0% found this document useful (0 votes)
66 views767 pages

EAGLE40 HiSecOS GUI Manual 3.4

Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
66 views767 pages

EAGLE40 HiSecOS GUI Manual 3.4

Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Hirschmann Automation and Control GmbH

EAGLE40 HiSecOS Rel. 03400

Reference Manuals
Graphical User Interface
Command Line Interface

User Manual
Configuration
Reference Manual
Graphical User Interface
Industrial Security Router
EAGLE40

RM GUI EAGLE Technical support


Release 3.4 03/2020 [Link]
The naming of copyrighted trademarks in this manual, even when not specially indicated, should not be taken to mean that
these names may be considered as free in the sense of the trademark and tradename protection law and hence that they may
be freely used by anyone.

© 2020 Hirschmann Automation and Control GmbH

Manuals and software are protected by copyright. All rights reserved. The copying, reproduction, translation, conversion into
any electronic medium or machine scannable form is not permitted, either in whole or in part. An exception is the preparation
of a backup copy of the software for your own use.

The performance features described here are binding only if they have been expressly agreed when the contract was made.
This document was produced by Hirschmann Automation and Control GmbH according to the best of the company's
knowledge. Hirschmann reserves the right to change the contents of this document without prior notice. Hirschmann can give
no guarantee in respect of the correctness or accuracy of the information in this document.

Hirschmann can accept no responsibility for damages, resulting from the use of the network components or the associated
operating software. In addition, we refer to the conditions of use specified in the license contract.

You can get the latest version of this manual on the Internet at the Hirschmann product site ([Link]).

Hirschmann Automation and Control GmbH


Stuttgarter Str. 45-51
72654 Neckartenzlingen
Germany

2020-03-25 RM GUI EAGLE


Release 3.4 03/2020
Contents

Contents

Safety instructions. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7

About this Manual . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8

Key. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9

Notes on the Graphical User Interface. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10

1 Basic Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
1.1 System . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
1.2 Network . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
1.3 Software . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
1.4 Load/Save . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26
1.5 External Memory . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37
1.6 Port. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40
1.7 Restart . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 45

2 Time. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47
2.1 Basic Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47
2.2 NTP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 48
2.2.1 Global. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49
2.2.2 Server. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51
2.2.3 NTP Multicast Groups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54

3 Device Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56
3.1 User Management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56
3.2 Authentication List . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 61
3.3 LDAP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 63
3.3.1 LDAP Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64
3.3.2 LDAP Role Mapping. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 69
3.4 Management Access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 71
3.4.1 Server. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72
3.4.2 IP Access Restriction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 84
3.4.3 Web . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 87
3.4.4 Command Line Interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 88
3.4.5 SNMPv1/v2 Community . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 91
3.5 Pre-login Banner . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 92

4 Network Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 94
4.1 Network Security Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 94
4.2 RADIUS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 95
4.2.1 RADIUS Global . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 97
4.2.2 RADIUS Authentication Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99
4.2.3 RADIUS Authentication Statistics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 101
4.3 Packet Filter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 102
4.3.1 Packet Filter Global . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 104
4.3.2 Firewall Learning Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 106
4.3.3 Packet Filter Rule. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 113

RM GUI EAGLE 3
Release 3.4 03/2020
Contents

4.3.4 Packet Filter Assignment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 118


4.3.5 Packet Filter Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 120
4.4 Deep Packet Inspection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 123
4.4.1 Deep Packet Inspection - Modbus Enforcer. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 124
4.4.2 Deep Packet Inspection - OPC Enforcer . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 131
4.5 DoS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 133
4.5.1 DoS Global. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 134

5 Virtual Private Network . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 138


5.1 VPN Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 138
5.2 VPN Certificates. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 146
5.3 VPN Connections. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 149

6 Switching . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 176
6.1 Switching Global . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 176
6.2 Rate Limiter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 178
6.3 Filter for MAC Addresses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 180

