Axis T8504-E User manual

AXIST8504–EOutdoorPoESwitch
UserManual

AXIST8504–EOutdoorPoESwitch
Tableofontents
Aboutthismanual..........................................3
Objectives.....................................................3
Intendedaudience...............................................3
Relateddocumentation...........................................3
Abbreviations...................................................3
Generalinformation.........................................5
Features.......................................................5
Useraccessandsecurity..........................................5
First-timeconguration..........................................7
UnitidenticationoverIPnetork.................................8
Webinterface..............................................9
Webinterfacemenu.............................................9
SSHserialinterface.........................................15
Mainmenu....................................................15
SNMPmonitoringandconguration...........................18
EnableSNMP...................................................18
SNMPMIBs....................................................18
SysLogMessage............................................20
Troubleshooting............................................22
Support.......................................................22
Learnmore!....................................................23
2

AXIST8504–EOutdoorPoESwitch
Aboutthismanual
Aboutthismanual
Objectives
AXIST8504–EisanoutdoorPoEsitch.Themajorbenetsofthisproductisitsoutdoorcapabilitiesandthecapabilitytoextend
themaximumreachofthenetorkbyanadditional100meters,toatotalof200meters,beteenthesitchandthepoered
devices,hileprovidingupto2x60Wand2x30Wtoitsnetork-poeredPoEdevices.
ThisusermanualprovidesinformationonhotomanageAXIST8504–EthroughAXISIPv4/IPv6,VLAN,RADIUS,TACACS+,eb
interface,SNMPandSHH.
Intendedaudience
Thisusermanualisintendedfornetorkadministrators,supervisorsandinstallationtechniciansithknoledgeabout:
•Basicconceptsandterminologyofnetorking
•NetorktopologyincludingVLAN
•Netorkprotocols
•UserauthenticationprotocolsincludingRADIUSandTACACS+
Reateddocumentation
Foradditionalinformation,seethefolloingdocumentation:
•Productinstallationguide
•RFC3621SNMPMIBandprivateMIB
•CreatingcerticateforT8504–Esecuredebserver
Abbreviations
Abbreviationescription
8021.QSameasVLAN
DESDataEncryptionStandard
DGWDefaultGateWay
DHCPv4DynamicIPv4HostCongurationProtocol
DHCPv6DynamicIPv46HostCongurationProtocol
IPv432–bitlongIPaddress
IPv6128–bitlongIPaddress
MD5Messagedigestalgorithm
MDIMediaDependentInterface
MIBManagementInformationBase
PoEPoeroverEthernet
RADIUSRemoteAuthenticationDial-inUserService
SFPFiberinterface,smallform-factorplug
3

AXIST8504–EOutdoorPoESwitch
Aboutthismanual
SHAMessagedigestalgorithm
SNMPSimpleNetorkManagementProtocol
SSHSecureShell
SSLSecureSocketsLayer
SysLogSystemLog
TACACS+TerminalAccessControllerAccess-Control
TFTPTrivialFileTransferProtocol
TLSTransportLayerSecurity
VLANVirtualLocalAreaNetork
4

AXIST8504–EOutdoorPoESwitch
Generalinformation
Generalinformation
Features
Anumberoffeaturesareprovidedthroughsystemnetorkmanagement.
•EasysoftareupdateduringruntimeithoutaffectingactivePoEports
•Congurationandreal-timemonitoringusinggraphicalrepresentationoftheremotedevice
•Systemstatusdisplay
•SysLogreportingonPoEevents,invalidremoteuseraccess,initialDHCPv4/v6addressetc.
•SNMPtrapsreportingonvariousPoEeventssuchasPoEpoereddeviceinsertionorremoval
Ethernetswitchnetworkcapabiities
•FoureathersealedRJ45Ethernetportscapableof10Mbit,100Mbit,1000Mbithalf-duplexand1000Mbitfull-duplex
Ethernetspeed
•SingleeathersealedSFPEthernetport
•8KinternalMACaddresslookupengine
•VLAN—Access,TrunkandFilteredtrunk
•AutoMDIX
•10KBjumboframes
PoEcapabiities
ThefolloingPoEoptionsareavailable:
•Two4PairPoEportshichdeliverupto60Wperport
•TwoIEEE802.3atPoEportshichdeliverupto30Wperport
•PoEenable/disabletoenableordisablePoEportspoeroutput.Ethernetdataisalaysenabled.
•Remotedeviceresettoresetattachedpoereddevice.Thedeviceistemporarilypoeredoffandthenturnedbackon.
Supportednetworkprotocos
Thefolloingnetorkprotocolsaresupported:
•IPv4–32–bitlongIPaddress(static/DHCPv4)
•IPv6–128–bitlongIPaddress(static/DHCPv6)
•VLAN–Access,TrunkandFilteredtrunk
Useraccessandsecurity
Accessoptions
Youcanaccesstheunitthroughdifferentinterfaces:
•Webinterfaceviaawebbrowser–tovietheunitPoEstatus,netorkstatus,unitcongurationandunitproduction
information
5

