Reference Manual: Web-Based Interface Industrial ETHERNET (Gigabit) Switch RS20/RS30/RS40, MS20/MS30, OCTOPUS
Reference Manual: Web-Based Interface Industrial ETHERNET (Gigabit) Switch RS20/RS30/RS40, MS20/MS30, OCTOPUS
Web-based Interface
Industrial ETHERNET (Gigabit) Switch
RS20/RS30/RS40, MS20/MS30, OCTOPUS
Manuals and software are protected by copyright. All rights reserved. The copying, reproduction,
translation, conversion into any electronic medium or machine scannable form is not permitted,
either in whole or in part. An exception is the preparation of a backup copy of the software for
your own use. For devices with embedded software, the end-user license agreement on the
enclosed CD applies.
The performance features described here are binding only if they have been expressly agreed
when the contract was made. This document was produced by Hirschmann Automation and
Control GmbH according to the best of the company's knowledge. Hirschmann reserves the right
to change the contents of this document without prior notice. Hirschmann can give no guarantee
in respect of the correctness or accuracy of the information in this document.
Hirschmann can accept no responsibility for damages, resulting from the use of the network
components or the associated operating software. In addition, we refer to the conditions of use
specified in the license contract.
You can get the latest version of this manual on the Internet at the Hirschmann product site
(www.beldensolutions.com).
Printed in Germany
Hirschmann Automation and Control GmbH
Stuttgarter Str. 45-51
72654 Neckartenzlingen
Germany
Tel.: +49 1805 141538
Key 9
1 Basic Settings 15
1.1 System 16
1.2 Network 21
1.3 Software 23
1.3.1 View the software versions present on the device 23
1.3.2 TFTP Software Update 24
1.3.3 HTTP Software Update 24
1.3.4 Automatic software update by ACA 25
1.4 Port Configuration 26
1.5 Power over ETHERNET 28
1.6 Loading/Saving the Configuration 31
1.6.1 Loading a Configuration 32
1.6.2 Saving the Configuration 32
1.6.3 URL 33
1.6.4 Deleting a configuration 34
1.6.5 Using the AutoConfiguration Adapter (ACA) 34
1.6.6 Canceling a configuration change 36
1.7 Restart 37
2 Security 39
2.1 Password / SNMPv3 access 40
2.2 SNMPv1/v2 Access Settings 43
2.3 Telnet/Web Access 46
2.3.1 Description of Telnet Access 47
2.3.2 Description of Web Access 47
2.4 Port Security 48
3 Time 51
Contents
4 Switching 79
4.1 Switching Global 80
4.2 Filters for MAC addresses 84
4.3 Rate Limiter 86
4.3.1 Rate Limiter settings 86
4.4 Multicasts 89
4.4.1 IGMP (Internet Group Management Protocol) 89
4.5 VLAN 97
4.5.1 VLAN Global 97
4.5.2 Current VLAN 100
4.5.3 VLAN Static 102
4.5.4 VLAN Port 105
5 QoS/Priority 107
5.1 Global 108
5.2 Port Configuration 111
5.2.1 Entering the port priority 112
5.3 802.1D/p mapping 113
5.4 IP DSCP mapping 115
6 Redundancy 117
6.1 Ring Redundancy 118
6.1.1 Configuring the HIPER-Ring 120
6.1.2 Configuring the MRP-Ring 124
6.2 Ring/Network Coupling 127
6.2.1 Preparing a Ring/Network Coupling 127
6.3 Spanning Tree 134
RM Web L2E
4 Release 7.0 05/2011
Contents
7 Diagnostics 153
7.1 Syslog 154
7.2 Trap Log 159
7.3 Ports 160
7.3.1 Statistics table 160
7.3.2 Network Load 161
7.3.3 SFP modules 162
7.4 Topology Discovery 164
7.4.1 LLDP Information from Neighbor Devices 164
7.5 Port Mirroring 166
7.6 Device Status 168
7.7 Signal contact 171
7.7.1 Manual Setting 171
7.7.2 Function monitoring 171
7.7.3 Device status 173
7.7.4 Trap Configuration 173
7.8 Alarms (Traps) 175
7.9 Report 178
7.9.1 180
7.9.2 Event Log 180
7.10 IP address conflict detection 181
7.11 Self Test 183
7.12 Service Mode 184
7.12.1 Activating the service mode 185
7.12.2 Deactivating the service mode 186
8 Advanced 189
8.1 DHCP Relay Agent 190
8.2 Industrial Protocols 192
8.2.1 PROFINET IO 192
8.2.2 EtherNet/IP 194
8.3 Command Line 195
A Appendix 197
RM Web L2E
Release 7.0 05/2011 5
Contents
B Index 207
RM Web L2E
6 Release 7.0 05/2011
About this Manual
The “Basic Configuration” user manual contains the information you need to
start operating the device. It takes you step by step from the first startup
operation through to the basic settings for operation in your environment.
The “Industry Protocols” user manual describes how the device is connected
by means of a communication protocol commonly used in the industry, such
as EtherNet/IP or PROFINET IO.
RM Web L2E
Release 7.0 05/2011 7
About this Manual
RM Web L2E
8 Release 7.0 05/2011
Key
Key
List
Work step
Subheading
Link Cross-reference with link
Note: A note emphasizes an important fact or draws your attention to a dependency.
Courier ASCII representation in user interface
Symbols used:
Router
Switch
Bridge
RM Web L2E
Release 7.0 05/2011 9
Key
Hub
A random computer
Configuration Computer
Server
PLC -
Programmable logic
controller
I/O -
Robot
RM Web L2E
10 Release 7.0 05/2011
Opening the Web-based Interface
To open the Web-based interface, you need a Web browser (a program that
can read hypertext), for example Mozilla Firefox version 1 or later, or
Microsoft Internet Explorer version 6 or later.
RM Web L2E
Release 7.0 05/2011 11
Opening the Web-based Interface
Click on OK.
Note: The changes you make in the dialogs will be copied to the device when
you click “Set”. Click “Reload” to update the display.
To save any changes made so that they will be retained after a power cycle
or reboot of the device use the save option on the "Load/Save" dialog (see
page 31 “Loading/Saving the Configuration“)
RM Web L2E
12 Release 7.0 05/2011
Opening the Web-based Interface
Note: If you enter an incorrect configuration, you may block access to your
device.
Activating the function “Cancel configuration change” in the “Load/Save”
dialog enables you to return automatically to the last configuration after a set
time period has elapsed. This gives you back your access to the device.
RM Web L2E
Release 7.0 05/2011 13
Opening the Web-based Interface
The menu section displays the menu items. By placing the mouse pointer in
the menu section and clicking the alternate mouse button you can use “Back”
to return to a menu item you have already selected, or “Forward” to jump to
a menu item you have already selected.
RM Web L2E
14 Release 7.0 05/2011
Basic Settings
1 Basic Settings
The Basic Settings menu contains the dialogs, displays and tables for the
basic configuration:
System
Network
Software
Port Configuration
Power over Ethernet
Load/Save
Restart
RM Web L2E
Release 7.0 05/2011 15
Basic Settings 1.1 System
1.1 System
Device Status
System data
Device view
Reloading data
Device Status
This section of the website provides information on the device status and
the alarm states the device has detected.
RM Web L2E
16 Release 7.0 05/2011
Basic Settings 1.1 System
1 2 3
System Data
This area of the Web-based interface displays the system parameters of
the device. Here you can change the following settings:
– the system name,
– the location description,
– the name of the contact person for this device,
– the availability of the media modules (see fig. 6)
– the temperature threshold values.
Name Meaning
Name System name of this device
Location Location of this device
Contact The contact for this device
Basic module Hardware version of the device
Media module 1 Hardware version of media module 1
Media module 2 Hardware version of media module 2
Media module 3 Hardware version of media module 3
Media module 4 Hardware version of media module 4
Media module 5 Hardware version of media module 5
Media module 6 Hardware version of media module 6
Media module 7 Hardware version of media module 7
Power supply (P1/P2) Status of power units (P1/P2)
Uptime Time that has elapsed since this device was last restarted.
Temperature Temperature of the device. Lower/upper temperature
threshold values. If the temperature goes outside this range,
the device generates an alarm.
RM Web L2E
Release 7.0 05/2011 17
Basic Settings 1.1 System
1 2 3
Device View
The device view shows the device with the current configuration. The
status of the individual ports is indicated by one of the symbols listed
below. You will get a full description of the port's status by positioning the
mouse pointer over the port's symbol.
RM Web L2E
18 Release 7.0 05/2011
Basic Settings 1.1 System
Updating
This area of the website at the bottom left displays the countdown time
until the applet requests the current data of this dialog again. Clicking the
"Reload" button calls the current dialog information immediately.
The applet polls the current data of the device automatically every
100 seconds.
RM Web L2E
Release 7.0 05/2011 19
Basic Settings 1.1 System
RM Web L2E
20 Release 7.0 05/2011
Basic Settings 1.2 Network
1.2 Network
With the Basic settings:Network dialog you define the source from
which the device gets its IP parameters after starting, and you assign the IP
parameters and VLAN ID and configure the HiDiscovery access.
Under “Mode”, you enter where the device gets its IP parameters:
In the BOOTP mode, the configuration is via a BOOTP or DHCP
server on the basis of the MAC address of the device (see on page 31
“Loading/Saving the Configuration“).
In the DHCP mode, the configuration is via a DHCP server on the
basis of the MAC address or the name of the device (see on page 31
“Loading/Saving the Configuration“).
In the local mode the net parameters in the device memory are used.
RM Web L2E
Release 7.0 05/2011 21
Basic Settings 1.2 Network
You enter the name applicable to the DHCP protocol in the “Name” line in
the system dialog of the Web-based interface.
Note: When you change the network mode from ”Local“ to ”BOOTP“ or
”DHCP“, the server will assign a new IP address to the device. If the server
does not respond, the IP address will be set to 0.0.0.0, and the BOOTP/
DHCP process will try to obtain an IP address again.
RM Web L2E
22 Release 7.0 05/2011
Basic Settings 1.3 Software
1.3 Software
The software dialog enables you to display the software versions in the
device and to carry out a software update of the device via file selection, tftp
or AutoConfiguration Adapter (ACA).
RM Web L2E
Release 7.0 05/2011 23
Basic Settings 1.3 Software
Stored Version
The software version stored in the flash memory.
Running Version
The currently loaded software version.
RM Web L2E
24 Release 7.0 05/2011
Basic Settings 1.3 Software
File not found (reason: file name not found or does not exist).
Connection error (reason: path without file name).
After the update is completed successfully, you activate the new software:
Select the Basic settings: Restart dialog and perform a cold start.
In a cold start, the device reloads the software from the non-volatile
memory, restarts, and performs a self-test.
In your browser, click on “Reload” so that you can access the device again
after it is booted.
RM Web L2E
Release 7.0 05/2011 25
Basic Settings 1.4 Port Configuration
This configuration table allows you to configure each port of the device and
also display each port‘s current mode of operation (link state, bit rate (speed)
and duplex mode).
In the “Name” column, you can enter a name for every port.
In the “Ports on” column, you can switch on the port by selecting it here.
In the “Propagate connection error” column, you can specify that a link
alarm will be forwarded to the device status and/or the the signal contact
is to be opened.
