background image

 

RADIUS authenticated login 

 

 

 

Motorola, Inc. 

549453-001-00-a 

Page 19 of 51 

R

R

A

A

D

D

I

I

U

U

S

S

 

 

n

n

e

e

t

t

w

w

o

o

r

r

k

k

 

 

a

a

u

u

t

t

h

h

e

e

n

n

t

t

i

i

c

c

a

a

t

t

e

e

d

d

 

 

l

l

o

o

g

g

i

i

n

n

 

 

XLT will authenticate network logins from user accounts and passwords maintained on a remote RADIUS server.  
XLT implements RADIUS access-requests.  RADIUS network authenticated logins allows the administrators to easily 
change all passwords by changing the password on the RADIUS server, simplifying management of a large network 
with multiple users. 
 
Some RADIUS servers can authenticate using Microsoft Active Directory; thus network logins can be tied to the 
technicians network login account.  Using this method, password management is tied directly to the users network 
authentication. 
 
To use RADIUS network authentication, you will need a properly configured RADIUS server (free RADIUS servers are 
available for Linux operating systems or fee-based server products are available on UNIX and Microsoft NOS). 
 
RADIUS authenticated logins only support the “admin” user account privileges with the following exceptions: 
 

  The RADIUS account cannot disable RADIUS login support 

  The RADIUS account cannot change the built-in “Admin” password 

 
To create a RADIUS server configuration from the CLI, use the following command: 
 

radius server config

 <

1-5

(index)> <

ip-address

 #.#.#.#> <

shared-secret

 

string

> <

timeout

 

1-10

> <

retries

 

1-120

 

Options Description 

index 5 

RADIUS 

servers can be added.  Authentication will be performed starting with the server in 

index 1 

ip-address 

IP address of the RADIUS server 

shared-secret 

This is the password used by the RADIUS server to authentication the Access-Request 
packets from the Tut OS 

timeout 

Number of seconds to wait after sending an Access-Request packet before sending another 
request or trying another server.  Practical timeout value is 5 seconds. 

retries 

Number of retries before giving up and trying a different server.  A practical entry for retries is 
2 to 3. 

 
 
Note:  The “admin” account name is not reserved.  You may create an “admin” account on the RADIUS server.  If so, 
the Tut OS will first check the password against the local “admin” account password before trying the RADIUS server.  
Unless there is a special reason to do so, we recommend not using an “admin” account on the RADIUS server. 

Summary of Contents for mT2a - PowerBroadband EthernetXD Switch

Page 1: ...Motorola Inc 549453 001 00 a Page 1 of 51 USER GUIDE T2 2500 PowerBroadband aka mT2a EthernetXD ...

Page 2: ...infringement of third party rights Companies names and data used in the examples herein are fictitious unless otherwise noted Pass Through Licenses Net SNMP Copyright 1989 1991 1992 1996 1998 2004 LwIP Copyright 2001 2002 Swedish Instie of Computer Science Net SNMP and LwIP source code are provided under the terms of their respective license agreements Source code and copyright notices are availab...

Page 3: ...cations Operation of this equipment in a residential area is likely to cause harmful interference in which case the user will be required to correct the interference at his own expense Radio Frequency Interference Requirements Canada This Class A digital apparatus complies with Canadian ICES 003 Cet appareil numérique de la classe A est conforme à la norme NMB 003 du Canada Marking and European Ec...

Page 4: ...k should be such that the amount of air flow required for safe operation of the equipment is not compromised Mechanical Loading Mounting of the equipment in the rack should be such that a hazardous condition is not achieved due to uneven mechanical loading Circuit Overloading Consideration should be given to the connection of the equipment to the supply circuit and the effect that overloading of c...

Page 5: ...ling weee Italiano per i clienti dell UE tutti i prodotti che sono giunti al termine del rispettivo ciclo di vita devono essere restituiti a Motorola al fine di consentirne il riciclaggio Per informazioni sulle modalità di restituzione visitare il seguente sito Web www motorola com recycling weee Magyar Az EU ban vásárlóknak Minden tönkrement terméket a Motorola vállalathoz kell eljuttatni újrahas...

Page 6: ... Commit mode 16 Reset to Default Configuration 17 Other Configuration Help 17 Access Control Lists ACLs 18 RADIUS network authenticated login 19 WallPlate Installation 20 Installation Guidelines 20 Installation 1 Install over 70mm x 114mm wall plate 21 Installation 2 Install over European wall plate with 65mm offset 22 Installation 3 External mounting tabs 23 Remove the cover to service the WallPl...

