NETGEAR, Inc. Technical Support Thank you for choosing NETGEAR. To register your product, get the latest product updates, or get support online, visit us at http://support.netgear.com.
Table of Contents Chapter 1 Getting Started Getting Started with the FS728TP Smart Switch....10 Switch Management Interface ........11 Connecting the Switch to the Network.
Page 4
FS728TP Smart Switch Software Administration Manual LLDP-MED Port Settings ........62 Local Information .
Page 5
FS728TP Smart Switch Software Administration Manual 802.1p to Queue Mapping ........126 DSCP to Queue Mapping .
Page 6
FS728TP Smart Switch Software Administration Manual Chapter 6 Monitoring the System Ports ........... . .190 Switch Statistics .
Page 7
FS728TP Smart Switch Software Administration Manual Appendix B Configuration Examples Virtual Local Area Networks (VLANs)......238 VLAN Example Configuration.
Getting Started ® The NETGEAR FS728TP Smart Switch Software Administration Manual describes how to configure and operate the FS728TP Smart Switch by using the Web-based graphical user interface (GUI). This manual describes the software configuration procedures and explains the options available within those procedures.
FS728TP Smart Switch Software Administration Manual Getting Started with the FS728TP Smart Switch This chapter provides an overview of starting your NETGEAR FS728TP Smart Switch and accessing the user interface. It also leads you through the steps to use the Smart Control Center utility.
In addition to enabling NETGEAR switch discovery, the Smart Control Center provides several utilities to help you maintain the NETGEAR switches on your network, such as password management, firmware upgrade, and configuration file backup. For more information, see on page 19.
FS728TP Smart Switch Software Administration Manual Connecting the Switch to the Network To enable remote management of the switch through a Web browser or SNMP, you must connect the switch to the network and configure it with network information (an IP address, subnet mask, and default gateway).
FS728TP Smart Switch Software Administration Manual Switch Discovery in a Network with a DHCP Server This section describes how to set up your switch in a network that has a DHCP server. The DHCP client on the switch is enabled by default. When you connect it to your network, the DHCP server will automatically assign an IP address to your switch.
Page 14
FS728TP Smart Switch Software Administration Manual Make a note of the displayed IP address assigned by the DHCP server. You will need this value to access the switch directly from a Web browser (without using the Smart Control Center). Select your switch by clicking the line that displays the switch, then click the Web Browser Access button.
FS728TP Smart Switch Software Administration Manual Switch Discovery in a Network without a DHCP Server This section describes how to use the Smart Control Center to set up your switch in a network without a DHCP server. If your network has no DHCP service, you must assign a static IP address to your switch.
FS728TP Smart Switch Software Administration Manual You must enter the current password every time you use the Smart Tip: Control Center to update the switch setting. The default password is password. Click Apply to configure the switch with the network settings. Please ensure that your PC and the switch are in the same subnet.
Page 17
FS728TP Smart Switch Software Administration Manual WARNING! When you change the IP address of your administrative system, you will loose your connection to the rest of the network. Be sure to write down your current network address settings before you change them.
FS728TP Smart Switch Software Administration Manual Web Access To access the FS728TP management interface, use one of the following methods: From the Smart Control Center, select the switch and click Web Browser Access. • Open a Web browser and enter the IP address of the switch in the address field. •...
FS728TP Smart Switch Software Administration Manual Smart Control Center Utilities In addition to device discovery and network address assignment, the Smart Control Center includes several maintenance features. This section describes the following Smart Control Center utilities: on page 19 • Network Utilities on page 20 •...
FS728TP Smart Switch Software Administration Manual Changing the Switch Password Select the switch. Click Change Password. Additional fields appear on the screen. Type the switch password in the Current Password field. The default password for the switch is password. Type the new password in the New Password and Confirm Password fields. The password can contain up to 20 ASCII characters.
Page 21
FS728TP Smart Switch Software Administration Manual Click OK. Enter the switch password and click Apply. The file is uploaded to the administrative computer as a *.cfg file. You can open it and view the contents with a text editor. To restore the configuration to a previously saved version: Click the Maintenance tab and select the device with the configuration to restore.
Secondary Storage option. To prevent the switch from using the downloaded firmware as the active image, make sure the Run this FW after download option is clear. NETGEAR recommends that you download the same image as the Note: primary and secondary image for redundancy.
Page 23
FS728TP Smart Switch Software Administration Manual Click Open. You can choose to schedule a later time to complete the download and installation by clearing the Run Now? option and selecting a date and time to perform the firmware download and installation. The scheduled firmware download appears in the Tasks list. Enter the switch password to continue downloading the firmware.
FS728TP Smart Switch Software Administration Manual Viewing and Managing Tasks From the Tasks tab, you can view information about configuration downloads and firmware upgrades that have already occurred, are in progress, or are scheduled to take place at a later time. You can also delete or reschedule selected tasks. The following figure shows the Tasks page.
FS728TP Smart Switch Software Administration Manual Understanding the User Interfaces The FS728TP Smart Switch software includes a set of comprehensive management functions for configuring and monitoring the system by using one of the following methods: Web user interface • Simple Network Management Protocol (SNMP) •...
Page 26
FS728TP Smart Switch Software Administration Manual Navigation Tab Feature Link Help LInk Logout Button Help Page Page Menu Configuration Status and Options Figure 3. Administrative Page Layout Navigation Tabs, Feature Links, and Page Menu The navigation tabs along the top of the Web interface give you quick access to the various switch functions.
FS728TP Smart Switch Software Administration Manual Page Link Configuration Pages Figure 4. Menu Hierarchy Configuration and Status Options The area directly under the feature links and to the right of the page menu displays the configuration information or status for the page you select. On pages that contain configuration options, you can input information into fields or select options from drop-down menus.
Page 28
FS728TP Smart Switch Software Administration Manual The following image shows the Device View of the FS728TP. Click the port you want to view or configure to see a menu that displays statistics and configuration options. Click the menu option to access the page that contains the configuration or monitoring options.
FS728TP Smart Switch Software Administration Manual Help Page Access Every page contains a link to the online help , which contains information to assist in configuring and managing the switch. The online help pages are context sensitive. For example, if the IP Addressing page is open, the help topic for that page displays if you click Help.
FS728TP Smart Switch Software Administration Manual Interface Naming Convention The FS728TP Smart Switch supports physical and logical interfaces. Interfaces are identified by their type and the interface number. Physical ports 1–24 are Fast Ethernet interfaces, and physical ports 25–28 are gigabit interfaces. The number of the port is identified on the front panel.
Configuring System Information Use the features in the System tab to define the switch’s relationship to its environment. The System tab contains links to the following features: on page 32 • Management on page 47 • on page 53 • SNMP on page 58 •...
FS728TP Smart Switch Software Administration Manual Management This section describes how to display the switch status and specify some basic switch information, such as the management interface IP address, system clock settings, and DNS information. From the Management link, you can access the following pages: on page 32 •...
FS728TP Smart Switch Software Administration Manual To define system information: Open the System Information page. Define the following fields: System Name. Enter the name you want to use to identify this switch. You may use • up to 31 alphanumeric characters. The factory default is blank. System Location.
Page 34
FS728TP Smart Switch Software Administration Manual To configure the network information for the management interface: Select the appropriate radio button to determine how to configure the network information for the switch management interface: Dynamic IP Address (DHCP). Specifies that the switch must obtain the IP address •...
FS728TP Smart Switch Software Administration Manual port VLAN ID (PVID) of the port to be connected in that management VLAN be the same as the management VLAN ID. The management VLAN has the following requirements: Only one management VLAN can be active at a time. •...
FS728TP Smart Switch Software Administration Manual SNTP time definitions are assessed and determined by the following time levels: T1: Time at which the original request was sent by the client. • T2: Time at which the original request was received by the server. •...
Page 37
FS728TP Smart Switch Software Administration Manual To configure the time by using the CPU clock cycle as the source: From the Clock Source field, select Local. In the Date field, enter the date in the DD/MM/YYYY format. In the Time field, enter the time in HH:MM:SS format. If you do not enter a date and time, the switch will calculate the date Note: and time using the CPU’s clock cycle.
FS728TP Smart Switch Software Administration Manual Field Description Last Attempt Time Specifies the local date and time (UTC) of the last SNTP request or receipt of an unsolicited message. Last Attempt Status Specifies the status of the last SNTP request or unsolicited message for both unicast mode.
Page 39
FS728TP Smart Switch Software Administration Manual To configure a new SNTP Server: Enter the appropriate SNTP server information in the available fields: Server Type. Specifies whether the address for the SNTP server is an IP address • (IPv4) or hostname (DNS). Address.