7 Routing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 182
7.1 Routing Global . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 182
7.2 Routing Interfaces . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 184
7.2.1 Routing Interfaces Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 185
7.2.2 Routing Interfaces Secondary Interface Addresses. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 191
7.3 ARP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 192
7.3.1 ARP Global . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 193
7.3.2 ARP Current. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 195
7.3.3 ARP Static . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 196
7.4 Open Shortest Path First . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 197
7.4.1 OSPF Global . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 199
7.4.2 OSPF Areas . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 207
7.4.3 OSPF Stub Areas. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 209
7.4.4 OSPF Not So Stubby Areas. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 211
7.4.5 OSPF Interfaces. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 214
7.4.6 OSPF Virtual Links. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 219
7.4.7 OSPF Ranges . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 222
7.4.8 OSPF Diagnostics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 224
7.5 Routing Table. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 235
7.6 Tracking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 239
7.6.1 Tracking Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 240
7.6.2 Tracking Applications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 246
7.7 L3 Relay . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 247
7.8 Loopback Interface. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 252
7.9 L3-Redundancy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 254
7.9.1 VRRP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 254
[Link] VRRP Configuration. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 255
[Link] VRRP Statistics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 266
[Link] VRRP Tracking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 268
7.10 NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 269

4 RM GUI EAGLE
Release 3.4 03/2020
Contents

7.10.1 NAT Global. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 270


7.10.2 1:1 NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 272
[Link] 1:1 NAT Rule . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 273
7.10.3 Destination NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 275
[Link] Destination NAT Rule. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 277
[Link] Destination NAT Mapping . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 281
[Link] Destination NAT Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 283
7.10.4 Masquerading NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 285
[Link] Masquerading NAT Rule . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 286
[Link] Masquerading NAT Mapping . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 289
[Link] Masquerading NAT Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 291
7.10.5 Double NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 292
[Link] Double NAT Rule . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 294
[Link] Double NAT Mapping. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 296
[Link] Double NAT Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 298

8 Diagnostics. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 300
8.1 Status Configuration. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 300
8.1.1 Device Status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 301
8.1.2 Security Status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 305
8.1.3 Signal Contact . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 310
[Link] Signal Contact 1 / Signal Contact 2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 311
8.1.4 Alarms (Traps) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 315
8.2 System . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 317
8.2.1 System Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 318
8.2.2 Configuration Check. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 319
8.2.3 ARP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 321
8.2.4 Selftest . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 322
8.3 Syslog . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 324
8.4 Ports. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 326
8.4.1 SFP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 327
8.5 LLDP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 328
8.5.1 LLDP Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 329
8.5.2 LLDP Topology Discovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 333
8.6 Report . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 334
8.6.1 Report Global . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 335
8.6.2 Persistent Logging . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 339
8.6.3 System Log . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 342
8.6.4 Audit Trail . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 343

9 Advanced . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 344
9.1 DNS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 344
9.1.1 DNS Client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 344
[Link] DNS Client Global . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 345
[Link] DNS Client Current . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 346
[Link] DNS Client Static . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 347
[Link] DNS Client Static Hosts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 349
9.1.2 DNS Cache . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 350

RM GUI EAGLE 5
Release 3.4 03/2020
Contents

[Link] DNS Cache Global. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 351


9.2 Command Line Interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 351

A Index . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 353

B Further support . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 357

C Readers’ Comments . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 358

6 RM GUI EAGLE
Release 3.4 03/2020
Safety instructions

Safety instructions

WARNING
UNCONTROLLED MACHINE ACTIONS

To avoid uncontrolled machine actions caused by data loss, configure all the data transmission
devices individually.

Before you start any machine which is controlled via data transmission, be sure to complete the
configuration of all data transmission devices.

Failure to follow these instructions can result in death, serious injury, or equipment
damage.

RM GUI EAGLE 7
Release 3.4 03/2020
About this Manual

About this Manual

The “Configuration” user manual contains the information you need to start operating the device. It
takes you step by step from the first startup operation through to the basic settings for operation in
your environment.

The “Installation” user manual contains a device description, safety instructions, a description of the
display, and the other information that you need to install the device.

The “Graphical User Interface” reference manual contains detailed information on using the
graphical user interface to operate the individual functions of the device.

The “Command Line Interface” reference manual contains detailed information on using the
Command Line Interface to operate the individual functions of the device.