AXIST8504–EOutdoorPoESwitch
Generalinformation
HTTPisaeb-basedfriendlycongurationinterface.
HTTPS-TLSisasecuredeb-basedfriendlycongurationinterface.
•SNMPviaanSNMPmanagerapplication–tomonitortheunitoverthenetork(MIB-IIRFC1213)andtomonitoror
conguretheunitPoEcapabilities(RFC3621)
SNMPv2cfornon-securedSNMPmanagement
SNMPv3forsecuredandencryptedmanagement
RFC1213MIB-IIfornetorkstatistics
RFC3621forPoESNMPMIBs
PrivateMIBextensionforRFC3621PoEMIB
VariousinfrastructureandnetorkMIBssuchasIP-MIB,TCP-MIB,UDP-MIBetc.
•SSHviaanSSHclient–tovietheunitPoEpoerreport,netorkstatus,unitcongurationandproductioninformation;
toupdatesoftare,enableordisablePoEfunctionalityandtopingremotenetorkdevicesforconnectivitytests
Remoteuserauthentication
Useraccesscanbemanagedinthefolloingays:
•Local–Usernameandpassordismanagedlocallybythedevice
•RAIUS–UsernameandpassordisauthenticatedbyRADIUSserveroverthenetork
•TACACS+–UsernameandpassordisauthenticatedbyTACACS+serveroverthenetork
Security
WebHTTPandHTTPS,SNMPv2,SNMPv3andSSH,usedforaccessingtheunit,offerdifferentlevelsofsecuritystrength.AlsoRADIUS
andTACACS+,usedforremoteuserauthentication,offerdifferentsecuritylevels.
SNMPv1andSNMPv2usecommunitystringforGet/Set/Trapauthentication.SNMPv1andSNMPv2areconsideredasunsecured
protocolsincethecommunitystringpassordcaneasilybeinterceptedbyanynetorksnifngdevice.
SNMPv3resolvesSNMPv1/v2securityissuesbyaddingauthenticationandencryptionlayerontopofSNMPpackets.
DefautunitIP,usernameandpassword
Theunitisshippediththefolloingfactorydefaultusernamesandpassords:
UnitdefaultIPv4address
IP=192.168.0.254
Mask=255.255.255.0
WebHTTP/HTTPSandSSH
Username=root
Passord=pass
SNMPv2
GETcommunitystring=public
SETcommunitystring=rite
Readcommunity=public
Writecommunity=rite
Trapcommunity=public
SNMPv3
Username=admin
6

AXIST8504–EOutdoorPoESwitch
Generalinformation
Authenticationpassord(MD5)=passord
Privacypassord(DES)=passord
Authenticationandencryptionmode=MD5+DES
SNMPv3notication
Username=trap
Authenticationpassord=passord
Privacypassord=passord
Authenticationandencryptionmode=None
Forinformationabouthotorecoverusernameandpassord,seeRecoverusernameandpasswordonpage7.
Recoverusernameandpassword
Note
TherecoveryprocedurecanonlybeperformedfromthelocalLANandnotoverInternetorfromanotherIPnetork.The
usershouldbeabletoturnofftheunitpoerhenneeded.AllPoEportsmustbedisconnectedandtheunitmusthave
onlyonesingleactiveEthernetlink.
Note
YoumightneedtoaddaTelnetclientservicetoWindos7orWindos8.
Note
Theentirerecoveryprocedurefromunitpoeronuntiltheusernameandpassordisappliedmusttakelessthan120seconds.
1.DisconnectallPoEportsfromtheunitexceptforoneEthernetcable.OnlyonesingleEthernetportshouldbeactive.
2.TurnoffthereallorenableUDPport514.ThenrunIPv4capableSysLogServeronyourcomputer.
3.Turnofftheunit.Wait10seconds,thenturntheunitbackon.
4.ASysLogmessageappearsafterapproximately15seconds.IdentifytheunitLink-localIPv6address.ALink-localIPv6
addressalaysstartsithFE80.
5.Openacommandindoonyourcomputer.
-ForWindos7,gotoStartandtypecmd.
-ForWindos8,presstheWINDOWSkeyandtheRkey,thentypecmd.
6.TypeipcongtoidentifythevirtualinterfaceindexofLink-localIPv6address.Thevirtualinterfaceindexisindicatedbya
numberafter%.Example:fe80::9c39:db8b:62de:7bv4%17
7.PreparetheSSHconnectionbytypingTelnet[unitLocal-linkIPv6address][%virtualinterfacenumber]2525,butdon’t
pressENTER.Example:Telnetfe80::9c39:db8b:62de:7bv4%172525
8.Turnofftheunit.Wait10seconds,thenturntheunitbackon.
9.Wait30seconds,thenpressENTERtostarttheTelnetsessiononTCPport2525.
10.Typeaxispasswordrecoveryasusernameandaxispasswordrecoveryaspassord.Arecoveryoptiontorestoretheentire
unittocompletefactorydefaultincludingunitnetorkcongurationispresented.PressYtorestoretheunit.Theunit
restartsithdefaultIPv4192.168.0.254,usernamerootandpassordpass.
First-timeconguration
Whenconguringtheunitforthersttime,follothestepsbelo:
1.CongureyourPCEthernetnetorkinterfacetothefolloingIPv4parameters:
7

