Ports

The ports are visually represented on the page in the same manner as the actual physical ports on the device. Each port is numbered according to the port number on the switch and displays its current status. Select a port to open the port configuration.

Viewing Port Details

The following section describes the different behaviors of the switch ports.

Figure 1  Switch Ports

Color of the Ports

The color of the port is based on the number of error packets seen on the port over the total number of packets that pass on the port

The color of the port will be:

  • Green, if the error rate is less than 0.1% and the port is in full-duplex mode
  • Yellow, if the error rate is greater than 0.1% and the port is in full-duplex mode
  • Green, if the error rate is less than 2% and the port is in half-duplex mode
  • Yellow, if the error rate is greater than 2% and the port is in half-duplex mode

Port Icons

The following table lists some of the key icons that are displayed on the switch ports.

Table 1: Port Icons

Symbol

Definition

Powered by PoE.

PoE denied, indicating that the port is disconnected.

PoE fault

Transceiver issue.

Link flapping

Loop detected

Identification

Under Identification, when a port is selected the following options are displayed:

  • Name of the port in read and write mode.
  • Enabled —Select the checkbox to enable the port. To disable the port, unselect the checkbox. Clients and devices are allowed to draw power and connect to the port when it is set to Enabled. This setting is available for PoE ports with or without connected site devices.
  • State—State of the port.
  • Use Port Profile—Allows you to assign a port profile to the selected port.
  • Port Profile—On enabling Use Port Profile, the Port Profile field is displayed.

    From the Port Profile drop-down list, select either an existing port profile or create a new port profile.

    For more information on creating a port profile, see Creating a Port Profile.

    After a port profile assigning, View Port Profile is displayed. On clicking the View Port Profile, opens the port profile detail panel on the left.

    Click View Details, to navigate to the port profile configuration page.

    If a port profile is assigned, then Security, Authentication, Power Management sections are not displayed. These parameters are configured in the port profile.

PoE Specification

The port details also displays the PoE specification, when the port is powered by PoE. The information is displayed as power supplied, power allocated, PoE class as highlighted in the screen capture below.

Figure 2  PoE Specification

Security

The security section consists of the following options:

  • Untrusted Port Protections (DHCP and ARP)—Enable this option when untrusted devices are connected to the port. This setting in combination with Network Security configuration is used to prevent DHCP and ARP attacks on the wired network. This setting is enabled by default. For more information, see Security.
  • Port Isolation (Protected Port)—Enable this option to provide Layer 2 isolation between interfaces (Ethernet ports and LAGs) that belong to the same broadcast domain (VLAN). This ensures that the specific ports can be isolated from others within the same VLAN. When this option is enabled, the port can only send traffic to unprotected ports. Any packets received on a protected port are filtered at the egress of other protected ports, preventing communication between them. This option is disabled by default. Protected ports are not supported on Instant On 1830 switches.
  • Spanning Tree Protections (BPDU Guard)—Enable this option to protect spanning tree configurations from interference. BPDU protection is a security feature designed to protect the active MSTP topology by preventing spoofed BPDU packets from entering the MSTP domain. This option is disabled by default. The options listed under Spanning tree protections are:
    • No spanning tree protections (default)—The default spanning tree protection settings without the BPDU option.
    • Filter spanning tree protocol (BPDU filter)—Filters incoming and outgoing BPDUs on the port.
    • Block spanning tree protocol (BPDU guard)—Stops the incoming and outgoing BPDUs received on the port.
    • Root bridge protection (Root guard)—Protects the designated root bridge by preventing unauthorized ports from becoming a root bridge.

 

 

Authentication

    The 802.1X Authentication section consists of the following options:

    These settings are available only for ports that do not have devices connected to it. However, the authentication mode can be updated regardless of the connected clients.

    • No authenticationInstant On devices and clients can connect to the port without authenticating. This is the default setting.
    • Port-based—All Instant On devices and clients connected to the port are authorized after the initial 802.1x RADIUS authentication is successful.
    • Client-based—Requires each Instant On device or client connecting to the port to separately authenticate to the 802.1x RADIUS server to gain access.

      This is an optional setting. When Client-based is selected as the 802.1X Authentication type, an additional Authentication Options section is displayed. You can select one of the following options:

      • 802.1X + MAC Authentication—Enables a secondary attempt at MAC-based authentication if the initial 802.1X request times out. If 802.1X is explicitly refused by the server (for example, during an invalid credentials), MAC authentication is not attempted.
      • Unauthenticated User Guest Access—Enables a fallback to a wired guest network for clients that fail 802.1X authentication. This requires a wired Guest Network to be configured on the Instant On site. On enabling this option the guest network is displayed as Untagged guest network under the Network Assignment > Included Networks section of the port configuration.

    The Port-based and Client-based authentication methods, require configuration a RADIUS profile to determine how authentication behaves across all access controlled ports.

Port Access

Under Ports > Port Access, select the Specific Clients checkbox to allow the port to connect to specific clients.

Connected Clients and Devices

This setting allows users to select clients from the connected clients list and add them to the Allowed clients and devices list. Only the clients that appear in the list will be able to access the network when connected through that port. Disabling this feature will allow any wired client to connect to the port.

The following procedure describes how to add clients and devices to the allowed list, for a specific port on an Instant On switch:

  1. Click the Devices () tile on the Instant On web application home page or click Devices from the navigation pane on the left. The Device Overview page is displayed.
  2. Use one of the following methods to view the switch details:
    1. Clicking on the switch name.
    2. Hover the cursor to the end of the row, click the button, and select View Details from the drop-down list.
  3. Under Ports > Port Access, select the Specific Clients checkbox.
  4. Under Allowed Clients and Devices, click Add.
  5. Click the Search button and connect the clients and devices to the port to be discovered.
  6. Once the search is complete, select the checkbox next to the clients and devices you want to add to the Allowed list and click the Add Clients and Devices button.
  7. Click Update.
  • The Allowed selected clients and devices setting can be enabled on a maximum of 10 ports on the switch, and you can add only up to 10 allowed clients to one port.
  • This setting is not supported for Instant On 1830 switches and cannot be enabled for Uplink ports or ports to which Instant On devices are connected.

Clients and Devices Connected to this Port

Connected Clients and Devices— Allows you to view devices connected to port sorted by network. By default, All Networks is selected. To filter the clients and devices connected to a specific network, select a network from the Wired Network drop-down list. The clients and infrastructure devices directly connected to the port are displayed as a link that takes you to the client details page. The indirectly connected clients are displayed by their MAC address.

Power Management

Power management options allow you to configure PoE supply to devices connected to the switch. These options are unavailable for ports that are part of LACP.

  • Power Allocation — Select either one of the following options to configure a power supply policy for the port:
    • No Power over Ethernet—No power is allocated to the port.
    • Usage(default) — The power allocated to the port is based on usage and is unrestricted.
    • Class — The power allocated to the port is based on the PoE standard of the device. The power class of devices are categorized as follows:

      Table 2: Power Class of Devices

      Class

      Maximum Power from PSE

      Class 0

      15.4 Watts

      Class 1

      4 Watts

      Class 2

      7 Watts

      Class 3

      15.4 Watts

      Class 4

      30 Watts

      Class 5

      45 Watts

      Class 6

      60 Watts

  • Port Priority — Assigns a priority level to the ports. When there is a budget constraint for delivering PoE power at the switch, power is delivered to the connected devices based on the port priority. The power is delivered in the following order: Critical > High > Low. Under Port Priority, assign any one of the following priority level to the port:
    • Low (default) — Configures the port as a low priority port.
    • High — Configures the port as a high priority port.
    • Critical — Configures the port as a critical priority port.
    • When two ports belonging to the same priority are demanding power, the port with the least port number is given priority. Example: When port 2 and 5 are assigned Critical class and the switch has a power budget constraint, device on port 2 will receive full power and the remaining power budget will be allocated to the device on port 5.

    • PoE priority cannot be configured for Instant On devices. By default, Instant On devices are configured with Usage mode and Critical for Port Priority.

  • Power schedule — Select this checkbox to either enable or disable power schedule on the port. If enabled, the PoE supply to the port is determined by the power schedule defined. To change the power schedule, click on View power schedule. For more information on configuring Power Schedule, see Power Management.

Port Options

Port Option option displays the link speed and how the port handles the traffic in both directions (Half or Full-Duplex). The data volume is displayed in Mbps.

The configurations displayed under Speed/Duplex are:

  • Auto Negotiated(default)—displays the recommended setting for almost all devices.
  • Manual—displays the port to a specific speed and duplex values by selecting Manual Speed / Duplex Options from the drop-down list. (e.g., 100 Mbps Half-Duplex, 100 Mbps Full-Duplex, 1 G Full-Duplex, 2.5 G Full-Duplex).

Under Port Options > Advanced Options, select the Limit Broadcast and Multicast Storms checkbox to limit excessive broadcast and multicast traffic.

Port Usage

Port Usage option displays the total accumulated data over the past 24-hour period. The data volume is displayed in bytes.
The configurations displayed under Power Management are:

  • Downloaded—displays the total accumulated download data over the previous 24-hour period.
  • Uploaded—displays the total accumulated upload data over the previous 24-hour period.

Port Usage option includes the total number of packets processed during the 24-hour period.

  • pkts for values less than 1,000,000 packets. Values between 1,000 and 999,999 packets represents standard decimal notation (i.e. 1.5 pkts for 1,500 packets).
  • M pkts for values from 1,000,000 up to (but not including) 1,000,000,000 packets.

  • G pkts for values of 1,000,000,000 packets and greater.

Connected Clients and Devices

On selecting the port, the Connected Clients and Devices section displays the list of clients and devices connected to the port. By default, the clients and devices for All Networks applicable to the port are displayed. The clients and infrastructure devices directly connected to the port are displayed as a link to the client details page. The indirectly connected clients are displayed by their MAC address. To filter the clients and devices connected to a specific network, select a network from the Wired Network drop-down list.