In the “Automatic Configuration” column, you can activate the automatic
selection of the the operating mode (Autonegotiation) and the automatic
assigning of the connections (Auto cable crossing) of a TP port by
selecting the appropriate field. After the autonegotiation has been
switched on, it takes a few seconds for the operating mode to be set.
In the “Manual Configuration” column, you can set the operating mode for
this port. The choice of operating modes depends on the media module.
The possible operating modes are:
– 10 Mbit/s half duplex (HDX)
– 10 Mbit/s full duplex (FDX)
– 100 Mbit/s half duplex (HDX)
– 100 Mbit/s full duplex (FDX)
– 1000 Mbit/s half duplex (HDX)
– 1000 Mbit/s full duplex (FDX)
– 10 Gbit/s full duplex (FDX)
The “Link/Current Operating Mode” column displays the current operating
mode and thereby also an existing connection.
In the “Cable Crossing (Auto. Conf. off)” column, you assign the
connections of a TP port, if “Automatic Configuration” is deactivated for
this port. The possible settings are:
– enable: the device swaps the send and receive line pairs of the
TP cable for this port (MDIX).
– disable: the device does not swap the send and receive line pairs of
the TP cable for this port (MDI).
– unsupported: the port does not support this function (optical port,
TP SFP port).
In the “Flow Control” column, you checkmark this port to specify that flow
control is active here. You also activate the global “Flow Control” switch
(see on page 80 “Switching Global“).
RM Web L2E
26 Release 7.0 05/2011
Basic Settings 1.4 Port Configuration
Note: The active automatic configuration has priority over the manual
configuration.
Note: When you are using a redundancy function, you deactivate the flow
control on the participating ports. Default setting: flow control deactivated
globally and activated on all ports.
If the flow control and the redundancy function are active at the same time,
the redundancy may not work as intended.
Note: The following settings are required for the ring ports in a HIPER-Ring:
When you switch the DIP switch for the ring ports, the device sets the
required settings for the ring ports in the configuration table. The port, which
has been switched from a ring port to a normal port, is given the settings
Autonegotiation (automatic configuration) on and Port on. The settings
remain changeable for all ports.
RM Web L2E
Release 7.0 05/2011 27
Basic Settings 1.5 Power over ETHERNET
Note: The following devices are equipped with Power over Ethernet (PoE)
ports:
RS20/30
MS20/30
PowerMICE
Octopus
You will learn in this section how these devices operate.
Devices with Power over ETHERNET (PoE) media modules or PoE ports
enable you to supply current to terminal devices such as IP phones via the
twisted-pair cable. PoE media modules and PoE ports support Power over
ETHERNET in accordance with IEEE 802.3af.
The Power over ETHERNET function is activated globally and at all PoE-
capable ports on delivery.
RM Web L2E
28 Release 7.0 05/2011
Basic Settings 1.5 Power over ETHERNET
Frame "Operation":
With “Function On/Off” you turn the PoE on or off.
Frame "Configuration":
„Verschicke Trap" bietet Ihnen die Möglichkeit, das Gerät zu veranlassen,
in folgenden Fällen einen Trap zu senden:
– beim Überschreiten/Unterschreiten der Leistungsschwelle.
– beim Ein-/Ausschalten der PoE-Versorgungsspannung an
mindestens einem Port.
In „Threshold“ (Leistungsschwelle) geben Sie die Leistungsschwelle an,
bei deren Überschreiten/Unterschreiten das Gerät ein Trap sendet,
sofern „Verschicke Trap" eingeschaltet ist. Die Leistungsschwelle geben
Sie in Prozent der abgegebenen Leistung zur nominalen Leistung ein.
"Nominale Leistung" zeigt die Leistung an, die das Gerät nominal für alle
PoE-Ports zusammen zur Verfügung stellt.
„Reservierte Leistung“ zeigt an, wieviel Leistung das Gerät allen
angeschlossenen PoE-Geräten zusammen auf Grund ihrer
Klassifizierung maximal zur Verfügung stellt.
"Abgegebene Leistung" zeigt an, wie groß der momentane
Leistungsbedarf an allen PoE-Ports ist.
With “Send Trap” you can get the device to send a trap in the following
cases:
– If a value exceeds/falls below the performance threshold.
– If the PoE supply voltage is switched on/off at at least one port.
Enter the power threshold in “Threshold”. When this value is exceeded/
not achieved, the device will send a trap, provided that “Send Trap” is
enabled. For the power threshold you enter the power yielded as a
percentage of the nominal power.
“Nominal Power” displays the power that the device nominally provides
for all PoE ports together.
“Reserved Power” displays the maximum power that the device provides
to all the connected PoE devices together on the basis of their
classification.
“Delivered Power” shows how large the current power requirement is at
all PoE ports.
The difference between the "nominal" and "reserved" power indicates how
much power is still available to the free PoE+ ports.
Port Table:
The table only shows ports that support PoE.
In the “POE on” column, you can enable/disable PoE at this port.
RM Web L2E
Release 7.0 05/2011 29
Basic Settings 1.5 Power over ETHERNET
RM Web L2E
30 Release 7.0 05/2011
Basic Settings 1.6 Loading/Saving the Configuration
RM Web L2E
Release 7.0 05/2011 31
Basic Settings 1.6 Loading/Saving the Configuration
If you change the current configuration (for example, by switching a port off),
the Web-based interface changes the “load/save” symbol in the navigation
tree from a disk symbol to a yellow triangle. After saving the configuration,
the Web-based interface displays the “load/save” symbol as a disk again.
RM Web L2E
32 Release 7.0 05/2011
Basic Settings 1.6 Loading/Saving the Configuration
If you change the current configuration (for example, by switching a port off),
the Web-based interface changes the “load/save” symbol in the navigation
tree from a disk symbol to a yellow triangle. After saving the configuration,
the Web-based interface displays the “load/save” symbol as a disk again.
After you have successfully saved the configuration on the device, the device
sends an alarm (trap) hmConfigurationSavedTrap together with the
information about the AutoConfiguration Adapter (ACA), if one is connected.
When you change the configuration for the first time after saving it, the device
sends a trap hmConfigurationChangedTrap.
1.6.3 URL
The URL identifies the path to the tftp server on which the configuration file
is to be stored. The URL is in the format: tftp://IP address of the tftp server/
path name/file name (e.g. tftp://192.168.1.100/device/
config.dat).
RM Web L2E
Release 7.0 05/2011 33
Basic Settings 1.6 Loading/Saving the Configuration
Note: The configuration file includes all configuration data, including the
passwords for accessing the device. Therefore, pay attention to the access
rights on the tftp server.
Note: If you replace a device with DIP switches, check that the DIP switch
settings to be sure that they are the same.
RM Web L2E
34 Release 7.0 05/2011
Basic Settings 1.6 Loading/Saving the Configuration
Note: Before loading the configuration data from the ACA, the device
compares the password in the device with the password in the ACA
configuration data.
Status Meaning
notPresent No ACA present
ok The configuration data from the ACA and the device
match.
removed The ACA was removed after booting.
notInSync - The configuration data of the ACA and the device do
not match, or only one file existsa,
or
- no configuration file is present on the ACA or on the
deviceb.
outOfMemory The local configuration data is too extensive to be
stored on the ACA.
wrongMachine The configuration data in the ACA originate from a
different device type and cannot be read or converted.
checksumErr The configuration data are damaged.
RM Web L2E
Release 7.0 05/2011 35
Basic Settings 1.6 Loading/Saving the Configuration
a
In cases like this the ACA status is the same as the "ACA not in sync“
status which sends "Not OK“ to the signal contacts and the device status.
b
In this case the ACA status ("notInSync") differs from the "ACA not in
sync" status which sends “OK” to the signal contacts and the device
status.
Function
If the function is activated and the connection to the device is interrupted
for longer than the time specified in the field “Period to undo while
connection is lost [s]”, the device then loads the last configuration saved.
Activate the function before you configure the device so that you will
then be reconnected if an incorrect configuration interrupts your
connection to the device.
Enter the “Period to undo while the connection is lost [s]” in seconds.
Possible values: 10-600 seconds.
Default setting: 600 seconds.
Note: Deactivate the function after you have successfully saved the
configuration. In this way you prevent the device from reloading the
configuration after you close the web interface.
Note: If you access the device cia ssh, additionally note the TCP
connection timeouts for the canceling of a configuration change.
Watchdog IP address
“Watchdog IP address” shows you the IP address of the PC from which
you have activated the (watchdog) function. The device monitors the link
to the PC with this IP address, checking for interruptions.
RM Web L2E
36 Release 7.0 05/2011
Basic Settings 1.7 Restart
1.7 Restart
initiate a cold start of the device. The device reloads the software from the
non-volatile memory, restarts, and performs a self-test.
Reload the website in your browser to reaccess the device after
restarting.
initiate a warm start of the device. In this case the device checks the
software in the volatile memory and restarts. If a warm start is not
possible, the device automatically performs a cold start.
reset the entries with the status “learned” in the filter table (MAC address
table).
reset the ARP table.
The device maintains an ARP table internally.
If, for example, you assign a new IP address to a computer and
subsequently cannot set up a connection to the device, you then reset the
ARP table.
reset the port counters.
delete the log file.
Note: During the restart, the device temporarily does not transfer any data,
and it cannot be accessed via the Web-based interface or other management
systems such as HiVision.
RM Web L2E
Release 7.0 05/2011 37
Basic Settings 1.7 Restart
RM Web L2E
38 Release 7.0 05/2011
Security 1.7 Restart
2 Security
The “Security” menu contains the dialogs, displays and tables for configuring
the security settings:
Password/SNMPv3 access
SNMPv1/v2 access
Telnet/Web access
Port security
RM Web L2E
Release 7.0 05/2011 39
Security 2.1 Password / SNMPv3 access
This dialog gives you the option of changing the read and read/write
passwords for access to the device via the Web-based interface, via the CLI,
and via SNMPv3 (SNMP version 3).
Set different passwords for the read password and the read/write password
so that a user that only has read access (user name “user”) does not know,
or cannot guess, the password for read/write access (user name “admin”).
If you set identical passwords, when you attempt to write this data the device
reports a general error.
The Web-based interface and the user interface (CLI) use the same
passwords as SNMPv3 for the users “admin” and “user”.
RM Web L2E
40 Release 7.0 05/2011
Security 2.1 Password / SNMPv3 access
Note: If you do not know a password with “read/write” access, you will not
have write access to the device.
Note: For security reasons, the device does not display the passwords.
Make a note of every change. You cannot access the device without a valid
password.
Note: For security reasons, SNMPv3 encrypts the password. With the
“SNMPv1” or “SNMPv2” setting in the dialog Security:SNMPv1/v2
access, the device transfers the password unencrypted, so that this can
also be read.
Note: Use between 5 and 32 characters for the password in SNMPv3, since
many applications do not accept shorter passwords.
RM Web L2E
Release 7.0 05/2011 41
Security 2.1 Password / SNMPv3 access
You can block access via a Web browser or Telnet client in a separate dialog
(see on page 46 “Telnet/Web Access“).
RM Web L2E
42 Release 7.0 05/2011
Security 2.2 SNMPv1/v2 Access Settings
With this dialog you can select access via SNMPv1 or SNMPv2. In the state
on delivery, both protocols are activated.
You can thus manage the device with HiVision and communicate with earlier
versions of SNMP.