AXIST8504–EOutdoorPoESwitch
Generalinformation
PCIPv4address:192.168.0.40
PCIPv4mask:255.255.255.0
2.ConnectyourPCEthernetnetorkinterfacetoanyoftheunit’sEthernetports.
3.Openaebbroserandtype192.168.0.254intheaddresseld.
4.Loginiththedefaultusernameandpassord.SeeDefaultunitIP,usernameandpasswordonpage6.
5.Conguretheunit.Itisrecommendedtochangetheusernamesandpassordstootherthanthedefaultvalues.
UnitidenticationoverIPnetwork
TolocatetheunitovertheIPnetork,theunitsendsIPv4SysLogmessage#0inbroadcastformat255.255.255.255uponpoer-up.
AnySysLogserverconnectedoverLANreceivesthisSysLogmessage.ThesameSysLogmessageisalsosenttotheoptionalSysLog
servers1and2,iftheyarecongured.
Theunitsendsthemessagetice.ThisistoensurethattheSysLogmessageisreceivedbytheSysLogservers,regardlessofnetork
conguration.ThemessageisrstsentbeforeVLANcongurationismadeandlateragainafterVLANcongurationisdone.
SysLogmessage#0containsalltheinformationhichisrequiredtobeabletoprovideaccesstotheunitoverthenetork.
Example:MsgID#000-SystemUP.APP:v3.51.06BOOT:v3.16RST:Power-OnBOOT:0=[APP
OK]Host:axis-00055A034B49MAC:00:05:5a:03:4b:49VLAN:YESVLAN_MNGR:5
VLAN_UPLINK_PORT:3VLAN_UPLINK_MODE:TRUNKDHCPv4:NoIP1v4:192.168.0.254/24DHCPv6:No
IP1v6:2345::205:5AFF:FE03:4B49/64IP2v6:FE80::205:5AFF:FE03:4B49/64
FieldValueescription
MsgID#000-SystemUPSysLogmessagenumber
APP:v3.51.06Unitapplicationsoftareversion
BOOT:v3.16Unitbootversion,usedforsoftare
update
RST:Power-OnResetreason
BOOT:0=[APPOK]
Host:axis-00055A034B49axisfolloedbyunitMACaddress
MAC:00:05:5a:03:4b:49UnitMACaddress
VLAN:YESVLANstatusenabledordisabled
VLAN_UPLINK_PORT:3Ethernetportnumberusedforunit
management
VLAN_UPLINK_MODE:TRUNKManagementportisconguredasAccess
orTrunk
DHCPv4:NoDHCPv4YesorNo
IP1v4:192.168.0.254/24UnitIPv4address
DHCPv6:NoDHCPv6YesorNo
IP1v6:2345::205:5AFF:FE03:4B49/64UnitIPv6address
IP2v6:FE80::205:5AFF:FE03:4B49/64Unitlink-localIPv6address
8

AXIST8504–EOutdoorPoESwitch
Webinterface
Webinterface
Webinterfacemenu
Status
GotoStatustovietheunitstatus.Thepageisupdatedautomaticallyeveryfeseconds.
Note
TheEthernetnetorklinkisalaysenabled,regardlessofPoEconguration(enabledordisabled).
Parameterescription
Bluesymbol—PoEpoerisprovided
Graysymbol—NoPoEpoer
Bluesymbol—PoEportisenabled
Graysymbol—PoEportisdisabled
Bluesymbol—Ethernetlinkison
Graysymbol—NoEthernetlink
Bluesymbol—SFPmoduleisinsertedintotheuplinkport
Graysymbol—UplinkporthasnoSFPmoduleinserted
NetorkReportstheEthernetlinkspeed(10/100/1000MB)andifthenetorkconnectionisupordon
StatusReportsthePoEportstatus,ifitisenabled,disabled,deliveringpoer,etc.
PoerusageReportstheactualpoerconsumptionandthemaximumpoeritcandeliver
PoEresetClickResettoturnoffthePoEportpoerandrestorethePoEpoerbackon.
Note
APoEporthichisdisabledbySSHorSNMPillbeenabledafteraPoEreset.
TotalpoerusageReportstheaggregatedpoerconsumedbyallPoEportsandthepercentageoftheconsumed
poerrelativetotheinternalpoersupplypoercapabilities.
Basic
GotoBasictoviebasicinformationabouttheproduct.
IPaddressinuse-GotoIPaddressinusetovieinformationaboutIPv4andIPv6addresses,masks,defaultgateaysand
DomainNameServers(DNS).
Productinformation-GotoProductinformationtoviegeneralproductinformationsuchasproductname,serialnumber,
softareversionandPoErmareversion,andSFPmoduleinformationsuchasSFPtype,vendor,partnumberandserialnumber.
9

