Configuring Port Settings for a Switch

Port settings allow you to configure the behavior of individual ports on a switch, stack, or switch group. These settings are essential for managing network performance and security.

By configuring port settings, you can apply Access Control Lists (ACLs) to invoke Quality of Service (QoS) settings, prioritizing specific types of traffic, such as Voice over IP (VoIP) and VIDEO VLAN traffic.

    Note:
  • Port settings for QoS can only be configured for switches that are executing firmware version 08.0.95 and above.
  • When SmartZone is configured in 'IPv6 only' mode, it removes support for ACL.
  • Port-level DHCP v4/v6 settings and Point-to-Point Protocol over Ethernet Intermediate Agent (PPPoE IA) server port configuration are supported only on the ICX8200 series.
  • SmartZone supports configuring PPPoE IA on IPv4 only, dual mode, and IPv6 only mode.
  1. On the menu, click Network > Wired > Switches to display the Switches window.
  2. On the Switches page, select the switch you want to view.
    The switch details appear in the Details section at the bottom of the page.
  3. Click the Ports tab.
  4. To configure the Port Settings, either double-click a port in the Ports View section OR double click a port name under the Port Details section.

    Ports View

    Ports View

    Port Details

    Port Details

  5. In the Port Settings page, complete the following configurations.

    Port Settings Window

    Port Settings Window
    1. Port Name: Enter the port name.
    2. Port Enabled: Click to enable the port.
    3. Port Protected: Click to enable the protected port.
      Note: Port Protected field is displayed only for the switches using SmartZone 5.2.1 and above.

      Port VLANs

      Port VLANs
    4. Port VLANs: If you configure VLAN on both group model configuration and port settings, port level changes takes precedence.
    5. Customize: Click customize to identify the ports that need to stay customized.
    6. Use Group Settings: Click the user group settings to rebind the identified ports back to the group level.
    7. Tagged VLANs: Enter the tagged VLAN ID or VLAN ID range.
    8. Untagged VLAN: Enter an untagged VLAN ID.

      Port Settings - PoE

      Port Settings - PoE
    9. POE Enable: Click the POE Enable toggle button to enable (ON).
    10. POE Class: ​Select the PoE class. You can configure the PoE budget on ports by setting the PoE class to 0 through 4.
    11. POE Priority: Enter the PoE priority.
    12. POE Budget: Allows you to manually set the PoE power limit.

      Port Settings - ACL and Ports Speed

      Port Settings - ACL and Ports Speed
    13. Ingress ACL: Select the Ingress ACL from the list.
      Note: When SmartZone is configured in 'IPv6 only' mode, the Ingress ACL field is hidden.
    14. Egress ACL: Select the Egress ACL from the list.
      Note: When SmartZone is configured in 'IPv6 only' mode, the Egress ACL field is hidden.
    15. Port Speed: Select the required Port Speed from the list.

      Port Settings - Storm Control

      Port Settings - Storm Control
    16. Broadcast Limit: Limits the rate of broadcast frames accepted on the interface to prevent excessive VLAN flooding. Broadcast frames exceeding the configured limit are dropped at ingress and are not replicated to other VLAN member ports. Configure the threshold to define how many dropped broadcast packets must occur before a configured corrective action (port shutdown) is triggered.
      Configure the following values:
      • Limit: Accepted values range from 1 through 8,388,607 packets per second (pps), or from 1 through 1,000,000 kbps when the port speed is set to Auto or Optic; for fixed port speeds, accepted values are from 1 kbps through the configured port speed.
      • Threshold: Accepted values range from 1 through 8,388,607 packets per second (pps) when the limit is configured in pps, or from 1 through 1,048,576 kbps when the limit is configured in kbps.
        Note: Configure conservative limits on access ports, and use thresholds only to automate mitigation of sustained violations.
    17. Multicast Limit: Limits the rate of multicast frames accepted on the interface to control VLAN replication and bandwidth consumption. Multicast frames exceeding the configured limit are dropped at ingress and are not forwarded to other VLAN member ports. Configure the threshold to define how many dropped multicast packets must occur before a configured corrective action (port shutdown) is triggered.
      Configure the following values:
      • Limit: Accepted values range from 1 through 8,388,607 packets per second (pps), or from 1 through 1,000,000 kbps when the port speed is set to Auto or Optic; for fixed port speeds, accepted values are from 1 kbps through the configured port speed.
      • Threshold: Accepted values range from 1 through 8,388,607 packets per second (pps) when the limit is configured in pps, or from 1 through 1,048,576 kbps when the limit is configured in kbps.
        Note: Configure conservative limits on access ports, and use thresholds only to automate mitigation of sustained violations.
    18. Unknown -Unicast Limit: Limits the rate of unknown unicast frames accepted on the interface to prevent excessive VLAN flooding during MAC learning. Unknown unicast frames exceeding the configured limit are dropped at ingress and are not flooded to other VLAN member ports. Configure the threshold to define how many dropped unknown-unicast packets must occur before a configured corrective action (port shutdown) is triggered.
      Configure the following:
      • Limit: Accepted values range from 1 through 8,388,607 packets per second (pps), or from 1 through 1,000,000 kbps when the port speed is set to Auto or Optic; for fixed port speeds, accepted values are from 1 kbps through the configured port speed.
      • Threshold: Accepted values range from 1 through 8,388,607 packets per second (pps) when the limit is configured in pps, or from 1 through 1,048,576 kbps when the limit is configured in kbps.
        Note: Configure conservative limits on access ports, and use thresholds only to automate mitigation of sustained violations.

      Port Settings - RSTP Edge Port

      Port Settings - RSTP Edge Port
    19. RSTP Admin Edge Port: Click to enable the RSTP Admin Edge Port.
    20. STP BPDU Guard: Click the STP BPDU Guard toggle button to enable (ON).
    21. STP Root Guard: Click the STP Root Guard toggle button to enable (ON).