FS728TP Smart Switch Software Administration Manual Field Description Address Specifies all the existing Server Addresses. If no Server configuration exists, a message saying “No SNTP server exists” flashes on the screen. Last Update Time Specifies the local date and time (UTC) that the response from this server was used to update the system clock.
Page 41
FS728TP Smart Switch Software Administration Manual Auto-DoS Configuration The Auto-DoS Configuration page lets you automatically enable all the DoS features available on the switch, except for the L4 Port attack. See the previous section for information about the types of DoS attacks the switch can monitor and block. To access the Auto-DoS Configuration page, click System ...
Page 42
FS728TP Smart Switch Software Administration Manual To configure individual DoS settings: Select the types of DoS attacks for the switch to monitor and block and configure any associated values, as the following list describes. Denial of Service SIP=DIP. Enable or disable this option by selecting the appropriate •...
FS728TP Smart Switch Software Administration Manual Denial of Service L4 Port. Enable or disable this option by selecting the appropriate • radio button. Enabling L4 Port DoS prevention causes the switch to drop packets that have TCP/UDP source port equal to TCP/UDP destination port. The factory default is Disable.
Enter the DNS default domain name to include in DNS queries. When the system is performing a lookup on an unqualified hostname, this field is provided as the domain name (for example, if default domain name is netgear.com and the user enters test, then test is changed to test.netgear.com to resolve the name).
Page 45
FS728TP Smart Switch Software Administration Manual To add a static entry to the local DNS table: Specify the static host name to add. Enter up to 158 characters. Specify the IP address in standard IPv4 dot notation to associate with the hostname. Click Add.
FS728TP Smart Switch Software Administration Manual Green Ethernet Configuration Use this page to configure Green Ethernet features. Using the Green Ethernet features allows for power consumption savings. To access this page, click System Management Green Ethernet Configuration. To configure the Green Ethernet feature: Enable or disable the Auto Power Down Mode.
FS728TP Smart Switch Software Administration Manual The switch ports on the FS728TP are IEEE802.3af-compliant ports. Each port is capable of delivering up to 15.4W of reliable, uninterrupted power to connected PoE-powered devices (PD). The FS728TP can provide a total of 192W of power to all connected devices. You can configure per-port priority settings, timers, and power limits to manage the power supplied to the connected PDs and to ensure that the FS728TP power budget is used effectively.
FS728TP Smart Switch Software Administration Manual To configure PoE trap settings: Select the appropriate radio button to enable or disable SNMP traps. Click Apply to apply the new settings to the system. Click Cancel to cancel the configuration on the screen and reset the data on the screen to the latest value of the switch.
Page 49
FS728TP Smart Switch Software Administration Manual Configure or view the settings: Admin Mode. Enable or disable the ability of the port to deliver power. • Priority Level. Determine which ports can deliver power if the total power delivered • by the switch crosses a certain threshold. The switch may not be able to supply power to all connected devices.
FS728TP Smart Switch Software Administration Manual Status. View the operational status of the port PD detection. • Disabled. Indicates no power is being delivered. • Delivering Power. Indicates power is being drawn by a connected device. • Fault. Indicates a problem with the port. •...
FS728TP Smart Switch Software Administration Manual To configure global timer settings: Specify the Timer Schedule administrative mode. If the mode is disabled, no timers are used. To add a timer, enter a name in the Timer Schedule Name field, and click Add. To remove a timer, select the check box associated with the timer and click Delete.
Page 52
FS728TP Smart Switch Software Administration Manual For a timer schedule to operate, the switch clock source must be Note: SNTP. Use the System > Time page to configure the clock source. For more information, see on page 36. Time Configuration To configure timer schedules: Select the name of the schedule created on the Timer Global Configuration page.
FS728TP Smart Switch Software Administration Manual SNMP From SNMP link under the System tab, you can configure SNMP settings for SNMP V1/V2 and SNMPv3. From the SNMP link, you can access the following pages: on page 53 • SNMPV1/V2 on page 55 •...
FS728TP Smart Switch Software Administration Manual To configure SNMP communities: To add a new SNMP community, enter community information in the available fields described below, and then click Add. Management Station IP. Specify the IP address of the management • station.Together, the Management Station IP and the Management Station IP Mask denote a range of IP addresses from which SNMP clients may use that community to access this device.
FS728TP Smart Switch Software Administration Manual To configure SNMP trap settings: To add a host that will receive SNMP traps, enter trap configuration information in the available fields described below, and then click Add. Recipients IP. The address in x.x.x.x format to receive SNMP traps from this device. •...
Page 56
FS728TP Smart Switch Software Administration Manual To access the Trap Flags page, click System SNMP SNMP V1/V2 Trap Flags. To configure the trap flags: From the Authentication field, enable or disable activation of authentication failure traps by selecting the corresponding button. The factory default is Enable. From the Link Up/Down field, enable or disable activation of link status traps by selecting the corresponding button.
FS728TP Smart Switch Software Administration Manual SNMP v3 User Configuration This is the configuration for SNMP v3. To access this page, click System SNMP SNMP V3 User Configuration. The SNMPv3 Access Mode is a read-only field that shows the access privileges for the user account.
FS728TP Smart Switch Software Administration Manual LLDP The IEEE 802.1AB-defined standard, Link Layer Discovery Protocol (LLDP), allows stations on an 802 LAN to advertise major capabilities and physical descriptions. This information is viewed by a network manager to identify system topology and detect bad configurations on the LAN.
FS728TP Smart Switch Software Administration Manual To configure global LLDP settings: Configure the following LLDP properties. TLV Advertised Interval. Specify the interval at which frames are transmitted. The • default is 30 seconds, and the valid range is 1–32768 seconds. Hold Multiplier.
Page 60
FS728TP Smart Switch Software Administration Manual To configure LLDP port settings: Change the LLDP port settings described below: Interface. Specifies the port to be affected by these parameters. • Admin Status. Select the status for transmitting and receiving LLDP packets: •...
FS728TP Smart Switch Software Administration Manual LLDP-MED Network Policy This page displays information about the LLPD-MED network policy TLV transmitted in the LLDP frames on the selected local interface. To display this page, click System LLDP Advanced LLDP-MED Network Policy. From the Interface menu, select the interface with the information to view.
FS728TP Smart Switch Software Administration Manual Field Description User Priority Specifies the priority associated with the policy. DSCP Specifies the DSCP associated with a particular policy type. Click Refresh to refresh the page with the most current data from the switch. LLDP-MED Port Settings Use this page to enable LLDP-MED mode on an interface and configure its properties.
FS728TP Smart Switch Software Administration Manual Click Apply to send the updated configuration to the switch. These changes occur immediately and the configuration will be saved. Click Cancel to cancel the configuration on the screen and reset the data on the screen to the latest value of the switch.
Page 64
FS728TP Smart Switch Software Administration Manual A popup window displays information for the selected port. The following table describes the detailed local information that displays for the selected port. Field Description Managed Address Address SubType Displays the type of address the management interface uses, such as an IPv4 address.
FS728TP Smart Switch Software Administration Manual Field Description MED Details Capabilities Supported Displays the MED capabilities enabled on the port. Current Capabilities Displays the TLVs advertised by the port. Device Class Network Connectivity indicates the device is a network connectivity device. Network Policies Application Type Specifies the media application type associated with the policy.
Page 66
FS728TP Smart Switch Software Administration Manual The following table describes the information that displays for all LLDP neighbors that have been discovered. Field Description MSAP Entry Displays the Media Service Access Point (MSAP) entry number for the remote device. Local Port Displays the interface on the local system that received LLDP information from a remote system.
Page 67
FS728TP Smart Switch Software Administration Manual Field Description Port Details Local Port Displays the interface on the local system that received LLDP information from a remote system. MSAP Entry Displays the Media Service Access Point (MSAP) entry number for the remote device.
Page 68
FS728TP Smart Switch Software Administration Manual Field Description MED Details Capabilities Supported Specifies the supported capabilities that were received in MED TLV from the device. Current Capabilities Specifies the advertised capabilities that were received in MED TLV from the device. Device Class Displays the LLDP-MED endpoint device class.
Page 69
FS728TP Smart Switch Software Administration Manual Field Description Network Policies Application Type Specifies the media application type associated with the policy advertised by the remote device. VLAN ID Specifies the VLAN ID associated with the policy. VLAN Type Specifies whether the VLAN associated with the policy is tagged or untagged. User Priority Specifies the priority associated with the policy.