Page 7: ...mic packet classification 36 QoS Example 37 VLAN Tutorials 38 Tutorial 1 Simple Hotel configuration 38 Tutorial 2 Mixed Mode VLAN configuration with QoS 39 Tutorial 3 Per port 802 1Q VLANs 41 Tutorial 4 Network Privacy without 802 1Q VLANs cascade optional 43 Line Status 45 Appendix A Pin out Assignments 47 Appendix B Hardware Specifications 49 Appendix C Compliance 51 ...

Page 8: ...ystem interface exit system A Ad dm mi in ni is st tr ra at ti iv ve e C Co om mm ma an nd ds s Most commands discussed in this guide are administrative commands which change the configuration of the system or affect the operation of the system These commands can only be executed from the admin account Configuration changes take affect immediately and are recorded in non volatile memory NVRAM in t...

Page 9: ...of all show subcommands Style Conventions The style conventions used in this manual distinguish various elements of the commands and facilitate the proper interpretation of command syntax parameters and their use This document refers to actual command syntax as little as possible For a complete command syntax document please refer to the Command Reference guide for a complete list of all available...

Page 10: ...l jack 45101 RoHS compliant version of 45001 45003 4 port m4a WallPlate 4 x Fast Ethernet ports 1 x high speed DSL port 1 x analog POTs RJ11 port Two powering options Adaptive Line Power from the 45025 switch or local power adapter Designed for installation over existing RJ11 wall jack RoHS compliant 45002 4 port m4 Service Unit 4 x Fast Ethernet ports and 1 x high speed DSL port Two powering opti...

Page 11: ... un nt ti in ng g O Op pt ti io on ns s T2 ships with mounting ears designed for a standard EIA 19 equipment rack The ears can be rotated 180 degrees S Sw wi it tc ch h R Re ea ar r P Pa an ne el l C Co on nn ne ec ct ti io on ns s LINE RJ21 PBX PSTN block or breakout panel PHONE RJ21 House block or breakout panel POWER 100 240VAC IEC320 male connector LINE RJ21 Connect to PBX PHONE RJ21 Connect t...

Page 12: ...o route an RJ11 cable behind the unit The line in RJ11 jack is located on the external side of the unit The Service Unit does not have an integrated POTS filter DC power connector not used from 0 to 600meters RJ11 filtered phone port Eth1 10 100 auto sensing Ethernet Eth2 10 100 auto sensing Ethernet Eth3 10 100 auto sensing Ethernet Eth4 10 100 auto sensing Ethernet RJ11 line in port not shown ac...

Page 13: ...0 8 N 1 no flow control Telnet Requires Eth1 or Eth2 enabled and a valid IP address HTTP Requires Eth1 or Eth2 enabled and a valid IP address Browser support IE6 or greater Mozilla Management URL http IP address Default login and password Default user name for administrative access admin Default password blank Default user name for monitoring only user Default password blank C CL LI I C Co on nf f...

Page 14: ...configuration security If editable configuration is desired use the CLI script files Configuration files from the webUI can be used to create secure template configurations Note The Configuration File contains every configuration possible including the Admin account password When combined with RADIUS network authentication the non editable Configuration Files provide a secure method to pre configu...

Page 15: ...nd any required changes If the WallPlate image requires a reload as during a system image upgrade the time to upload all 25 WallPlates is approximately 20 minutes During the upgrade time the WallPlates will not be available for network activity Currently there are no WallPlate upgrades planned for current releases of mT2 software System image can be upgrade using FTP or TFTP Commands used are Usin...

Page 16: ...nfig command syntax Summary Use the command show system config summary This command displays the configuration in an organized summary of each configured feature Use this output to quickly view the active configuration Startup Use the command show system config startup Displays only the commands entered by the administrator that result in a configuration change AND have been saved to memory Use th...

Page 17: ...nfig commit R Re es se et t t to o D De ef fa au ul lt t C Co on nf fi ig gu ur ra at ti io on n From the CLI enter the following command system config default Note This command is only available from a local serial login session O Ot th he er r C Co on nf fi ig gu ur ra at ti io on n H He el lp p The mT2 Command Reference is the master text for all T2 configurations It contains an alphabetical li...