Note: To be able to read and/or change the data in this dialog, log in to the
Web-based interface with the user name “admin” and the relevant password.
In the “IP Address” column, you enter the IP address which may access
the device. No entry in this field, or the entry “0.0.0.0”, allows access to
this device from computers with any IP address. In this case, the only
access protection is the password.
In the “IP Mask” column, much the same as with netmasks, you have the
option of selecting a group of IP addresses.
Example:
255.255.255.255: a single IP address
255.255.255.240 with IP address = 172.168.23.20:
the IP addresses 172.168.23.16 to 172.168.23.31.
RM Web L2E
Release 7.0 05/2011 43
Security 2.2 SNMPv1/v2 Access Settings
In the “Access Mode” column, you specify whether this computer can
access the device with the read password (access mode “readOnly”) or
with the read/write password (access mode “readWrite”).
Note: The password for the “readOnly” access mode is the same as the
SNMPv3 password for read access.
The password for the “readWrite” access mode is the same as the
SNMPv3 password for read/write access.
If you are changing one of the passwords, manually set the
corresponding password for SNMPv3 to the same value (see on
page 40 “Password / SNMPv3 access“). This way you ensure that you
can also access with the same password via SNMPv3.
Note: If you have not activated any row, the device does not apply any
access restriction with regard to the IP addresses.
Note: The device prevents deleting or changing the row with the password
currently in use.
RM Web L2E
44 Release 7.0 05/2011
Security 2.2 SNMPv1/v2 Access Settings
RM Web L2E
Release 7.0 05/2011 45
Security 2.3 Telnet/Web Access
This dialog allows you to switch off the Telnet server and the Web server on
the device.
RM Web L2E
46 Release 7.0 05/2011
Security 2.3 Telnet/Web Access
After the Web server has been switched off, it is no longer possible to log in
via a Web browser. The login in the open browser window remains active.
Note: The Command Line Interface allows you to reactivate the Web server.
RM Web L2E
Release 7.0 05/2011 47
Security 2.4 Port Security
The device allows you to configure each port to help prevent unauthorized
access. Depending on your selection, the device checks the MAC address or
the IP address of the connected device.
In the “Configuration” frame, you set whether the port security works with
MAC or with IP addresses.
Name Meaning
MAC-Based Port Security Check source MAC address of the received data packet.
IP-Based Port Security IP-Based Port Security internally relies on MAC-Based Port
Security.
Principle of operation:
When you configure the function, the device translates the
entered source IP address into the respective MAC address. In
operation, it checks the source MAC address of the received
data packet against the internally stored MAC address.
Set the individual parameters for each port in the port table.
Name Meaning
Module.Port Port identification using module and port numbers of the device,
e.g. 2.1 for port one of module two.
Port Status enabled: Port is switched on and transmitting.
disabled: Port is switched off and not transmitting.
The port is switched on if
- an authorized address accesses the port
or
- an unauthorized address attempts to access the port and
trapOnly or none is selected under “Action”.
The port is switched off if
- an unauthorized address attempts to access the port and
portDisable is selected under “Action”.
RM Web L2E
48 Release 7.0 05/2011
Security 2.4 Port Security
Name Meaning
Allowed MAC Addresses MAC addresses of the devices with which you allow data exchange
at this port.
The Web-based interface allows you to enter up to 50 MAC
addresses, each separated by a space. After each MAC address
you can enter a slash followed by a number identifying an address
area. This number, between 2 and 47, indicates the number of
relevant bits. Example:
00:80:63:01:02:00/40 stands for
00:80:63:01:02:00 to 00:80:63:01:02:FF
or
00:80:63:00:00:00/24 stands for
00:80:63:00:00:00 to 00:80:63:FF:FF:FF
If there is no entry, any number of devices can communicate via this
port.
Current MAC Address Shows the MAC address of the device from which the port last
received data. The Web-based interface allows you to copy an entry
from the “Current MAC Address” column into the “Allowed MAC
Addresses” column by dragging and dropping with the mouse
button.
Allowed IP Addresses IP addresses of the devices with which you allow data exchange at
this port.
The Web-based interface allows you to enter up to 10 IP addresses,
each separated by a space.
If there is no entry, any number of devices can communicate via this
port.
Action Action performed by the device after an unauthorized access:
– none: no action
– trapOnly: send alarm
– portDisable: disable the port with the corresponding entry in
the port configuration table (see on page 26 “Port
Configuration“) and send an alarm.
Note: This entry in the port configuration table is part of the configuration
(see on page 31 “Loading/Saving the Configuration“) and is saved together
with the configuration.
Note: Prerequisites for the device to be able to send an alarm (trap) (see on
page 175 “Alarms (Traps)“):
– You have entered at least one recipient
– You have selected at least one recipient in the “Active” column
– In the “Selection” frame, you have selected “Port Security”.
RM Web L2E
Release 7.0 05/2011 49
Security 2.4 Port Security
RM Web L2E
50 Release 7.0 05/2011
Time 2.4 Port Security
3 Time
With this dialog you can enter time-related settings independently of the time
synchronization protocol selected.
The “System Time (UTC)” displays the time with reference to Universal
Time Coordinated.
The time displayed is the same worldwide. Local time differences are not
taken into account.
The ”system time” uses "System Time (UTC)", allowing for the local time
difference from "System Time (UTC)".
“System time” = “System Time (UTC)” + “local offset”.
“Time source” displays the source of the following time data. The device
automatically selects the source with the greatest accuracy.
Possible sources are: local, ptp and sntp. The source is initially
local.
If PTP is activated and the device receives a valid PTP frame, it sets its
time source to ptp. If SNTP is activated and if the device receives a valid
SNTP packet, the device sets its time source to sntp. The device gives
the PTP time source priority over SNTP
With “Set time from PC”, the device takes the PC time as the system time
and calculates the system time (UTC) using the local time difference.
“System Time (UTC)” = “system time” - “local offset”
The “local offset” is for displaying/entering the time difference between the
local time and the “System Time (UTC)”.
With ”Set offset from PC“, the device determines the time zone on your
PC and uses it to calculate the local time difference.
Note: When setting the time in zones with summer and winter times, make
an adjustment for the local offset, if applicable. The device can also get the
SNTP server IP address and the local offset from a DHCP server.
RM Web L2E
Release 7.0 05/2011 51
Time 2.4 Port Security
RM Web L2E
52 Release 7.0 05/2011
Time 3.1 SNTP configuration
The Simple Network Time Protocol (SNTP) enables you to synchronize the
system time in your network.
The device supports the SNTP client and the SNTP server function.
The SNTP server makes the UTC (Universal Time Coordinated) available.
UTC is the time relating to the coordinated world time measurement. The
time displayed is the same worldwide. Local time differences are not taken
into account.
SNTP uses the same packet format as NTP. In this way, an SNTP client can
receive the time from an SNTP server as well as from an NTP server.
Note: For accurate system time distribution with cascaded SNTP servers
and clients, use only network components (routers, switches, hubs) in the
signal path between the SNTP server and the SNTP client which forward
SNTP packets with a minimized delay.
RM Web L2E
Release 7.0 05/2011 53
Time 3.1 SNTP configuration
Note: If you have enabled PTP at the same time, the SNTP client first
collects 60 time stamps before it deactivates itself. The device thus
determines the drift compensation for its PTP clock. With the preset server
request interval, this takes about half an hour.
Note: If you are receiving the system time from an external/redundant server
address, switch off the reception of SNTP Broadcasts (see “Accept SNTP
Broadcasts”). You thus ensure that the device only takes the time from a
defined SNTP server.
RM Web L2E
54 Release 7.0 05/2011
Time 3.1 SNTP configuration
Table 10: Destination address classes for SNTP and NTP packets
RM Web L2E
Release 7.0 05/2011 55
Time 3.1 SNTP configuration
RM Web L2E
56 Release 7.0 05/2011
Time 3.2 PTP (IEEE 1588)
Devices without PTP hardware support, which only have ports absent a
time stamp unit, support the PTP simple mode. This mode gives a less
accurate division of time.
With these devices
enable/disable the PTP function in the PTP Dialog,
select PTP mode in the PTP Dialog.
– Select v1-simple-mode if the reference clock uses PTP Version 1.
– Select v2-simple-mode, if the reference clock uses PTP Version 2.
Note: In the simple mode a device synchronizes itself with PTP messages
received. This mode provides a precision comparable to SNTP absent other
functions, such as PTP management or runtime measuring.
If you want to transport PTP time accurately through your network, only use
devices with PTP hardware support on the transport paths.
Devices with PTP hardware support, which have ports with a time stamp
unit, support other modes subject to the version of the time stamp unit.
MS20, MS30 and PowerMICE devices with the modules
– MM3-4TX1-RT
– MM3-2FXM2/2TX1-RT
– MM3-2FXS2/2TX1-RT
– MM3-2FLM4/2TX1-RT
RM Web L2E
Release 7.0 05/2011 57
Time 3.2 PTP (IEEE 1588)
RM Web L2E
58 Release 7.0 05/2011
Time 3.2 PTP (IEEE 1588)
RM Web L2E
Release 7.0 05/2011 59
Time 3.2 PTP (IEEE 1588)
Table 11: Selecting the PTP version and the PTP mode
1. For the MS20, MS30 and PowerMICE devices with MM23 or MM33
modules, (see on page 57 “PTP (IEEE 1588)“.)
RM Web L2E
60 Release 7.0 05/2011
Time 3.2 PTP (IEEE 1588)
RM Web L2E
Release 7.0 05/2011 61
Time 3.2 PTP (IEEE 1588)
RM Web L2E
62 Release 7.0 05/2011
Time 3.2 PTP (IEEE 1588)
RM Web L2E
Release 7.0 05/2011 63
Time 3.2 PTP (IEEE 1588)
RM Web L2E
64 Release 7.0 05/2011
Time 3.2 PTP (IEEE 1588)
Note: PTPv1 uses as the device UUID 48 bits which are identical to the
MAC address of the particular device.
RM Web L2E
Release 7.0 05/2011 65
Time 3.2 PTP (IEEE 1588)
You select the PTP version you will use in the Time:PTP:Global dialog.
Global
RM Web L2E
66 Release 7.0 05/2011
Time 3.2 PTP (IEEE 1588)
Note: PTPv2 uses as the device UUID 64 bits, consisting of the device's
MAC address, between whose No. 3 and No. 4 bytes the values ff and fe
are added.
A port UUID consists of the device UUID followed by a 16-bit port ID.
The device displays UUIDs as a byte sequence in hexadecimal notation.
RM Web L2E
Release 7.0 05/2011 67
Time 3.2 PTP (IEEE 1588)
RM Web L2E
68 Release 7.0 05/2011
Time 3.2 PTP (IEEE 1588)
Port
RM Web L2E
Release 7.0 05/2011 69
Time 3.2 PTP (IEEE 1588)
RM Web L2E
70 Release 7.0 05/2011
Time 3.2 PTP (IEEE 1588)
RM Web L2E
Release 7.0 05/2011 71
Time 3.2 PTP (IEEE 1588)
Note:
Also take the port's VLAN
setting (see on page 102 “VLAN
Static“) into account here, in
particular whether the VLAN
exists and if the port is a tagged
or untagged member in the
VLAN.
none: The device always
sends PTP frames absent a
VLAN tag, even if the port is a
tagged member of the VLAN.