AXIST8504–EOutdoorPoESwitch
Webinterface
Networkconguration-GotoNetworkcongurationtoenableordisableDHCP,congureIPv4,IPv6andnetorkhostname.
HostnameisusedbybothIPv4andIPv6toregistertheunitnameinDHCPv4/v6server.NotethatIPv6usestheFQDNterminology
ashostname.
NetworkservicesIPv4/IPv6-GotoNetworkservicesIPv4/IPv6tocongureDNSandSysLogservers.
PoEconguration-GotoPoEcongurationtocongurePoEportpoer.FourPoEpoerschemesofferdifferentpoer
distributionsbeteenthefourPoEports.Allfouroptionscomplyiththeunitmaximumpoercapacities.
•60W:DeliverpoeroverfourpairsinsidetheEthernetcable.Eachpairdeliversupto30W.
•30W:DeliverpoerovertooutoffourpairsinsidetheEthernetcable
•15.4W:DeliverpoerovertooutoffourpairsinsidetheEthernetcable
•––:NoPoEpoer.Ethernetportisenabledandfunctional,butPoEisdisabled.
Security
Securityconguration
GotoSecuritycongurationtoconguretheunitusernameandpassordforremoteeborSSHaccess.
Note
OnlyASCIIcharacters33–90and94–122canbeusedfortheusernameandpassordelds.
HTTPS
GotoHTTPStocongurehetherHTTPorHTTPS(securedeb)shouldbeused.WhenHTTPSisenabled,TLSv1.2isusedtoencrypt
ebnetorktrafc.
Note
ToeliminateebbroserarningheneveraccessingtheunitoverHTTPS,addanexceptionruletotheebbrosertelling
theebbroserthattheebsiteislegitimateoruploadaunitself-signed/CA-signedcerticate.
RADIUS/TACACS+
RADIUS/TACACS+enablesremoteuserauthenticationhenuseraccessestheunitovereborSSH.Usernameandpassordarethen
authenticatedbytheRADIUS/TACACS+server.
TheadvantagesithRADIUS/TACACS+isthatusernameandpassordareeasytoupdate,especiallyifmanynetorkdevices
aretobemanaged.
ThedisadvantageithRADIUS/TACACS+isthattheunitisnotaccessibleifbothRADIUS/TACACS+serversaredon.Itispossible
toenableLocalloginfallbackhichallostheunittouseitslocalusernameandpassordheneverthereisnoreplyfrom
RADIUS/TACACS+servers.
RADIUS/TACACS+commonparameters
Parameterescription
EnableauthenticationCongureifRADIUS/TACACS+shouldbeenabledordisabled.WhenRADIUS/TACACS+isdisabled,
localusernameandpassordareused.
EnablelocalloginfallbackWhenlocalloginfallbackisenabled,localusernameandpassordareusedheneverthereisno
replyfromRADIUS/TACACS+servers.Thiscanhappenhentheserversaredonorincaseof
anetorkproblem.
AuthenticationprotocolSelecteitherRADIUSorTACACS+authenticationprotocol.
SharedsecretThesameprivatekeystringmustbeconguredonboththeunitandtheRADIUS/TACACS+server.
10

AXIST8504–EOutdoorPoESwitch
Webinterface
PrimaryserverIPaddressConguretheprimaryIPv4,IPv6orhostnametobeusedtoaccessthemainRADIUS/TACACS+
server.
SecondaryserverIPaddressCongurethesecondaryIPv4,IPv6orhostnametobeusedtoaccessthemainRADIUS/TACACS+
server.
Timout(Sec)Congurethetimeforareplytimeout.
RADIUSextraparameters
Parameterescription
AuthenticationUDPportConguretheUDPportusedbytheRADIUSserver.
TACACS+extraparameters
Parameterescription
AuthenticationTCPportConguretheTCPportusedbytheTACACS+server.
Note
Softareversion3.51.06onlysupportsaccessingRADIUS/TACACS+serversoverIPv4,eitherithanIPv4addressora
hostnametoberesolvedbyDNSserver.
TestRADIUS/TACACS+
GotoTestRAIUS/TACACS+toverifytheRADIUS/TACACS+congurationbeforeactivatingit.
Note
Duringtesting,theEnableauthenticationshouldbedisabled.
1.CongureallRADIUS/TACACS+parameters,leavingtheEnableauthenticationdisabled.
2.Savetheconguration.Ifnot,theparametersillberestoredtosavedvaluesaftereachtest,erasinganyunsavedvalue.
3.Typetheusernameandpassord.
4.ClickTestconguration.Aaitingmessageillappear,folloedbyeitherOKorFAIL.
5.Ifneeded,changeandsavethecongurationandtestagain.
6.WhenthetestresultisOK,setEnableauthenticationtoenabled.Savetheconguration,hichactivatesthe
RADIUS/TACACS+conguration.
VLANconguration
VLANcongurationsanitycheckisdoneuponunitpoer-upandhenaVLANcongurationchangeisrequestedovertheeb.The
sanitycheckistomakesurethattheunitremainsmanageableoverthenetorkafterVLANcongurationisapplied.Incasethene
VLANcongurationmaycausetheunittobecomeunmanageable,anerrormessageappearsontheebpageforrequestsoverthe
eb.Whenaproblemisdetecteduponpoer-up,theunitcongurationillberestoredtofactorydefault.
VLANenable&managementport
Parameterescription
EnableVLANEnableordisableVLANfunctionality.
11