      Port Settings - DHCP Snooping

      Port Settings - DHCP Snooping
    22. VLAN DHCP Snooping Trust Port: Click the toggle button to enable (ON) the VLAN DHCP Snooping on the port. The switch port will trust the received DHCP responses as legit and will forward them to the corresponding destination.
        Note:
      • Starting from SmartZone version 7.1.1, the port name DHCP Snooping Trust Port is changed to VLAN DHCP Snooping Trust Port.
      • When VLAN DHCP Snooping Trust Port is enabled, the controller automatically disables the standard DHCP Snooping setting for that port.
    23. DHCPv6 Snooping Trust Port: Designates the port as trusted for DHCPv6 server traffic. When enabled, the port forwards DHCPv6 messages from legitimate servers and blocks rogue DHCPv6 server responses on untrusted ports.
    24. DHCP Snooping Port: Select Enable if you want the port to participate in DHCP Snooping. The switch port, when enabled with DHCP snooping, will disregard unauthorized DHCP responses and maintain a DHCP snooping binding table. This table records DHCP operations on the port to validate subsequent DHCP messages, ensuring they come from legitimate sources and enhancing network security. When enabled, enter a descriptive string (from 1 to 63 characters) in the Circuit ID field to identify the port or location, and in the Remote ID field to identify the relay agent or forwarding device.
        Note:
      • In IPv4 DHCP Snooping, the Circuit ID and the Remote ID are optional inputs.
      • In IPv6 DHCP Snooping, the Remote ID is an optional input.

      Port Settings - ARP Inspection

      Port Settings - ARP Inspection
    25. ARP Inspection Trust Port: Click the toggle button to enable (ON) the ARP Inspection Trust Port. Configure this option on uplink or other trusted ports to allow legitimate ARP traffic while preventing ARP spoofing on untrusted interfaces.
    26. ARP Inspection: Click the toggle button to enable (ON) the ARP Inspection.
        Note:
      • IPv6-only SmartZone Controllers do not support ARP Inspection.
      • The following requirements must be met to enable ARP Inspection on the controller.
        • RUCKUS ICX devices must be running FastIron firmware version 10.0.20c or later.
        • SmartZone must be running version 7.1.1 or later.
        • RUCKUS ICX models supported: ICX 8200.

      Port Settings - Neighbor Inspection

      Port Settings - Neighbor Inspection
    27. IPv6 Neighbor Inspection Trust : Click the toggle button to enable (ON) the Neighbor Discover Inspection (IPv6) Trust Port. This trust setting is used on ports that connect to known, trusted devices to ensure the proper forwarding of Neighbor Discovery (ND) messages while still enforcing inspection on untrusted ports.
    28. Neighbor Discover Inspection (IPv6): Click the toggle button to enable (ON) the Neighbor Discover Inspection (IPv6).
        Note:
      • IPv6-only SmartZone Controllers do not support Neighbhor Discover Inspection (IPv6).
      • The following requirements must be met to enable Neighbhor Discover Inspection (IPv6) on the controller.
        • RUCKUS ICX devices must be running FastIron firmware version 10.0.20c or later.
        • SmartZone must be running version 7.1.1 or later.
        • RUCKUS ICX models supported: ICX 8200.

      Port Settings - PPPoE Intermediate Agent

      Port Settings - PPPoE Intermediate Agent
    29. PPPoE Intermediate Agent: The Point-to-Point Protocol over Ethernet (PPPoE) is a network protocol that encapsulates Point-to-Point Protocol (PPP) frames inside Ethernet frames. When enabled, the PPPoE Intermediate Agent facilitates the insertion of PPPoE tags and manages PPPoE sessions between clients and servers. The PPPoE Intermediate Agent setting allows you to configure the PPPoE port role as either a Server or a Client interface.
      • If you select Server; configure the following.

        The Vendor Tag Policy field becomes available with two options:

        • None: Vendor-specific tags are passed through unchanged.
        • Strip: Vendor-specific tags are removed from PPPoE packets.

      • If you select Client; configure the following.

        The Circuit ID and Remote ID textboxes are displayed.

        • Circuit ID: Enter a descriptive string (range from 1 to 63 characters) to identify the port or location.
        • Remote ID: Enter a string (range from 1 to 63 characters) to identify the relay agent or forwarding device.

      Port Settings - IPSG, ILLDP, DSCP Trust

      Port Settings - IPSG, ILLDP, DSCP Trust
    30. IPSG: Click IPSG toggle button to enable (ON).
    31. ILLDP: Click ILLDP toggle button to enable (ON).
    32. DSCP Trust: Click DSCP toggle button to enable (ON). With this setting, the switch port will honor the DSCP markings of the received traffic and prioritize it accordingly.
      Note: When enabling Voice VLAN, the controller will automatically enable DSCP Trust Port.

      Port Settings - Voice VLAN and QoS Settings

      Port Settings - Voice VLAN and QoS Settings
    33. Voice VLAN: Select the VLAN (tagged or untagged).
    34. LLDP QoS: Click to enable LLDP-MED settings.
    35. Application type: Enter one of the application types : Guest_Voice, Guest_Voice_Signaling, Softphone_Voice, Streaming_Video, Video_Conferencing, Video_Signaling, Voice, and Voice_Signaling.
    36. VLAN type: The VLAN type can be priority-tagged, tagged, or untagged.
    37. VLAN ID: Enter the VLAN ID of the VLAN type.
    38. Priority: Enter the priority for the QoS setting.
    39. DSCP: Enter the DSCP value for the LLDP setting.
  6. Click OK.
Note: PoE per port settings. The below video displays the tasks to be performed to configure PoE on a port.