Allworx PowerFlex P810 User manual

PowerFlex 8/24/48 Port GbE PoE Managed
Switch
User’s Guide
Updated October 30, 2013


PowerFlex 8/24/48 Port GbE PoE Managed Switch
User’s Guide

PowerFlex 8/24/48 Port GbE PoE Managed Switch User’s Guide
© 2013 Allworx Corp, a Windstream Communications company. All rights reserved. No part of this
publication may be reproduced, stored in a retrieval system, or transmitted, in any form or by any
means, electronic, mechanical, photocopy, recording, or otherwise without the prior written permission
of Allworx Corp. All brand and product names referenced in this guide are trademarks or registered
trademarks of their respective companies.
Software in this product is © 2013 Allworx Corp, a Windstream Communications company, or its
vendors. All rights are reserved. The software is protected by United States of America copyright laws
and international treaty provisions applicable worldwide. Allworx® Software Products End User License
Agreement
Purpose
This guide gives specific information on how to operate and use the management functions of the
switch.
Audience
Intended use: For use by network administrators who are responsible for operating and maintaining
network equipment; consequently, it assumes a basic working knowledge of general switch functions,
the Internet Protocol (IP), and Simple Network Management Protocol (SNMP).
Warranty
Find a copy of the specific warranty terms applicable to this product at www.allworx.com.
Conventions
This guide uses the following conventions throughout this guide to show information:
Notification for installation, operation, maintenance, performance, or
general tips that are important, but not hazardous to anything or
anyone.
Description of a potentially hazardous situation, which if not avoided,
could result in death or serious or moderate. It can also advise
against unsafe practices.
Description of a potentially hazardous situation, which if not avoided,
could result in minor or moderate injury. It can also advise against
unsafe practices.
Toll Free 1-866-ALLWORX • 585-421-3850 • www.allworx.com
Revised: October 30, 2013
Page ii

PowerFlex 8/24/48 Port GbE PoE Managed Switch User’s Guide
Compliances and Safety Statements
FCC – Class A
This equipment has been tested and found to comply with the limits for a Class A computing device
pursuant to Subpart J of part 15 of FCC Rules, which are designed to provide reasonable protection
against such interference when operated in a commercial environment.
This equipment generates, uses, and can radiate radio frequency energy and, if not installed and used
in accordance with the instruction manual, may cause harmful interference to radio communications.
Operation of this equipment in a residential area is likely to cause harmful interference in which case
the user must correct the interference at their own expense.
CAUTION: changes or modifications not expressly approved by the party
responsible for compliance could void the authority to operate the
equipment.
It is possible to use unshielded twisted-pair (UTP) for RJ-45 connections - Category 3 or better for 10
Mbps connections, Category 5 or better for 100 Mbps connections, Category 5, 5e, or 6 for 1000 Mbps
connections. For fiber optic connections, it is possible use a 50/125 or 62.5/125 micron multimode fiber
or 9/125 micron single-mode fiber.
CE Mark Declaration of Conformance for EMI and Safety (EEC)
This equipment has been tested and found to comply with the protection requirements of European
Emission Standard EN55022/EN61000-3 and the Generic European Immunity Standard EN55024.
Caution: Maintenance Personnel:
To avoid electric shock, turn the power off and detach the input power cord prior
to doing any equipment maintenance.
.
After completing the equipment maintenance, verify the ground connection and setup.
Toll Free 1-866-ALLWORX • 585-421-3850 • www.allworx.com
Revised: October 30, 2013
Page iii

PowerFlex 8/24/48 Port GbE PoE Managed Switch User’s Guide
Revision History
This section summarizes the changes in each revision of this guide.
Release Date Revision
V2.29 09/09/2013 A3
V1.52 05/22/2013 A2
V1.07 10/17/2011 A1
Toll Free 1-866-ALLWORX • 585-421-3850 • www.allworx.com
Revised: October 30, 2013
Page iv

