Cisco Small Business 300 Series Managed Switches Administration
Total Page:16
File Type:pdf, Size:1020Kb
ADMINISTRATION GUIDE Cisco Small Business 300 Series Managed Switch Administration Guide Release 1.3.5 Contents Table of Contents Chapter 1: Getting Started 1 Starting the Web-based Configuration Utility 1 Quick Start Device Configuration 4 Interface Naming Conventions 5 /Window Navigation 7 Chapter 2: Status and Statistics 11 System Summary 11 Viewing Ethernet Interfaces 11 Viewing Etherlike Statistics 13 Viewing 802.1X EAP Statistics 14 Health 15 Managing RMON 15 View Log 23 Chapter 3: Administration: System Log 24 Setting System Log Settings 24 Setting Remote Logging Settings 26 Viewing Memory Logs 28 Chapter 4: Administration: File Management 30 System Files 30 Upgrade/Backup Firmware/Language 33 Download/Backup Configuration/Log 37 Configuration Files Properties 42 Copy/Save Configuration 43 Auto Configuration via DHCP 44 Cisco Small Business 300 Series Managed Switch Administration Guide 1 Contents Chapter 5: Administration 51 Device Models 51 System Settings 53 Management Interface 55 User Accounts 55 Defining Idle Session Timeout 55 Time Settings 56 System Log 56 File Management 56 Rebooting the Device 56 Health 58 Diagnostics 59 Discovery - Bonjour 59 Discovery - LLDP 59 Discovery - CDP 60 Ping 60 Chapter 6: Administration: Time Settings 62 System Time Options 63 SNTP Modes 64 Configuring System Time 65 Chapter 7: Administration: Diagnostics 73 Testing Copper Ports 73 Displaying Optical Module Status 75 Configuring Port and VLAN Mirroring 77 Viewing CPU Utilization and Secure Core Technology 78 Chapter 8: Administration: Discovery 80 Bonjour 80 Cisco Small Business 300 Series Managed Switch Administration Guide 2 Contents LLDP and CDP 81 Configuring LLDP 82 Configuring CDP 102 Chapter 9: Administration: Unidirectional Link Detection 112 UDLD Overview 112 UDLD Operation 113 Usage Guidelines 116 Dependencies On Other Features 116 Default Settings and Configuration 117 Before You Start 117 Common UDLD Tasks 117 Configuring UDLD 118 Chapter 10: Port Management 122 Configuring Ports 122 Setting Port Configuration 123 Link Aggregation 127 PoE 134 Configuring Green Ethernet 134 Chapter 11: Smartport 143 Overview 143 What is a Smartport 144 Smartport Types 144 Smartport Macros 147 Macro Failure and the Reset Operation 148 How the Smartport Feature Works 149 Auto Smartport 149 Error Handling 153 Cisco Small Business 300 Series Managed Switch Administration Guide 3 Contents Default Configuration 153 Relationships with Other Features and Backwards Compatibility 154 Common Smartport Tasks 154 Configuring Smartport Using The Web-based Interface 156 Built-in Smartport Macros 161 Chapter 12: Port Management: PoE 174 PoE on the Device 174 Configuring PoE Properties 177 Configuring PoE Settings 178 Chapter 13: VLAN Management 181 VLANs 181 Configuring Default VLAN Settings 184 Creating VLANs 185 Configuring VLAN Interface Settings 186 Defining VLAN Membership 187 Voice VLAN 190 Chapter 14: Spanning Tree 204 STP Flavors 204 Configuring STP Status and Global Settings 205 Defining Spanning Tree Interface Settings 207 Configuring Rapid Spanning Tree Settings 209 Chapter 15: Managing MAC Address Tables 212 Configuring Static MAC Addresses 213 Managing Dynamic MAC Addresses 214 Chapter 16: Multicast 216 Multicast Forwarding 216 Cisco Small Business 300 Series Managed Switch Administration Guide 4 Contents Defining Multicast Properties 219 Adding MAC Group Address 220 Adding IP Multicast Group Addresses 222 Configuring IGMP Snooping 224 MLD Snooping 226 Querying IGMP/MLD IP Multicast Group 228 Defining Multicast Router Ports 229 Defining Forward All Multicast 230 Defining Unregistered Multicast Settings 231 Chapter 17: IP Configuration 234 Overview 234 IPv4 Management and Interfaces 236 Domain Name 250 Chapter 18: Security 256 Defining Users 257 Configuring RADIUS 260 264 Management Access Method 264 Management Access Authentication 269 Secure Sensitive Data Management 270 SSL Server 270 SSH Client 272 Configuring TCP/UDP Services 273 Defining Storm Control 274 Configuring Port Security 275 802.1X 278 Denial of Service Prevention 278 Cisco Small Business 300 Series Managed Switch Administration Guide 5 Contents Chapter 19: Security: 802.1X Authentication 282 Overview of 802.1X 282 Authenticator Overview 284 Common Tasks 288 802.1X Configuration Through the GUI 289 Chapter 20: Security: First Hop Security 296 First Hop Security Overview 297 Router Advertisement Guard 301 Neighbor Discovery Inspection 301 DHCPv6 Guard 302 Neighbor Binding Integrity 303 Attack Protection 305 Policies, Global Parameters and System Defaults 307 Common Tasks 308 Default Settings and Configuration 310 Before You Start 311 Configuring First Hop Security through Web GUI 311 Chapter 21: Security: Secure