You can select VLANs that
you have already set up using of
the table row drop-down list.
VLAN Priority The VLAN priority (Layer 2, 0 - 7 0
IEEE 802.1p) with which the device
sends PTP frames to this port.
If you have set the VLAN ID to none,
the device ignores the VLAN priority.
For the MS20, MS30 and PowerMICE devices with MM23 or MM33
modules:
The following settings enable you to also use the TC for Unicast PTP
messages:
– Selecting the E2E mechanism
RM Web L2E
72 Release 7.0 05/2011
Time 3.2 PTP (IEEE 1588)
– Syntonize disabled
– PTP Management disabled.
You select the PTP version you will use in the Time:PTP:Global dialog.
RM Web L2E
Release 7.0 05/2011 73
Time 3.2 PTP (IEEE 1588)
RM Web L2E
74 Release 7.0 05/2011
Time 3.2 PTP (IEEE 1588)
RM Web L2E
Release 7.0 05/2011 75
Time 3.2 PTP (IEEE 1588)
Note:
Also take the port's VLAN
setting (see on page 102 “VLAN
Static“) into account here, in
particular whether the VLAN
exists and if the the port is a
tagged or untagged member in
the VLAN.
none: The device always
sends PTP frames absent a
VLAN tag, even if the port is a
tagged member of the VLAN.
You can select VLANs that
you have already set up using of
the table row drop-down list.
VLAN Priority The VLAN priority (Layer 2, 0 - 7 0
IEEE 802.1p) with which the device
sends tagged PTP frames.
If you have set the VLAN ID to
none, the device ignores the VLAN
priority.
RM Web L2E
76 Release 7.0 05/2011
Time 3.2 PTP (IEEE 1588)
Note: PTPv2 uses as the device UUID 64 bits, consisting of the device's
MAC address, between whose No. 3 and No. 4 bytes the values ff and fe
are added.
A port UUID consists of the device UUID followed by a 16-bit port ID.
The device displays UUIDs as a byte sequence in hexadecimal notation.
RM Web L2E
Release 7.0 05/2011 77
Time 3.2 PTP (IEEE 1588)
RM Web L2E
78 Release 7.0 05/2011
Switching 3.2 PTP (IEEE 1588)
4 Switching
The switching menu contains the dialogs, displays and tables for configuring
the switching settings:
Switching Global
Filters for MAC Addresses
Rate Limiter
Multicasts
VLAN
RM Web L2E
Release 7.0 05/2011 79
Switching 4.1 Switching Global
Note: When you are using a redundancy function, you deactivate the flow
control on the participating ports. Default setting: flow control deactivated
globally and activated on all ports.
If the flow control and the redundancy function are active at the same time,
the redundancy may not work as intended.
RM Web L2E
80 Release 7.0 05/2011
Switching 4.1 Switching Global
The following table lists the duplex operating modes for TX ports together
with the possible error events. The terms in the table mean:
Collisions: In half-duplex mode, collisions mean normal operation.
Duplex problem: Duplex modes do not match.
EMI: Electromagnetic interference.
Network extension: The network extension too great, or too many hubs
are cascaded.
RM Web L2E
Release 7.0 05/2011 81
Switching 4.1 Switching Global
Collisions, late collisions: In full-duplex mode, the port does not count
collisions or late collisions.
CRC error: The device only evaluates these errors as duplex mismatches
in the manual full duplex mode.
RM Web L2E
82 Release 7.0 05/2011
Switching 4.1 Switching Global
RM Web L2E
Release 7.0 05/2011 83
Switching 4.2 Filters for MAC addresses
The filter table for MAC addresses is used to display and edit filters. Each row
represents one filter. Filters specify the way in which data packets are sent.
They are set automatically by the device (learned status) or manually. Data
packets whose destination address is entered in the table are sent from the
receiving port to the ports marked in the table. Data packets whose
destination address is not in the table are sent from the receiving port to all
other ports. The following conditions are possible:
learned: The filter was created automatically by the device.
invalid: With this status you delete a manually created filter.
permanent: The filter is stored permanently in the device or on the URL
(see on page 31 “Loading/Saving the Configuration“).
igmp: The filter was created by IGMP Snooping.
In the “Create” dialog (see buttons below), you can create new filters.
RM Web L2E
84 Release 7.0 05/2011
Switching 4.2 Filters for MAC addresses
Note: For Unicast addresses, the device allows you to include one or no
ports in a filter entry. Do not include any ports if you want to create a discard
filter entry.
Note: The filter table allows you to create up to 100 filter entries for Multicast
addresses.
RM Web L2E
Release 7.0 05/2011 85
Switching 4.3 Rate Limiter
To ensure reliable operation at a high level of traffic, the device allows you to
limit the rate of traffic at the ports.
Entering a limit rate for each port determines the amount of traffic the device
is permitted to transmit and receive.
If the traffic at this port exceeds the maximum rate entered, then the device
suppresses the overload at this port.
Note: The limiter functions only work on Layer 2 and are used to limit the
effect of storms by frame types that the Switch floods (typically broadcasts).
In doing so, the limiter function disregards the protocol information of higher
layers, such as IP or TCP. This can affect on TCP traffic, for example.
You can minimize these effects by:
limiting the limiter function to particular frame types (e.g. to broadcasts,
multicasts and unicasts with unlearned destination addresses) and
receiving unicasts with destination addresses established by the
limitation,
using the output limiter function instead of the input limiter function
because the former works slightly better together with the TCP flow
control due to switch-internal buffering.
increasing the aging time for learned unicast addresses.
RM Web L2E
86 Release 7.0 05/2011
Switching 4.3 Rate Limiter
RM Web L2E
Release 7.0 05/2011 87
Switching 4.3 Rate Limiter
RM Web L2E
88 Release 7.0 05/2011
Switching 4.4 Multicasts
4.4 Multicasts
Operation
In this frame you can:
RM Web L2E
Release 7.0 05/2011 89
Switching 4.4 Multicasts
RM Web L2E
90 Release 7.0 05/2011
Switching 4.4 Multicasts
The parameters
– Max. Response Time,
– Send Interval and
– Group Membership Interval
have a relationship to one another:
Max. Response Time < Send Interval < Group Membership Interval.
If you enter values that contradict this relationship, the device then
replaces these values with a default value or with the last valid values.
RM Web L2E
Release 7.0 05/2011 91
Switching 4.4 Multicasts
Multicasts
In this frame you specify how the device transmits packets with
unknown MAC/IP multicast addresses not learned with IGMP
Snooping
known MAC/IP multicast addresses learned with IGMP Snooping.
RM Web L2E
92 Release 7.0 05/2011
Switching 4.4 Multicasts
RM Web L2E
Release 7.0 05/2011 93
Switching 4.4 Multicasts
RM Web L2E
94 Release 7.0 05/2011
Switching 4.4 Multicasts
RM Web L2E
Release 7.0 05/2011 95
Switching 4.4 Multicasts
Note: If the device is incorporated into a HIPER-Ring, you can use the
following settings to quickly reconfigure the network for data packets with
registered Multicast destination addresses after the ring is switched:
Switch on the IGMP Snooping on the ring ports and globally, and
activate “IGMP Forward All” per port on the ring ports.
RM Web L2E
96 Release 7.0 05/2011
Switching 4.5 VLAN
4.5 VLAN
VLAN contains dialogs and attributes for configuring and monitoring the
VLAN function in accordance with the IEEE 802.1Q standard.
Parameter Meaning
Biggest VLAN ID Displays the biggest possible VLAN ID (see on page 102 “VLAN
Static“)
Max. Number of Displays the maximum number of VLANs (see on page 102 “VLAN
VLANs Static“).
VLANs Configured Displays the number of VLANs configured (see on page 102 “VLAN
Static“).
Note: The device provides the VLAN with the ID 1. The VLAN with ID 1 is
always present.
RM Web L2E
Release 7.0 05/2011 97
Switching 4.5 VLAN
Note: If you are using the GOOSE protocol in accordance with IEC61850-8-
1, then you activate the “VLAN 0 transparent mode”. In this way, the
prioritizing information remains in the data packet in accordance with
IEEE802.1D/p when the device forwards the data packet.
This also applies to other protocols that use this prioritizing in accordance
with IEEE 802.1D/p, but do not require any VLANs according to
IEEE 802.1Q.
Note: When using the “Transparent Mode” in this way, note the following:
For RS20/RS30/RS40, MS20/MS30, RSR20/RSR30, MACH 100,
MACH 1000 and OCTOPUS:
In “Transparent mode”, the devices ignore the port VLAN ID set. Set the
VLAN membership of the ports of VLAN 1 to U (Untagged) or T (Tagged),
(see on page 102 “VLAN Static“).
RM Web L2E
98 Release 7.0 05/2011
Switching 4.5 VLAN
RM Web L2E
Release 7.0 05/2011 99
Switching 4.5 VLAN
RM Web L2E
100 Release 7.0 05/2011
Switching 4.5 VLAN
RM Web L2E
Release 7.0 05/2011 101
Switching 4.5 VLAN
RM Web L2E
102 Release 7.0 05/2011
Switching 4.5 VLAN
Note: When configuring the VLAN, ensure that the management station still
has access to the device after the VLAN configuration is saved.
You achieve this by connecting the management station to a port that is a
member in VLAN 1. The device transmits the data of the management
station in VLAN 1.
Note: The device automatically creates VLANs for MRP rings. The MRP ring
function prevents the deletion of these VLANs.
Note: Note the tagging settings for ports (see table 40) that are part of a
redundant Ring or the Ring/network coupling.
RM Web L2E
Release 7.0 05/2011 103
Switching 4.5 VLAN
Table 40: Required VLAN settings for ports that are part of redundant Rings or Ring/
Network coupling.
Note: In a redundant ring with VLANs, you should only operate devices
whose software version supports VLANs:
RS2 xx/xx (from rel. 7.00)
RS2-16M
RS20, RS30, RS40 (with software variants L2E, L2P)
MICE (from rel. 3.0)
PowerMICE
MS20, MS30
RSR20, RSR30
MACH 100
MACH 1000
MACH 4000
MACH 3000 (from Rel. 3.3),
OCTOPUS
RM Web L2E
104 Release 7.0 05/2011
Switching 4.5 VLAN
RM Web L2E
Release 7.0 05/2011 105
Switching 4.5 VLAN
RM Web L2E
106 Release 7.0 05/2011
QoS/Priority 4.5 VLAN
5 QoS/Priority
The QoS/Priority menu contains the dialogs, displays and tables for
configuring the QoS/priority settings:
Global
Port configuration
IEEE 802.1D/p mapping
IP DSCP mapping
RM Web L2E
Release 7.0 05/2011 107
QoS/Priority 5.1 Global
5.1 Global
Note: Certain DSCP values have DSCP names, such as be/cs0 to cs7
(class selector) or af11 to af43 (assured forwarding) and ef (expedited
forwarding).
RM Web L2E
108 Release 7.0 05/2011
QoS/Priority 5.1 Global
“trustDot1p”:
The device prioritizes received packets that contain VLAN tag
information according to this information (assigning them to a traffic
class - see “802.1D/p mapping“).
The device prioritizes received packets that do not contain any tag
information (assigning them to a traffic class - see “Entering the port
priority“) according to the port priority of the receiving port .
