Sign In
Upload
Manuals
Brands
HP Manuals
Switch
ProCurve 5300xl
HP ProCurve 5300xl Manuals
Manuals and User Guides for HP ProCurve 5300xl. We have
6
HP ProCurve 5300xl manuals available for free PDF download: Management Manual, Management And Configuration Manual, Access Security Manual, Supplementary Manual, Specification Sheet
HP ProCurve 5300xl Management Manual (664 pages)
Advanced Traffic
Brand:
HP
| Category:
Switch
| Size: 10.41 MB
Table of Contents
Table of Contents
5
Command Syntax Statements
24
Getting Started
24
Conventions
24
Overview
24
Command Prompts
25
Screen Simulations
25
Keys
26
Related Publications
26
Getting Documentation from the Web
28
Sources for more Information
29
Need Only a Quick Start
30
IP Addressing
30
To Set up and Install the Switch in Your Network
30
Contents
31
Overview
32
Static Virtual Lans (Vlans)
32
General VLAN Operation
33
Introduction
33
Types of Static Vlans Available in the Switch
34
Port-Based Vlans
34
Protocol-Based Vlans
34
Designated Vlans
34
Terminology
35
Static VLAN Operation
36
VLAN Environments
37
VLAN Operation
38
Routing Options for Vlans
39
Overlapping (Tagged) Vlans
39
VLAN Operating Rules
43
General Steps for Using Vlans
46
Multiple VLAN Considerations
47
Single Forwarding Database Operation
48
Correct It
49
Example of an Unsupported Configuration and How to
49
Multiple Forwarding Database Operation
50
Configuring Vlans
51
Menu: Configuring Port-Based VLAN Parameters
51
To Change VLAN Support Settings
51
Adding or Editing VLAN Names
54
Adding or Changing a VLAN Port Assignment
55
CLI: Configuring Port-Based and Protocol-Based VLAN
57
Parameters
57
Web: Viewing and Configuring VLAN Parameters
67
802.1Q VLAN Tagging
68
Special VLAN Types
73
VLAN Support and the Default VLAN
73
The Primary VLAN
73
The Secure Management VLAN
74
Preparation
76
Configuration
77
Deleting the Management VLAN
78
Operating Notes for Management Vlans
78
Voice Vlans
79
Operating Rules for Voice Vlans
79
Components of Voice VLAN Operation
80
Voice VLAN Qos Prioritizing (Optional)
80
Voice VLAN Access Security
81
Effect of Vlans on Other Switch Features
81
Spanning Tree Operation with Vlans
81
IP Interfaces
82
VLAN MAC Address
82
Port Trunks
82
Port Monitoring
82
VLAN Restrictions
83
Switches
83
Jumbo Packet Support on the Series 3400Cl and Series 6400Cl
83
Contents
85
Gvrp
86
Overview
86
Introduction
87
General Operation
88
Per-Port Options for Handling GVRP "Unknown Vlans
91
Per-Port Options for Dynamic VLAN Advertising and Joining
93
GVRP and VLAN Access Control
95
Port-Leave from a Dynamic VLAN
95
Planning for GVRP Operation
96
Configuring GVRP on a Switch
97
Menu: Viewing and Configuring GVRP
97
CLI: Viewing and Configuring GVRP
98
Web: Viewing and Configuring GVRP
102
GVRP Operating Notes
102
Contents
105
Multimedia Traffic Control with IP Multicast (IGMP)
106
Overview
106
IGMP General Operation and Features
107
IGMP Terms
108
IGMP Operating Features
109
CLI: Configuring and Displaying IGMP
110
Web: Enabling or Disabling IGMP
115
How IGMP Operates
115
Operation with or Without IP Addressing
117
Automatic Fast-Leave IGMP
117
Forced Fast-Leave IGMP
119
Configuration Options for Forced Fast-Leave
119
Listing the Forced Fast-Leave Configuration
120
Configuring Per-Port Forced Fast-Leave IGMP
122
Using the Switch as Querier
123
Excluding Well-Known or Reserved Multicast Addresses from IP Multicast Filtering
124
Excluding Well-Known or Reserved Multicast Addresses from IP Multicast Filtering
125
PIM-DM (Dense Mode) on the 5300Xl Switches
127
Contents
127
Overview
128
Introduction
129
Feature Overview
130
PIM-DM Operation
130
Multicast Flow Management
133
General Configuration Elements
135
Terminology
135
PIM-DM Operating Rules
136
Configuring PIM-DM on the Series 5300Xl Switches
137
PIM Global Configuration Context
138
PIM VLAN (Interface) Configuration Context
141
Displaying PIM Data and Configuration Settings on the Series 5300Xl Switches
148
Displaying PIM Data and Configuration Settings on the Series
148
Displaying PIM Route Data
149
Displaying PIM Status
153
Operating Notes
160
Troubleshooting
162
Messages Related to PIM Operation
163
Applicable Rfcs
166
