. The default is 20 milliseconds. Select the desired port for NTDP status configuration. Displays the port number of the switch. Displays NTDP status (enabled or disabled) of the current port. Click the Enable button to
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 196
    following entries are displayed on this screen: ¾ Global Cluster: Displays the cluster status (enabled or disabled) of the switch. Cluster Role: Displays the role the switch plays in the cluster. z For a member switch, the following page is displayed: Figure 13-10 Cluster Summary for Member
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 197
    to. Choose the menu Cluster→Cluster→Cluster Config to load the following page. z For a candidate switch, the following page is displayed. Figure 13-12 Cluster Configuration for Candidate Switch The following entries are displayed on this screen: ¾ Current Role Role: Displays the role the current
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 198
    to change the role of the switch to be candidate switch. 13.4 Application Example for Cluster Function ¾ Network Requirements Three switches form cluster, one commander switch (Here take TP-LINK TL-SL5428E as an example) and two member switches (Here take TP-LINK TL-SG3210 as an example). The 191
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 199
    to the external network, port 2 is connecting to member switch 1 and port 3 is connecting to member switch 2. z IP pool: 175.128.0.1, Mask: 255.255.255.0. ¾ Network Diagram Figure 13-15 Network diagram ¾ Configuration Procedure z Configure the member switch Step Operation Description 1 Enable
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 200
    4 Configure the member switch On Cluster→Cluster→Member Config page, select the member switch and click the Manage button to log on to its Web management page. Or On Cluster→Cluster→Cluster Topology page, double-click the switch icon to view its detailed information; click the switch icon and
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 201
    and the CPU of switch. (2) Log: View the configuration parameters of the switch and find out the errors via the Logs. (3) Cable Test: Test the connection status of the cable to locate and diagnose the trouble spot of the network. (4) Loopback: Test whether the ports of the switch and its peer device
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 202
    Figure 14-1 CPU Monitor Click the Monitor button to enable the switch to monitor and display its CPU utilization rate every four seconds. 14.1.2 Memory Monitor Choose the menu Maintenance→System Monitor→Memory Monitor to load the following page. 195
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 203
    to monitor and display its Memory utilization rate every four seconds. 14.2 Log The Log system of switch can record, classify and manage the system information effectively, providing powerful support for network administrator to monitor network operation and diagnose malfunction. The Logs of
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 204
    switch supports logs output to two directions, namely, log buffer and log file. The information in log buffer will be lost after the switch is rebooted or powered event occurs. The log can get the correct time after you configure on the System ->System Info->System Time Web management page. Module
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 205
    14.2.2 Local Log Local Log is the log information saved in switch. By default, all system logs are saved in log buffer and the logs with severities from level_0 to level_4 are saved in log file meanwhile. On this page, you can set the output channel for logs. Choose the menu Maintenance→Log→Local
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 206
    switch supports 4 log hosts. Host IP: Configure the IP for the log host. UDP Port: Displays the UDP port used for receiving/sending log information. Here we use the standard port download it on the Internet. 14.2.4 Backup Log Backup Log feature enables the system logs saved in the switch to
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 207
    to the switch, which facilitates you to locate and diagnose the trouble spot of the network. Choose the menu Maintenance→Device Diagnose→Cable Test to load the following page. Figure 14-7 Cable Test The following entries are displayed on this screen: ¾ Cable Test Port: Select the port for cable
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 208
    connected to the port of the switch is available ¾ Loopback Port Loopback Port: Select the desired port for loopback test. Test: Click the Test button to start the loopback test for the port. 14.4 Network Diagnose This switch provides Ping test and Tracert test functions for network diagnose
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 209
    The following entries are displayed on this screen: ¾ Ping Config Destination IP: Enter the IP address of the destination node for Ping test. Ping Times: Enter the amount of times to send test data during Ping testing. The default value is recommended. Data Size: Enter the size of the sending
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 210
    Figure 14-10 Tracert The following entries are displayed on this screen: ¾ Tracert Config Destination IP: Enter the IP address of the destination device. Max Hop: Specify the maximum number of the route hops the test data can pass through. Return to CONTENTS 203
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 211
    Flow Control IEEE802.1p Priority IEEE802.1q VLAN Bridge IEEE802.1X Port-based Access Authentication Ethernet: 10Mbps HD,20Mbps Power, System,1000Mbps, Link/Act Transmission Method Store and Forward Packets Forwarding Rate 10BASE-T:14881pps/port 100BASE-TX:148810pps/port 1000Base-T:1488095pps/port
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 212
    section, we'll introduce how to install and configure the TCP/IP correctly in Windows 2000. First make sure your Ethernet Adapter is working, refer to the adapter's manual if necessary. 1) On the Windows taskbar, prompt page that showed below, double click on the Internet Protocol (TCP/IP). 205
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 213