FS728TP Smart Switch Software Administration Manual Services — DHCP Filtering DHCP Filtering is a useful feature that can be employed as a security measure against unauthorized DHCP servers. A known attack is when an unauthorized DHCP server responds to a client that is requesting an IP address. The server configures the gateway for the client to be equal to the IP address of the server.
FS728TP Smart Switch Software Administration Manual Interface Configuration Use the DHCP Filtering Interface Configuration page to view and configure each port as a trusted or untrusted port. Any DHCP responses received on a trusted port are forwarded. If a port is configured as untrusted, any DHCP (or BootP) responses received on that port are discarded.
Configuring Switching Information Use the features in the Switching tab to define Layer 2 features. The Switching tab contains links to the following features: on page 74 • Ports on page 77 • Link Aggregation Groups on page 82 • VLANs on page 87 •...
FS728TP Smart Switch Software Administration Manual Ports The pages on the Ports tab allow you to view and monitor the physical port information for the ports available on the switch. From the Ports link, you can access the following pages: on page 74 •...
FS728TP Smart Switch Software Administration Manual Enable: The port can participate in the network (default). • Disable: The port is administratively down and does not participate in the network. • Port Speed. Use the menu to select the port’s speed and duplex mode. If you select •...
Page 76
FS728TP Smart Switch Software Administration Manual To configure global flow control settings: From the Global Flow Control (IEEE 802.3x) Mode field, enable or disable IEEE 802.3x flow control on the system. The factory default is Disable. Enable. The switch sends pause packets if the port buffers become full. •...
FS728TP Smart Switch Software Administration Manual Link Aggregation Groups Link aggregation groups (LAGs), which are also known as port-channels, allow you to combine multiple full-duplex Ethernet links into a single logical link. Network devices treat the aggregation as if it were a single link, which increases fault tolerance and provides load sharing.
FS728TP Smart Switch Software Administration Manual To configure LAG settings: Select the check box next to the LAG to configure. You can select multiple LAGs to apply the same setting to the selected interfaces. Select the check box in the heading row to apply the same settings to all interfaces.
Page 79
FS728TP Smart Switch Software Administration Manual To configure LAG members: From the LAG ID field, select the LAG to which to assign ports. Optionally, in the LAG Name field, enter the name you want assigned to the LAG. You may enter any string of up to 15 alphanumeric characters.
FS728TP Smart Switch Software Administration Manual LACP Configuration To display the LACP Configuration page, click Switching LAG Advanced LACP Configuration. To configure LACP: From the LACP System Priority field, specify the device’s link aggregation priority relative to the devices at the other ends of the links on which link aggregation is enabled.
FS728TP Smart Switch Software Administration Manual LACP Port Configuration To display the LACP Port Configuration page, click Switching LAG Advanced LACP Port Configuration. To configure LACP port priority settings: Select the check box next to the port to configure. You can select multiple ports to apply the same setting to all selected ports.
FS728TP Smart Switch Software Administration Manual VLANs Adding Virtual LAN (VLAN) support to a Layer 2 switch offers some of the benefits of both bridging and routing. Like a bridge, a VLAN switch forwards traffic based on the Layer 2 header, which is fast, and like a router, it partitions the network into logical segments, which provides better administration, security and management of multicast traffic.
FS728TP Smart Switch Software Administration Manual To configure VLANs: To add a VLAN, configure the VLAN ID, name, and type, and then click Add. VLAN ID. Specify the VLAN Identifier for the new VLAN. (You can enter data in this •...
FS728TP Smart Switch Software Administration Manual To configure VLAN membership: From the VLAN ID field, select the VLAN to which you want to add ports. Click the orange bar below the VLAN Type field to display the physical ports on the switch. Click the lower orange bar to display the LAGs on the switch.
Page 85
FS728TP Smart Switch Software Administration Manual If you want to change the port’s default PVID, you must first create a VLAN that includes • the port as a member. Use the Port VLAN ID (PVID) Configuration page to configure a virtual LAN on a port. •...
Page 86
FS728TP Smart Switch Software Administration Manual Specify the default 802.1p priority assigned to untagged packets arriving at the port. Possible values are 0–7. Click Cancel to cancel the configuration on the screen and reset the data on the screen to the latest value of the switch.
FS728TP Smart Switch Software Administration Manual Voice VLAN Configure the Voice VLAN settings for ports that carry traffic from IP phones. The Voice VLAN feature can help ensure that the sound quality of an IP phone is safeguarded from deteriorating when the data traffic on the port is high. From the VLAN link, you can access the following pages: on page 87 •...
FS728TP Smart Switch Software Administration Manual Click Cancel to cancel the configuration on the screen and reset the data on the screen to the latest value of the switch. If you make any changes to this page, click Apply to send the updated configuration to the switch.
FS728TP Smart Switch Software Administration Manual Voice VLAN OUI The Organizational Unique Identifier (OUI) identifies the IP phone manufacturer. The switch comes preconfigured with the following OUIs: 00:01:E3: SIEMENS • 00:03:6B: CISCO1 • 00:12:43: CISCO2 • 00:0F:E2: H3C • 00:60:B9: NITSUKO •...
Page 90
FS728TP Smart Switch Software Administration Manual To configure OUI settings: To add a new OUI prefix, type the VOIP OUI prefix in the Telephony OUI(s) field, provide a description of the prefix, and click Add. The OUI prefix must be in the format AA:BB:CC.
FS728TP Smart Switch Software Administration Manual Spanning Tree Protocol The Spanning Tree Protocol (STP) provides a tree topology for any arrangement of bridges. STP also provides one path between end stations on a network, eliminating loops. Spanning tree versions supported include Common STP, Multiple STP, and Rapid STP. Classic STP provides a single path between end stations, avoiding and eliminating loops.
Page 92
FS728TP Smart Switch Software Administration Manual To configure STP settings on the switch: From the Spanning Tree State field, specify whether to enable or disable Spanning Tree operation on the switch. From the STP Operation Mode field, Specifies the Force Protocol Version parameter for the switch.
FS728TP Smart Switch Software Administration Manual The following table describes the STP Status information displayed on the screen. Field Description Bridge Identifier The bridge identifier for the CST. It is made up using the bridge priority and the base MAC address of the bridge. Time Since Topology Change The time in seconds since the topology of the CST last changed.
Page 94
FS728TP Smart Switch Software Administration Manual To configure CST settings: Specify values for CST in the appropriate fields: Bridge Priority. When switches or bridges are running STP, each is assigned a • priority. After exchanging BPDUs, the switch with the lowest priority value becomes the root bridge.
FS728TP Smart Switch Software Administration Manual Click Cancel to cancel the configuration on the screen and reset the data on the screen to the latest value of the switch If you make any configuration changes, click Apply to send the updated configuration to the switch.
FS728TP Smart Switch Software Administration Manual To configure CST settings for both physical ports and LAGs, click ALL. Select the check box next to the port or LAG to configure. You can select multiple ports and LAGs to apply the same setting to the selected interfaces. Select the check box in the heading row to apply the same settings to all interfaces.
Page 97
FS728TP Smart Switch Software Administration Manual The following table describes the CST Status information displayed on the screen. Field Description Interface Select a physical or port channel interface to configure. The port is associated with the VLAN(s) associated with the CST. Port Role Each MST Bridge Port that is enabled is assigned a Port Role for each spanning tree.
FS728TP Smart Switch Software Administration Manual Rapid STP Use the Rapid STP page to view information about Rapid Spanning Tree (RSTP) port status. To display the Rapid STP page, click Switching > STP > Advanced RSTP. The following table describes the Rapid STP Status information displayed on the screen. Field Description Interface...
Page 99
FS728TP Smart Switch Software Administration Manual To configure an MST instance: To add an MST instance, configure the MST values and click Add: MST ID. Specify the ID of the MST to create. Valid values for this are between 1 and •...
FS728TP Smart Switch Software Administration Manual For each configured instance, the information described in the following table displays on the page. Field Description Bridge Identifier The bridge identifier for the selected MST instance. It is made up using the bridge priority and the base MAC address of the bridge.
Page 101
FS728TP Smart Switch Software Administration Manual To configure MST port settings: To configure MST settings for a physical port, click PORTS. To configure MST settings for a Link Aggregation Group (LAG), click LAGS. To configure MST settings for both physical ports and LAGs, click ALL. Select the check box next to the port or LAG to configure.
FS728TP Smart Switch Software Administration Manual Field Description Port Forwarding State Indicates the current STP state of a port. If enabled, the port state determines what forwarding action is taken on traffic. Possible port states are: Disabled: STP is currently disabled on the port. The port forwards traffic •...