PowerFlex 8/24/48 Port GbE PoE Managed Switch User’s Guide
Table of Contents
1Introduction .................................................................................................. 1
1.1 Overview ................................................................................................... 1
1.2 Overview of this User’s Guide.................................................................... 1
2Operation of Web-Based Management ...................................................... 2
2.1 Initial Configuration .................................................................................... 2
2.2 IP Configuration......................................................................................... 2
3System Configuration.................................................................................. 4
3.1 System Information.................................................................................... 4
3.2 Time .......................................................................................................... 7
3.3 Account ................................................................................................... 10
3.4 IP............................................................................................................. 13
3.5 SYSLOG.................................................................................................. 16
3.6 SNMP ...................................................................................................... 19
3.7 Groups .................................................................................................... 24
3.8 Views....................................................................................................... 25
3.9 Access..................................................................................................... 26
3.10 Trap......................................................................................................... 27
4Configuration.............................................................................................. 29
4.1 Port.......................................................................................................... 29
4.2 ACL ......................................................................................................... 38
4.3 Aggregation ............................................................................................. 46
4.4 LACP....................................................................................................... 48
4.5 Spanning Tree ......................................................................................... 51
4.6 IGMP Snooping ....................................................................................... 62
4.7 MLD Snooping......................................................................................... 70
4.8 MVR ........................................................................................................ 77
4.9 LLDP ....................................................................................................... 81
4.10 PoE ......................................................................................................... 98
4.11 VLAN..................................................................................................... 107
4.12 Voice VLAN ........................................................................................... 119
4.13 GARP .................................................................................................... 123
4.14 GVRP .................................................................................................... 126
4.15 QoS ....................................................................................................... 129
4.16 sFlow Agent........................................................................................... 147
4.17 Loop Protection ..................................................................................... 149
4.18 Single IP................................................................................................ 151
4.19 Easy Port............................................................................................... 153
4.20 Mirroring ................................................................................................ 155
4.21 Trap Event Severity ............................................................................... 157
4.22 SMTP Configuration .............................................................................. 158
4.23 UPnP..................................................................................................... 159
5Security..................................................................................................... 160
Toll Free 1-866-ALLWORX • 585-421-3850 • www.allworx.com
Revised: October 30, 2013
Page v

PowerFlex 8/24/48 Port GbE PoE Managed Switch User’s Guide
5.1 IP Source Guard.................................................................................... 160
5.2 ARP Inspection...................................................................................... 163
5.3 DHCP Snooping .................................................................................... 166
5.4 DHCP Relay .......................................................................................... 168
5.5 NAS....................................................................................................... 171
5.6 AAA ....................................................................................................... 183
5.7 Port Security.......................................................................................... 192
5.8 Access Management ............................................................................. 198
5.9 SSH....................................................................................................... 200
5.10 HTTPS................................................................................................... 201
5.11 Auth Method .......................................................................................... 202
6Maintenance ............................................................................................. 203
6.1 Restart Device ....................................................................................... 203
6.2 Firmware ............................................................................................... 204
6.3 Save / Restore....................................................................................... 206
6.4 Export / Import ....................................................................................... 208
6.5 Diagnostics............................................................................................ 210
7Glossary of Web-based Management .................................................... 213
Toll Free 1-866-ALLWORX • 585-421-3850 • www.allworx.com
Revised: October 30, 2013
Page vi

PowerFlex 8/24/48 Port GbE PoE Managed Switch User’s Guide
1Introduction
1.1 Overview
This user’s manual instructs how to install, configure and monitor the PowerFlex™ 8/2410/48 port
switch through the built-in web-based management.
The PowerFlex 8/24/48 series, the next generation L2+ managed switches, is a portfolio of affordable
managed switches that provides a reliable business network infrastructure. These switches deliver
intelligent features needed to improve the availability of critical business applications, protect sensitive
information, and optimize network bandwidth to deliver information and applications more effectively. It
provides the ideal combination of affordability and capabilities for entry level networking including small
business or enterprise applications and helps create a more efficient, better-connected workforce.
PowerFlex 8/24/48 L2+ Managed Switches provide 8, 24 or 48 100/1000 ports, depending on the
model; the specifications are as follows:
•L2+ features provide better manageability, security, QoS, and performance.
•High port count design with all Gigabit Ethernet ports
•Support guest VLAN, voice VLAN, Port based, tag-based and Protocol based VLANs.
•Support 802.3az Energy Efficient Ethernet standard
•Support 802.3at High power PoE Plus standard
•Support IPv6/ IPv4 Dual stack
•Support sFlow
•Support Easy-Configuration-Port for easy implementation of IP Phones, IP Cameras or
Wireless environment.
1.2 Overview of this User’s Guide
•Chapter 2 “Operation of Web-based Management”
•Chapter 3 “Maintenance”
Toll Free 1-866-ALLWORX • 585-421-3850 • www.allworx.com
Revised: October 30, 2013
Page 1

