WGSW-Series (V3) User Manual
Table Of Contents
- 1. INTRODUCTION
- 2. INSTALLATION
- 3. SWITCH MANAGEMENT
- 4. WEB CONFIGURATION
- 4.1 Main Web Page
- 4.2 System
- 4.2.1 Management
- 4.2.1.1 System Information
- 4.2.1.2 IP Configuration
- 4.2.1.3 IP Status
- 4.2.1.4 ARP Configuration
- 4.2.1.5 Users Configuration
- 4.2.1.6 Privilege Levels
- 4.2.1.7 NTP Configuration
- 4.2.1.7.1 System Time Correction Manually
- 4.2.1.8 Time Configuration
- 4.2.1.9 UPnP
- 4.2.1.10 DHCP Relay
- 4.2.1.11 DHCP Relay Statistics
- 4.2.1.12 CPU Load
- 4.2.1.13 System Log
- 4.2.1.14 Detailed Log
- 4.2.1.15 Remote Syslog
- 4.2.1.16 SMTP Configuration
- 4.2.2 Simple Network Management Protocol
- 4.2.3 RMON
- 4.2.4 DHCP server
- 4.2.5 Remote Management
- 4.2.1 Management
- 4.3 Switching
- 4.3.1 Port Management
- 4.3.2 Link Aggregation
- 4.3.3 VLAN
- 4.3.3.1 VLAN Overview
- 4.3.3.2 IEEE 802.1Q VLAN
- 4.3.3.3 VLAN Port Configuration
- 4.3.3.4 VLAN Membership Status
- 4.3.3.5 VLAN Port Status
- 4.3.3.6 Private VLAN
- 4.3.3.7 Port Isolation
- 4.3.3.8 VLAN setting example:
- 4.3.3.8.1 Two Separate 802.1Q VLANs
- 4.3.3.8.2 VLAN Trunking between two 802.1Q aware switches
- 4.3.3.8.3 Port Isolate
- 4.3.3.9 MAC-based VLAN
- 4.3.3.10 IP Subnet-based VLAN
- 4.3.3.11 Protocol-based VLAN
- 4.3.3.12 Protocol-based VLAN Membership
- 4.3.4 VLAN Translation
- 4.3.5 Spanning Tree Protocol
- 4.3.6 Multicast
- 4.3.6.2 Profile Table
- 4.3.7 MLD Snooping
- 4.3.8 MVR (Multicast VLAN Registration)
- 4.3.9 LLDP
- 4.3.10 MAC Address Table
- 4.3.11 Loop Protection
- 4.3.12 UDLD
- 4.3.13 GVRP
- 4.4 Quality of Service
- 4.5 Security
- 4.6 Power over Ethernet (For WGSW-20160HP/WGSW-24040HP_24040HP4)
- 4.7 ONVIF
- 4.8 Maintenance
- 4.8.1 Web Firmware Upgrade
- 4.8.2 Save Startup Config
- 4.8.3 Configuration Download
- 4.8.4 Configuration Upload
- 4.8.5 Configure Activate
- 4.8.6 Configure Delete
- 4.8.7 Image Select
- 4.8.8 Factory Default
- 4.8.9 System Reboot
- 4.8.10 Ping
- 4.8.11 IPv6 Ping
- 4.8.12 Remote IP Ping
- 4.8.13 Cable Diagnostics
- 4.8.14 Traceroute (IPv4)
- 4.8.15 Traceroute (IPv6)
- 5. SWITCH OPERATION
- APPENDIX A: Networking Connection
User’s Manual of WGSW Series Managed Switch
296
4.5.4.3 Port Security Detail
This page shows the MAC addresses secured by the Port Security module. Port Security is a module with no direct
configuration. Configuration comes indirectly from other modules - the user modules. When a user module has enabled port
security on a port, the port is set-up for software-based learning. In this mode, frames from unknown MAC addresses are
passed on to the port security module, which in turn asks all user modules whether to allow this new MAC address to forward or
block it. For a MAC address to be set in the forwarding state, all enabled user modules must unanimously agree on allowing the
MAC address to forward. If only one chooses to block it, it will be blocked until that user module decides otherwise. The Port
Security Detail screen in Figure 4-5-4-3 appears.
Figure 4-5-4-3: Port Security Detail Screen Page Screenshot
The page includes the following fields:
Object Description
• Clear
Click to remove this particular MAC addresses from MAC table.
• VLAN ID & MAC
Address
The VLAN ID and MAC address that is seen on this port. If no MAC addresses
are learned, a single row stating "No MAC addresses attached" is displayed.
• State
Indicates whether the corresponding MAC address is violating (administrative
user has configured the interface in "Restrict" mode and the MAC address is
blocked), blocked, or forwarding.
• Age/Hold
If at least one user module has decided to block this MAC address, it will
stay in the blocked state until the hold time (measured in seconds) expires.
If all user modules have decided to allow this MAC address to forward, and
aging is enabled, the Port Security module will periodically check that this
MAC address still forwards traffic.
If the age period (measured in seconds) expires and no frames have been
seen, the MAC address will be removed from the MAC table. Otherwise a
new age period will begin.
If aging is disabled or a user module has decided to hold the MAC address
indefinitely, a dash (-) will be shown.