Page 18: ...ough index 10 If no matches are found the access is granted Place the most restrictive access rules on the lower index number To enter ACLs from the CLI use the following command ip access list config 1 10 index deny permit type ip address mask service all ftp telnet http snmp Ex To block all HTTP access from any device enter ip access list config 1 deny http Ex To block all network access from al...

Page 19: ...account privileges with the following exceptions The RADIUS account cannot disable RADIUS login support The RADIUS account cannot change the built in Admin password To create a RADIUS server configuration from the CLI use the following command radius server config 1 5 index ip address shared secret string timeout 1 10 retries 1 120 Options Description index 5 RADIUS servers can be added Authentica...

Page 20: ...ng the keyhole slots mount over a 70mm x 114mm telephone wall plate as found in North America South America Asia Pacific 2 Using the horizontal slots mount over a telephone wall plate with 65mm offset mounting screws Most European telephone wall plates have 65mm offset mounting screws Other mounting options When the above option is not possible mount the m2a to a flat surface using the external mo...

Page 21: ...rew heads 3 Slide bracket over retaining screws 4 Tighten retaining screws to affix bracket to RJ11 wall plate Step 2 Install RJ11 line cable 5 Connect short RJ11 pigtail cable to internal RJ11 connector on the m2a circuit board 6 Connect other side of RJ11 pigtail cable to RJ11 connector on the RJ11 wall plate Step 3 Attach cover to the bracket 7 Use a slight angle to align the bottom connector 8...

Page 22: ...dimensions and thread style when planning the installation Typical required length is 10mm to 20mm Replacement machine screws should be obtained locally prior to the installation Step 1 Remove and discard cover over existing wall plate 3 Remove plastic cover and expose RJ11 bracket and mounting screws 4 Remove mounting screws 5 Align bracket horizontal slots over 65mm offset mounting holes 6 Insta...

Page 23: ...299 to the internal RJ11 connector on the m2a circuit board 2 Route the RJ11 cable out of the bracket using the exit hole next to the Ethernet ports Step 2 Assemble the m2 WallPlate 3 Snap the cover and bracket together 4 Install WallPlate unit to the wall or structurally sound flat surface using the external mounting tabs R Re em mo ov ve e t th he e c co ov ve er r t to o s se er rv vi ic ce e t...

Page 24: ...o or r I ID DF F 1 Install mT2a to equipment rack using the rack mount ears provided 2 Connect the AC line cord to the IEC320 male receptor on the rear of the unit I In ns st ta al ll l c cr ro os ss s c co on nn ne ec ct ts s 3 Siemens S66M2 5W TP is the recommended cross connect block Note the TP on the part number 4 Connect the LINE side mT2 RJ21 to the left side of the S66M2 5W TP block using ...

Page 25: ... login for the initial configuration Default IP 192 168 1 3 Enter these commands at the system prompt Login with default username and password Username admin Password blank Assign IP address to unit ip config ip address 192 168 20 2 mask 255 255 255 0 gateway 192 168 20 1 Enable Ethernet ports interface Ethernet enable eth2 system reboot Enable all High Speed DSL ports interface dsl enable port 1 ...

Page 26: ...11 blanking plug 2 Number 6 oval head screws 0 25 Components required to purchase Regulated 12V power supply Use of the wrong power supply could result in damage to your WallPlate unit Please order a small quantity of regulated 12V power supplies from Motorola PBN to use during installation If you do not have the correct regulated 12V power supply STOP Order a regulated 12V power supply from your ...

Page 27: ...adapter to the WallPlate 2 Connect the analogue phone to the RJ11 phone jack 3 Connect an Ethernet cable not supplied to a laptop The blue LED will flash slow then fast to indicate the unit is linking When the LED stops flashing the unit is linked Step 5 After WallPlate blue LED is solid connect with the mT2 switch using a valid IP address and HTTP or telnet 1 AC power adapter used during installa...

Page 28: ...ddress of your PC will appear along with the connected line Enable line power From the telnet CLI enter this command interface dsl power enable portx enable only the port being installing F Fi in ni is sh h t th he e i in ns st ta al ll la at ti io on n Remove the 12V regulated power supply If the correct port is enabled for line power the WallPlate will reset and operate from in line power Test t...

Page 29: ...SL links between the T2 Switch and the WallPlate are always TAGGED PVID In the 802 1Q standard each port is assigned a PVID This is the default VLAN ID assigned to untagged packets received ingress on that port The PVID is sometimes called the port Native VLAN By default all ports are assigned VLAN 1 Tagged T2 will optionally tag packets when transmitting egress on the port Set the port as a tagge...