PowerFlex 8/24/48 Port GbE PoE Managed Switch User’s Guide
2Operation of Web-Based Management
2.1 Initial Configuration
This chapter describes configuring and managing the PowerFlex series switches through the web user
interface. With this facility, users can easily access and monitor the switch, including MIBs status, port
activity, Spanning tree status, port aggregation status, and multicast traffic, VLAN, and priority status,
and even illegal access record and so on.
The PowerFlex Series switches ship with a preconfigured firmware image. This eliminates the need to
make changes to the switch in order for it to work with the Allworx servers and phones. The default
configuration is detailed below. Following the instructions below makes the server, switch, and phones
a plug-n-play network.
2.2 IP Configuration
The switch has DHCP enabled to obtain an address from the Allworx server. If for some reason DHCP
fails, the switch falls back to the configured static IP.
NOTE: If DHCP has failed in a multiple PowerFlex switch configuration, it will be
necessary to disconnect each switch from the others before attemplting to log into
the switches using the default IP.
IP Address 192.168.2.200
Subnet Mask 255.255.255.0
Default Gateway 192.168.2.254
Username admin
Password <blank>
Once the switch has obtained its IP address, users may determine its current address from the DHCP
lease table of the network’s DHCP server. In a default configuration, an Allworx server is the DHCP
server. The IP information may be viewed by navigating to the Servers>DHCP page of the Allworx
server. In the “Active Leases” section, match the hardware address in the table to the MAC address
printed on the label of the PowerFlex switch. Access the switch via the web interface using the
associated IP address. For instance, browse to http://192.168.2.x using a web browser. A pop-up screen
prompts users to enter the username and password.
The default username is “admin”and password is empty.
NOTE: It is recommended for security purposes to change the username and
password after initial login.
The PowerFlex Series supports a simple user management function enabling only one administrator to
configure the system at any given time. If there are two or more users using administrator’s identity,
only the first user to login is able to configure the system. The other logged in users, even with
Toll Free 1-866-ALLWORX • 585-421-3850 • www.allworx.com
Revised: October 30, 2013
Page 2

PowerFlex 8/24/48 Port GbE PoE Managed Switch User’s Guide
administrator’s identity, can only monitor the system. Those who are not configured as administrators
can only monitor the system. A maximum of only three users can log in to the switch at once.
Figure 1: Login Page
NOTE: To optimize the display effect, use Microsoft IE 6.0 or above, Netscape
V7.1 or above or FireFox V1.00 or above and have the resolution set to 1024x768.
To configure a function or parameter, access the online Help in the web GUI.
Toll Free 1-866-ALLWORX • 585-421-3850 • www.allworx.com
Revised: October 30, 2013
Page 3

PowerFlex 8/24/48 Port GbE PoE Managed Switch User’s Guide
3System Configuration
This chapter describes all the basic configuration tasks which include the System Information and
management of the Switch (e.g. Time, Account, IP, Syslog and SNMP.)
3.1 System Information
After log in, the switch displays the system information. This is the default page and displays the basic
information of the system, including “Model Name”, “System Description”, “Contact”, “Device Name”,
“System Up Time”, “BIOS Version”, “Firmware Version”, etc.
3.1.1 Information
The switch system information is provided here.
To view the System Information from the web interface:
Navigate to System > System Information > Information.
Figure 2: System Information
Parameter Description
Model Name The device model name.
System Description A brief description of the switch.
Location User-defined location of the switch.
Contact User-defined contact person for switch administration. Configure this parameter
through the device user interface or SNMP.
Device name User-defined name for the switch.
Toll Free 1-866-ALLWORX • 585-421-3850 • www.allworx.com
Revised: October 30, 2013
Page 4

PowerFlex 8/24/48 Port GbE PoE Managed Switch User’s Guide
System Date Display the system time and date. Format: year, day of week, month, hours :
minutes : seconds.
System up time Time the system has been up since powering on or last reboot. Format: days,
hours : minutes : seconds.
BIOS version The switch BIOS version.
Firmware version The switch firmware version.
Hardware-Mechanical
version
The version of Hardware and Mechanical. The figure before the hyphen is the
version of the electronic hardware; the one after the hyphen is the version of
mechanical.
Series number The serial number is assigned by the Manufacturer.
Host IP address, Subnet
Mask and Gateway IP
Address
The IP address, subnet mask and gateway IP address set on the switch.
Host MAC address The Ethernet MAC address of the management agent in the switch.
RAM size The size of the RAM switch in MB.
Flash size Switch flash memory size in MB.
Bridge FDB size Displays the bridge RDB size.
Transmit Queue Displays the device’s transmit hardware priority queue information.
Maximum Frame size Display the device maximum frame size.
Toll Free 1-866-ALLWORX • 585-421-3850 • www.allworx.com
Revised: October 30, 2013
Page 5