“trustIpDscp”:
The device prioritizes received IP packets (assigning them to a traffic
class - see “IP DSCP mapping“) according to their DSCP value.
The device prioritizes received packets that are not IP packets
(assigning them to a traffic class - see “Entering the port priority“)
according to the port priority of the receiving port .
For received IP packets:
The device also performs VLAN priority remarking.
In VLAN priority remarking, the device modifies the VLAN priority of
the IP packets if the packets are to be sent with a VLAN tag (see on
page 102 “VLAN Static“).
Based on the traffic class to which the IP packet was assigned (see
above), the device assigns the new VLAN priority to the IP packet in
accordance with table 42.
Example: A received IP packet with a DSCP value of 32 (cs4) is
assigned to traffic class 2 (default setting). The packet was received at
a port with port priority 2. Based on table 42, the VLAN priority is set
to 4.
Note: Changing the global setting for „Trust Mode“ and clicking “Set“ will set
all ports‘ settings at once. You can then modifiy each port's settings
individually.
Changing the global setting again will overwrite the individual port settings.
RM Web L2E
Release 7.0 05/2011 109
QoS/Priority 5.1 Global
RM Web L2E
110 Release 7.0 05/2011
QoS/Priority 5.2 Port Configuration
Parameter Meaning
Module Module of the device on which the port is located.
Port Port to which this entry applies.
Port priority Enter the port priority.
RM Web L2E
Release 7.0 05/2011 111
QoS/Priority 5.2 Port Configuration
Port priority Traffic class (default setting) IEEE 802.1D traffic type
0 1 Best effort (default)
1 0 Background
2 0 Standard
3 1 Excellent effort (business critical)
4 2 Controlled load (streaming multimedia)
5 2 Video, < 100 ms of latency and jitter
6 3 Voice, < 10 ms of latency and jitter
7 3 Network control reserved traffic
RM Web L2E
112 Release 7.0 05/2011
QoS/Priority 5.3 802.1D/p mapping
The 802.1D/p mapping dialog allows you to assign a traffic class to every
VLAN priority.
Enter the desired value from 0 to 3 in the Traffic Class field for every
VLAN priority.
RM Web L2E
Release 7.0 05/2011 113
QoS/Priority 5.3 802.1D/p mapping
Port priority Traffic class (default setting) IEEE 802.1D traffic type
0 1 Best effort (default)
1 0 Background
2 0 Standard
3 1 Excellent effort (business critical)
4 2 Controlled load (streaming multimedia)
5 2 Video, < 100 ms of latency and jitter
6 3 Voice, < 10 ms of latency and jitter
7 3 Network control reserved traffic
Note: Network protocols and redundancy mechanisms use the highest traffic
class 3. Therefore, select other traffic classes for application data.
RM Web L2E
114 Release 7.0 05/2011
QoS/Priority 5.4 IP DSCP mapping
The IP DSCP mapping table allows you to assign a traffic class to every
DSCP value.
Enter the desired value from 0 to 3 in the Traffic Class field for every
DSCP value (0-63).
The different DSCP values get the device to employ a different forwarding
behavior, namely Per-Hop Behavior (PHB).
PHB classes:
Class Selector (CS0-CS7): For reasons of compatibility to TOS/IP
Precedence
Expedited Forwarding (EF): Premium service.
Reduced delay, jitter + packet loss (RFC 2598)
RM Web L2E
Release 7.0 05/2011 115
QoS/Priority 5.4 IP DSCP mapping
Table 46: Mapping the DSCP values onto the traffic classes
RM Web L2E
116 Release 7.0 05/2011
Redundancy 5.4 IP DSCP mapping
6 Redundancy
Under Redundancy you will find the dialogs and views for configuring and
monitoring the redundancy functions:
Ring Redundancy
Ring/Network coupling
Spanning Tree
RM Web L2E
Release 7.0 05/2011 117
Redundancy 6.1 Ring Redundancy
Depending on the device model, the Ring Redundancy dialog allows you to:
Select one of the available Ring Redundancy versions, or change it.
Display an overview of the current Ring Redundancy configuration.
RM Web L2E
118 Release 7.0 05/2011
Redundancy 6.1 Ring Redundancy
Note: Only one Ring Redundancy method can be enabled on one device at
any one time. When changing to another Ring Redundancy method,
deactivate the function for the time being.
Parameter Meaning
Version Select the Ring Redundancy version you want to use:
HIPER-Ring
MRP
Default setting is HIPER-Ring
Ring port No. In a ring, every device has 2 neighbors. Define 2 ports as ring ports to which the
neighboring devices are connected.
Module Module identifier of the ports used as ring ports
Port Port identifier of the ports used as ring ports
Operation Value depends on the Ring Redundancy version used. Described in the
following sections for the corresponding Ring Redundancy version.
RM Web L2E
Release 7.0 05/2011 119
Redundancy 6.1 Ring Redundancy
Note: Configure all the devices of the HIPER-Ring individually. Before you
connect the redundant line, you must complete the configuration of all the
devices of the HIPER-Ring. You thus avoid loops during the configuration
phase.
Parameter Meaning
Ring port X.X operation Display in “Operation” field:
active: This port is switched on and has a link.
inactive: This port is switched off or it has no link.
Ring Manager Status Status information, no input possible:
Active (redundant line): The redundant line was closed
because a data line or a network component within the ring failed.
Inactive: The redundant ring is open, and all data lines and
network components are working.
RM Web L2E
120 Release 7.0 05/2011
Redundancy 6.1 Ring Redundancy
Parameter Meaning
Ring Recovery The settings in the ”Ring Recovery“ frame are only effective for
devices that are ring managers.
In the ring manager, select the desired value for the test packet
timeout for which the ring manager waits after sending a test
packet before it evaluates the test packet as lost.
Standard: test packet timeout 480 ms
Accelerated: test packet timeout 280 ms
RM Web L2E
Release 7.0 05/2011 121
Redundancy 6.1 Ring Redundancy
Figure 34: Selecting ring redundancy, entering ring ports, enabling/disabling ring
manager and selecting ring recovery.
Note: Deactivate the Spanning Tree protocol (STP) for the ports connected
to the redundant ring, because the Spanning Tree and the Ring Redundancy
work with different reaction times (Redundancy:Spanning Tree:Port).
If you used the DIP switch to activate the HIPER-Ring function, STP is
automatically switched off.
Note: If you have configured VLANs, note the VLAN configuration of the ring
ports.
In the configuration of the HIPER-Ring, you select for the ring ports
– VLAN ID 1 and
– VLAN membership Untagged in the static VLAN table.
RM Web L2E
122 Release 7.0 05/2011
Redundancy 6.1 Ring Redundancy
RM Web L2E
Release 7.0 05/2011 123
Redundancy 6.1 Ring Redundancy
Note: Configure all the devices of the MRP-Ring individually. Before you
connect the redundant line, you must have completed the configuration of all
the devices of the MRP-Ring. You thus avoid loops during the configuration
phase.
Parameter Meaning
Ring port X.X Display in “Operation” field:
operation forwarding: This port is switched on and has a link.
blocked: This port is blocked and has a link.
disabled: This port is switched off.
not connected: This port has no link.
Ring Manager Deactivate the advanced mode if a device in the ring does not support the
Configuration advanced mode for fast switching times. Otherwise you activate the advanced
mode.
Note: All Hirschmann devices that support the MRP-Ring also support the
advanced mode.
Operation When you have configured all the parameters for the MRP-Ring, you switch the
operation on with this setting. When you have configured all the devices in the
MRP-Ring, you close the redundant line.
RM Web L2E
124 Release 7.0 05/2011
Redundancy 6.1 Ring Redundancy
Parameter Meaning
Ring Recovery For the device for which you have activated the ring manager, select the value
200 ms if the stability of the ring meets the requirements for your network.
Otherwise select 500 ms.
Note: Settings in the “Ring Recovery” frame are only effective for devices that
are ring managers.
VLAN ID If you have configured VLANs, you select
VLAN ID 0 here if you do not want to assign the MRP-Ring configuration to a
VLAN. Note the VLAN configuration of the ring ports: Select for VLAN ID 1 and
VLAN membership U in the static VLAN table for the ring ports.
VLAN ID > 0 if you want to assign the MRP-Ring configuration to this VLAN.
Select this VLAN ID in the MRP-Ring configuration for all devices in this MRP-
Ring. Note the VLAN configuration of the ring ports: For all ring ports in this
MRP-Ring, select this corresponding VLAN ID and the VLAN membership T in
the static VLAN table.
Information If the device is a ring manager: The displays in this frame mean:
“Redundancy working”: When a component of the ring is down, the redundant
line takes over its function.
“Configuration failure”: You have configured the function incorrectly, or there is
no ring port connection.
Figure 35: Selecting MRP-Ring version, entering ring ports and enabling/disabling
ring manager
RM Web L2E
Release 7.0 05/2011 125
Redundancy 6.1 Ring Redundancy
Note: For all devices in an MRP-Ring, activate the MRP compatibility in the
Redundancy:Spanning Tree:Global dialog if you want to use RSTP in
the MRP-Ring. If this is not possible, perhaps because individual devices do
not support the MRP compatibility, you deactivate the Spanning Tree
protocol at the ports connected to the MRP-Ring. Spanning Tree and Ring
Redundancy affect each other.
Note: If you combine RSTP with an MRP-Ring, you must give the devices in
the MRP-Ring a better (i.e. numerically lower) RSTP bridge priority than the
devices in the connected RSTP network. You thus help avoid a connection
interruption for devices outside the Ring.
RM Web L2E
126 Release 7.0 05/2011
Redundancy 6.2 Ring/Network Coupling
STAND-BY switch
All devices have a STAND-BY switch, with which you can define the role
of the device within a Ring/Network coupling.
Depending on the device type, this switch is a DIP switch on the devices,
or else it is exclusively a software setting (Redundancy:Ring/Network
Coupling dialog). By setting this switch, you define whether the device
has the main coupling or the redundant coupling role within a Ring/
Network coupling. You will find details on the DIP switches in the
“Installation” user manual.
Note: Depending on the model, the devices have a DIP switch, with which
you can choose between the software configuration and the DIP switch
configuration. When you set the DIP switches so that the software
configuration is selected, the DIP switches are effectively deactivated.
RM Web L2E
Release 7.0 05/2011 127
Redundancy 6.2 Ring/Network Coupling
RM Web L2E
128 Release 7.0 05/2011
Redundancy 6.2 Ring/Network Coupling
One-Switch coupling
On the device set the 'STAND BY' dip switch to the ON position or use the
software configuration to assign the redundancy function to it.
Two-Switch coupling
Assign the device in the redundant line the DIP switch setting “STAND-
BY”, or use the software configuration to assign the redundancy function
to it.
RM Web L2E
Release 7.0 05/2011 129
Redundancy 6.2 Ring/Network Coupling
Parameter Meaning
Selecting the Depending on your local conditions, select “One-Switch coupling”,
configuration “Two-Switch coupling, Slave”, “Two-Switch coupling, Master”, “Two-
Switch coupling with control line, Slave” or “Two-Switch coupling with
control line, Master”. These options are presented as buttons from left
to right.
Depending on the device type (see table 52), you make this setting:
– only using DIP switches
– only using software
– using DIP switch and software
You will find details on the DIP switches on the devices in the
“Installation” user manual.