Page 103
FS728TP Smart Switch Software Administration Manual The following table describes the information available on the STP Statistics page. Field Description Interface Select a physical or port channel interface to view its statistics. STP BPDUs Received Number of STP BPDUs received at the selected port. STP BPDUs Transmitted Number of STP BPDUs transmitted from the selected port.
FS728TP Smart Switch Software Administration Manual Multicast Multicast IP traffic is traffic that is destined to a host group. Host groups are identified by class D IP addresses, which range from 224.0.0.0 to 239.255.255.255. From the Multicast link, you can access the following pages: on page 104 •...
Page 105
FS728TP Smart Switch Software Administration Manual To configure IGMP Snooping: Enable or disable IGMP Snooping on the switch. Enable. The switch snoops all IGMP packets it receives to determine which • segments should receive packets directed to the group address. Disable.
FS728TP Smart Switch Software Administration Manual The following table displays information about the global IGMP snooping status and statistics on the page. Field Description Multicast Control Frame Displays the number of multicast control frames that have been processed Count by the CPU. Interfaces Enabled for IGMP Lists the interfaces currently enabled for IGMP Snooping.
FS728TP Smart Switch Software Administration Manual To configure IGMP Snooping settings for both physical ports and LAGs, click ALL. Select the check box next to the port or LAG to configure. You can select multiple ports and LAGs to apply the same setting to the selected interfaces. Select the check box in the heading row to apply the same settings to all interfaces.
Page 108
FS728TP Smart Switch Software Administration Manual The following table describes the fields in the IGMP Snooping Table. Field Description MAC Address A multicast MAC address for which the switch has forwarding and/or filtering information. The format is 6 two-digit hexadecimal numbers that are separated by colons, for example, 01:00:5e:45:67:89.
Page 109
FS728TP Smart Switch Software Administration Manual When a packet enters the switch, the destination MAC address is combined with the VLAN ID and a search is performed in the Layer 2 Multicast Forwarding Database. If no match is found, then the packet is either flooded to all ports in the VLAN or discarded, depending on the switch configuration.
FS728TP Smart Switch Software Administration Manual Field Description Interface The list of interfaces that are designated for forwarding (Fwd) and filtering (Flt) for the selected address. Forwarding Interfaces The resultant forwarding list is derived from combining all the forwarding interfaces and removing the interfaces that are listed as the static filtering interfaces.
FS728TP Smart Switch Software Administration Manual Enter a value between 0 and 3600 seconds. The default is 0 seconds, which means there is no expiration. Query Mode. Enable or disable the IGMP Querier Mode for the specified VLAN ID. • Query Interval.
FS728TP Smart Switch Software Administration Manual To configure IGMP Snooping Querier settings: From the Querier Admin Mode field, enable or disable the administrative mode for IGMP Snooping Querier. In the Snooping Querier Address field, specify the IP address to be used as source address in periodic IGMP queries.
FS728TP Smart Switch Software Administration Manual To configure Querier VLAN settings: To create a new VLAN ID for IGMP Snooping, select New Entry from the VLAN ID field and complete the following fields: VLAN ID. Specifies the VLAN ID for which the IGMP Snooping Querier is to be •...
Page 115
FS728TP Smart Switch Software Administration Manual The following table describes the information available on the Querier VLAN Status page. Field Description VLAN ID Specifies the VLAN ID on which the IGMP Snooping Querier is administratively enabled and for which VLAN exists in the VLAN database. Operational State Specifies the operational state of the IGMP Snooping Querier on a VLAN: Querier: The snooping switch is the querier in the VLAN.
FS728TP Smart Switch Software Administration Manual Forwarding Database The forwarding database maintains a list of MAC addresses after having received a packet from this MAC address. The transparent bridging function uses the forwarding database entries to determine how to forward a received frame. The Address Table folder contains links to the following features: on page 116 •...
FS728TP Smart Switch Software Administration Manual Interface: Select Interface from the menu, enter the interface ID in e1, e2... format, • then, click Go. If any entries learned on that interface exist, they are displayed. Click Clear to clear Dynamic MAC Addresses in the table. Click Refresh to redisplay the page to show the latest MAC Addresses.
FS728TP Smart Switch Software Administration Manual To configure the Dynamic Address setting: Specify the number of seconds the forwarding database should wait before deleting a learned entry that has not been updated. IEEE 802.1D-1990 recommends a default of 300 seconds. You may enter any number of seconds between 10 and 1000000. The factory default is 300.
Page 119
FS728TP Smart Switch Software Administration Manual To configure a static MAC address: To add a static MAC address entry a. Select the VLAN ID corresponding to the MAC address to add. b. Specify the MAC address to add. c. Specify the interface associated with the MAC address. d.
Configuring Quality of Service Use the features in the QoS tab to configure Quality of Service (QoS) settings on the switch. The QoS tab contains links to the following features: on page 122 • Class of Service on page 129 •...
FS728TP Smart Switch Software Administration Manual Class of Service The Class of Service (CoS) queueing feature lets you directly configure certain aspects of switch queueing. This provides the desired QoS behavior for different types of network traffic when the complexities of DiffServ are not required. The priority of a packet arriving at an interface can be used to steer the packet to the appropriate outbound CoS queue through a mapping table.
FS728TP Smart Switch Software Administration Manual To configure global CoS settings: Select the Global radio button to configure the trust mode settings that apply to all interfaces. Alternatively, you can select the Interface radio button to apply trust mode settings to individual interfaces.
Page 124
FS728TP Smart Switch Software Administration Manual To configure CoS settings for an interface: To configure CoS settings for a physical port, click PORTS. To configure CoS settings for a Link Aggregation Group (LAG), click LAGS. To configure CoS settings for both physical ports and LAGs, click ALL. Select the check box next to the port or LAG to configure.
FS728TP Smart Switch Software Administration Manual Interface Queue Configuration Use the Interface Queue Configuration page to define what a particular queue does by configuring switch egress queues. User-configurable parameters control the amount of bandwidth used by the queue, the queue depth during times of congestion, and the scheduling of packet transmission from the set of all queues on a port.
FS728TP Smart Switch Software Administration Manual Scheduler Type. Selects the type of queue processing from the drop down menu. • Options are Weighted and Strict. Defining on a per-queue basis allows the user to create the desired service characteristics for different types of traffic. Weighted: Weighted round robin associates a weight to each queue.
FS728TP Smart Switch Software Administration Manual Select the queue to map to the predefined 802.1p priority values. The 802.1p Priority row contains traffic class selectors for each of the eight 802.1p priorities to be mapped. The priority goes from low (0) to high (7). For example, traffic with a priority of 0 is for most data traffic and is sent using “best effort.”...
Page 128
FS728TP Smart Switch Software Administration Manual To map DSCP values to queues: For each DSCP value, select a hardware queue to associate with the value. The traffic class is the hardware queue for a port. Higher traffic class values indicate a higher queue position.
FS728TP Smart Switch Software Administration Manual Differentiated Services The QoS feature contains Differentiated Services (DiffServ) support that allows traffic to be classified into streams and given certain QoS treatment in accordance with defined per-hop behaviors. Standard IP-based networks are designed to provide “best effort” data delivery service. “Best effort”...
FS728TP Smart Switch Software Administration Manual Diffserv Configuration Use the Diffserv Configuration page to display DiffServ General Status Group information, which includes the current administrative mode setting as well as the current and maximum number of rows in each of the main DiffServ private MIB tables. To display the page, click QoS ...
FS728TP Smart Switch Software Administration Manual Field Description Policy Attributes Displays the current and maximum number of rows of the policy attributes table. Table Service Table Displays the current and maximum number of rows of the service table. Class Configuration Use the Class Configuration page to add a new DiffServ class name, or to rename or delete an existing class.
Page 132
FS728TP Smart Switch Software Administration Manual To configure the class match criteria: Click the class name for an existing class. The class name is a hyperlink. The following figure shows the configuration fields for the class. 132 | Chapter 4: Configuring Quality of Service...
Page 133
FS728TP Smart Switch Software Administration Manual Define the criteria to associate with a DiffServ class: Reference Class. Selects a class to start referencing for criteria. A specified class • can reference at most one other class of the same type. Class of Service.
FS728TP Smart Switch Software Administration Manual Policy Configuration Use the Policy Configuration page to associate a collection of classes with one or more policy statements. After creating a Policy, click the policy link to the Policy page. To display the page, click QoS DiffServ Advanced Policy Configuration. To configure a DiffServ policy: To create a new policy, enter a policy name in the Policy Selector field, select the existing DiffServ class to associate with the policy, and click Add.