PowerFlex 8/24/48 Port GbE PoE Managed Switch User’s Guide
3.1.2 Configuration
Users can identify the system by configuring the contact information, name, and location of the switch.
To configure System Information in the web interface:
1. Navigate to System > System Information > Configuration.
2. Specify the System Contact, System Name and System Location information.
3. Click Apply. 0.
Figure 3: System Configuration
Parameter Description
System Contact The contact person for this managed switch, along with the contact
information. The string length is 0 to 255, and the content is ASCII characters
from 32 to 126.
System Name An assigned name for this managed switch. By convention, this is the node's
fully-qualified domain name. A domain name is a text string drawn from the
alphabet (A-Z a-z), digits (0-9), minus sign (-). No space characters are
permitted as part of a name. The first character must be an alpha character
and the first or last character must not be a minus sign. The string length is 0 to
255.
System Location The physical location of this switch (e.g., telephone closet, 3rd floor). The string
length is 0 to 255, and the content is ASCII characters from 32 to 126.
Toll Free 1-866-ALLWORX • 585-421-3850 • www.allworx.com
Revised: October 30, 2013
Page 6

PowerFlex 8/24/48 Port GbE PoE Managed Switch User’s Guide
3.2 Time
This page enables configuring the system time manually or automatically using NTP server(s).
3.2.1 Manual
Manual setting is simple, just enter “Year”, “Month”, “Day”, “Hour”, “Minute” and “Second” within the
valid value range indicated in each item.
To configure system time manually from the web interface:
1. Navigate to System > Time > Manual.
2. Specify the parameters in each field.
3. Click Apply. 0.
Figure 4: Manual Time Configuration
Parameter Description
Clock Source Select “Use local Settings” or “Use NTP Server” for the clock source.
Local Time Display the current time of the system.
Time Zone Offset Provide the timezone offset relative to UTC/GMT. The offset is given in minutes east
of GMT. The valid range is from -720 to 720 minutes.
Daylight Saving Daylight saving is adopted in some countries. If set, it adjusts the time lag or advance
in unit of hours, according to the starting date and the ending date. For example, if
setting the day light saving to be 1 hour, when the time passes over the starting time,
the system time increases by one hour after one minute at the time since it passed
over and when the time passes over the ending time, the system time decreases by
one hour after one minute at the time since it passed over.
The valid configurable day light saving time is –5 ~ +5 step one hour. A zero for this
parameter indicates no adjustment to the current time, equivalent to in-act daylight
saving. Users do not need to set the starting/ending date as well. If setting daylight
saving to be non-zero, set the starting/ending date as well; otherwise, the daylight
saving function is not active.
Toll Free 1-866-ALLWORX • 585-421-3850 • www.allworx.com
Revised: October 30, 2013
Page 7

PowerFlex 8/24/48 Port GbE PoE Managed Switch User’s Guide
Time Set Offset Provide the Daylight saving time set offset. The offset is given in minutes east of
GMT. The valid range is from 1 to 1440 minutes. Default is 60 mins.
Daylight Saving type Select “ By Dates” or “Recurring”.
From Configure Daylight saving start date and time. The format is “YYYY-MM-DD HH:MM”.
To Configure Daylight saving end date and time. The format is “YYYY-MM-DD HH:MM”
Toll Free 1-866-ALLWORX • 585-421-3850 • www.allworx.com
Revised: October 30, 2013
Page 8

