User Manual
Table Of Contents
- M4300 Intelligent Edge Series Fully Managed Stackable Switches
- Contents
- 1 Get Started
- 2 Configure System Information
- Configure and Display the System and Slot Information
- Configure a Loopback Interface
- Configure Management Interfaces
- Manage the Time Settings
- Manage Precision Time Protocol
- Configure DNS Settings
- Configure the Switch Database Management Template Preference
- Configure Green Ethernet Settings
- Configure and Display Bonjour Settings
- Configure DHCP Server Settings
- Manage a DHCP L2 Relay
- Manage the DHCPv6 Server
- Configure Power over Ethernet
- Configure SNMP
- Configure LLDP
- Configure LLDP Global Settings
- Configure the LLDP Interface
- View LLDP Statistics
- View LLDP Local Device Information
- View LLDP Remote Device Information
- View LLDP Remote Device Inventory
- Configure LLDP-MED Global Settings
- Configure LLDP-MED Interface
- View LLDP-MED Local Device Information
- View LLDP-MED Remote Device Information
- View LLDP-MED Remote Device Inventory
- Configure Link Dependency
- Configure ISDP
- Manage Timer Schedules
- 3 Manage Stacking
- M4300 Series Switch Stacking Overview
- Firmware Synchronization and Upgrade
- Stack Configuration Maintenance
- Stack Master Election
- Stack Factory Defaults Reset Behavior
- Stack NSF
- Configure a Stack
- Run Stack Port Diagnostics
- Configure Stack Firmware Synchronization
- View NSF Summary Data
- View NSF Checkpoint Statistics
- 4 Configure Switching Information
- Configure VLANs
- Configure Basic VLAN Settings
- Reset the VLAN Configuration to Default Setting
- Configure an Internal VLAN
- Configure VLAN Trunking
- Configure VLAN Membership
- View the VLAN Status
- Configure Port PVID Settings
- Configure a MAC-Based VLAN
- Configure Protocol-Based VLAN Groups
- Configure Protocol-Based VLAN Group Membership
- Configure an IP Subnet-Based VLAN
- Configure a Port DVLAN
- Configure a Voice VLAN
- Configure GARP Switch Settings
- Configure a GARP Port
- Configure Auto-VoIP
- Configure iSCSI Settings
- Configure Spanning Tree Protocol
- Manage Multicast
- View the MFDB Table
- View the MFDB Statistics
- Manage IGMP Snooping
- Configure IGMP Snooping Automatically with IGMP Plus Mode
- Configure IGMP Snooping Manually
- Configure IGMP Snooping for Interfaces
- Configure IGMP Snooping for VLANs Automatically with IGMP Plus Mode
- Configure IGMP Snooping for VLANs Manually
- Configure a Multicast Router
- Configure a Multicast Router VLAN
- IGMP Snooping Querier Overview
- Configure IGMP Snooping Querier
- Configure IGMP Snooping Querier for VLANs
- Configure MLD Snooping Automatically with MLD Plus Mode
- Configure MLD Snooping Manually
- Configure an MLD Snooping Interface
- Configure MLD Snooping for VLANs Automatically with MLD Plus Mode
- Configure MLD Snooping for VLANs Manually
- Enable or Disable a Multicast Router on an Interface
- Configure Multicast Router VLAN Settings
- Configure MLD Snooping Querier
- Configure MLD Snooping Querier VLAN Settings
- Configure MVR
- Search and Manage the MAC Address Table
- Manage Port Settings
- Manage Link Aggregation Groups
- Manage the Multiple Registration Protocol Settings
- Manage Loop Protection
- Configure VLANs
- 5 Manage Routing
- Manage Routes
- Configure the Routing IP Settings
- Configure Routing Parameters for the Switch
- Manage IPv6
- Configure IPv6 Global Settings
- View the IPv6 Route Table
- Configure IPv6 Interface Settings
- Configure the IPv6 Prefix Settings
- View IPv6 Statistics
- View the IPv6 Neighbor Table and Clear IPv6 Neighbors
- Configure an IPv6 Static Route
- View the IPv6 Route Table
- Configure IPv6 Route Preferences
- Configure IPv6 Tunnels