Page 135
FS728TP Smart Switch Software Administration Manual To configure the policy attributes: Click the name of the policy. Chapter 4: Configuring Quality of Service | 135...
Page 136
FS728TP Smart Switch Software Administration Manual The policy name is a hyperlink. The following figure shows the configuration fields for the policy. Select the queue to which packets will of this policy-class will be assigned . Configure the policy attributes:. Drop.
FS728TP Smart Switch Software Administration Manual Color Conform Mode. The match-criteria of the color Conform class. • Committed Rate. The committed rate is specified in kilobits-per-second (Kbps) and is • an integer from 1–4294967295. Committed Burst Size. The committed burst size is specified in kilobytes (KB) and is •...
FS728TP Smart Switch Software Administration Manual To configure DiffServ policy settings on an interface: To configure DiffServ policy settings for a physical port, click PORTS. To configure DiffServ policy settings for a Link Aggregation Group (LAG), click LAGS. To configure DiffServ policy settings for both physical ports and LAGs, click ALL. Select the check box next to the port or LAG to configure.
Page 139
FS728TP Smart Switch Software Administration Manual Field Description Interface Displays the interface for which service statistics are to display. Direction Displays the direction of packets for which service statistics display, which is always In. Policy Name Displays the policy associated with the selected interface. Operational Status Displays the operational status of this service interface, which is either Up or Down.
Managing Device Security Use the features available from the Security tab to configure management security settings for port, user, and server security. The Security tab contains links to the following features: on page 142 • Management Security Settings on page 153 •...
FS728TP Smart Switch Software Administration Manual Management Security Settings From the Management Security Settings page, you can configure the login password, Remote Authorization Dial-In User Service (RADIUS) settings, Terminal Access Controller Access Control System (TACACS+) settings, and authentication lists. To display the page, click the Security Management Security tab. The Management Security folder contains links to the following features: on page 142 •...
FS728TP Smart Switch Software Administration Manual If you make changes to the page, click Apply to apply the changes to the system. In the case of a lost password, press the Factory Default Reset Note: button on the front panel for more than one second to restore the factory default.
FS728TP Smart Switch Software Administration Manual The Current Server IP Address field is blank if no servers are configured (see RADIUS on page 144). The switch supports up to three configured RADIUS Server Configuration servers. If more than one RADIUS servers are configured, the current server is the server configured as the primary server.
Page 145
FS728TP Smart Switch Software Administration Manual To configure a RADIUS server: To add a RADIUS server, specify the settings the following list describes, and click Add. In the Server Address field, specify the IP address of the RADIUS server to add. •...
Page 146
FS728TP Smart Switch Software Administration Manual The following table describes the RADIUS server statistics available on the page. Field Description Server Address This displays all configured RADIUS servers. Round Trip Time The time interval, in hundredths of a second, between the most recent Access-Reply/Access-Challenge and the Access-Request that matched it from this RADIUS authentication server.
Page 147
FS728TP Smart Switch Software Administration Manual To access the RADIUS Accounting Server Configuration page, click Security Management Security RADIUS Accounting Server Configuration. To configure the RADIUS accounting server: In the Accounting Server Address field, specify the IP address of the RADIUS accounting server to add.
FS728TP Smart Switch Software Administration Manual The following table describes RADIUS accounting server statistics available on the page. Field Description Accounting Server Address Displays the IP address of the supported RADIUS accounting server. Round Trip Time (secs) Displays the time interval, in hundredths of a second, between the most recent Accounting-Response and the Accounting-Request that matched it from this RADIUS accounting server.
Page 149
FS728TP Smart Switch Software Administration Manual The TACACS+ protocol ensures network security through encrypted protocol exchanges between the device and TACACS+ server. The TACACS+ folder contains links to the following features: on page 148 • Configuring TACACS+ on page 149 •...
Page 150
FS728TP Smart Switch Software Administration Manual To display the TACACS+ Server Configuration page, click Security Management Security, and then click the TACACS+ Server Configuration link. To configure TACACS+ server settings: To add a new TACACS+ server, select Add from the TACACS+ Server field, enter the IP address of the server to add, and click Apply.
FS728TP Smart Switch Software Administration Manual In the Connection Timeout field, specify the amount of time that passes before the connection between the device and the TACACS+ server times out. The field range is from 1 to 30 seconds. If you make changes to the page, or add a new entry, click Apply to apply the changes to the system.
Page 152
FS728TP Smart Switch Software Administration Manual Local: The user's locally stored ID and password will be used for authentication. • Since the local method does not time out, if you select this option as the first method, no other method will be tried, even if you have specified more than one method. RADIUS: The user's ID and password will be authenticated using the RADIUS server.
FS728TP Smart Switch Software Administration Manual Configuring Management Access From the Access page, you can configure HTTP and Secure HTTP access to the FS728TP management interface. You can also configure Access Control Profiles and Access Rules. The Security Access tab contains the following folders: on page 153 •...
FS728TP Smart Switch Software Administration Manual In the HTTP Session Hard Timeout field, specify the hard timeout for HTTP sessions. This timeout is unaffected by the activity level of the session. The value must be in the range of (0–168) hours. A value of zero corresponds to an infinite timeout. The default value is 24 hours.
FS728TP Smart Switch Software Administration Manual The currently configured value is shown when the Web page is displayed. The default value is Disable. You can only download SSL certificates when the HTTPS Admin mode is disabled. Use the radio buttons in the SSL Version 3 field to enable or disable Secure Sockets Layer Version 3.0.
Page 156
FS728TP Smart Switch Software Administration Manual To configure the certificate download settings for HTTPS sessions: From the File Type menu, select the type of SSL certificate to download, which can be one of the following: SSL Trusted Root Certificate PEM File. SSL Trusted Root Certificate File (PEM •...
FS728TP Smart Switch Software Administration Manual Access Profile Configuration Use the Access Profile Configuration page to configure settings that control management access to the switch. Access profile configuration requires three steps: Use the Access Profile Configuration page to create an access profile. To add rules to the profile, the access profile must be deactivated, which is the default setting.
FS728TP Smart Switch Software Administration Manual The Profile Summary table shows the rules that are configured for the profile, as the following table describes. Field Description Rule Type Identifies the action the rule takes, which is either Permit or Deny. Service Type Displays the type of service to allow or prohibit from accessing the switch management interface:...
Page 159
FS728TP Smart Switch Software Administration Manual Before you create access rules, make sure: An access profile exists. • The access profile is deactivated. • To configure access profile rules: To add an access profile rule, configure the following settings and click Add. Rule Type: Specify whether the rule permits or denies access to the FS728TP •...
FS728TP Smart Switch Software Administration Manual Port Authentication In port-based authentication mode, when 802.1X is enabled globally and on the port, successful authentication of any one supplicant attached to the port results in all users being able to use the port without restrictions. At any given time, only one supplicant is allowed to attempt authentication on a port in this mode.
FS728TP Smart Switch Software Administration Manual To configure global 802.1X settings: Select the appropriate radio button in the Port Based Authentication State field to enable or disable 802.1X administrative mode on the switch. Enable. Port-based authentication is permitted on the switch. •...
Page 162
FS728TP Smart Switch Software Administration Manual To configure 802.1X settings for the port: Select the check box next to the port to configure. You can also select multiple check boxes to apply the same settings to the selected ports, or select the check box in the heading row to apply the same settings to all ports.
Page 163
FS728TP Smart Switch Software Administration Manual Authorized: Places the interface into an authorized state without being • authenticated. The interface sends and receives normal traffic without client port-based authentication. Unauthorized: Denies the selected interface system access by moving the • interface into unauthorized state.
Page 164
FS728TP Smart Switch Software Administration Manual exerts control over communication in both directions (disabling both incoming and outgoing frames). This field is not configurable. Protocol Version. This field displays the protocol version associated with the • selected port. The only possible value is 1, corresponding to the first version of the 802.1X specification.
FS728TP Smart Switch Software Administration Manual Port Summary Use the Port Summary page to view information about the port access control settings on a specific port. To access the Port Summary page, click Security Port Authentication Advanced Port Summary.
FS728TP Smart Switch Software Administration Manual Field Description Reauthentication Enabled Displays if reauthentication is enabled on the selected port. This is a configurable field. The possible values are true and false. If the value is true, reauthentication will occur. Otherwise, reauthentication will not be allowed. Port Status This field displays the authorization status of the specified port.