AXIST8504–EOutdoorPoESwitch
Webinterface
ManagementuplinkportThisparameterhasnoeffectonactualVLANtrafc.Themanagementuplinkportassiststhe
unittoevaluateiftheneVLANcongurationmightblocktheunitfrombeingmanaged
overVLANfromthisport.Ifapossibleconictisdetected,anerrormessageappearsandthe
neVLANcongurationisrejected.
ManagementVLANIDCongurehichVLANIDtobeusedhenmanagingtheunitheneverVLANisenabled.
VLANportsconguration
Parameterescription
VLANmodeSetVLANmodetoAccessorTrunkforeachoftheEthernetports.
Access—VLANisusedonlyinsidetheunittosplitorlimitpacketaccesstospecicports
only.AnyincomingVLANtaggedpacketsreceivedbyVLANaccessportisdiscarded.VLAN
taggingisaddedtotheunitpacketforVLANAccessincomingpackets.UnitinternalVLAN
taggingisstrippedoutforVLANAccessoutgoingpackets.
Trunk—AllEthernetpacketsareVLANtagged.AnyuntaggedVLANpacketsreceivedby
VLANtrunkportisdiscarded.
AccessmodeVLANIDConguretheVLANIDtobeusedhenevertheportisconguredasAccess.Theunit
internalmanagementportactsasaccessonly.Itcanonlybereachedfromasingle
managementVLANID.
TRUNK–FilterunknonVLANConguretheVLANTrunkportaslteredorunltered.
Enabled—OnlydataofromsomeVLANIDs,speciedintheTrunkVLANslist,passes
throughVLANTrunkport.AllotherVLANtaggedtrafcisdiscarded.
Disabled—DataofromallVLANIDspassesthroughVLANTrunkport.
TRUNKVLANsListtheVLANIDsthatmaypassthroughVLANTrunkportheneverTRUNK–Filter
unknownVLANisenabled.
SNMPconguration
GotoSNMPcongurationtocongureparametersapplicabletoSNMPv2candSNMPv3.
SNMPv2c
Parameterescription
EnableSNMPv2cEnableordisableSNMPv2csupport.
ReadcommunityConguretheSNMPv2cGETcommunitystring.Example:public.
WritecommunityConguretheSNMPv2cSETcommunitystring.Example:private.
TrapcommunityConguretheSNMPv2cTrapcommunitystring.Example:public.
Systeminformation(MIB-II,v2c/v3)
Parameterescription
SystemcontactConguretheSNMPMIB-IIsystemcontactOiDstring.Example:John.
SystemnameConguretheSNMPMIB-IIsystemname.Example:MyUnit.
SystemlocationConguretheSNMPMIB-IIsystemlocation.Example:University.
PoEMIB(RFC3621,v2c/v3)
12

AXIST8504–EOutdoorPoESwitch
Webinterface
Parameterescription
EnablenoticationEnableordisablethefolloingPoEtrapreports:
•PoEpoerasprovided/removedfrompoereddevice
•Unittotalpoerconsumptionexceedsxy%outofmaxunitpoer
•Unittotalpoerconsumptionasrestoredtolessthanxy%outofmax
unitpoer
Notifyexceededpoerusage
(1–99%)
Ifenabled,userisnotiedheneverunittotalpoerconsumption(xy%)percentageout
ofunitmaxpoerexceedsordropsbelospeciedvalue.
SNMPv3
Parameterescription
EnableSNMPv3EnableordisableSNMPv3support.
UsernameCongureSNMPv3usernamestring.
AuthenticationpassordCongureSNMPv3passordtobeusedbyMD5/SHA.
PrivacypassordCongureSNMPv3passordtobeusedbyDES/AES.
AuthenticationandencryptionmodeConguretheSNMPv3authenticationandencryptionmode.
None—noauthenticationorencryption,hichmeansnosecurity.
MD5—MD5authenticationithnoencryption.Packetcanbechanged,bycaneasilybe
analyzedbynetorksniffers.
SHA—SHAauthenticationithnoencryption.
MD5+DES—MD5authenticationandDESencryption
SHA+DES—SHAauthenticationandDESencryption
MD5+AES—MD5authenticationandAESencryption
SHA+AES—SHAathenticationandAESencryption
SNMPv3notication(Trap)
Parameterescription
UsernameCongureSNMPv3noticationusernamestring.
AuthenticationpassordCongureSNMPv3noticationpassordtobeusedbyMD5/SHA.
PrivacypassordCongureSNMPv3noticationpassordtobeusedbyDES/AES.
AuthenticationandencryptionmodeConguretheSNMPv3noticationauthenticationandencryptionmode.
None—noauthenticationorencryption,hichmeansnosecurity.
MD5—MD5authenticationithnoencryption.Packetcanbechanged,bycaneasilybe
analyzedbynetorksniffers.
SHA—SHAauthenticationithnoencryption.
MD5+DES—MD5authenticationandDESencryption
SHA+DES—SHAauthenticationandDESencryption
MD5+AES—MD5authenticationandAESencryption
SHA+AES—SHAathenticationandAESencryption
RemoteIPv4/IPv6SNMPtrapmanagers(v2c/v3)
Parameterescription
Trapmanager#1ConguretherstIPv4/IPv6/DNSnameofremoteSNMPmanagerserverreceivingunit
trapreportssuchasCold-Start,etc.
Trapmanager#2CongurethesecondIPv4/IPv6/DNSnameofremoteSNMPmanagerserverreceiving
unittrapreportssuchasCold-Start,etc.
13