Exceptions to Support for RFC 2932 - Multicast Routing MIB
167
Spanning-Tree Operation
169
Contents
169
Overview
170
The RSTP (802.1W) and STP (802.1D) Spanning Tree Options
173
RSTP (802.1W)
174
Stp (802.1D)
174
How STP and RSTP Operate
175
Configuring Rapid Reconfiguration Spanning Tree (RSTP)
177
Overview
177
Transitioning from STP to RSTP
178
Optimizing the RSTP Configuration
179
Configuring RSTP
179
CLI: Configuring RSTP
180
Menu: Configuring RSTP
186
Web: Enabling or Disabling RSTP
188
D Spanning-Tree Protocol (STP)
189
Menu: Configuring 802.1D STP
189
CLI: Configuring 802.1D STP
192
STP Fast Mode
196
Fast-Uplink Spanning Tree Protocol (STP)
197
Terminology
199
Operating Rules for Fast Uplink
200
Menu: Viewing and Configuring Fast-Uplink STP
201
CLI: Viewing and Configuring Fast-Uplink STP
207
Operating Notes
210
Web: Enabling or Disabling STP
211
Multiple Spanning Tree Protocol (MSTP)
212
MSTP Structure
213
How MSTP Operates
215
MST Regions
215
Regions, Legacy STP and RSTP Switches, and the Common Spanning Tree (CST)
217
MSTP Operation with 802.1Q Vlans
217
Terminology
218
Operating Rules
220
Transitioning from STP or RSTP to MSTP
221
Tips for Planning an MSTP Application
222
Steps for Configuring MSTP
223
Configuring MSTP Operation Mode and Global Parameters
225
Configuring Basic Port Connectivity Parameters
229
Configuring MST Instance Parameters
231
Configuring MST Instance Per-Port Parameters
234
Enabling or Disabling Spanning Tree Operation
237
Enabling an Entire MST Region at Once or Exchanging One Region Configuration for Another
237
Displaying MSTP Statistics and Configuration
239
Displaying MSTP Statistics
239
Displaying the MSTP Configuration
242
Operating Notes
246
Troubleshooting
246
Switch Meshing
247
Contents
247
Introduction
248
Switch Meshing Fundamentals
250
Terminology
250
Operating Rules
251
Using a Heterogeneous Switch Mesh
254
Bringing up a Switch Mesh Domain
256
Further Operating Information
256
Configuring Switch Meshing
257
Preparation
257
Menu: to Configure Switch Meshing
257
CLI: to View and Configure Switch Meshing
260
Viewing Switch Mesh Status
260
CLI: Configuring Switch Meshing
263
Operating Notes for Switch Meshing
264
Flooded Traffic
264
Unicast Packets with Unknown Destinations
265
Spanning Tree Operation with Switch Meshing
266
Filtering/Security in Meshed Switches
268
IP Multicast (IGMP) in Meshed Switches
268
Static Vlans
269
Dynamic Vlans
270
Jumbo Packets (3400Cl and 6400Cl Switches Only)
270
Requirements and Restrictions
271
Quality of Service (Qos): Managing Bandwidth more Effectively
275
Contents
275
Introduction
276
Terminology
279
Overview
280
Classifiers for Prioritizing Outbound Packets
283
5300Xl Packet Classifiers and Evaluation Order
283
3400Cl/6400Cl Packet Classifiers and Evaluation Order
284
Preparation for Configuring Qos
287
Planning Qos for the Series 3400Cl/6400Cl Switches
289
Prioritizing and Monitoring Qos, ACL, and Rate Limiting Feature Usage on the 3400Cl/6400Cl Switches
289
Qos Resource Usage and Monitoring on 3400Cl/6400Cl
290
Switches
290
Switches
291
Managing Qos Resource Consumption on the 3400Cl/6400Cl
291
Troubleshooting a Shortage of Per-Port Rule Resources on the 3400Cl/6400Cl Switches
292
Examples of Qos Resource Usage on 3400Cl/6400Cl
293
Switches
293
Using Qos Classifiers to Configure Quality of Service for
296
Viewing the Qos Configuration
296
Using Qos Classifiers to Configure Quality of Service for Outbound Traffic
296
No Override
297
Qos UDP/TCP Priority
298
Number
299
Assigning a DSCP Policy Based on TCP or UDP Port
300
Number
300
Qos IP-Device Priority
304
Assigning a Priority Based on IP Address
305
Assigning a DSCP Policy Based on IP Address
306
Qos IP Type-Of-Service (Tos) Policy and Priority
310
Assigning an 802.1P Priority to Ipv4 Packets on the Basis of the Tos Precedence Bits
311
Assigning an 802.1P Priority to Ipv4 Packets on the Basis of Incoming DSCP
312
Assigning a DSCP Policy on the Basis of the DSCP in Ipv4 Packets Received from Upstream Devices
316
Details of Qos IP Type-Of-Service
320
Qos Layer-3 Protocol Priority (5300Xl Switches Only)
323
Assigning a Priority Based on Layer-3 Protocol
323
Assigning a Priority Based on VLAN-ID