Page 167
FS728TP Smart Switch Software Administration Manual To configure MAC filter settings: To configure a new MAC filter: a. Select Create Filter from the MAC Filter menu. If no filters have been configured, this is the only option available. b. From the VLAN ID menu, select the VLAN to use with the MAC address to fully identify packets you want filtered.
FS728TP Smart Switch Software Administration Manual MAC Filter Summary Use the MAC Filter Summary page to view the MAC filters that are configured on the system. To display the MAC Filter Summary page, click Security Traffic Control, and then click the MAC Filter ...
Page 169
FS728TP Smart Switch Software Administration Manual To configure storm control settings: Select the check box next to the port to configure. Select multiple check boxes to apply the same setting to all selected ports. Select the check box in the heading row to apply the same settings to all ports.
FS728TP Smart Switch Software Administration Manual Port Security Configuration Use the Port Security feature to lock one or more ports on the system. When a port is locked, only packets with an allowable source MAC addresses can be forwarded. All other packets are discarded.
FS728TP Smart Switch Software Administration Manual Port Security Interface Configuration A MAC address can be defined as allowable by one of two methods: dynamically or statically. Both methods are used concurrently when a port is locked. Dynamic locking implements a first arrival mechanism for Port Security. You specify how many addresses can be learned on the locked port.
FS728TP Smart Switch Software Administration Manual Max Allowed Dynamically Learned MAC. Sets the maximum number of • dynamically learned MAC addresses on the selected interface. Valid range is 0–600. Max Allowed Statically Locked MAC. Sets the maximum number of statically locked •...
FS728TP Smart Switch Software Administration Manual Field Description VLAN ID Displays the VLAN ID corresponding to the Last Violation MAC address. MAC Address Displays the MAC addresses learned on a specific port. Click Refresh to refresh the page with the most current data from the switch. Protected Ports Membership If a port is configured as protected, it does not forward traffic to any other protected port on the switch, but it will forward traffic to unprotected ports.
FS728TP Smart Switch Software Administration Manual Configuring Access Control Lists Access Control Lists (ACLs) ensure that only authorized users have access to specific resources while blocking off any unwarranted attempts to reach network resources. ACLs are used to provide traffic flow control, restrict contents of routing updates, decide which types of traffic are forwarded or blocked, and above all provide security for the network.
FS728TP Smart Switch Software Administration Manual Optionally, use the MAC Binding Table page to view the configurations. To display the MAC ACL page, click Security ACL. The MAC ACL page is under the Basic link. The MAC ACL table displays the number of ACLs currently configured in the switch and the maximum number of ACLs that can be configured.
Page 176
FS728TP Smart Switch Software Administration Manual To configure MAC ACL rules: From the ACL Name field, specify the existing MAC ACL to which the rule will apply. To set up a new MAC ACL use the MAC ACL page. To add a new rule, enter an ID for the rule, configure the following settings, and click Add. Action.
FS728TP Smart Switch Software Administration Manual EtherType User Value. This field is configurable if you select User Value from the • EtherType drop down menu. The value you enter specifies a customized Ethertype to compare against an Ethernet frame. The valid range of values is 0x0600–0xFFFF. Source MAC.
FS728TP Smart Switch Software Administration Manual The packet filtering direction for ACL is Inbound, which means the MAC ACL rules are applied to traffic entering the port. Specify an optional sequence number to indicate the order of this access list relative to other access lists already assigned to this interface and direction.
FS728TP Smart Switch Software Administration Manual The following table describes the information displayed in the MAC Binding Table. Field Description Interface Displays the interface to which the MAC ACL is bound. Direction Specifies the packet filtering direction for ACL. The only valid direction is Inbound, which means the MAC ACL rules are applied to traffic entering the port.
Page 180
FS728TP Smart Switch Software Administration Manual The IP ACL area shows the current size of the ACL table versus the maximum size of the ACL table. The current size is equal to the number of configured IPv4 plus the number of configured MAC ACLs.
FS728TP Smart Switch Software Administration Manual IP Rules Use the IP Rules page to define rules for IP-based standard ACLs. The access list definition includes rules that specify whether traffic matching the criteria is forwarded normally or discarded. There is an implicit “deny all” rule at the end of an ACL list. This Note: means that if an ACL is applied to a packet and if none of the explicit rules match, then the final implicit “deny all”...
FS728TP Smart Switch Software Administration Manual Source IP Address. Requires a packet’s source IP address to match the address • listed here. Type an IP Address in the appropriate field using dotted-decimal notation. The address you enter is compared to a packet's source IP Address. Source IP Mask.
Page 183
FS728TP Smart Switch Software Administration Manual To configure rules for an IP ACL: To add an IP ACL rule, select the ACL ID to add the rule to, select the check box in the Extended ACL Rule table, and click Add. The page displays the extended ACL Rule Configuration fields.
Page 184
FS728TP Smart Switch Software Administration Manual Permit. Forwards packets which meet the ACL criteria. • Deny. Drops packets which meet the ACL criteria. • Egress Queue. Specifies the hardware egress queue identifier used to handle all • packets matching this ACL rule. Enter an identifying number from 0–7 in the appropriate field.
FS728TP Smart Switch Software Administration Manual Destination L4 Port Number: If the destination L4 keyword is Other, enter a • user-defined Port ID by which packets are matched to the rule. Service Type. Choose one of the Service Type match conditions for the extended IP •...
Page 186
FS728TP Smart Switch Software Administration Manual To configure IP ACL interface bindings: Select an existing IP ACL from the ACL ID menu. The packet filtering direction for ACL is Inbound, which means the IP ACL rules are applied to traffic entering the port. Specify an optional sequence number to indicate the order of this access list relative to other access lists already assigned to this interface and direction.
FS728TP Smart Switch Software Administration Manual IP Binding Table Use the IP Binding Table page to view or delete the IP ACL bindings. To display the IP Binding Table, click Security ACL, then click the Advanced Binding Table link The following table describes the information displayed in the MAC Binding Table.
Monitoring the System Use the features available from the Monitoring tab to view a variety of information about the switch and its ports and to configure how the switch monitors events. The Monitoring tab contains links to the following features: on page 190 •...
FS728TP Smart Switch Software Administration Manual Ports The pages available from the Ports link contain a variety of information about the number and type of traffic transmitted from and received on the switch. From the Ports link, you can access the following pages: on page 190 •...
Page 191
FS728TP Smart Switch Software Administration Manual The following table describes the Switch Statistics displayed on the screen. Field Description ifIndex This object indicates the ifIndex of the interface table entry associated with the processor of this switch. Octets Received The total number of octets of data received by the processor (excluding framing bits, but including FCS octets).
FS728TP Smart Switch Software Administration Manual Field Description Most VLAN Entries Ever The largest number of VLANs that have been active on this switch since the Used last reboot. Static VLAN Entries The number of presently active VLAN entries on this switch that have been created statically.
FS728TP Smart Switch Software Administration Manual The following table describes the per-port statistics displayed on the screen. Field Description Interface Lists the ports on the system. Total Packets Received The total number of packets received that were without errors. Without Errors Packets Received With Error The number of inbound packets that contained errors preventing them from being deliverable to a higher layer protocol.
Page 194
FS728TP Smart Switch Software Administration Manual The following table describes the detailed port information displayed on the screen. To view information about a different port, select the port number from the Interface menu. Field Description Interface Use the drop down menu to select the interface for which data is to be displayed or configured.
Page 195
FS728TP Smart Switch Software Administration Manual Field Description Port Channel ID If the port is a member of a port channel, the port channel's interface ID and name are shown. Otherwise, Disable is shown. Port Role Each MST Bridge Port that is enabled is assigned a Port Role for each spanning tree.
Page 196
FS728TP Smart Switch Software Administration Manual Field Description Packets RX and TX The total number of packets (including bad packets) received or transmitted 128-255 Octets that were between 128 and 255 octets in length inclusive (excluding framing bits but including FCS octets). Packets RX and TX The total number of packets (including bad packets) received or transmitted 256-511 Octets...
Page 197
FS728TP Smart Switch Software Administration Manual Field Description Unicast Packets Received The number of subnetwork-unicast packets delivered to a higher-layer protocol. Multicast Packets Received The total number of good packets received that were directed to a multicast address. This number does not include packets directed to the broadcast address.
Page 198
FS728TP Smart Switch Software Administration Manual Field Description Broadcast Storm Recovery The number of frames discarded that are destined for FF:FF:FF:FF:FF:FF when Broadcast Storm Recovery is enabled. CFI Discards The number of frames discarded that have CFI bit set and the addresses in RIF are in non-canonical format.