AXIST8504–EOutdoorPoESwitch
Webinterface
Maintenance
Reset-Therearefourdifferentresetoptions:
•oasaferestartwithoutlosingPoEpowerresetstheinternalnetorkmanagerandtheinternalEthernet
sitch(netorkillbedonforafeseconds),leavingthePoEpoerunchanged.Poereddevicescontinue
normaloperationsasifnoresetisdone.
•oasaferestartresetstheinternalnetorkmanager,internalPoEcontrollerandinternalEthernetsitch.
•RestorethefactoryvaluesbutkeeptheIPsettingsresetsunitcongurationtofactorydefault,leavingIPv4/IPv6
netorkcongurationunchanged.VLANandRADIUS/TACACS+isdisabled.Theoptiontoaccesstheunitoverthe
netorkasbeforeismaintained.
•Restoreallfactoryvaluesrestorestheunittofulldefaultfactorysetting.UnitIPissetto192.168.0.254and
VLANisdisabled.
Firmwareupgrade-Armareupgradeupgradesonlytheinternalnetorkmanager.PoErmareisunchanged.Theupgradecan
takeupto10minutes.Duringthistimenetorksitchingfunctionalityremainsuninterrupted,buttheunitisunmanageable.PoE
functionalityremainsactive,butnetorktrafcmaybeinterruptedforseveralseconds.
Productconguration-GotoProductcongurationtodonloadoruploadaproductcongurationle.Thisfunctionalitycan
beusedtobackupunitconguration,modifyunitcongurationofineortocreateamastercongurationletoeasilycongure
severalunits.
14

AXIST8504–EOutdoorPoESwitch
SSHserialinterface
SSHserialinterface
TheSSHinterfaceisdesignedforvariousmaintenancetaskssuchasPoErmareupdateetc.Itisdesignedtoprovideaneasyand
convenientinterfaceforITmanagershoarefamiliarithSSH.TosimplifySSHusage,theSSHinterfaceismenu-driven.
SSHispassordprotectedandsharesthesameusernameandpassordasforebaccess.
SSHsupportsRADIUSandTACACS+usernameandpassordauthentication.
Note
OnlyoneremoteuseratatimecanaccesstheunitoverSSH.IncaseasecondremoteSSHusertriestoaccesstheunit
hiletherstSSHuserisstillactive,amessageisshontothesecondSSHuser,requestingtheusertotryandreconnect
overSSHlater.
Note
Non-activeSSHsessions(nokeystrokesbytheremoteuser)areterminatedautomaticallyafterthreeminutes.
Mainmenu
Toeasilyidentifytheaccessedunit,theunithostnamestringisshontotherightoftheMainmenutitle.Thisisespecially
usefulhentheuserhasmultipleunits.
Viewmenu
ViewmenuprovidesinformationonPoEportsstatus,netorkparametersandunitinformation.
Menuitemescription
1.ViePoEportsstatusGotothismenuitemtogetthefolloinginformation:
•Netork—InformationaboutEthernetlinkspeed(10/100/1000)andHD/FD
connectiontype
•PoE—Informationaboutpoerconsumptionforeachconnecteddevice
•Totalpoer—Informationabouttotalpoerconsumptionofallpoered
devicesconnectedtoallactivePoEports.Alsoshosmaximumavailable
poer.
•Poersupply—Informationaboutinternalpoersupplyvoltagefortheunit
15

