Model-Based Configurations
- On the menu, click to display the Switches window.
- Select or Switch Group and click the Configuration tab.
- In the Model Configuration section, select the Switch Model from
the drop-down list and click Configure to
display the Feature Configuration <group
name> dialog box.Note: The Feature Configuration dialog box displays details about the ACL, VLAN, and static for the selected model. You can create, edit, and delete these configurations as necessary.
- Configure the
ACL settings.
- Click the ACL tab.
- Click Create to display the ACL fields.
- Complete the
following fields:
- ACL Name/ID: Enter the name of the access control list or provide the list identifier.
- ACL Type: Select Standard or Extended from the drop down list.
- Rules: Click Create to create an ACL rule.
- Complete the following fields to configure the
following ACL rule for the Extended ACL type:
You must provide the list sequence (Seq#), Action (Permit or Deny) and Source Network information to create the rule.
Note: Controller supports the "equal to" operator only. - Complete the following fields to configure the
following ACL rule for the Extended ACL type:
- Seq#: Enter the sequence number, which determines the order in which the ACL rules are applied.
- Action: Select Permit to allow traffic or Deny to block traffic based on the rule
- Source Network: Enter the source network address, specifying where the traffic originates.
- Destination Network: Enter the destination network address, specifying where the traffic is headed.
- Source Port: Enter the source port number. By default, port 22 (commonly used for SSH) is selected.
- Destination Port: Enter the destination port number. By default, port 22 is selected.
- DSCP Matching: Enter the Differentiated Services Code Point (DSCP) value to match incoming traffic for quality of service (QoS) purposes. DSCP values are used to classify and manage network traffic to ensure efficient data transmission.
- DSCP Marking: Enter the DSCP value to mark outgoing traffic, setting its priority for QoS. This helps in managing bandwidth and ensuring that high-priority traffic is transmitted efficiently.
- Internal Priority Marking: Enter the internal priority value to classify and prioritize traffic within the network.
- Traffic Policy: Select a traffic policy from the drop-down list to apply to the rule.
- Complete the following fields to configure the
following ACL rule for the Extended ACL type:
- Apply ACL Config: Select Now or Schedule Later. If you choose to schedule the configuration deployment for later, provide the time and date.
- Click OK to add the newly created ACL configuration to the ACL page. You can edit the configuration by selecting Configure.
- Configure the
VLAN settings.
- Click the VLAN tab.
- Click Create to display the VLAN fields.
- Complete the
following VLAN fields:
- VLAN #: Enter the number of the VLAN.
- VLAN Name: Enter the name of the Layer 2 VLAN.
- As Default VLAN: If you enable the As Default VLAN the VLAN Name is changed to DEFAULT-VLAN and the Management settings correspond to the previous VLAN settings.
- Management VLAN: By enabling this, you can configure Management VLAN for the switches or switch groups.
-
7.0 Beta FeatureIPv4 DHCP Snooping: Monitors and filters DHCP traffic on a network switch to prevent unauthorized or rogue DHCP servers from distributing IP addresses. If you enable IPv4 DHCP Snooping, you must provide the breakout port for this option in the DHCP Snooping Trust Port field.Attention: To complete this change, the ICX will reboot after the controller syncs the configuration updates.
- APR
Inspection: Validates ARP packets to
prevent ARP spoofing and man-in-the-middle attacks by
ensuring correct MAC-to-IP address bindings. You must
provide the breakout port for this option in the
ARP
Inspection Trust Port field.
Attention: To complete this change, the ICX reboots after the controller syncs the configuration updates.
- IGMP Snooping: Ensures that multicast traffic is only forwarded to devices that have requested it, thereby preventing unnecessary traffic and conserving bandwidth. Select None, Active, or Passive from the list. Ensures that multicast traffic is only forwarded to devices that have requested it, thereby preventing unnecessary traffic and conserving bandwidth. If you select Active or Passive, you are required to select the Multicast Version as well.
- Spanning Tree: Select None, STP (802.1d), or RSTP (802.1w) from the list. If you select STP 802.1d or RSTP 802.1w, you are required to select the Spanning Tree Priority as well.
- Ports: Click Create and complete the following
fields:
Note: Different set of ports can be entered for each switch model.
- Apply VLAN Config: Select Now or Schedule Later. If you choose to schedule the configuration deployment for later, provide the time and date.
- Click OK to add the newly created VLAN configuration to the VLAN page.
Note: You can also edit and delete the VLAN configuration by selecting the options Configure and Delete respectively, from the VLAN tab.Note: Beginning with the 7.0 release, when you modify the VLAN # and VLAN Name , the ICX System log displays the SZ Administrator name associated with this configuration activity. In the earlier releases, the ICX System log showed a generic message indicating that the network controller made the change.
- Configure the
Static Route settings.
- Click the Static Route tab.
- Click Create to display the Static Route fields.
- Complete the
following Static Route fields:
- Destination IP: Enter the destination IP address.
- Next Hop: Enter the next-hop IP address. Multicast and broadcast IP addresses are not allowed.
- Admin Distance: Enter a value from 1 through 255.
- Apply Static Route Config: Select Now or Schedule Later. If you choose to schedule the configuration deployment for later, provide the time and date.
- Click OK to add the newly created static route configuration to the Static Route page.
- Click Close.
The IP address is added to the Model Configuration page under Property. If you want to edit the configuration, select it and click Edit to edit the settings.Note: Any changes made to the group level configuration including common configuration and switch model-based configuration will be applied to all the switches belonging to the group.Configuration defined at group level can be chosen to be applied instantaneously by selecting the Now option or schedule for a later time using Schedule later option. The scheduling option is only applicable if you are trying to make changes to existing switches in the group. For any new switches that are joining the group, this configuration gets applied instantaneously.
- Configure the
ACL settings.
%20Access%20Points%20and%20Switch%20Management%20Guide%207.2.0_v2_GUID-A7E97382-FE30-4D84-8798-282DAD40F0B6/Feature%20Configuration=GUID-A94538A2-D48C-4488-9BC4-C39D490613BA=2=en-US=Low.png)
%20Access%20Points%20and%20Switch%20Management%20Guide%207.2.0_v2_GUID-A7E97382-FE30-4D84-8798-282DAD40F0B6/VLAN%20Configuration=GUID-E2CD7C0A-DECF-4E34-B140-F11300F77224=3=en-US=Low.png)
%20Access%20Points%20and%20Switch%20Management%20Guide%207.2.0_v2_GUID-A7E97382-FE30-4D84-8798-282DAD40F0B6/switch-model-static-route=GUID-D0605B2C-F0E7-4F6A-B4F6-30C558FECA26=3=en-US=Low.png)