Page 199
FS728TP Smart Switch Software Administration Manual Field Description Broadcast Packets The total number of packets that higher-level protocols requested be Transmitted transmitted to the Broadcast address, including those that were discarded or not sent. Total Transmit Errors The sum of Single, Multiple, and Excessive Collisions. Tx FCS Errors The total number of packets transmitted that had a length (excluding framing bits, but including FCS octets) of between 64 and 1518 octets, inclusive, but...
FS728TP Smart Switch Software Administration Manual Click Clear to clear all the counters. This resets all statistics for this port to the default • values. Click Refresh to refresh the data on the screen and display the most current statistics. •...
FS728TP Smart Switch Software Administration Manual Field Description Length Error Frames Received Displays the number of EAPOL frames with an invalid Packet Body Length received on this port. Response/ID Frames Received Displays the number of EAP Respond ID frames that have been received on the port.
Page 202
FS728TP Smart Switch Software Administration Manual The following table describes the cable information displayed on the screen. Field Description Interface Specifies the interface that has the connected cable. Cable Status Displays the cable status. Normal: the cable is working correctly. •...
FS728TP Smart Switch Software Administration Manual System Logs The switch may generate messages in response to events, faults, or errors occurring on the platform as well as changes in configuration or other occurrences. These messages are stored locally and can be forwarded to one or more centralized points of collection for monitoring purposes or long term archival storage.
Page 204
FS728TP Smart Switch Software Administration Manual To configure the Memory Log settings: Use the radio buttons in the Admin Status field to determine whether to log messages. Enable: Enables system logging. • Disable: Prevents the system from logging messages. • From the Behavior menu, specify the behavior of the log when it is full.
FS728TP Smart Switch Software Administration Manual The following example shows the standard format for a log message: <14> Mar 24 05:34:05 10.131.12.183-1 UNKN[2176789276]: main_login.c(179) 3855 %% HTTP Session 19 initiated for user admin connected from 10.27.64.122 The number contained in the angle brackets represents the message priority, which is derived from the following values: Priority = (facility value ×...
Page 206
FS728TP Smart Switch Software Administration Manual To configure the FLASH Log settings: Use the radio buttons in the Admin Status field to determine whether to log messages to persistent storage. Enable: Enables persistent logging. • Disable: Prevents the system from logging messages in persistent storage. •...
FS728TP Smart Switch Software Administration Manual Use the buttons at the bottom of the page to perform the following actions: Click Clear to clear the messages out of the buffered log. • Click Refresh to refresh the page with the most current data from the switch. •...
FS728TP Smart Switch Software Administration Manual The Messages Ignored field shows the number of messages that were ignored. • To configure a remote log server To add a remote syslog host (log server), specify the settings in the following list and click Add.
Page 209
FS728TP Smart Switch Software Administration Manual The following table describes the Trap Log information displayed on the screen. Field Description Number of Traps Since The number of traps that have occurred since the switch last reboot. Last Reset Trap Log Capacity The maximum number of traps stored in the log.
FS728TP Smart Switch Software Administration Manual Event Logs Use the Event Log page to display the event log, which is used to hold error messages for catastrophic events. After the event is logged and the updated log is saved in flash memory, the switch will be reset.
FS728TP Smart Switch Software Administration Manual Port Mirroring The page under the Mirroring link allows you to view and configure port mirroring on the system. Multiple Port Mirroring Port mirroring selects the network traffic for analysis by a network analyzer. This is done for specific ports of the switch.
Page 212
FS728TP Smart Switch Software Administration Manual Click Apply to apply the settings to the system. If the port is configured as a source port, the Mirroring Port field value is Mirrored. To delete a mirrored port, select the check box next to the mirrored port, and then click Delete.
Page 213
Maintenance Use the features available from the Maintenance tab to help you manage the switch. The Maintenance tab contains links to the following features: on page 214 • Reset on page 216 • Upload File From Switch on page 219 •...
FS728TP Smart Switch Software Administration Manual Reset The Reset menu contains links to the following options: on page 214 • Device Reboot on page 214 • Factory Default Device Reboot Use the Device Reboot page to reboot the FS728TP. To access the Device Reboot page, click Maintenance Reset Device Reboot. To reboot the switch: Select the check box on the page.
Page 215
FS728TP Smart Switch Software Administration Manual To reset the switch to the factory default settings: Select the check box on the page. Click Apply. The switch resets immediately. Chapter 7: Maintenance | 215...
FS728TP Smart Switch Software Administration Manual Upload File From Switch The switch supports system file uploads from the switch to a remote system by using either TFTP or HTTP. The Upload menu contains links to the following options: on page 216 •...
FS728TP Smart Switch Software Administration Manual IPv4. Indicates the TFTP server address is an IP address in dotted-decimal format. • DNS. Indicates the TFTP server address is a hostname. • In the Server Address field, specify the IP address or hostname of the TFTP server. The address you type must be in the format indicated by the TFTP Server Address Type.
Page 218
FS728TP Smart Switch Software Administration Manual non-active image. This is a safety feature for faults occurring during the boot upgrade process. Text Configuration: A text-based configuration file enables you to edit a configured • text file (startup-config) offline as needed without having to translate the contents for the switch to understand.
FS728TP Smart Switch Software Administration Manual Download File To Switch The switch supports system file downloads from a remote system to the switch by using either TFTP or HTTP. The Download menu contains links to the following options: on page 219 •...
Page 220
FS728TP Smart Switch Software Administration Manual non-active image. This is a safety feature for faults occurring during the boot upgrade process. Text Configuration: A text-based configuration file enables you to edit a configured • text file (startup-config) offline as needed without having to translate the contents for the switch to understand.
FS728TP Smart Switch Software Administration Manual HTTP File Download Use the HTTP File Download page to download files of various types to the switch using an HTTP session (for example, via your Web browser). To display this page, click Maintenance Download HTTP File Download. To download a file to the switch from by using HTTP: From the File Type menu, Specify what type of file you want to download to the switch: Code: The code is the system software image, which is saved in one of two flash...
Page 222
FS728TP Smart Switch Software Administration Manual If you are downloading an FS728TP image (Code), select the image on the switch to overwrite. This field is only visible when Code is selected as the File Type. It is recommended that you not overwrite the active image. The Note: system will display a warning that you are trying to overwrite the active image.
FS728TP Smart Switch Software Administration Manual File Management The system maintains two versions of the FS728TP software in permanent storage. One image is the active image, and the second image is the backup image. The active image is loaded during subsequent switch restarts. This feature reduces switch down time when upgrading or downgrading the FS728TP software.
FS728TP Smart Switch Software Administration Manual After activating an image, you must perform a system reset of the Note: switch in order to run the new code. To remove the selected image from permanent storage on the switch, select the Delete Image check box.
Page 225
FS728TP Smart Switch Software Administration Manual Field Description Current-active Displays the currently active image on this switch. Next-active Displays the image to be used on the next restart of this switch. Image1 Description Displays the description associated with the image1 code file. Image2 Description Displays the description associated with the image2 code file.
FS728TP Smart Switch Software Administration Manual Troubleshooting The Troubleshooting menu contains links to the following options: on page 226 • Ping on page 227 • Traceroute Ping Use the Ping page to tell the switch to send a Ping request to a specified IP address. You can use this feature to check whether the switch can communicate with a particular network host.
FS728TP Smart Switch Software Administration Manual If successful, you will see “Reply From IP/Host: icmp_seq = 0. time = xx usec. Tx = x, • Rx = x Min/Max/Avg RTT = x/x/x msec.” If a reply to the ping is not received, you will see “Reply From IP/Host: Destination •...
Page 228
FS728TP Smart Switch Software Administration Manual Port. Specify the UDP destination port in probe packets. The valid range is 1–65535. • Size. Specify the size of probe packets. The valid range is 0–65507. • Click Cancel to cancel the operation on the screen and reset the data on the screen to the latest value of the switch.
• User Guide Support Use the Support page to connect to the Online Support site at netgear.com. To access the Support page, click Help Support. To connect to the NETGEAR support site for the FS728TP, click Apply. Chapter 8: Help...
User Guide Use the User Guide page to access the FS728TP Smart Switch Software Administration Manual (the guide you are now reading) that is available on the NETGEAR Website. To access the User Guide page, click Help User Guide.
FS728TP Smart Switch Software Administration Manual FS728TP Switch Features and Defaults Feature Sets Supported Default Auto negotiation/static All ports Auto negotiation speed/duplex Auto MDI/MDIX Enabled 802.3x flow control/back pressure 1 (per system) Disabled Port mirroring Disabled Port trunking (aggregation) Pre-configured 802.1D spanning tree Disabled 802.1w RSTP...