325
Qos VLAN-ID (VID) Priority
325
Assigning a DSCP Policy Based on VLAN-ID (VID)
327
Qos Source-Port Priority
331
Assigning a Priority Based on Source-Port
331
Assigning a DSCP Policy Based on the Source-Port
333
Differentiated Services Codepoint (DSCP) Mapping
336
Default Priority Settings for Selected Codepoints
338
Quickly Listing Non-Default Codepoint Settings
338
Note on Changing a Priority Setting
339
IP Multicast (IGMP) Interaction with Qos
343
Qos Messages in the CLI
343
Qos Operating Notes and Restrictions
344
Access Control Lists (Acls) for the Series 5300Xl
347
Contents
347
Introduction
349
Terminology
351
ACL Inbound and Outbound Application Points
354
Types of IP Acls
354
Overview
354
Features Common to All Acls
355
General Steps for Planning and Configuring Acls
356
ACL Operation
358
Introduction
358
The Packet-Filtering Process
359
Planning an ACL Application
362
Traffic Management and Improved Network Performance
362
Security
363
Guidelines for Planning the Structure of an ACL
364
ACL Configuration and Operating Rules
364
How an ACE Uses a Mask to Screen Packets for Matches
366
What Is the Difference between Network (or Subnet) Masks and the Masks Used with Acls
366
Rules for Defining a Match between a Packet and an Access Control Entry (ACE)
367
General Steps for Implementing Acls
371
Configuring and Assigning an ACL
371
Overview
371
Types of Acls
372
ACL Configuration Structure
372
Standard ACL Structure
373
Extended ACL Configuration Structure
374
ACL Configuration Factors
375
The Sequence of Entries in an ACL Is Significant
375
In any ACL, There will Always be a Match
377
Interface
377
You Can Assign an ACL Name or Number to a VLAN Even if the ACL Does Not yet Exist in the Switch's Configuration
377
Using the CLI to Create an ACL
377
General ACE Rules
378
Using CIDR Notation to Enter the ACL Mask
378
Configuring and Assigning a Numbered, Standard ACL
379
Configuring and Assigning a Numbered, Extended ACL
384
Configuring a Named ACL
390
Enabling or Disabling ACL Filtering on a VLAN
392
Deleting an ACL from the Switch
393
Displaying ACL Data
394
Display an ACL Summary
394
Display the Content of All Acls on the Switch
395
Display the ACL Assignments for a VLAN
396
Displaying the Content of a Specific ACL
397
Display All Acls and Their Assignments in the Switch Startup-Config File and Running-Config File
399
Editing Acls and Creating an ACL Offline
399
Using the CLI to Edit Acls
399
General Editing Rules
400
Deleting any ACE from an ACL
400
Working Offline to Create or Edit an ACL
402
Enable ACL "Deny" Logging
405
Requirements for Using ACL Logging
405
Enabling ACL Logging on the Switch
406
ACL Logging Operation
406
Operating Notes for ACL Logging
408
General ACL Operating Notes
409
Introduction
413
Terminology
416
Overview
419
Types of IP Acls
419
ACL Inbound Application Points
419
Features Common to All Acls
420
General Steps for Planning and Configuring Acls
421
ACL Operation
422
The Packet-Filtering Process
423
Switch Resource Usage
426
Prioritizing and Monitoring ACL, IGMP, Qos, and Rate Limiting Feature Usage
427
ACL Resource Usage and Monitoring
427
Standard Acls
428
Extended Acls
428
Managing ACL Resource Consumption
430
Oversubscribing Available Resources
430
Troubleshooting a Shortage of Per-Port Resources
431
Example of ACL Resource Usage
433
Viewing the Current Per-Port Rule and Mask Usage
433
Traffic Management and Improved Network Performance
436
Security
436
Guidelines for Planning the Structure of an ACL
437
ACL Configuration and Operating Rules
438
How an ACE Uses a Mask to Screen Packets for Matches
440
What Is the Difference between Network (or Subnet) Masks and the Masks Used with Acls
440
Rules for Defining a Match between a Packet and an Access Control Entry (ACE)
441
General Steps for Implementing Acls
445
Types of Acls
445
Overview
445
Advertisement
HP ProCurve 5300xl Management And Configuration Manual (508 pages)
Brand:
HP
| Category:
Network Router
| Size: 3.59 MB
Table of Contents
Table of Contents
5
Contents
21
Overview
22
Command Prompts
23
Keys
24
Getting Documentation from the Web
26
Sources for more Information
27
Need Only a Quick Start?