– For devices configured only using DIP switches, you use these
switches to make the settings. In this case, the buttons in the dialog
are only for display purposes.
– For devices without DIP switches, you only use the software to
make settings. You can select the configuration using the buttons.
– For devices that can be configured using DIP switches and
software, you can activate or deactivate the DIP switches. If you
have activated the DIP switches, you cannot overwrite the DIP
switch settings using the software - settings that cannot be selected
using the software are grayed-out in the dialog.
To configure using the software, select the relevant Ring/Network
coupling constellation by pressing the corresponding button.
Coupling port This is the port to which you have connected a redundant connection.
Note: Configure the coupling port and the ring ports, if there are any
ring ports, on different ports.
Note: To avoid continuous loops, the device sets the port status of the
coupling port to “off” if you switch off the function or change the
configuration while the connections are operating at these ports.
Port mode - active You have switched the port on.
- stand-by The port is in stand-by mode.
Port state - active: You have switched the port on.
- stand-by: The port is in stand-by mode.
- not connected: You have not connected the port.
Partner coupling port This is the port at which the partner has made its connection. It is only
possible and necessary to enter a port if “One-Switch coupling” is being
set up.
Note: Configure the partner coupling port and the ring ports, if there are
any ring ports, on different ports.
IP address If you have selected “Two-Switch coupling”, the device displays the IP
address of the partner here, once you have already started operating
the partner in the network.
Control port This is the port to which you connect the control line.
RM Web L2E
130 Release 7.0 05/2011
Redundancy 6.2 Ring/Network Coupling
Parameter Meaning
Operation Here you switch the Ring/Network coupling for this device on or off
Information If the device is a ring manager: The displays in this frame mean:
“Redundancy working”: When a component of the ring is down, the
redundant line takes over its function.
“Configuration failure”: You have configured the function incorrectly, or
there is no ring port connection.
Redundancy Mode With the “Redundant Ring/Network Coupling” setting, either the main
line or the redundant line is active. Both lines are never active
simultaneously.
With the “Extended Redundancy” setting, the main line and the
redundant line are simultaneously active if a problem is detected in the
connection line between the devices in the connected (i.e., the remote)
network. During the reconfiguration period, package duplications may
possibly occur. Therefore, only select this setting if your application
detects package duplications.
Coupling Mode Here you define whether the constellation you are configuring is a
coupling of redundancy rings (HIPER-Ring, MRP-Ring), or network
segments.
The following tables show the selection options and default settings for
the ports used in the Ring/Network coupling.
RM Web L2E
Release 7.0 05/2011 131
Redundancy 6.2 Ring/Network Coupling
Table 56: Port assignment for the redundant coupling (two-Switch coupling)
Table 57: Port assignment for the redundant coupling (two-Switch coupling with
control line)
RM Web L2E
132 Release 7.0 05/2011
Redundancy 6.2 Ring/Network Coupling
Note: For the coupling ports, select the following settings in the Basic
Settings:Port Configuration dialog:
– Port: on
– Automatic configuration (autonegotiation):
on for twisted-pair connections
– Manual configuration: 100 Mbit/s FDX, 1 Gbit/s FDX or 10 Gbit/s FDX
for glass fiber connections, depending on the port’s capabilities
Note: If you have configured VLANS, note the VLAN configuration of the
coupling and partner coupling ports.
In the Ring/Network Coupling configuration, select for the coupling and
partner coupling ports
– VLAN ID 1 and “Ingress Filtering” disabled in the port table and
– VLAN membership U in the static VLAN table.
Note: If you are operating the Ring Manager and two-Switch coupling
functions at the same time, there is the possibility of creating a loop.
RM Web L2E
Release 7.0 05/2011 133
Redundancy 6.3 Spanning Tree
Under Spanning Tree you will find the dialogs and views for configuring and
monitoring of the Spanning Tree function according to the IEEE 802.1Q-
2005 standard, Rapid Spanning Tree (RSTP).
Note: The Spanning Tree Protocol is a protocol for MAC bridges. For this
reason, the following description uses the term bridge for Switch.
Introduction
Local networks are getting bigger and bigger. This applies to both the
geographical expansion and the number of network participants. Therefore,
it is advantageous to use multiple bridges, for example:
to reduce the network load in sub-areas,
to set up redundant connections and
to overcome distance limitations.
RM Web L2E
134 Release 7.0 05/2011
Redundancy 6.3 Spanning Tree
Note: RSTP reduces a layer 2 network topology with redundant paths into a
tree structure (Spanning Tree) that does not contain any more redundant
paths. One of the Switches takes over the role of the root bridge here. The
maximum number of devices permitted in an active branch (from the root
bridge to the tip of the branch) is specified by the variable Max Age for the
current root bridge. The preset value for Max Age is 20, which can be
increased up to 40.
If the device working as the root is inoperable and another device takes over
its function, the Max Age setting of the new root bridge determines the
maximum number of devices allowed in a branch.
Note: You have the option of coupling RSTP network segments to an MRP-
Ring. For this, you activate the MRP compatibility. This enables you to
operate RSTP via an MRP-Ring.
If the root bridge is within the MRP-Ring, the devices in the MRP-Ring count
as a single device when calculating the length of the branch. A device that is
connected to a random Ring bridge receives such RSTP information as if it
were directly connected to the root bridge.
Note: The RSTP standard dictates that all the devices within a network work
with the (Rapid) Spanning Tree Algorithm. If STP and RSTP are used at the
same time, the advantages of faster reconfiguration with RSTP are lost in the
network segments that are operated in combination.
A device that only supports RSTP works together with MSTP devices by not
assigning an MST region to itself, but rather the CST (Common Spanning
Tree).
Note: By changing the IEEE 802.1D-2004 standard for RSTP, the Standards
Commission reduced the maximum value for the “Hello Time” from 10 s to
2 s. When you update the Switch software from a release before 5.0 to
release 5.0 or higher, the new software release automatically reduces the
locally entered “Hello Time” values that are greater than 2 s to 2 s.
If the device is not the RSTP root, “Hello Time” values greater than 2 s can
remain valid, depending on the software release of the root device.
RM Web L2E
Release 7.0 05/2011 135
Redundancy 6.3 Spanning Tree
Note: The following text uses the term Spanning Tree (STP) to describe
settings or behavior that applies to STP, RSTP or MSTP.
6.3.1 Global
With this dialog you can:
switch the Rapid Spanning Tree Protocol on/off,
display bridge-related information on the Spanning Tree Protocol,
configure bridge-related parameters of the Spanning Tree Protocol,
set bridge-related additional functions,
display the parameters of the root bridge and
display bridge-related topology information.
The following tables show the selection options and default settings, and
information on the global Spanning Tress settings for the bridge.
RM Web L2E
136 Release 7.0 05/2011
Redundancy 6.3 Spanning Tree
RM Web L2E
Release 7.0 05/2011 137
Redundancy 6.3 Spanning Tree
RM Web L2E
138 Release 7.0 05/2011
Redundancy 6.3 Spanning Tree
Note: The parameters Forward Delay and Max Age have the following
relationship:
Forward Delay ≥ (Max Age/2) + 1
If you enter values that contradict this relationship, the device then replaces
these values with the last valid values or the default value.
RM Web L2E
Release 7.0 05/2011 139
Redundancy 6.3 Spanning Tree
RM Web L2E
140 Release 7.0 05/2011
Redundancy 6.3 Spanning Tree
If you have activated the “MRP Compatibility” function, the device displays
the “Information” frame with additional information on MRP compatibility:
RM Web L2E
Release 7.0 05/2011 141
Redundancy 6.3 Spanning Tree
6.3.2 Port
Note: Deactivate the Spanning Tree protocol for the ports connected to a
HIPER-Ring, Fast HIPER-Ring, or Ring/Network coupling, because
Spanning Tree and Ring Redundancy or Ring/Network coupling affect each
other.
Activate the MRP compatibility in an MRP-Ring if you want to use RSTP and
MRP in combination.
If you combine RSTP with an MRP-Ring, you must give the devices in the
MRP-Ring a better (i.e. numerically lower) RSTP bridge priority than the
devices in the connected RSTP network. You thus help avoid a connection
interruption for devices outside the Ring.
RM Web L2E
142 Release 7.0 05/2011
Redundancy 6.3 Spanning Tree
If you are using the device in a Multiple Spanning Tree (MSTP) environment,
the device only participates in the Common Spanning Tree (CST) instance.
This chapter of the manual also uses the term Global MST instance to
describe this general case.
RM Web L2E
Release 7.0 05/2011 143
Redundancy 6.3 Spanning Tree
RM Web L2E
144 Release 7.0 05/2011
Redundancy 6.3 Spanning Tree
a
– These columns show you more detailed information than that available
up to now:
For designated ports, the device displays the information for the STP-
BPDU last received by the port. This helps with the diagnosis of possible
STP problems in the network.
For the port roles alternative, back-up, master and root, in the stationary
RM Web L2E
Release 7.0 05/2011 145
Redundancy 6.3 Spanning Tree
RM Web L2E
146 Release 7.0 05/2011
Redundancy 6.3 Spanning Tree
RM Web L2E
Release 7.0 05/2011 147
Redundancy 6.3 Spanning Tree
RM Web L2E
148 Release 7.0 05/2011
Redundancy 6.3 Spanning Tree
RM Web L2E
Release 7.0 05/2011 149
Redundancy 6.3 Spanning Tree
RM Web L2E
150 Release 7.0 05/2011
Redundancy 6.3 Spanning Tree
RM Web L2E
Release 7.0 05/2011 151
Redundancy 6.3 Spanning Tree
RM Web L2E
152 Release 7.0 05/2011
Diagnostics 6.3 Spanning Tree
7 Diagnostics
RM Web L2E
Release 7.0 05/2011 153
Diagnostics 7.1 Syslog
7.1 Syslog
The “Syslog” dialog enables you to additionally send to one or more syslog
servers, the events that the device writes to its event log. You can switch the
function on or off, and you can manage a list of up to 8 syslog server entries.
You also have the option to specify that the device informs various syslog
servers, depending on the minimum “level to report” of the event.
Additionally, you can also send the SNMP requests to the device as events
to one or more syslog servers. Here you have the option of treating GET and
SET requests separately, and of assigning a “level to report” to the requests
to be logged.
Note: You will find the actual events that the device has logged in the “Trap
Log” dialog (see on page 159 “Trap Log“) and in the log file (see on page 180
“Event Log“).
The device evaluates SNMP requests as events if you have activated “Log
SNMP Set/Get Request” (see table 66).
RM Web L2E
154 Release 7.0 05/2011
Diagnostics 7.1 Syslog
RM Web L2E
Release 7.0 05/2011 155
Diagnostics 7.1 Syslog
RM Web L2E
156 Release 7.0 05/2011
Diagnostics 7.1 Syslog
Note: When you activate the logging of SNMP requests, the device sends
these as events with the preset level to report notice to the list of syslog
servers. The preset minimum level to report for a syslog server entry is
critical.
To send SNMP requests to a syslog server, you have a number of options to
change the default settings. Select the ones that meet your requirements
best.
Set the level to report for which the device creates SNMP requests as
events to warning or error and change the minimum level to report for
a syslog entry for one or more syslog servers to the same value.
You also have the option of creating a separate syslog server entry for
this.