- Manage VLANs
- Configure Address Resolution Protocol
- Configure RIP
- Configure Router Discovery
- Configure Virtual Router Redundancy Protocol
- 6 Configure OSPF and OSPFv3
- Configure OSPF
- Configure Basic OSPF Settings
- Configure the OSPF Default Route Advertise Settings
- Configure OSPF Settings
- Configure the OSPF Common Area ID
- Configure the OSPF Stub Area
- Configure the OSPF NSSA Area
- Configure the OSPF Area Range
- Configure the OSPF Interface
- View and Clear OSPF Statistics for an Interface
- View the OSPF Neighbor Table and Clear OSPF Neighbors
- View the OSPF Link State Database
- Configure the OSPF Virtual Link
- Configure the OSPF Route Redistribution
- View the NSF OSPF Summary
- Configure OSPFv3
- Configure Basic OSPFv3 Settings
- Configure OSPFv3 Default Route Advertise Settings
- Configure the Advanced OSPFv3 Settings
- Configure the OSPFv3 Common Area
- Configure an OSPFv3 Stub Area
- Configure the OSPFv3 NSSA Area
- Configure the OSPFv3 Area Range
- Configure the OSPFv3 Interface
- View and Clear OSPFv3 Interface Statistics
- View the OSPFv3 Neighbor Table and Clear OSPFv3 Neighbors
- View the OSPFv3 Link State Database
- Configure the OSPFv3 Virtual Link
- Configure OSPFv3 Route Redistribution
- View the NSF OSPFv3 Summary
- Configure OSPF
- 7 Configure Multicast Routing
- Multicast Overview
- View the Multicast Mroute Table
- Add Mroute Static Multicast Entries
- Configure Global Multicast Settings
- Configure the Multicast Interface
- Configure Global Multicast DVMRP Settings
- Configure the DVMRP Interface
- Search for DVMRP Neighbors
- View the DVMRP Next Hop Settings
- View the Multicast DVMRP Prune
- View the DVMRP Route
- Configure Multicast IGMP Settings
- Configure PIM Settings
- Configure the Multicast PIM Global Settings
- Configure PIM SSM Settings
- Configure PIM Interface
- View the PIM Neighbor
- View the PIM Candidate Rendezvous Point
- View the PIM Neighbor
- Configure the PIM Candidate Rendezvous Point
- Configure the PIM Bootstrap Router Candidate
- Configure the PIM Static Rendezvous Point
- Configure Multicast Static Routes
- Configure the Multicast Admin Boundary
- Configure IPv6 Multicast Settings
- View the IPv6 Multicast Mroute Table
- Configure the IPv6 PIM Global Settings
- Configure IPv6 PIM SSM
- Configure the IPv6 PIM Interface
- View the IPv6 PIM Neighbor
- Configure the IPv6 PIM Candidate Rendezvous Point
- Configure the IPv6 PIM Bootstrap Router Candidate Settings
- Configure the IPv6 PIM Static Rendezvous Point
- Configure IPv6 MLD Global Settings
- Configure the IPv6 MLD Routing Interface
- View IPv6 MLD Routing Interface Statistics
- View the IPv6 MLD Groups
- View and Clear IPv6 MLD Traffic
- Configure the IPv6 MLD Proxy Interface
- View IPv6 MLD Proxy Interface Statistics
- View the IPv6 MLD Proxy Membership
- Configure IPv6 Multicast Static Routes
- Multicast Overview
- 8 Configure Quality of Service
- 9 Manage Switch Security
- Manage User Accounts and Passwords
- Manage the RADIUS Server Settings
- Manage the TACACS Settings
- Configure Authentication Lists
- View Login Sessions
- Manage HHTP, HTTPS, and SSH Access
- Configure Telnet Access
- Configure Console Port Access
- Configure Denial of Service Settings
- Configure Access Control Settings
- Manage Port Authentication
- Control Traffic With MAC Filtering
- Configure Port Security and Private Groups
- Configure Protect Ports
- Set Up Private VLANs
- Manage the Storm Control Settings
- Configure DHCP Snooping
- Configure IP Source Guard Interfaces
- Configure Dynamic ARP Inspection
- Set Up Captive Portals
- Set Up and Manage Access Control Lists
- Use the ACL Wizard to Create a Simple ACL