28
Contents
29
Overview
30
Advantages of Using the Menu Interface
31
Advantages of Using the CLI
32
Advantages of Using the HP Web Browser Interface
33
Manager Plus
35
Contents
39
Overview
40
Starting and Ending a Menu Session
41
How to Start a Menu Interface Session
42
How to End a Menu Session and Exit from the Console:
43
Main Menu Features
45
Screen Structure and Navigation
47
Rebooting the Switch
50
Menu Features List
52
Where to Go from here
53
Contents
55
Overview
56
Privilege Levels at Logon
57
Privilege Level Operation
58
Manager Privileges
59
How to Move between Levels
61
Listing Commands and Command Options
62
Listing Command Options
64
Displaying CLI "Help"
65
Configuration Commands and the Context Configuration Modes
67
CLI Control and Editing
70
Contents
71
Overview
72
General Features
73
Starting an HP Web Browser Interface Session with the Switch
74
Plus (PCM+)
75
Tasks for Your First HP Web Browser Interface Session
77
Interface
78
Entering a User Name and Password
80
Online Help for the HP Web Browser Interface
81
Support/Mgmt Urls Feature
82
Support URL
83
Status Reporting Features
84
The Port Utilization and Status Displays
85
Port Status
87
The Alert Log
88
Alert Types and Detailed Views
89
The Status Bar
90
Setting Fault Detection Policy
92
Contents
95
Overview
96
Using the CLI to Implement Configuration Changes
99
Configuration Changes
102
Rebooting from the Menu Interface
104
Web: Implementing Configuration Changes
105
Using Primary and Secondary Flash Image Options
106
Switch Software Downloads
108
Local Switch Software Replacement and Removal
109
Rebooting the Switch
111
Operating Notes
113
Multiple Configuration Files on 5300Xl Switches
114
General Operation
116
Transitioning to Multiple Configuration Files
118
Listing and Displaying Startup-Config Files
119
Displaying the Content of a Specific Startup-Config File
121
Managing Startup-Config Files in the Switch
123
Renaming an Existing Startup-Config File
124
Erasing a Startup-Config File
126
Switch to Its Default Configuration
127
Transferring Startup-Config Files to or from a Remote Server
129
Connected Host
130
Operating Notes for Multiple Configuration Files
131
Contents
133
Overview
134
Interface Access: Console/Serial Link, Web, and Inbound Telnet
135
Menu: Modifying the Interface Access
136
CLI: Modifying the Interface Access
137
Sessions
140
System Information
141
Menu: Viewing and Configuring System Information
142
CLI: Viewing and Configuring System Information
143
Web: Configuring System Parameters
146
Contents
147
Overview
148
IP Configuration
149
Just Want a Quick Start with IP Addressing?
150
Menu: Configuring IP Address, Gateway, and Time-To-Live (TTL)
151
CLI: Configuring IP Address, Gateway, and Time-To-Live (TTL)
153
Web: Configuring IP Addressing
157
How IP Addressing Affects Switch Operation
158
Dhcp/Bootp Operation
159
Network Preparations for Configuring Dhcp/Bootp
161
Onfiguration File Downloads
162
Enabling IP Preserve
163
Contents
167
Overview
168
Protocol Operation
169
Disabling Time Synchronization
170
Menu: Viewing and Configuring SNTP
171
CLI: Viewing and Configuring SNTP
174
Configuring (Enabling or Disabling) the SNTP Mode
176
Timep: Viewing, Selecting, and Configuring
181
Menu: Viewing and Configuring Timep
182
CLI: Viewing and Configuring Timep
184
Configuring (Enabling or Disabling) the Timep Mode
186
SNTP Unicast Time Polling with Multiple SNTP Servers
190
Displaying All SNTP Server Addresses Configured on the Switch
191
Configured
193
Contents
195
Overview
196
Menu: Port Configuration
200
CLI: Viewing Port Status and Configuring Port Parameters
202
Port Mode
203
Enabling or Disabling Flow Control
205
Configuring a Broadcast Limit on the Switch
208
Configuring HP Auto-MDIX
209
Web: Viewing Port Status and Configuring Port Parameters
212
Using Friendly (Optional) Port Names
213
Configuring Friendly Port Names
214
Displaying Friendly Port Names with Other Port Data
215
Contents
219
Poe Operation on the Series 5300Xl Switches
220
Poe Terminology
221
Overview of Operation
222
General Poe Operation
223
PD Support
224
Power Priority Operation
226
Configuring Poe Operation
228
Disabling or Re-Enabling Poe Port Operation
229
Configuring Optional Poe Port Identifiers
230
Viewing Poe Configuration and Status
233
Displaying an Overview of Poe Status on All Ports
234
Displaying the Poe Status on Specific Ports
235
Planning and Implementing a Poe Configuration
237
Assigning Priority Policies to Poe Traffic
238
Calculating the Maximum Load for an Xl Poe Module
239
Poe Operating Notes
240
Poe Event Log Messages
241
Contents
245
Overview
246
Port Trunk Features and Operation
248
Trunk Configuration Methods
249
Menu: Viewing and Configuring a Static Trunk Group
253