    Figure B-2 5) The following TCP/IP Properties window will display and the IP Address tab is open on this window by default. 206
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 214
    6) Select Use the following IP address. And the following items will be available. If the switch's IP address is 192.168.0.1, specify IP address as 192.168.0.x (x is from 2 to 254), and the Subnet mask as 255.255.255.0. Now: Click OK to save your settings. Return to CONTENTS 207
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 215
    Figure C-1 1) Connect FTP server to port 1 of the switch. 2) Connect the Console port of the PC to the switch. 3) Save the firmware of the switch in the shared file of FTP server. Please write down the user name, password and the firmware name. 2. Configure the Hyper Terminal After the hardware
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 216
    Figure C-2 Open Hyper Terminal 2) The Connection Description Window will prompt shown as the following figure. Enter a name into the Name field and click OK. Figure C-3 Connection Description 3) Select the port to connect in the figure below and click OK. 209
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 217
    click OK. Figure C-5 Port Settings 3. Download Firmware via bootUtil menu To download firmware to the switch via FTP function, you need to enter into the bootUtil menu of the switch and take the following steps. 1) Connect the console port of the PC to the console port of the switch and open hyper
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 218
    as the figure below. Enter the command and press Enter. [TP-LINK] : ifconfig ip 172.31.70.22 mask 255.255.255.0 gateway 172.31.70.1 4) Configure the parameters of the FTP server which keeps the upgrade firmware. Later you can download the firmware to the switch from the FTP server. The format of the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 219
    [TP-LINK] : start Start User Access Login User : Return to CONTENTS 212
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 220
    .1X protocol standard for 802.1X authentication. When the switch TL-SG3210 works as the authenticator system, please take the following instructions to install the TpSupplicant provided on the attached CD for the supplicant Client. 1. Installation Guide 1) Insert the provided CD into your CD-ROM
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 221
    To continue, choose the destination location for the installation files and click Next on the following screen. Figure D-4 Choose Destination Location By default, the installation files are saved on the Program Files folder of system disk. Click the Change button to modify the destination location
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 222
    Figure D-5 Install the Program 6) The InstallShield Wizard is installing TpSupplicant-V2.0 shown as the following screen. Please wait. Figure D-6 Setup Status 7) On the following screen, click Finish to complete the installation. 215
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 223
    .org to download the latest version of WinPcap for installation. 2. Uninstall Software If you want to remove the TpSupplicant, please take the following steps: 1) On the Windows taskbar, click the Start button, point to All ProgramsÆTP-LINK ÆTpSupplicant-V2.0, and then click Uninstall TP-LINK 802.1X
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 224
    Yes to remove the application from your PC. Figure D-10 Uninstall the Application 4) Click Finish to complete. Figure D-11 Uninstall Complete 3. Configuration 1) After completing installation, double click the icon Software. The following screen will appear. to run the TP-LINK 802.1X Client 217
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 225
    Figure D-12 TP-LINK 802.1X Client Enter the Name and the Password specified in the Authentication Server. The length of Name and Password should be less than 15 characters. 2) Click the Properties button on Figure D-12 to load the following screen for configuring the connection properties. Figure D-
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 226
    period. 3) To continue, click Connect button after entering the Name and Password on Figure D-12. Then the following screen will appear to prompt that the Radius server is being searched. Figure D-14 Authentication Dialog 4) When passing the
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 227
    Q2: Is this TP-LINK 802.1X Client Software compliable with the switches of the other manufacturers? A2: No. This TP-LINK 802.1X Client Software is customized for TP-LINK switches. Q3: Is it safe to set the password being automatically saved? A3: Yes. The password saved in the configuration files is
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 228
    and prevent blockage of lower-level queues. Priority may be set according to the port default, the packet's priority bit (in the VLAN tag), TCP/UDP port number, or DSCP priority bit. Differentiated Services Code Point (DSCP) DSCP uses a six-bit tag to provide for up to 64 different forwarding
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 229
    controls access to the switch ports by requiring users to first enter a user ID and password for authentication. IEEE 802.3ac Defines frame extensions for VLAN tagging. IEEE 802.3x Defines Ethernet frame start/stop requests and timers used for flow control on full-duplex links. (Now incorporated in
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 230
    MAC addresses. Link Aggregation See Port Trunk. Link Aggregation Control Protocol (LACP) Allows ports to automatically negotiate a trunked link with LACP-configured ports on another device. Management Information Base (MIB) An acronym for Management Information Base. It is a set of database objects
  • TP-Link TL-SG3210 | TL-SG3210 V1 User Guide - Page 231
    or backup linked network systems. IP protocol commonly used for software downloads. User Datagram Protocol (UDP) UDP provides a datagram mode for packet-switched communications. It uses IP as the underlying transport mechanism to provide access to IP-like services the network. A VLAN serves as a
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231

TL-SG3210
JetStream L2 Lite Managed Switch
Rev: 1.0.0
1910010508