Only set the level to report for SNMP requests to critical or higher.
The device then sends SNMP requests as events with the level to report
critical or higher to the syslog servers.
Only set the minimum level to report for one or more syslog server entries
to notice or lower. Then it may happen that the device sends a large
number of events to the syslog servers.
RM Web L2E
Release 7.0 05/2011 157
Diagnostics 7.1 Syslog
RM Web L2E
158 Release 7.0 05/2011
Diagnostics 7.2 Trap Log
You have the option to also send the logged events to one or more syslog
servers (see on page 154 “Syslog“).
RM Web L2E
Release 7.0 05/2011 159
Diagnostics 7.3 Ports
7.3 Ports
The port menu contains displays and tables for the individual ports:
Statistics table
Utilization
SFP Modules
RM Web L2E
160 Release 7.0 05/2011
Diagnostics 7.3 Ports
RM Web L2E
Release 7.0 05/2011 161
Diagnostics 7.3 Ports
Parameter Meaning
Module Module of the device on which the port is located.
Port Port to which this entry applies.
Module Type Type of SFP module, e.g. M-SFP-SX/LC.
Supported Shows whether the media module supports the SFP module.
Temperature in ° C Shows the SFP's operating temperature.
Transmission Power in Shows the transmission power in mW.
mW
Receive power in mW Shows the receive power in mW.
Transmission power in Shows the transmission power in dBm.
dBm
Receive power in dBm Shows the receive power in dBm.
Receive Power Status Shows the power level of the signal received.
– good receive power
– limited receive power
– insufficient receive power
RM Web L2E
162 Release 7.0 05/2011
Diagnostics 7.3 Ports
RM Web L2E
Release 7.0 05/2011 163
Diagnostics 7.4 Topology Discovery
RM Web L2E
164 Release 7.0 05/2011
Diagnostics 7.4 Topology Discovery
If several devices are connected to one port, for example via a hub, the table
will contain one line for each connected device.
When devices both with and without an active topology discovery function
are connected to a port, the topology table hides the devices without active
topology discovery.
RM Web L2E
Release 7.0 05/2011 165
Diagnostics 7.5 Port Mirroring
The port mirroring function enables you to review the data traffic at up to
8 ports of the device for diagnostic purposes. The device additionally
forwards (mirrors) the data for these ports to another port. This process is
also called port mirroring.
The ports to be reviewed are known as source ports. The port to which the
data to be reviewed is copied is called the destination port. You can only use
physical ports as source or destination ports.
In port mirroring, the device copies valid incoming and outgoing data packets
of the source port to the destination port. The device does not affect the data
traffic at the source ports during port mirroring.
A management tool connected at the destination port, e.g. an RMON probe,
can thus monitor the data traffic of the source ports in the sending and
receiving directions.
The destination port forwards all data to be sent.
On the devices PowerMICE, MACH 104, MACH 1040 and MACH 4000, the
destination port blocks received data, on all other devices, the destinations
port also forwards received data.
Select the source ports whose data traffic you want to review from the list
of physical ports by checkmarking the relevant boxes.
You can select a maximum of 8 source ports. Ports that cannot be
selected are displayed as inactive by the device, e.g. the port currently
being used as the destination port, or if you have already selected 8 ports.
Default setting: no source ports.
Select the destination port to which you have connected your
management tool from the list element in the “Destination Port” frame.
The device does not display ports that cannot be selected in the list, e.g.
the ports currently being used as source ports. Default setting: port 0.0
(no destination port).
Select “On” in the “Function” frame to switch on the function. Default
setting: “Off”.
The “Reset configuration” button in the dialog allows you to reset all the port
mirroring settings of the device to the state on delivery.
RM Web L2E
166 Release 7.0 05/2011
Diagnostics 7.5 Port Mirroring
Note: When port mirroring is active, the specified destination port is used
solely for reviewing, and does not participate in the normal data traffic.
RM Web L2E
Release 7.0 05/2011 167
Diagnostics 7.6 Device Status
The device status provides an overview of the overall condition of the device.
Many process visualization systems record the device status for a device in
order to present its condition in graphic form.
In the "Monitoring" field, you select the events you want to monitor.
To monitor the temperature, you set the temperature thresholds in the
Basics:System dialog at the end of the system data.
RM Web L2E
168 Release 7.0 05/2011
Diagnostics 7.6 Device Status
Name Meaning
Power supply ... Monitor/ignore supply voltage(s).
Temperature Monitor/ignore temperature thresholds set (see on page 16 “System“) for
temperatures that are too high/too low
Module removal Monitor/ignore the removal of a module (for modular devices).
ACA removal Monitor/ignore the removal of the ACA.
ACA not in sync Monitor/ignore the non-matching of the configuration in the device and on
the ACAa
Connection error Monitor/ignore the link status (Ok or inoperable) of at least one port.
The reporting of the link status can be masked for each port by the
management (see on page 26 “Port Configuration“). Link status is not
monitored in the state on delivery.
Ring Redundancy Monitor/ignore the ring redundancy (for the HIPER-Ring, only in ring
manager operation).
On delivery, ring redundancy is not monitored.
Note: If the device is a normal ring member and not a ring manager, it
doesn't report anything for the HIPER-Ring; for the Fast HIPER-Ring and
for MRP it only reports detected errors in the local configuration.
Ring/Network Monitor/ignore the redundant coupling operation.
coupling On delivery, no monitoring of the redundant coupling is set.
For two-Switch coupling with control line, the slave additionally reports
the following conditions:
– Incorrect link status of the control line
– Partner device is also a slave (in standby mode).
RM Web L2E
Release 7.0 05/2011 169
Diagnostics 7.6 Device Status
Note: With a non-redundant voltage supply, the device reports the absence
of a supply voltage. If you do not want this message to be displayed, feed the
supply voltage over both inputs or switch off the monitoring (see on page 171
“Signal contact“).
RM Web L2E
170 Release 7.0 05/2011
Diagnostics 7.7 Signal contact
Application options:
Simulation of an error during SPS error monitoring.
Remote control of a device via SNMP, such as switching on a camera.
RM Web L2E
Release 7.0 05/2011 171
Diagnostics 7.7 Signal contact
In the “Mode Signal contact” box, you select the “Monitoring correct
operation” mode. In this mode, the signal contacts monitor the functions
of the device, thus enabling remote diagnosis.
A break in contact is reported via the potential-free signal contact (relay
contact, closed circuit).
Loss of the supply voltage 1/2 (either of the external voltage supply or of
the internal voltage).1 Select “Monitor” for the respective power supply if
the signal contact shall report the loss of the power supply voltage, or of
the internal voltage that is generated from the external power supply.
One of the temperature thresholds has been exceeded (see on page 17
“System Data“). Select “Monitor” for the temperature if the signal contact
should report an impermissible temperature.
Removing a module. Select “Monitor” for removing modules if the signal
contact is to report the removal of a module (for modular devices).
The removal of the ACA. Select “Monitor” for ACA removal if the signal
contact is to report the removal of an ACA (for devices which support the
ACA).
Non-matching of the configuration in the device and on the ACA2. Select
“Monitor” ACA not in sync if the signal contact is to report the non-
matching of the configuration (for devices which support ACA).
The inoperable link status of at least one port. The reporting of the link
status can be masked via the management for each port in the device.
Link status is not monitored in the state on delivery. Select “Monitor” for
bad connections if the signal contact is to report an inoperative link status
for at least one port.
If the device is part of a redundant ring: the elimination of the reserve
redundancy (i.e. the redundancy function did actually switch on), (see on
page 118 “Ring Redundancy“). Select “Monitor” for the ring redundancy if
the signal contact is to report the elimination of the reserve redundancy in
the redundant ring.
Default setting: no monitoring.
RM Web L2E
172 Release 7.0 05/2011
Diagnostics 7.7 Signal contact
Note: If the device is a normal ring member and not a ring manager, it
doesn't report anything for the HIPER-Ring; for the Fast HIPER-Ring
and for MRP it only reports detected errors in the local configuration.
RM Web L2E
Release 7.0 05/2011 173
Diagnostics 7.7 Signal contact
The Signal Contact dialog has a card index ("Signal Contact 1") for devices
with a signal contact.
The Signal Contact dialog has two card indexes ("Signal Contact 1" and
"Signal Contact 2") for devices with two signal contacts.
RM Web L2E
174 Release 7.0 05/2011
Diagnostics 7.8 Alarms (Traps)
This dialog allows you to determine which events trigger an alarm (trap) and
where these alarms should be sent.
RM Web L2E
Release 7.0 05/2011 175
Diagnostics 7.8 Alarms (Traps)
Name Meaning
Authentication The device has rejected an unauthorized access attempt (see on page 43
“SNMPv1/v2 Access Settings“).
Link Up/Down At one port of the device, the link to another device has been established/
interrupted.
Spanning Tree The topology of the Rapid Spanning Tree has changed.
Chassis Summarizes the following events:
– The status of a supply voltage has changed (see the System dialog).
– The status of the signal contact has changed.
To take this event into account, you activate “Create trap when status
changes” in the Diagnostics:Signal Contact 1/2 dialog.
- The AutoConfiguration Adapter (ACA), has been added or removed.
- The configuration on the AutoConfiguration Adapter(ACA) does not match
that in the device.
– The temperature thresholds have been exceeded/not reached.
– The receiver power status of a port with an SFP module has changed (see
dialog Diagnostics:Ports:SFP Modules).
– The configuration has been successfully saved in the device and in the
AutoConfiguration Adapter (ACA), if present.
– The configuration has been changed for the first time after being saved in
the device.
Redundancy The redundancy status of the ring redundancy (redundant line active/
inactive) or (for devices that support redundant ring/network coupling) the
redundant ring/network coupling (redundancy exists) has changed.
Port security On one port a data packet has been received from an unauthorized terminal
device (see the Port Security dialog).
RM Web L2E
176 Release 7.0 05/2011
Diagnostics 7.8 Alarms (Traps)
RM Web L2E
Release 7.0 05/2011 177
Diagnostics 7.9 Report
7.9 Report
Note: You have the option to also send the logged events to one or more
syslog servers (see on page 154 “Syslog“).
RM Web L2E
178 Release 7.0 05/2011
Diagnostics 7.9 Report
The device creates the file name of the applet automatically in the format
<device type><software variant><software version)>_<software revision
of applet>.jar, e.g. for a device of type PowerMICE with software variant
L3P: “pmL3P06000_00.jar”.
RM Web L2E
Release 7.0 05/2011 179
Diagnostics 7.9 Report
7.9.1
The System Information is an HTML file with system-relevant data.
RM Web L2E
180 Release 7.0 05/2011
Diagnostics 7.10 IP address conflict detection
This dialog allows you to detect address conflicts the device is having with its
own IP address and rectify them (Address Conflict Detection, ACD).
Mode Meaning
enable Enables active and passive detection.
disable Disables the function
activeDetectionOnly Enables active detection only. After connecting to a network or after an
IP address has been configured, the device immediately checks whether
its IP address already exists within the network.
If the IP address already exists, the device will return to the previous
configuration, if possible, and make another attempt after 15 seconds.