AXIST8504–EOutdoorPoESwitch
SSHserialinterface
2.VienetorkparametersGotothismenuitemtogetthefolloinginformation:
•In-useIPv4netorkparameters—ShosifDHCPv4isenabledordisabled.
Alsoshosthein-useIPv4address,IPv4maskandIPv4defaultgateay.
•In-useIPv6netorkparameters—ShosifDHCPv6isenabledordisabled.
Alsoshosthein-useIPv6address,IPv6prexandIPv6defaultgateay.
IPv6canreportseveralIPv6addresseshichereobtainedautomaticallyin
additiontoastatic/DHCPv6IPv6address.
•In-useDNSnetorkparameters—Informationaboutin-useIPv4/IPv6
domainnameserverIPs,hichareconguredstaticallyorobtainedby
DHCPv4/DHCPv6.
•Morenetorkparameters—InformationabouttheunitMACaddress
3.VieunitinformationGotothismenuitemtogetasummaryofunitproductionparameters:
•Partnumber—Informationaboutunitmarketingpartnumber(T8504–E)
•S/N—Informationaboutunitsix-digitserialnumber
•Productnumber—Informationaboutunitproductionnumber(forinternal
useonly)
•Appver—Informationaboutnetorkmanagersoftareversion
•Bootver—Informationaboutnetorkmanagerbootversion
•Firmare—PoErmareversion
•Systemuptime—Informationaboutthetimepassedsincetheunitas
resetorpoeredup
•SystemGMTtime—InformationaboutunitGMTtimeasitasobtainedfrom
anNTPserver.WhenevertheunitisunabletoobtainNTPtimefromanNTP
server,themessage“incorrect”isshon.
•Systemlocaltime—Informationaboutunitlocaltime(GMTplustimezone
shift).WhenevertheunitisunabletoobtainNTPtimefromanNTPserver,
themessage“incorrect”isshon.
Congurationandmaintenancemenu
GotoCongurationandmaintenancemenutocongureorresettheunitortoupdatesoftare.
Menuitemescription
1.Enable/DisablePoEportEnableordisableaPoEport.Ethernetlinkremainsenabledevenhennopoeris
provided.
2.DonloadWEBSSLcerticatefrom
TFTPserver(resetonlyebserver)
Donloadself-signedorCAsignedcerticatesfromaTFTPserver,toallosecureeb
brosingtotheunitithsecurityconrmationbytheebbroser(greenlockinthe
ebbroserURLarea)
3.UpdateunitPoErmare(reset
unit)
UpdatePoErmare.UpdatelesaredonloadedfromaTFTPserver.PoEfunctionalityis
notavailableduringthermareupdate(approximately5–10minutes).
4.Restoreunittosemifactorydefault
(excludingIPconguration)
Restoretheunitcongurationtofactorydefault,butleavestheIPv4/IPv6netork
congurationunchanged.Thismaintainstheoptiontoaccesstheunitoverthenetork
asbefore.
5.RestoreunittofullfactorydefaultRestoretheentireunittofullfactorydefault.
6.ResetonlynetorkmanagerResetonlytheinternalnetorkmanager,hichisresponsibleforunitnetork
managementinterfacessuchastheeb,SSH,SNMP,etc.InternalEthernetsitchisalso
reset;thenetorkillbedonforafeseconds.OnlyPoEpoerisunchanged.Poered
devicescontinuenormaloperationasifnoresetasdone.
16

AXIST8504–EOutdoorPoESwitch
SSHserialinterface
7.ResetunitResettheentireunitincludingtheinternalnetorkmanager,PoEcontrollerandinternal
Ethernetsitch.
8.Enable/Disableautoping
defaultgateaytoensurenetork
connectivity
Enableordisableautopingtodefaultgateay.Whenenabled,theunitveriesproper
netorkconnectivitybypingingdefaultgateayevery12seconds(IPv4DGWorIPv6
DGW).After10consecutivepingfailures,netorkmanagementmoduleresetsitself
ithoutaffectingPoEports.
Pingremotehost
GotoPingremotehosttotestnetorkconnectivityissues.
17

AXIST8504–EOutdoorPoESwitch
SNMPmonitoringandconfiguration
SNMPmonitoringandconfiguration
Multipleunitscanbemonitoredandmanagedbyusingthird-partystandardnetorkmanagementtoolssuchasHPOpenvie,
IBMTivoli,SNMPcetc.
EnabeSNMP
ThenetorkmanagerinterfacesupportsSNMPv1,SNMPv2andSNMPv3.TheunitacceptsandrepliestoSNMPv1packets,butsince
SNMPv1isobsolete,SNMPtrapsandnoticationsaresentinSNMPv2,SNMPv3orboth.
Note
Duetosecurityreasons,theunitisshippedithSNMPv2andSNMPv3disabled.PriortoenablingSNMP,itishighly
recommendedtomodifySNMPcommunitystringsbeforeenablingit.
ToenableSNMP:
•GotoSecurity>SNMMPcongurationandenableSNMPv2orSNMPv3.
•MakesurethatSNMPv2communitystringsmatchyourSNMPmanagerconguration.
•MakesureSNMPv3username,authenticationpassord,privacypassordandencryptionmethodsmatchyourSNMP
managerconguration.
Toenabletraps:
•GotoRemoteIPv4/IPv6SNMPtrapmanagersandconguretheremotemanagerIPaddress.
•MakesureSNMPv3noticationusername,authenticationpassord,privacypassordandencryptionmethodsmatchyour
SNMPtrapmanagerconguration.
•GotoPoEMIBandenablePoEnoticationstogetnoticationsaboutchangesinPoEportstatus,unitpoerconsumption
exceedsorfallsbeloacertainleveletc.
SNMPMIBs
SeveralMIBsaresupportedbytheSNMPmanager.
NetworkMIBs-VariousnetorkMIBs,suchasRFC1213MIB-II,canbeusedforprovidingnetorkstatistics.NotethattheseMIBs
arenotintendedtobeusedfornetorkcongurationoverSNMP.
RFC3621-PoeroverEthernet(PoE)MIBhichprovidesvariousPoEcapabilities.SeeRFC3621PoEIBonpage18.
PrivateMIB-EnhancesPoEfunctionalitybeyondRFC3621PoEMIB.SeePrivateIBonpage19.
RFC3621PoEMIB
RFC3621PoEMIBislocatedunderthe1.3.6.1.2.1.105SNMPMIBtree.TheMIBisdividedintothreesections.
Portparameters-TherstsectionhandlesPoEportsandprovidesfunctionalitysuchasenableanddisableports,readportstatus,
class,etc.EachOiDisaccessedasato-dimensionalarraytable.
MainPSEparameters-ThesecondsectionhandlesthepoersourcethatprovidespoertoagroupofPoEports.Itenables
readingthetotalpoerconsumption,poersupplystatus,etc.
PoEtraps-ThethirdsectionenablesanddisablesPoEtrapstobesenttoremoteSNMPmanagers.
18