PowerFlex 8/24/48 Port GbE PoE Managed Switch User’s Guide
3.2.2 NTP
Use the Network Time Protocol to synchronize the network time based on Greenwich Mean Time
(GMT). If using the NTP mode, users can manually set up to 5 NTP servers. The switch syncs the time
in a short time after pressing the Apply button. Though it synchronizes the time automatically, NTP
does not update the time periodically without user’s processing.
Time Zone is an offset time off GMT. Select the time zone first, and then do a time sync via NTP. The
switch combines this time zone offset and updated NTP time to calculate the local time; otherwise, the
time is incorrect. The switch supports configurable time zone from –12 to +13 step 1 hour.
Default Time zone: +8 Hrs.
To configure Time in the web interface:
1. Navigate to System > Time > NTP.
2. Specify the NTP server address (es).
3. Click Apply. 0.
Figure 5: NTP Configuration
Parameter Description
Server 1 to 5 Provide the NTP IPv4 or IPv6 address. IPv6 address is in 128-bit records represented
as eight fields of up to four hexadecimal digits with a colon separating each field (:).
For example, 'fe80::215:c5ff:fe03:4dc7'. The symbol '::' is a special syntax that can be
used as a shorthand way of representing multiple 16-bit groups of contiguous zeros;
but it can only appear once.It can also represent a legally valid IPv4 address.For
example, '::192.1.2.34
Toll Free 1-866-ALLWORX • 585-421-3850 • www.allworx.com
Revised: October 30, 2013
Page 9

PowerFlex 8/24/48 Port GbE PoE Managed Switch User’s Guide
3.3 Account
Only the administrator can create, modify, or delete the username and password. Administrator can
modify other guest identities’ password without confirming the password but it is necessary to modify
the administrator-equivalent identity. Guest-equivalent identity can modify his password only. It is
necessary to confirm administrator/guest identity in the field of Authorization in advance before
configuring the username and password. There can be only one administrator account, but there can
be up to 4 guest accounts. No one can delete the administrator account.
3.3.1 Users
This page provides an overview of the current users. Currently the only way to login as another user on
the web server is to close and reopen the browser.
To configure Account in the web interface:
1. Navigate to System > Account > Users.
2. Click Add new user.
3. Specify the User Name and password for the user along with the Privilege Level.
4. Click Apply. 0.
Figure 6: User Account Configuration
Parameter Description
User Name The name identifying the user. This is also a link to Add/Edit User.
Password The string length is 0 to 255, and the content is the ASCII characters from 32 to
126.
Password (again) Retype the password typed in the Password field.
Privilege Level The privilege level of the user. The range is 1 to 15. If the privilege level value is
15, it can access all groups, i.e. granted full control of the device. . User's privilege
should be same or greater than the group privilege level to have access of that
group. By default, most groups’ privilege level 5 has the read-only access and
privilege level 10 has the read-write access. System maintenance (software
upload, factory defaults and etc.) requires user privilege level 15. In general, the
privilege level 15 can be used for an administrator account, privilege level 10 for a
standard user account and privilege level 5 for a guest account.
Toll Free 1-866-ALLWORX • 585-421-3850 • www.allworx.com
Revised: October 30, 2013
Page 10

PowerFlex 8/24/48 Port GbE PoE Managed Switch User’s Guide
3.3.2 Privilege Level
This page provides an overview of the privilege levels. Each group can have the Privilege Levels set
from 1 to 15.
To configure Privilege Level in the web interface:
1. Navigate to System > Account > Privilege Level.
2. Specify the Privilege parameter.
3. Click Apply. 0.
Figure 7: Privilege Level Configuration
Toll Free 1-866-ALLWORX • 585-421-3850 • www.allworx.com
Revised: October 30, 2013
Page 11

PowerFlex 8/24/48 Port GbE PoE Managed Switch User’s Guide
Parameter Description
Group Name The name identifying the privilege group. In most cases, a privilege level group
consists of a single module (e.g. LACP, RSTP or QoS), but a few contain more
than one. The following description defines these privilege level groups in detail:
System: Contact, Name, Location, Timezone, Log.
Security: Authentication, System Access Management, Port (contains Dot1x
port, MAC based and the MAC Address Limit), ACL, HTTPS, SSH, ARP
Inspection and IP source guard.
IP: Everything except 'ping'.
Port: Everything except 'VeriPHY'.
Diagnostics: 'ping' and 'VeriPHY'.
Maintenance: CLI- System Reboot, System Restore Default, System Password,
Configuration Save, Configuration Load and Firmware Load. Web- Users,
Privilege Levels and everything under Maintenance.
Debug: Only present in CLI.
Privilege Levels Every group has an authorization Privilege level for the following sub groups:
configuration read-only, configuration/execute read-write, status/statistics read-
only, status/statistics read-write (e.g. for clearing of statistics). User Privilege
should be same or greater than the authorization Privilege level to have access
to that group.
Toll Free 1-866-ALLWORX • 585-421-3850 • www.allworx.com
Revised: October 30, 2013
Page 12
Table of contents
Other Allworx Switch manuals