Page 30: ...gurations are also available from the webUI vlan config default Restore VLAN configuration to default vlan enable disable Enable or disable VLAN support Requires a system reboot after issuing this command vlan add Create or modify a VLAN vlan delete Delete a VLAN Group Remove all ports that are members of the group before deleting the group vlan name Enter a friendly name for the VLAN vlan members...

Page 31: ...d should be used to get familiar with the system Vlan General webUI VLAN Config Enable VLAN support Requires system reboot VLAN Mode Local Mode refers to the mT2 Switch Port based or Tag based is supported Remote Mode refers to the WallPlate Tag based or disabled is supported VLAN Special Interfaces If video is delivered on a defined video VLAN be sure to assign IGMP to the VLAN used for video Whe...

Page 32: ...ach port This is also known as the native VLAN for the port All packets received on these ports as from a PC connected to the port are assigned the PVID of the port Port based VLAN webUI When the local mode is set to Port based The mT2 Switch is the local mode use the Port based menu to create a Port Map By default Eth1 and Eth2 can communicate with each other All DSL ports can communicate with Et...

Page 33: ...12 25 Port 12 can communicate with both Eth1 and Eth2 Ports 6 and 12 can also communicate together Note that DSL ports can only talk to the upstream Eth1 or Eth2 The only exception is DSL ports 6 and 12 Port based mode on the mT2 Switch can be mixed with Tag based mode on the WallPlate for an effective method to configure VLANs for advanced services Note VLAN Tutorial One for an example of mixing ...

Page 34: ...ample if the critical queue were assigned a Priority mode then those packets would transmit on the port before other packets in the buffers Shaping queue mode Apply traffic shaping rules to individual queues Each queue is assigned a fixed amount of bitrate The cumulative bitrate of all the queues should not exceed the total line rate of the port Q Qo oS S c co om mm ma an nd ds s a an nd d c co on...

Page 35: ...ed traffic shaping parameter for each queue Note that a queue will never exceed the peak rate parameter regardless of other services on the port Where Queue the queue where you wish to shape traffic Valid options are critical high medium or low Peak the maximum rate for the queue in Mbits second Average the average rate for the queue in Mbits second Burst the maximum data burst allowed at the peak...

Page 36: ...x discard rate will be set to 100 network qos interface wred eth 1 2 port 1 25 interface id queue low medium high critical min threshold 1 100 max threshold 1 100 Set the minimum and maximum buffer threshold for each queue on each port Once either threshold is crossed frames are discarded at the discard rates specified by the network qos wred config command D Dy yn na am mi ic c p pa ac ck ke et t...

Page 37: ...allPlate The other flow will be connected to Eth2 of the mT2 switch and Port1 2 of the first WallPlate Commands network qos enable system reboot network qos interface priority eth1 mode static level high network qos interface priority eth2 mode static level medium network qos interface egress shaping port1 queue critical peak 30 average 30 burst 100 network qos interface egress shaping port1 queue...

Page 38: ...QoS in this network Every WallPlate will have the same VLAN IDs Privacy enforced between rooms by the port privacy feature on the mT2 switch QoS is not used VLAN Ids used in this tutorial 100 VLAN used for all wired ports in the network This VLAN will transmit on the upstream network Third party network configuration The mT2 switches will connect to an upstream switch likely a Cisco or HP Both the...

Page 39: ...low value service such as HSIA high speed Internet All packets are 802 1Q tagged in the mT2 network and transmitted on the core network High Value Service o WallPlate port 2 is connected to a high value service such as VoIP or IPTV All packets are 802 1Q tagged in the mT2 network and transmitted on the core network QoS is applied in the mT2 based on the 802 1P priority bit Privacy and QoS in this ...

Page 40: ...ngress port 1 25 1 pvid 100 vlan interface ingress port 1 25 2 pvid 200 Assign VLAN memberships to WallPlate ports vlan membership add 100 interface port 1 25 1 vlan membership add 200 interface port 1 25 2 Configure QoS for high value service network qos interface priority eth1 mode dynamic level low network qos classification 802 1p network qos interface egress wfq port1 queue critical weight 5 ...

Page 41: ...02 1Q VLANs 13 QoS is not used since there is a single service delivered to each user VLAN Ids used in this configuration 14 101 2501 Assigned to port 1 of each WallPlate The VLAN ID indicates the WallPlate and port number 15 The chart shows a sampling of VLAN Ids to illustrate the naming convention in this tutorial VLAN ID DSL PORT ETHERNET PORT 101 1 1 201 2 1 2401 24 1 2501 25 1 16 4090 This VL...