Page 234
FS728TP Smart Switch Software Administration Manual Feature Sets Supported Default 802.1X All ports Disabled MAC ACL 100 (Shared with IP ACL) All MAC addresses allowed IP access list 100 (shared with MACACL) All IP addresses allowed Password control access Idle timeout = 5 mins. Password = “password”...
Page 235
FS728TP Smart Switch Software Administration Manual Feature Sets Supported Default Smart Control Center Enabled Statistics Feature Sets Supported Default IGMP snooping v1/v2 All ports Disabled Configurations upload/download EAPoL flooding All ports Disabled BPDU flooding All ports Disabled Static multicast groups Disabled Filter multicast control Disabled...
Configuration Examples This chapter contains information about how to configure the following features: on page 238 • Virtual Local Area Networks (VLANs) on page 240 • Access Control Lists (ACLs) on page 243 • Differentiated Services (DiffServ) on page 247 •...
FS728TP Smart Switch Software Administration Manual Virtual Local Area Networks (VLANs) A local area network (LAN) can generally be defined as a broadcast domain. Hubs, bridges, or switches in the same physical segment or segments connect all end node devices. End nodes can communicate with each other without the need for a router.
FS728TP Smart Switch Software Administration Manual Packets leaving the switch are either tagged or untagged, depending on the setting for • that port’s VLAN membership properties. A U for a given port means that packets leaving the switch from that port are untagged. Inversely, a T for a given port means that packets leaving the switch from that port are tagged with the VLAN ID that is associated with the port.
FS728TP Smart Switch Software Administration Manual Access Control Lists (ACLs) ACLs ensure that only authorized users have access to specific resources while blocking off any unwarranted attempts to reach network resources. ACLs are used to provide traffic flow control, restrict contents of routing updates, decide which types of traffic are forwarded or blocked, and provide security for the network.
Page 241
FS728TP Smart Switch Software Administration Manual Destination MAC Mask: 00:00:00:00:FF:FF • Source MAC: 02:02:1A:BC:DE:EF • Source MAC Mask: 00:00:00:00:FF:FF • VLAN ID: 2 • For more information about MAC ACL rules, see on page 175. MAC Rules From the MAC Binding Configuration screen, assign the Sales_ACL to Ethernet ports 6, 7, and 8, and then click Apply (See on page 177).
FS728TP Smart Switch Software Administration Manual Standard IP ACL Example Configuration The following example shows how to create an IP-based ACL that prevents any IP traffic from the Finance department from being allowed on the ports that are associated with other departments.
FS728TP Smart Switch Software Administration Manual Differentiated Services (DiffServ) Standard IP-based networks are designed to provide best effort data delivery service. Best effort service implies that the network deliver the data in a timely fashion, although there is no guarantee that it will. During times of congestion, packets may be delayed, sent sporadically, or dropped.
FS728TP Smart Switch Software Administration Manual From a DiffServ point of view, there are two types of classes: DiffServ traffic classes • DiffServ service levels/forwarding classes • DiffServ Traffic Classes With DiffServ, you define which traffic classes to track on an ingress interface. You can define simple BA classifiers (DSCP) and a wide variety of multi-field (MF) classifiers: Layer 2;...
FS728TP Smart Switch Software Administration Manual packets that are either in excess of the conformance specification or are non-conformant. The DiffServ feature supports the following types of traffic policing treatments (actions): drop: the packet is dropped • send: the packet is forwarded without DiffServ modification •...
Page 246
FS728TP Smart Switch Software Administration Manual Click Apply. From the Policy Configuration screen, create a new policy with the following settings: Policy Selector: Policy1 • Member Class: Class1 • For more information about this screen, see on page 134. Policy Configuration Click Add to add the new policy.
FS728TP Smart Switch Software Administration Manual 802.1X Local Area Networks (LANs) are often deployed in environments that permit unauthorized devices to be physically attached to the LAN infrastructure, or permit unauthorized users to attempt to access the LAN through equipment already attached. In such environments, it may be desirable to restrict access to the services offered by the LAN to those users and devices that are permitted to use those services.
FS728TP Smart Switch Software Administration Manual A Port Access Entity (PAE) is able to adopt one of two distinct roles within an access control interaction: Authenticator: A Port that enforces authentication before allowing access to services available via that Port. Supplicant: A Port that attempts to access services offered by the Authenticator.
Page 249
FS728TP Smart Switch Software Administration Manual In the Guest VLAN field for ports e1–e8, enter 150 to assign these ports to the guest VLAN. You can configure additional settings to control access to the network through the ports. on page 171 for information about the settings. Port Security Interface Configuration Click Apply.
FS728TP Smart Switch Software Administration Manual MSTP Spanning Tree Protocol (STP) runs on bridged networks to help eliminate loops. If a bridge loop occurs, the network can become flooded with traffic. IEEE 802.1s Multiple Spanning Tree Protocol (MSTP) supports multiple instances of Spanning Tree to efficiently channel VLAN traffic over different interfaces.
FS728TP Smart Switch Software Administration Manual An MST Region comprises of one or more MSTP Bridges with the same MST Configuration Identifier, using the same MSTIs, and which have no Bridges attached that cannot receive and transmit MSTP BPDUs. The MST Configuration Identifier has the following components: Configuration Identifier Format Selector Configuration Name Configuration Revision Level...
Page 252
FS728TP Smart Switch Software Administration Manual Ports e1-e5 Ports e1-e5 Connected to Hosts Connected to Hosts Ports e6-e8 Connected to Switch 2 and 3 Switch 1 Root Bridge Switch 2 Ports e6-e8 Connected to Switch 1 and 2 Switch 3 Ports e1-e5 Connected to Hosts Perform the following procedures on each switch to configure MSTP:...
Page 253
FS728TP Smart Switch Software Administration Manual Since the edge ports are not at risk for network loops, ports with Fast Link enabled transition directly to the Forwarding state. Click Apply. You can use the CST Port Status screen to view spanning tree information about each port.
Notification of Compliance NETGEAR Wired Products Certificate of the Manufacturer/Importer It is hereby certified that the ProSafe™ FS728TP Smart Switch has been suppressed in accordance with the conditions set out in the BMPT-AmtsblVfg 243/1991 and Vfg 46/1992. The operation of some equipment (for example, test transmitters) in accordance with the regulations may, however, be subject to certain restrictions.
Page 255
Hereby, NETGEAR Inc., declares that this Radiolan is in compliance with the essential requirements and other relevant provisions of Directive 1999/5/EC. Español Por medio de la presente NETGEAR Inc. declara que el Radiolan cumple con los [Spanish] requisitos esenciales y cualesquiera otras disposiciones aplicables o exigibles de la Directiva 1999/5/CE.
Page 256
FCC Declaration Of Conformity We, NETGEAR, Inc., 350 East Plumeria Drive, Santa Clara, CA 95134, declare under our sole responsibility that the ProSafe™ FS728TP Smart Switch complies with Part 15 of FCC Rules. Operation is subject to the following two...
Consult the dealer or an experienced radio/TV technician for help. • Modifications made to the product, unless expressly approved by NETGEAR, Inc., could void the user's right to operate the equipment. Canadian Department of Communications Radio Interference Regulations This digital apparatus, (ProSafe™ FS728TP Smart Switch), does not exceed the Class A limits for radio-noise emissions from digital apparatus as set out in the Radio Interference Regulations of the Canadian Department of Communications.
Index Numerics LLDP MAC Filter 802.1X Management Access example configuration MST Port Network Settings on the Administrative System password Policy access control Port Security ACL example configuration Port VLAN ID ACLs RADIUS management interface Global authentication Secure HTTP 802.1X SNMP v3 User enable SNTP Server list...
Page 259
FS728TP Smart Switch Software Administration Manual LAG VLAN LAGPDUs LAGs EAPOL Membership Static LLDP Local Information file management neighbors information firmware packets firmware download port settings LLDP-MED getting started Green Ethernet guest VLAN configuration bridge identifier CPU Management Interface dynamic address filter summary help, HTML-based MFDB Table...
Page 260
FS728TP Smart Switch Software Administration Manual levels local RADIUS zone server TraceRoute statistics trademarks reboot traffic control reset trap button flags configuration to defaults manager switch RSTP Unicast upload configuration Security MAC Address server, HTTP severity, log message Simple Network Time Protocol VLAN SNMP example configuration...
Need help?
Do you have a question about the FS728TPv2 and is the answer not in the manual?
Questions and answers