The device therefore avoids to participate in the network traffic with a
duplicate IP address.
passiveOnly Enables passive detection only. The device listens passively on the
network to determine whether its IP address already exists. If it detects a
duplicate IP address, it will initially defend its address by employing the
ACD mechanism and sending out gratuitous ARPs. If the remote device
does not disconnect from the network, the management interface of the
local device will then disconnect from the network. Every 15 seconds, it
will poll the network to determine if there is still an address conflict. If there
isn't, it will connect back to the network.
RM Web L2E
Release 7.0 05/2011 181
Diagnostics 7.10 IP address conflict detection
RM Web L2E
182 Release 7.0 05/2011
Diagnostics 7.11 Self Test
RM Web L2E
Release 7.0 05/2011 183
Diagnostics 7.12 Service Mode
The service mode enables you to divide the device into 2 transmission areas.
You can thus, for example, perform test or service configurations in the field
area of a network while the ongoing operation continues in the backbone
area.
The device specifies the two transmission areas via the HIPER-Ring ports:
transmission area 1 only includes the HIPER-Ring ports of the device, while
all other ports belong to transmission area 2. When the service mode is
activated, the device creates a new VLAN in which all the ports of
transmission area 2 are members. You use the redundant supply voltage
(see below) to activate the service mode. You can view the configuration of
the newly created VLAN in the dialogs under Switching/VLAN, but the device
does not allow these entries to be changed, in order to keep the service
configuration.
By generating the VLAN, the device
resets the port VLAN IDs for all the ports of this VLAN to the new VLAN ID
deactivates GVRP at all ports of this VLAN. The device prevents GVRP
from dynamically changing the service mode port settings as a result.
activates “Ingress Filtering” at all ports of this VLAN. As a consequence,
the device only transmits packets when the input and output ports belong
to this VLAN.
RM Web L2E
184 Release 7.0 05/2011
Diagnostics 7.12 Service Mode
Note: If there is no redundant voltage when activating the service mode (by
clicking on “Set” - see below), the switch immediately creates the 2 switching
areas. Depending on the settings already entered, this may interrupt your
communication to the switch.
If you have verified that your communication with the Switch will not be
interrupted, click “OK” to activate the service mode.
The device will indicate in all dialogs that the service mode is activated.
RM Web L2E
Release 7.0 05/2011 185
Diagnostics 7.12 Service Mode
Note: Deactivate the service mode (see below) when saving the device
configuration (dialog: Basics:Load/Save:Save:On the Switch).
RM Web L2E
186 Release 7.0 05/2011
Diagnostics 7.12 Service Mode
Note: After the service mode is deactivated, the device takes on its previous
settings again.
RM Web L2E
Release 7.0 05/2011 187
Diagnostics 7.12 Service Mode
RM Web L2E
188 Release 7.0 05/2011
Advanced 7.12 Service Mode
8 Advanced
RM Web L2E
Release 7.0 05/2011 189
Advanced 8.1 DHCP Relay Agent
With Option 82, a DHCP relay agent which receives a DHCP request
adds an “Option 82” field to the request, as long as the request received
does not already have such a field.
When the function is switched off, the device will forward attached “Option
82” fields, but it will not add any on. Under “Type”, you specify the format
in which the device recognition of this device is entered in the “Option 82”
field by the DHCP relay agent.
The options are:
– IP address
– MAC Address (state on delivery)
– System name (client ID)
– Other (freely definable ID, which you can specify in the following rows).
“Remote ID entry for DHCP server” shows you the value which you enter
when configuring your DHCP server. “Type display” shows the device
recognition in the selected form.
The “Circuit ID” column in the table shows you the value that you enter
when configuring your DHCP server. In addition to the port number, the
“Circuit ID” also includes the ID of the VLAN that the DHCP relay received
the DHCP query from.
Note: The VLAN ID is located in the circuit ID's 4th and 5th octet. The
circuit ID displayed applies to untagged frames. If the DHCP relay
receives a VLAN-tagged frame, then the circuit ID that it sends to the
DHCP server can deviate from the one displayed.
RM Web L2E
190 Release 7.0 05/2011
Advanced 8.1 DHCP Relay Agent
This results in the entry for the “Hardware address” in the DHCP server:
B306000001000101000600806300061E
In the “Option 82 on” column in the table, you can switch this function on/
off for each port.
RM Web L2E
Release 7.0 05/2011 191
Advanced 8.2 Industrial Protocols
8.2.1 PROFINET IO
This dialog allows you to configure the PROFINET IO protocol. To integrate
this in a control system, perform the following steps.
General settings:
In the Basic Settings:Network dialog, check whether Local is
selected in the “Mode” frame (see on page 21 “Network“).
In the Switching:VLAN:Global dialog, check whether “VLAN 0
Transparent Mode” is selected (see on page 97 “VLAN Global“).
Configure the alarm settings and the threshold values for the alarms you
want to monitor (see on page 168 “Device Status“).
RM Web L2E
192 Release 7.0 05/2011
Advanced 8.2 Industrial Protocols
Select the port for which you want to set its PHY module to the fast start
mode, and select from the following in the Fast Start Up column:
- disable, to set the normal start mode,
- enable, to set the fast start mode.
The default setting is disable. If a port does not support the fast start
mode, the device will show unsupported in this column.
RM Web L2E
Release 7.0 05/2011 193
Advanced 8.2 Industrial Protocols
8.2.2 EtherNet/IP
This dialog allows you to activate the EtherNet/IP protocol. To integrate this
in a control system, perform the following steps.
General settings:
In the Switching:Multicast:IGMP dialog, check whether IGMP is
activated (see on page 89 “IGMP (Internet Group Management
Protocol)“).
EtherNet/IP settings:
Activate the function in the “EtherNet/IP” frame; the default setting is off.
Click on “Download EDS File” to load the EDS file onto your PC.
RM Web L2E
194 Release 7.0 05/2011
Advanced 8.3 Command Line
This window enables you to access the Command Line Interface (CLI) using
the Web interface.
You will find detailed information on CLI in the “Command Line Interface”
reference manual.
RM Web L2E
Release 7.0 05/2011 195
Advanced 8.3 Command Line
RM Web L2E
196 Release 7.0 05/2011
Appendix 8.3 Command Line
A Appendix
RM Web L2E
Release 7.0 05/2011 197
Appendix A.1 Technical Data
Switching
Size of MAC address table 8,000 (16,000 for PowerMICE and
(incl. static filters) MACH 4000)
Max. number of statically configured MAC 100
address filters
Max. number of MAC address filters learnable 512
via GMRP/IGMP Snooping
Max. length of over-long packets (from rel. 1,632 bytes
03.0.00)
VLAN
VLAN ID 1 to 4,042
Number of VLANs max. 255 simultaneously per device
max. 255 simultaneously per port
Number of VLANs in GMRP in VLAN 1 max. 255 simultaneously per device
max. 255 simultaneously per port
RM Web L2E
198 Release 7.0 05/2011
Appendix A.2 List of RFCs
RM Web L2E
Release 7.0 05/2011 199
Appendix A.2 List of RFCs
RM Web L2E
200 Release 7.0 05/2011
Appendix A.3 Underlying IEEE Standards
RM Web L2E
Release 7.0 05/2011 201
Appendix A.4 Underlying IEC Norms
RM Web L2E
202 Release 7.0 05/2011
Appendix A.5 Literature references
RM Web L2E
Release 7.0 05/2011 203
Appendix A.6 Copyright of Integrated Software
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
RM Web L2E
204 Release 7.0 05/2011
Appendix A.6 Copyright of Integrated Software
RM Web L2E
Release 7.0 05/2011 205
Appendix A.6 Copyright of Integrated Software
RM Web L2E
206 Release 7.0 05/2011
Index A.6 Copyright of Integrated Software
B Index
8 F
802.1D/p mapping 113 FAQ 213
Filters for MAC addresses 84
A Firmware update 23
ACA 31, 176, 176 Forward Delay 138, 140
Accept SNTP Broadcasts 54
Acceptable Frame Types 105 G
Access with Web-based interface, password General 15
40 Grandmaster 68
ACD 181
Address Conflict Detection 181 H
Advanced 189 Hello Time 137, 140
AF 116 HIPER-Ring 7, 104, 117
Aging Time 80 HIPER-Ring (source for alarms) 176
Alarm 175 HiVision 8
Assured Forwarding 116
Auto Configuration Adapter, 176 I
IGMP Querier 90
B IGMP settings 90
BPDU Guard 139 IGMP-Snooping 90
Broadcast Limiter Settings 86 Independent VLAN 99
Industry Protocols 192
C Industry protocols 7
Cable crossing 26 Ingress Filtering 105
Class Selector 115 IP DSCP mapping 107, 115
CLI 195 IP-DSCP value 108
CLI access, password 40
Clock 57 J
Cold start (after software update) 24 Java Runtime Environment 11
Coldstart 37 JavaScript 11
Command Line Interface 195
Configuring the HIPER-Ring 120 L
Configuring the MRP-Ring 124 Link State (Port) 26
Current VLAN Dialog 100 LLDP 164
Login 12
D
Device status 168 M
DHCP Option 82 190 Max Age 138, 140
DHCP Relay Agent 190 Media module (for modular devices) 17
Diagnose 153 Message URL http://
DiffServ 107 www.beldensolutions.com 213, 213
DIP switch 120 Message URL http://www.hicomcenter.com
DSCP 107 213, 213
MRP 7, 117
E Multicasts 89
EF 115
EtherNet/IP 194 N
Event Log 180 Network Load 161
Expedited Forwarding 115 Network load 134
RM Web L2E
Release 7.0 05/2011 207
Index A.6 Copyright of Integrated Software
RM Web L2E
208 Release 7.0 05/2011
Index A.6 Copyright of Integrated Software
Temperature (device) 17
Temperature (SFPs) 162
Time 51
Time Management 57
Time Stamp Unit 57
Topology 164
ToS 107
Training courses 213
Trap 175
Trap Log 159
Trust mode 108
TrustDot1p (global trust mode) 109
TrustIpDscp 109
TrustIpDscp (global trust mode) 109
Two-switch coupling 129
Two-Switch coupling with control line 129
TX Hold Count 138
Type of Service 107
U
Untrusted (global trust mode) 108
V
VLAN 97
VLAN (HIPER-Ring settings) 122
VLAN and GOOSE Protocol 98
VLAN and redundancy rings 105
VLAN Global dialog 97
VLAN ID (network parameter of the device)
21
VLAN Mapping 107
VLAN Mode 99
VLAN Port dialog 105
VLAN priority 107
VLAN priority 108
VLAN Static dialog 102
W
Web Access 46
Web-based interface 11
Web-based management 11
Website 12
RM Web L2E
Release 7.0 05/2011 209
Readers’ Comments A.6 Copyright of Integrated Software
C Readers’ Comments
RM Web L2E
210 Release 7.0 05/2011
Readers’ Comments A.6 Copyright of Integrated Software
General comments:
Sender:
Company / Department:
Street:
E-mail:
Date / Signature:
Dear User,
Please fill out and return this page
as a fax to the number +49 (0)7127/14-1600 or
by mail to
Hirschmann Automation and Control GmbH
Department AED
Stuttgarter Str. 45-51
72654 Neckartenzlingen
RM Web L2E
Release 7.0 05/2011 211
Readers’ Comments A.6 Copyright of Integrated Software
RM Web L2E
212 Release 7.0 05/2011
Further Support A.6 Copyright of Integrated Software
D Further Support
RM Web L2E
Release 7.0 05/2011 213