CLI: Viewing and Configuring Port Trunk Groups
255
Using the CLI to Configure a Static or Dynamic Trunk Group
258
Web: Viewing Existing Port Trunk Groups
261
Trunk Group Operation Using LACP
262
Default Port Operation
265
LACP Notes and Restrictions
266
Trunk Group Operation Using the "Trunk" Option
268
Trunk Operation Using the "FEC" Option on the 5300Xl Switches
269
How the Switch Lists Trunk Data
270
Contents
273
Overview
274
Rate-Limiting
275
Configuring Inbound Rate-Limiting
276
Displaying the Current Rate-Limit Configuration
277
Operating Notes for Rate-Limiting
278
Switches
281
Outbound Traffic
283
Configuration
285
GMB Operating Notes
286
Jumbo Packets on the Series 3400Cl and Series 6400Cl Switches
287
Operating Rules
288
Configuring Jumbo Packet Operation
289
Viewing the Current Jumbo Configuration
290
Enabling or Disabling Jumbo Traffic on a VLAN
292
Troubleshooting
295
Contents
297
Using SNMP Tools to Manage the Switch
299
SNMP Management Features
300
Configuring for SNMP Version 3 Access to the Switch
301
SNMP Version 3 Commands
302
Enabling Snmpv3
303
Snmpv3 Users
304
Group Access Levels
307
Snmpv3 Communities
308
Communities
310
CLI: Viewing and Configuring SNMP Community Names
312
Snmpv3 Notification and Traps
314
Snmpv1 and Snmpv2C Trap Features
316
Using the CLI to Enable Authentication Traps
319
Advanced Management: RMON
320
LLDP (Link-Layer Discovery Protocol)
321
LLDP Terminology
322
General LLDP Operation
323
LLDP Configuration Options
324
Options for Reading LLDP Information Collected by the Switch
326
LLDP Operating Rules
327
Cl Switches
328
Switches
330
Viewing the Current LLDP Configuration
331
Configuring Global LLDP Packet Controls
333
Configuring SNMP Notification Support
336
Configuring Per-Port LLDP Transmit and Receive Modes
337
Configuring LLDP Per-Port Advertisement Content
338
Displaying Advertisement Data
340
Displaying LLDP Statistics
345
LLDP Operating Notes
347
CDP on the Series 5300Xl Switches
349
CDP Terminology
350
General CDP Operation
351
Incoming CDP Packets
352
Viewing and Configuring CDP on the Switch
355
Viewing the Switch's Current CDP Configuration
356
Clearing (Resetting) the CDP Neighbors Table
358
Effect of Spanning Tree (STP) on CDP Packet Transmission
360
CDP Packets
361
CDP Neighbor Data and MIB Objects
362
Operating Notes
364
Contents
367
Overview
368
Using TFTP to Download Switch Software from a Server
369
Menu: TFTP Download from a Server to Primary Flash
370
CLI: TFTP Download from a Server to Flash
371
Using Secure Copy and SFTP
373
How It Works
374
The SCP/SFTP Process
375
Authentication
376
Workstation
378
Primary or Secondary Flash
379
Switch-To-Switch Download
380
CLI: Switch-To-Switch Downloads
381
Using HP PCM+ to Update Switch Software
383
Transferring Switch Configurations and ACL Command Files
384
TFTP: Copying a Configuration from a Remote Host
385
Server
386
Xmodem: Copying a Configuration File from the Switch to a Serially Connected PC or UNIX Workstation
388
Workstation
390
Copying Event Log Output to a Destination Device
391
Copying Crash Log Data Content to a Destination Device
392
Contents
393
Overview
394
Status and Counters Data
395
Menu Access to Status and Counters
396
General System Information
397
Switch Management Address Information
398
Module Information
399
Port Status
400
Viewing Port and Trunk Group Statistics and Flow Control Status
401
Menu Access to Port and Trunk Statistics
402
CLI Access to Port and Trunk Group Statistics
403
Menu Access to the MAC Address Views and Searches
404
CLI Access for MAC Address Views and Searches
407
Spanning Tree Protocol (STP) Information
408
CLI Access to STP Data
409
Internet Group Management Protocol (IGMP) Status
410
VLAN Information
411
Web Browser Interface Status Information
413
Interface Monitoring Features
414
Menu: Configuring Port and Static Trunk Monitoring
415
CLI: Configuring Port, Mesh, and Static Trunk Monitoring
417
Web: Configuring Port Monitoring
420
Contents
421
HP ProCurve 5300xl Access Security Manual (404 pages)
Brand:
HP
| Category:
Switch
| Size: 4.16 MB
Table of Contents
Table of Contents
5
Product Documentation
17
About Your Switch Manual Set
17
Feature Index
18
Contents
23
Getting Started
23
Conventions
24
Feature Descriptions by Model
24
Introduction
24
Keys
26
Port Identity Examples
26
Sources for more Information
26
Getting Documentation from the Web
28
Online Help
29
Need Only a Quick Start
30
Overview of Access Security Features
31
General Switch Traffic Security Guideline
32
Applications for Access Control Lists (Acls)
33
To Set up and Install the Switch in Your Network
31
Configuring Username and Password Security
36
Overview
36
Configuring Local Password Security
39
Menu: Setting Passwords
39
CLI: Setting Passwords and Usernames