Sensitive Data Management 323 Introduction 323 SSD Rules 324 SSD Properties 329 Configuration Files 332 SSD Management Channels 337 Menu CLI and Password Recovery 337 Configuring SSD 338 Chapter 22: Security: SSH Client 341 Secure Copy (SCP) and SSH 341 Cisco Small Business 300 Series Managed Switch Administration Guide 6 Contents Protection Methods 342 SSH Server Authentication 344 SSH Client Authentication 345 Before You Begin 346 Common Tasks 346 SSH Client Configuration Through the GUI 348 Chapter 23: Security: SSH Server 352 Overview 352 Common Tasks 353 SSH Server Configuration Pages 354 Chapter 24: Access Control 358 Access Control Lists 358 Defining MAC-based ACLs 360 IPv4-based ACLs 363 IPv6-Based ACLs 367 Defining ACL Binding 371 Chapter 25: Quality of Service 373 QoS Features and Components 374 Configuring QoS - General 375 Managing QoS Statistics 384 Chapter 26: SNMP 387 SNMP Versions and Workflow 387 Model OIDs 390 SNMP Engine ID 391 Configuring SNMP Views 393 Creating SNMP Groups 394 Cisco Small Business 300 Series Managed Switch Administration Guide 7 Contents Managing SNMP Users 396 Defining SNMP Communities 398 Defining Trap Settings 400 Notification Recipients 400 SNMP Notification Filters 405 Cisco Small Business 300 Series Managed Switch Administration Guide 8 Contents Cisco Small Business 300 Series Managed Switch Administration Guide 9 1 Getting Started This section provides an introduction to the web-based configuration utility, and covers the following topics: • Starting the Web-based Configuration Utility • Quick Start Device Configuration • Interface Naming Conventions • Window Navigation Starting the Web-based Configuration Utility This section describes how to navigate the web-based switch configuration utility. If you are using a pop-up blocker, make sure it is disabled. Browser Restrictions If you are using IPv6 interfaces on your management station, use the IPv6 global address and not the IPv6 link local address to access the device from your browser. Launching the Configuration Utility To open the web-based configuration utility: STEP 1 Open a Web browser. STEP 2 Enter the IP address of the device you are configuring in the address bar on the browser, and then press Enter. Cisco Small Business 200, 300 and 500 Series Managed Switch Administration Guide (Internal Version) 1 Getting Started 1 Starting the Web-based Configuration Utility NOTE When the device is using the factory default IP address of 192.168.1.254, its power LED flashes continuously. When the device is using a DHCP assigned IP address or an administrator-configured static IP address, the power LED is on solid. Logging In The default username is cisco and the default password is cisco. The first time that you log in with the default username and password, you are required to enter a new password. NOTE If you have not previously selected a language for the GUI, the language of the Login page is determined by the language(s) requested by your browser and the languages configured on your device. If your browser requests Chinese, for example, and Chinese has been loaded into your device, the Login page is automatically displayed in Chinese. If Chinese has not been loaded into your device, the Login page appears in English. The languages loaded into the device have a language and country code (en-US, en-GB and so on). For the Login page to be automatically displayed in a particular language, based on the browser request, both the language and country code of the browser request must match those of the language loaded on the device. If the browser request contains only the language code without a country code (for example: fr). The first embedded language with a matching language code is taken (without matching the country code, for example: fr_CA). To log in to the device configuration utility: STEP 1 Enter the username/password. The password can contain up to 64 ASCII characters. Password-complexity rules are described in the Setting Password Complexity Rules section of the Configuring Security chapter. STEP 2 If you are not using English, select the desired language from the Language drop- down menu. To add a new language to the device or update a current one, refer to the Upgrade/Backup Firmware/Language section. STEP 3 If this is the first time that you logged on with the default user ID (cisco) and the default password (cisco) or your password has expired, the Change Password Page appears. See Password Expiration for additional information. STEP 4 Choose whether to select Disable Password Complexity Enforcement or not. For more information on password complexity, see the Setting Password Complexity Rules section. STEP 5 Enter the new password and click Apply. 2 Cisco Small Business 200, 300 and 500 Series Managed Switch Administration Guide (Internal Version) Getting