- Configure an ACL Based on Destination MAC Address
- Use the ACL Wizard to Complete the Destination MAC ACL
- Configure a Basic MAC ACL
- Configure MAC ACL Rules
- Configure MAC Binding
- View and Delete MAC ACL Bindings in the MAC Binding Table
- Configure an IP ACL
- Configure Rules for an IP ACL
- Configure Rules for an Extended IP ACL
- Configure an IPv6 ACL
- Configure IPv6 Rules
- Configure IP ACL Interface Bindings
- View and Delete IP ACL Bindings in the IP ACL Binding Table
- Configure VLAN ACL Bindings
- 10 Monitor the Switch and Network
- 11 Maintenance and Troubleshooting
- A Configuration Examples
- B Default Settings
- C Acronyms and Abbreviations
M4300 Intelligent Edge Series Fully Managed Stackable Switches
Manage Switch Security User Manual624
• Action. Specify what action is taken if a packet matches the rule’s criteria. The choice
is Permit or Deny.
• Logging. When set to Enable, logging is enabled for this
ACL rule (subject to
resource availability in the device). If the access list trap flag is also enabled, this
causes periodic traps to be generated indicating the number of times this rule was hit
during the current report interval. A fixed 5-minute report interval is used for the entire
system. A trap is not issued if the ACL rule hit count is zero for the current interval.
This field is visible for a Deny action.
• Egress Queue.
The hardware egress queue identifier used to handle all packets
matching this IPv6 ACL rule. Valid range of queue IDs is 0 to 7. This field is visible
when Permit is chosen as the action.
• Interface. For a Permit action, use either a mirror interface or a redirect interface:
- Select the Mirror Interface radio button and use the menu to specify the egress
interface to which the matching traf
fic stream is copied, in addition to being
forwarded normally by the device.
- Select the Redirect Interface radio button and use the menu to specify the
egress interface to which the matching traf
fic stream is forced, bypassing any
forwarding decision normally performed by the device.
• Match Every. From the menu, select T
rue or False.
True signifies that all packets must match the selected IPv6 ACL and rule and are
either permitted or denied. In this case, because all packets match the rule, the option
of configuring other match criteria is not available.
To configure specific match criteria
for the rule, remove the rule and recreate it, or select False from the Match Every
menu.
• Protocol Type. Specify the IPv6 protocol
Type in one of the following ways:
- From the Protocol T
ype menu, select IPv6, TCP, UDP, or ICMPv6.
- From the Protocol T
ype menu, select Other, and in the associated field, specify
an integer ranging from 1 to 255. This number represents the IPv6 protocol.
• TCP Flag. For each
TCP flag, specify whether or not a packet’s TCP flag must be
matched. The TCP flag values are URG, ACK, PSH, RST, SYN, and FIN. You can set
each TCP flag separately to one of the following options:
- Ignore.
The packet’s TCP flag is ignored. This is the default setting.
- Set (+).
A packet matches this ACL rule if the TCP flag in this packet is set.
- Clear (-).
A packet matches this ACL rule if the TCP flag in this packet is not set.
Note: If the RST and ACK flags are set, the option Established is available,
indicating that a match occurs if either the RST- or ACK-specified bits
are set in the packet’s header.
• Src. In the Src field, enter a source IPv6 address to be compared to a packet’
s
source IPv6 address as a match criteria for the selected IPv6 ACL rule:
- If you select the IPv6 Address radio button, enter an IPv6 address to apply this
criteria. If this field is left empty
, it means any.