41
Front-Panel Security
42
Web: Setting Passwords and Usernames
42
When Security Is Important
43
Front-Panel Button Functions
44
Clear Button
45
Reset Button
45
Restoring the Factory Default Configuration
45
Configuring Front-Panel Security
47
Disabling the Clear Password Function of the Clear Button on the Switch's Front Panel
49
Re-Enabling the Clear Button on the Switch's Front Panel and Setting or Changing the "Reset-On-Clear" Operation
50
Changing the Operation of the Reset+Clear Combination
51
Disabling or Re-Enabling the Password Recovery Process
52
Password Recovery
52
Password Recovery Process
54
Contents
55
Virus Throttling (5300Xl Switches Only)
55
Introduction
57
Filtering Options
59
General Operation of Connection-Rate Filtering
59
Application Options
60
Sensitivity to Connection Rate Detection
60
Terminology
61
Operating Rules
62
For a Network that Is Relatively Attack-Free
63
For a Network that Appears to be under Significant Attack
64
Basic Connection-Rate Filtering Configuration
65
Global and Per-Port Configuration
65
Enabling Connection-Rate Filtering and Configuring Sensitivity
66
Configuring the Per-Port Filtering Mode
67
Example of a Basic Connection-Rate Filtering Configuration
68
Viewing and Managing Connection-Rate Status
70
Viewing the Connection-Rate Configuration
70
Listing and Unblocking the Currently-Blocked Hosts
72
Configuring and Applying Connection-Rate Acls
74
Connection-Rate ACL Operation
75
Configuring a Connection-Rate ACL Using Source IP Address Criteria
76
Configuring a Connection-Rate ACL Using UDP/TCP Criteria
77
Applying Connection-Rate Acls
80
Using CIDR Notation to Enter the ACE Mask
80
Example of Using an ACL in a Connection-Rate Configuration
81
Connection-Rate ACL Operating Notes
84
Connection-Rate Log and Trap Messages
85
General Configuration Guidelines
63
Contents
87
Web and MAC Authentication
87
Overview
88
Client Options
89
General Features
90
Authenticator Operation
91
How Web and MAC Authentication Operate
91
Web-Based Authentication
91
MAC-Based Authentication
93
Terminology
95
Operating Rules and Notes
96
General Setup Procedure for Web/Mac Authentication
98
Do These Steps before You Configure Web/Mac Authentication
98
Additional Information for Configuring the RADIUS Server to Support MAC Authentication
99
Configuring the Switch to Access a RADIUS Server
100
Configuring Web Authentication on the Switch
102
Overview
102
Configure the Switch for Web-Based Authentication
103
Configuring MAC Authentication on the Switch
107
Overview
107
Configure the Switch for MAC-Based Authentication
108
Show Status and Configuration of Web-Based Authentication
111
Show Status and Configuration of MAC-Based Authentication
112
Client Status
114
Contents
115
TACACS+ Authentication
115
Overview
116
Terminology Used in TACACS Applications
117
General Authentication Setup Procedure
119
General System Requirements
119
Before You Begin
122
Configuring TACACS+ on the Switch
122
CLI Commands Described in this Section
123
Viewing the Switch's Current Authentication Configuration
123
Viewing the Switch's Current TACACS+ Server Contact Configuration
124
Configuring the Switch's Authentication Methods
125
Configuring the Switch's TACACS+ Server Access
129
How Authentication Operates
134
General Authentication Process Using a TACACS+ Server
134
Local Authentication Process
136
Encryption Options in the Switch
137
General Operation
137
Using the Encryption Key
137
Controlling Web Browser Interface Access When Using TACACS+ Authentication
138
Controlling Web Browser Interface Access When Using TACACS
138
Authentication
138
Messages Related to TACACS+ Operation
139
Operating Notes
139
Contents
141
RADIUS Authentication and Accounting
141
Authentication Services
143
Overview
143
Accounting Services
144
RADIUS-Administered Cos and Rate-Limiting
144
Terminology
144
Switch Operating Rules for RADIUS
145
General RADIUS Setup Procedure
147
Configuring the Switch for RADIUS Authentication
148
Outline of the Steps for Configuring RADIUS Authentication
149
Configure Authentication for the Access Methods You Want RADIUS
150
To Protect
150
Enable the (Optional) Access Privilege Option
152
Configure the Switch to Access a RADIUS Server
153
Configure the Switch's Global RADIUS Parameters
155
Local Authentication Process
159
Controlling Web Browser Interface Access
160
Configuring the RADIUS Server
161
Services
161
Viewing the Currently Active Per-Port Cos and Rate-Limiting Configuration Specified by a RADIUS Server
162
RADIUS-Assigned Access Control Lists
165
Terminology
167
General Operation
169
The Packet-Filtering Process
170
Determining Traffic Policies
173
General Steps
173
Planning the Acls Needed to Enforce Designated
174