Page 42: ...ships to DSL ports configure tagging rules vlan membership add 101 interface port1 vlan membership add 2501 interface port25 vlan membership egress 101 interface port1 tag enable vlan membership egress 2501 interface port25 tag enable Assign VLAN memberships to WallPlate ports vlan membership add 101 interface port1 1 vlan membership add 2501 interface port25 1 vlan membership egress 101 interface...

Page 43: ... network attached storage or other network device can be connected to Eth1 or Eth2 Note this configuration is also shown in the webUI examples at the introduction to VLANs earlier in this manual In this network WallPlate port 1 is used for HSIA WallPlate port 2 is disabled to prevent the subscriber from using the wrong port Eth1 is used for all packets Eth2 is enabled as a cascade port Privacy and...

Page 44: ...onfiguration on the cascaded switch Configure cascaded switch exactly as the first switch Connect Eth1 of the cascaded switch to Eth2 of the first switch Repeat for each cascaded switch Convert this tutorial to a real world configuration Note that in this tutorial all packets are untagged outside of the T2 This allows for a very quick simple installation of multiple switches since every switch can...

Page 45: ...the WallPlate Shows the status of the remote Ethernet port Options are connected disconnected disabled Downstream Displays the line bitrate in the downstream direction in Mbits second Upstream Displays the line bitrate in the upstream direction in Mbits second SNR DSx SNR USx Where x is 1 or 2 mT2 uses a 4 band QAM modulation Three of the 4 bands are used by mT2 to maximize downstream line bitrate...

Page 46: ...se the following chart Line Current Value Watts Reference 255 2 58 Idle no load or wire attached 197 4 87 195 4 91 190 5 02 185 5 13 180 5 31 175 5 38 2m wire attached no load 170 5 49 165 5 60 162 5 71 160 5 82 155 5 93 150 6 11 145 6 25 140 6 40 135 6 58 130 6 80 125 7 02 120 7 24 115 7 45 113 7 53 112 7 64 110 7 71 105 7 93 100 8 18 95 8 47 90 8 76 85 9 13 600m wire attached 2 x 100Mb load 80 9...

Page 47: ...connections and one for PHONE also called House or Station connections The connector is wired as a 50 pin telco connector as follows RJ21 Line Connectors Pin 26 line 1 Tip Pin 1 line 1 Ring Pin 27 line 2 Tip Pin 2 line 2 Ring Pin 50 line 25 Tip Pin 25 line 25 Ring RS 232 console port Pin 1 Unused Pin 6 Unused Pin 2 TXD transmit data Pin 7 Unused Pin 3 RXD receive data Pin 8 Unused Pin 4 Unused Pin...

Page 48: ...pair A 2 BI_DA Bi directional pair A 3 BI_DB Bi directional pair B 4 BI_DC Bi directional pair C 5 BI_DC Bi directional pair C 6 BI_DB Bi directional pair B 7 BI_DD Bi directional pair D 8 BI_DD Bi directional pair D Fast Ethernet WallPlate ports 1 TX 2 TX 3 RX 4 Unused 5 Unused 6 RX 7 Unused 8 Unused ...

Page 49: ...rees Celsius fan cooled Relative Humidity 5 to 90 NC Compliance FCC Part 15A CE TUV EN60950 Telephone splitter Integrated analogue POTS splitter Management In Band Management Telnet Web UI SNMP v2 standard and enterprise MIB Out of Band Management Console Front Panel LEDs 1 x unit power status 25 x line link status 10 100 1000 link status activity Mounting Options Rack mount ears provided m2 WallP...

Page 50: ...Part 15A CE TUV EN60950 Telephone splitter Integrated analogue POTS splitter Management In Band Management Telnet Web UI SNMP v2 standard and enterprise MIB Front Panel LEDs 1 x unit power link status 10 100 link status activity Mounting Options Mounting bracket provided ...

Page 51: ...nstalling the equipment in an environment compatible with the manufacturer s maximum rated ambient temperature Tmra Reduced Air Flow Installation of the equipment in a rack should be such that the amount of air flow required for safe operation of the equipment is not compromised Mechanical Loading Mounting of the equipment in the rack should be such that a hazardous condition is not achieved due t...

Reviews: