Page 751 / 757 Scroll up to view Page 746 - 750
xStack
®
DGS-3600 Series Layer 3 Gigabit Ethernet Managed Switch CLI Manual
747
DGS-3627:admin# show wac
Command: show wac
Web-based Access Control
-----------------------------
State
: Enabled
Method
: RADIUS
Redirect Path
Virtual IP
: 0.0.0.0
Virtual IPv6
: 2000::20
Switch HTTP Port
: 80 (HTTP)
RADIUS Authorization
: Enabled
Local Authorization
: Enabled
DGS-3627:admin#
show wac ports
Purpose
Used to display web authentication port level setting.
Syntax
show wac ports { <portlist> }
Description
This command allows the user to display the port level setting.
Parameters
ports
- A range of member ports to show the status.
Restrictions
None.
Example usage:
To show WAC port state and other parameters:
DGS-3627:admin# show wac ports 1-3
Command: show wac ports 1-3
Port
State
Aging Time
Idle Time
Block Time
(min)
(min)
(sec)
------- ------------- -------------
------------ ------------
1:1
Enabled
60
30
120
1:2
Enabled
60
30
120
1:3
Enabled
120
60
120
Success.
DGS-3627:admin#
show wac user
Purpose
Used to user account for web authentication.
Syntax
show wac user
Description
The show wac user command allows you to show web authentication account.
Parameters
None.
Restrictions
None.
Example usage:
To show WAC local user:
Page 752 / 757
xStack
®
DGS-3600 Series Layer 3 Gigabit Ethernet Managed Switch CLI Manual
748
DGS-3627:admin# show wac user
Command: show wac user
User Name
Password
VID
---------
----------
------
Jim
pasx
1000
Total Entries: 1
DGS-3627:admin#
show wac auth_state
Purpose
Used to display the authentication state of a port.
Syntax
show wac auth_state ports { <portlist> }
Description
Used to display the authentication state for ports.
Parameters
ports
- Specifies the list of ports whose WAC state will be displayed.
Restrictions
None.
Example usage:
Supposed that port 1 is in host-based mode:
1.
MAC 00-00-00-00-00-01 is authenticated without VLAN assigned (may be the specified target VLAN does not
exist or target VLAN has not been specified at all), the ID of RX VLAN will be displayed (RX VLAN ID is 4004 in
this example).
2.
MAC 00-00-00-00-00-02 is authenticated with target VLAN assigned, the ID of target VLAN will be displayed
(target VLAN ID is 1234 in this example)
3.
MAC 00-00-00-00-00-03 failed to pass authentication, the VID field will be shown as “-” indicating that packets
with SA 00-00-00-00-00-03 will be dropped no matter which VLAN these packets are from.
4.
MAC 00-00-00-00-00-04 attempts to start authentication, the VID field will be shown as “-“until authentication
completed.
Supposed that port 2 is in port-based mode:
1.
MAC 00-00-00-00-00-10 is the MAC which made port 2 pass authentication; MAC address is followed by “(P)” to
indicate the port-based mode authentication. Supposed that port 3 is in port-based mode:
2.
MAC 00-00-00-00-00-20 attempts to start authentication, MAC address is followed by “(P)” to indicate the port-
based mode authentication.
3.
MAC 00-00-00-00-00-21 failed to pass authentication, MAC address is followed by “(P)” to indicate the port-
based mode authentication.
Page 753 / 757
xStack
®
DGS-3600 Series Layer 3 Gigabit Ethernet Managed Switch CLI Manual
749
DGS-3627:admin# show wac auth_state ports
Command: show wac auth_state ports
P:Port-based Pri: Priority
Port
MAC Address
Original
State
VID Pri Aging Time/ Idle
RX VID
Block Time
Time
------ -------------------- ---- -------------- ---- -- ----------- ----
1:3
00-00-00-00-00-01
20
Authenticated
4004 3
Infinite
40
1:3
00-00-00-00-00-02
20
Authenticated
1234 -
Infinite
50
1:11
00-00-00-00-00-03
100
Blocked
-
-
60
-
1:11
00-00-00-00-00-04
110
Authenticating
-
-
10
-
2:2
00-00-00-00-00-10(P) 2040
Authenticated
1234 2
1440
20
2:3
00-00-00-00-00-20(P) 2045
Authenticating
-
-
5
-
12:13
00-00-00-00-00-21
2041
Authenticated
-
6
1100
80
12:13
00-00-00-00-00-E4
2041
Blocked
-
-
100
-
Total Authenticating Hosts :2
Total Authenticated Hosts
:4
Total Blocked Hosts
:2
DGS-3627:admin#
clear wac auth_state
Purpose
Used to delete the authentication entries.