Planning the Acls Needed to Enforce Designated Traffic Policies
174
Traffic Policies
174
Operating Rules for RADIUS-Based Acls
176
Configuring an ACL in a RADIUS Server
178
Configuring the Switch to Support RADIUS-Based Acls
182
Displaying the Current RADIUS-Based ACL Activity
184
On the Switch
184
Event Log Messages
186
Causes of Client Deauthentication Immediately after Authenticating
187
Configuring RADIUS Accounting
188
Operating Rules for RADIUS Accounting
189
Steps for Configuring RADIUS Accounting
190
Configure the Switch to Access a RADIUS Server
191
Configure Accounting Types and the Controls for Sending Reports to the RADIUS Server
192
Optional) Configure Session Blocking and Interim Updating
194
Viewing RADIUS Statistics
196
General RADIUS Statistics
196
RADIUS Authentication Statistics
197
RADIUS Accounting Statistics
198
Changing RADIUS-Server Access Order
200
Messages Related to RADIUS Operation
201
Configuring Secure Shell (SSH)
204
Overview
204
Terminology
205
Prerequisite for Using SSH
207
Public Key Formats
207
Steps for Configuring and Using SSH for Switch and Client Authentication
208
General Operating Rules and Notes
210
Assigning a Local Login (Operator) and Enable (Manager) Password
211
Generating the Switch's Public and Private Key Pair
212
Providing the Switch's Public Key to Clients
214
Enabling SSH on the Switch and Anticipating SSH Client Contact
217
Behavior
217
Configuring the Switch for SSH Authentication
220
Use an SSH Client to Access the Switch
223
Further Information on SSH Client Public-Key Authentication
224
Messages Related to SSH Operation
229
Configuring the Switch for SSH Operation
211
Configuring Secure Socket Layer (SSL)
232
Overview
232
Terminology
233
Prerequisite for Using SSL
235
Steps for Configuring and Using SSL for Switch and Client Authentication
235
General Operating Rules and Notes
236
Assigning a Local Login (Operator) and Enable (Manager)Password
237
Configuring the Switch for SSL Operation
237
Generating the Switch's Server Host Certificate
239
To Generate or Erase the Switch's Server Certificate
240
With the CLI
240
Comments on Certificate Fields
241
Generate a Self-Signed Host Certificate with the Web Browser
243
Interface
243
Generate a CA-Signed Server Host Certificate with the Web Browser
245
Enabling SSL on the Switch and Anticipating SSL Browser Contact
247
Behavior
247
Using the CLI Interface to Enable SSL
249
Using the Web Browser Interface to Enable SSL
249
Common Errors in SSL Setup
251
Introduction
254
Overview
254
Advertisement
HP ProCurve 5300xl Access Security Manual (292 pages)
Brand:
HP
| Category:
Switch
| Size: 6.2 MB
Table of Contents
Table of Contents
5
Getting Started
14
Introduction
14
Overview of Access Security Features
14
General Switch Traffic Security Guideline
15
Applications for Access Control Lists (Acls)
16
Command Syntax Conventions
17
Simulating Display Output
17
Command Prompts
17
Getting Documentation from the Web
20
Sources for more Information
21
Need Only a Quick Start
22
To Set up and Install the Switch in Your Network
22
Configuring Username and Password Security
24
Overview
24
Configuring Local Password Security
27
Menu: Setting Passwords
27
To Delete Password Protection
28
To Recover from a Lost Manager Password
28
CLI: Setting Passwords and Usernames
29
Configuring Manager and Operator Passwords
29
To Remove Password Protection
29
Web: Setting Passwords and Usernames
30
Front Panel Security
30
When Security Is Important
31
Front Panel Button Functions
32
Clear Button
32
Reset Button
33
Restoring the Factory Default Configuration
33
Configuring Front Panel Security
35
Disabling the Clear Password Function of the Clear Button on the Switch's Front Panel
36
Re-Enabling the Clear Button on the Switch's Front Panel
38
Setting or Changing the "Reset-On-Clear" Operation
38
Changing the Operation of the Reset+Clear Combination
39
Password Recovery
40
Password Recovery Process
42
Web and MAC Authentication
43
Contents
43
Overview
44
Client Options
45
General Features
46
How Web and MAC Authentication Operate
47
Authenticator Operation
47
Web-Based Authentication
47
MAC-Based Authentication
49
Terminology
50
Operating Rules and Notes
52
General Setup Procedure for Web/Mac Authentication
54
Do These Steps before You Configure Web/Mac Authentication
54
Additional Information for Configuring the RADIUS Server to Support MAC Authentication
55
Configuring the Switch to Access a RADIUS Server
56
Configuring Web Authentication on the Switch
58
Overview
58
Configure the Switch for Web-Based Authentication
59
Configuring MAC Authentication on the Switch
63
Overview
63
Configure the Switch for MAC-Based Authentication
64
Show Status and Configuration of Web-Based Authentication
67
Show Status and Configuration of MAC-Based Authentication