AXIST8504–EOutdoorPoESwitch
SNMPmonitoringandconfiguration
PrivateMIB
ThefolloingSNMPOiDsaresupportedbytheSNMPprivateMIB:
OinameType(R/W)escription
poePortConsumptionPoerRPoEportpoerconsumption[Watt]
poePortMaxPoerRPoEportmaximumavailablepoer[Watt]
poePortTypeRPoEporttype—topair,30[Watt],fourpair,60
[Watt]
mainVoltageRUnitpoersupplyvoltage[Volt]
19

AXIST8504–EOutdoorPoESwitch
SysLogMessage
SysLogMessage
TheunitsendsvariouseventreportstoanexternalIPv4/IPv6hostrunningaSysLogdaemonapplication.TheIPv4/IPv6hostlogs
theeventsforfutureuse.CongureSysLogserverIPaddressbybrosingtotheunitcongurationebpageifSysLogevents
aretobesent.
Therearethreecategoriesoflogevents:
BroadcastIPv4SysLogevents-TheselogeventsaretobeinterceptedbyanySysLogserverontheLANregardlessofunitSysLog
conguration.ThisfacilitateslocatingofunitIPonthenetorkandreportingofmajoreventssuchasunitrecoveryfrompoer
failure,etc.
RFC3621PoEtraps-RFC3621PoEtrapsarealsosentasSysLogmessages,hichsimpliesthereadabilityofsucheventsforthe
remoteuser.
ProprietarySysLogevents-Theselogeventsincludepotentialfailuresorpotentialsecuritybreachesashenaremoteuser
triestoaccessithincorrectusernameovereb/SSH,etc.
SysLogmessagetypes
MessageIescriptionInformationprovidedComments
0SystemUPissenthenpoeris
providedtotheunitortheinternal
netorkmanagerresetsitself.
•Applicationversion
•Bootversion
•Resetcause
•Bootstatus
•Unithostname
•UnitMACaddress
•VLAN(Yes/No)
Ifyes,VLANIDisalso
provided.VLANIDis
usedtomanagethe
unit.Whichportandif
theportisconguredas
AccessorTrunk.
•IPv4address
(static/HDCPv4)
•AllIPv6address
(static/DHCPv6)
Messageissentinbroadcastformat
255.255.255.255toanySysLog
serverconnectedoverLANandto
SysLogserver1and2.
1PoEportstatuschangedissent
henPoEportstatusischanged,
suchashenadeviceisinsertedor
removed.
NePoEstateasdenedinRFC3621
(searching,deliveringpoer,fault,
etc.)
RFC3621SNMPPoEMIB,trap
equivalentSysLogreport
2PoEpowerusageexceedsxy%out
ofpowersupplymaximumpower
issenthenthePoEpoerusage
exceedsthesetvalue.
Poerusageinpercentoutofpoer
supplymaximumpoer
RFC3621SNMPPoEMIB,trap
equivalentSysLogreport
3PoEpowerusageislessthanxy%
outofpowersuplymaximum
powerissenthenthePoEpoer
usagegoesbelothesetvalue.
Poerusageinpercentoutofpoer
supplymaximumpoer
RFC3621SNMPPoEMIB,trap
equivalentSysLogreport
6efaultcongurationissent
henunitisrestoredtodefault
conguration
SysLogserverIPisunchanged
hentheunitisrestoredtodefault
conguration.
20
Other manuals for T8504-E
1
Table of contents
Other Axis Switch manuals

Axis
Axis 30 W Midspan AC/DC User manual

Axis
Axis T86 Series User manual

Axis
Axis T8120 User manual

Axis
Axis T85 User manual

Axis
Axis T8504-R User manual

Axis
Axis Dome Intrusion Switch C User manual

Axis
Axis T8524 PoE+ User manual

Axis
Axis T8120 Midspan 1-port User manual

Axis
Axis F41 User manual

Axis
Axis D8004 User manual