Syntax
clear wac auth_state [ports [ <portlist> | all ] { authenticated | authenticating | blocked }
| macaddr <macaddr>]
Description
Used to clear the authentication state of a port. If the port is port-based mode, the port will
return to un-authenticated state. The entire timer associated with the port will be reset.
If the port is host based mode, users on this port will be cleared. The user needs to be re-
authenticated to access the network.
Parameters
ports
- Specifies the list of ports whose WAC state will be cleared.
authenticated
- Specified to clear all authenticated users for a port.
authenticating
- Specified to clear all authenticating users for a port.
Restrictions
Only Administrator and Operator-level users can issue this command.
Example usage:
To delete WAC host:
DGS-3627:admin# clear wac auth_state ports 1-5
Command: clear wac auth_state ports 1-5
Success.
DGS-3627:admin#
Page 754 / 757
xStack
®
DGS-3600 Series Layer 3 Gigabit Ethernet Managed Switch CLI Manual
750
A
PASSWORD RECOVERY COMMANDS
This section describes the procedure for resetting passwords on D-Link Switches.
Authenticating any user who tries to access networks is necessary and important. The basic authentication method used
to accept qualified users is through a local login, utilizing a Username and Password. Sometimes, passwords get
forgotten or destroyed, so network administrators need to reset these passwords. This document will explain how the
Password Recovery feature can help network administrators reach this goal.
The following steps explain how to use the Password Recovery feature on D-Link devices to easily recover passwords.
Complete these steps to reset the password:
1.
For security reasons, the Password Recovery feature requires the user to physically access the device.
Therefore this feature is only applicable when there is a direct connection to the console port of the device. It
is necessary for the user needs to attach a terminal or PC with terminal emulation to the console port of the
switch.
2.
Power on the switch. After the runtime image is loaded to 100%, the Switch will allow 2 seconds for the user
to press the hotkey [^] ( Shift + 6 ) to enter the “Password Recovery Mode”. Once the Switch enters the
“Password Recovery Mode”, all ports on the Switch will be disabled.
Boot Procedure
1.10-B09
-------------------------------------------------------------------------------
Power On Self Test
......................................
100 %
MAC Address
: 00-1C-F0-B5-40-00
H/W Version
: A1
Please wait, loading V2.80.B31 Runtime image
............
100 %
Password Recovery Mode
>
3.
In the “Password Recovery Mode” only the following commands can be used.
Command
Parameters
reset config {force_agree(1)}
The reset config command resets the whole configuration will be back to the
default value
reboot {force_agree(1)}
The reboot command exits the Reset Password Recovery Mode and restarts
the switch. A confirmation message will be displayed to allow the user to save
the current settings.
reset account
The reset account command deletes all the previously created accounts.
reset password {<username>}
The reset password command resets the password of the specified user. If a
username is not specified, the password of all users will be reset.
show account
The show account command displays all previously created accounts.
Page 755 / 757
xStack
®
DGS-3600 Series Layer 3 Gigabit Ethernet Managed Switch CLI Manual
751
B
TECHNICAL SPECIFICATIONS
Specifications listed here apply to all Switches in the DGS-3600 Series except where otherwise noted.
General
Protocols
IEEE 802.3 10BASE-T Ethernet
IEEE 802.3u 100BASE-TX Fast Ethernet
IEEE 802.3ab 1000BASE-T Gigabit Ethernet
IEEE 802.3z 1000BASE-T (SFP “Mini GBIC”)
IEEE 802.3ae (10G Optional Modules)
IEEE 802.1D/w/s Spanning Tree (Rapid, Multiple)
IEEE 802.1P/Q VLAN
IEEE 802.1p Priority Queues
IEEE 802.1v Protocol VLAN
IEEE 802.1X Port-based Network Access Control
IEEE 802.3 NWay auto-negotiation
IEEE 802.3ad Link Aggregation Control
IEEE 802.3x Full-duplex Flow Control
IEEE 802.1u Fast Ethernet
Standards
CSMA/CD
Data Transfer Rates:
Ethernet
Fast Ethernet
Gigabit Ethernet
Fiber Optic
Half-duplex
Full-duplex
10 Mbps
20Mbps
100Mbps
200Mbps
N/A
2000Mbps
SFP (Mini GBIC) Support
IEEE 802.3u 100BASE-FX (DEM-210 transceiver)
IEEE 802.3u 100BASE-FX (DEM-211 transceiver)
IEEE 802.3z 1000BASE-LX (DEM-310GT transceiver)
IEEE 802.3z 1000BASE-SX (DEM-311GT transceiver)
IEEE 802.3z 1000BASE-SX (DEM-312GT2 transceiver)
IEEE 802.3z 1000BASE-LH (DEM-314GT transceiver)
IEEE 802.3z 1000BASE-ZX (DEM-315GT transceiver)
IEEE 802.3z WDM Transceiver (DEM-330T transceiver)

Rate

4.5 / 5 based on 2 votes.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top