68
Client Status
70
TACACS+ Authentication
71
Contents
71
Overview
72
Terminology Used in TACACS Applications
73
General System Requirements
75
General Authentication Setup Procedure
75
Configuring TACACS+ on the Switch
78
Beforeyou Begin
78
CLI Commands Described in this Section
79
Viewing the Switch's Current Authentication Configuration
79
Viewing the Switch's Current TACACS+ Server Contact
80
Configuration
80
Configuring the Switch's Authentication Methods
81
Configuring the Switch's TACACS+ Server Access
85
How Authentication Operates
90
General Authentication Process Using a TACACS+ Server
90
Local Authentication Process
92
Using the Encryption Key
93
Controlling Web Browser Interface Access When Using TACACS+ Authentication
94
Messages Related to TACACS+ Operation
95
Operating Notes
95
RADIUS Authentication and Accounting
97
Contents
97
Overview
98
Terminology
99
Switch Operating Rules for RADIUS
100
General RADIUS Setup Procedure
101
Configuring the Switch for RADIUS Authentication
102
Outline of the Steps for Configuring RADIUS Authentication
102
Configure Authentication for the Access Methods You Want RADIUS to Protect
104
Configure Authentication for the Access Methods You Want
104
RADIUS to Protect
104
Configure the Switch to Access a RADIUS Server
106
Configure the Switch's Global RADIUS Parameters
108
Local Authentication Process
111
Controlling Web Browser Interface Access When Using RADIUS Authentication
112
Configuring RADIUS Accounting
113
Operating Rules for RADIUS Accounting
114
Steps for Configuring RADIUS Accounting
114
Configuring RADIUS Accounting
114
Viewing RADIUS Statistics
120
General RADIUS Statistics
120
RADIUS Authentication Statistics
122
RADIUS Accounting Statistics
123
Changing RADIUS-Server Access Order
124
Messages Related to RADIUS Operation
126
Configuring Secure Shell (SSH)
128
Overview
128
Terminology
129
Prerequisite for Using SSH
131
Public Key Formats
131
Steps for Configuring and Using SSH for Switch and Client
132
Authentication
132
General Operating Rules and Notes
134
Assigning a Local Login (Operator) and Enable (Manager)
135
Configuring the Switch for SSH Operation
135
Generating the Switch's Public and Private Key Pair
136
Providing the Switch's Public Key to Clients
138
Enabling SSH on the Switch and Anticipating SSH Client Contact Behavior
141
Configuring the Switch for SSH Authentication
144
Use an SSH Client to Access the Switch
147
Further Information on SSH Client Public-Key
148
Authentication
149
Messages Related to SSH Operation
153
Configuring Secure Socket Layer (SSL)
156
Overview
156
Terminology
157
Prerequisite for Using SSL
159
Steps for Configuring and Using SSL for Switch and Client
159
Authentication
159
General Operating Rules and Notes
160
Configuring the Switch for SSL Operation
161
HP ProCurve 5300xl Supplementary Manual (38 pages)
Access Controller xl Module to the HP ProCurve 6400cl/5300xl/3400cl
Brand:
HP
| Category:
IP Access Controllers
| Size: 0.82 MB
Table of Contents
Management and Configuration Guide
1
Table of Contents
3
Applicable Switch Models
5
Applicable Secure Access 700Wl Models
5
Introduction
5
General Operation
5
Related Publications
6
Terminology
6
Access Controller Xl Module Overview
7
Module Operation
8
Using 5300Xl Features with the Access Controller Xl Module
10
Routing Infrastructure Support
13
Using 5300Xl Switch Network Address Translation with the ACM
15
The Role of Vlans
15
Client Vlans
15
Static VLAN Features Supported on Client Vlans
17
General Operating Rules
18
Configuring the ACM on the Network
18
Configuring the Access Controller Xl Module
20
Configuring Downlink Client Ports
20
Changing the VLAN-Base
22
Configuring Client Vlans
22
Configuring Uplink Network Ports
22
Configuring the Uplink VLAN
23
ACM Configuration Commands Summary and Syntax
24
Configuration Context Command Syntax
24
Access Controller Context Command Syntax
26
Displaying Access Controller Xl Status from the 5300Xl CLI
28
ACM Display Commands Summary and Syntax
28
Configuration Context Command Syntax
29
Access Controller Context Command Syntax
30
Managing the ACM
31
Using the Acm's Extended CLI
31
Downloading New Software to the Module
34
Operating Notes
35
HP ProCurve 5300xl Specification Sheet (12 pages)
Hewlett-Packard ProCurve Switch Specification Sheet
Brand:
HP
| Category:
Switch
| Size: 0.63 MB
Advertisement
Related Products
HP 5300
HP ProCurve 5304xl
HP ProCurve 5308xl
HP ProCurve 5308XL-48G
HP ProCurve 5304xl-G32
HP ProCurve 5308xl-G48
HP ProCurve 5304x1
HP ProCurve 5308x1
HP 5300xl Series
HP ProCurve 5372x1
HP Categories
Desktop
Laptop
Server
Monitor
Switch
More HP Manuals
Login
Sign In
OR
Sign in with Facebook
Sign in with Google
Upload manual
Upload from disk
Upload from URL