The Industrial HiVision Network Management software provides you with additional options for
smooth configuration and monitoring:
 Auto-topology discovery
 Browser interface
 Client/server structure
 Event handling
 Event log
 Simultaneous configuration of multiple devices
 Graphical user interface with network layout
 SNMP/OPC gateway

8 RM GUI EAGLE
Release 3.4 03/2020
Key

Key

The designations used in this manual have the following meanings:

 List
 Work step
Link Cross-reference with link
Note: A note emphasizes a significant fact or draws your attention to a dependency.
Courier Representation of a CLI command or field contents in the graphical user interface

Execution in the Graphical User Interface

Execution in the Command Line Interface

RM GUI EAGLE 9
Release 3.4 03/2020
Notes on the Graphical User Interface

Notes on the Graphical User Interface

The Graphical User Interface of the device is divided as follows:


 Navigation area
 Dialog area
 Buttons

Navigation area

The Navigation area is located on the left side of the Graphical User Interface.

The Navigation area contains the following elements:


 Toolbar
 Filter
 Menu

You have the option of collapsing the entire Navigation area, for example when displaying the
Graphical User Interface on small screens. To collapse or expand, you click the small arrow at the
top of the navigation area.

Toolbar

The toolbar at the top of the navigation area contains several buttons.
• When you position the mouse pointer over a button, a tooltip displays further information.
• If the connection to the device is lost, then the toolbar is grayed out.

The device automatically refreshes the toolbar information every 5 seconds.

Clicking the button refreshes the toolbar manually.

When you position the mouse pointer over the button, a tooltip displays the following information:
 User:
Name of the logged in user
 Device name:
Name of the device

Clicking the button opens the Device Security > User Management dialog.

When you position the mouse pointer over the button, a tooltip displays the summary of the
Diagnostics > System > Configuration Check dialog.

Clicking the button opens the Diagnostics > System > Configuration Check dialog.

10 RM GUI EAGLE
Release 3.4 03/2020
Notes on the Graphical User Interface

Clicking the button logs out the current user and displays the login page.

Displays the remaining time in seconds until the device automatically logs out an inactive user.

Clicking the button opens the Device Security > Management Access > Web dialog. There you can
specify the timeout.

When the configuration profile in the volatile memory (RAM) differs from the "Selected" configuration
profile in the non-volatile memory (NVM), this button is visible. Otherwise, the button is hidden.

Clicking the button opens the Basic Settings > Load/Save dialog.

By right-clicking the button you can save the current settings in the non-volatile memory (NVM).

When you position the mouse pointer over the button, a tooltip displays the following information:
 Device Status: This section displays a compressed view of the Device status frame in the Basic
Settings > System dialog. The section displays the alarm that is currently active and whose
occurrence was recorded first.
 Security Status: This section displays a compressed view of the Security status frame in the Basic
Settings > System dialog. The section displays the alarm that is currently active and whose
occurrence was recorded first.
 Boot Parameter: If you permanently save changes to the settings and at least one boot
parameter differs from the configuration profile used during the last restart, then this section
displays a note.
The following settings cause the boot parameters to change:
– Basic Settings > External Memory dialog, Software auto update parameter
– Basic Settings > External Memory dialog, Config priority parameter
– Device Security > Management Access > Server dialog, SNMP tab, UDP port parameter
– Diagnostics > System > Selftest dialog, SysMon1 is available parameter
– Diagnostics > System > Selftest dialog, Load default config on error parameter

Clicking the button opens the Diagnostics > Status Configuration > Device Status dialog.

Filter

The filter enables you to reduce the number of menu items in the menu. When filtering, the menu
displays only menu items matching the search string entered in the filter field.

RM GUI EAGLE 11
Release 3.4 03/2020
Notes on the Graphical User Interface

Menu

The menu displays the menu items.

You have the option of filtering the menu items. See section “Filter”.

To display the corresponding dialog in the dialog area, you click the desired menu item. If the
selected menu item is a node containing sub-items, then the node expands or collapses while
clicking. The dialog area keeps the previously displayed dialog.

You have the option of expanding or collapsing every node in the menu at the same time. When
you right-click anywhere in the menu, a context menu displays the following entries:
 Expand
Expands every node in the menu at the same time. The menu displays the menu items for every
level.
 Collapse
Collapses every node in the menu at the same time. The menu displays the top level menu
items.

Dialog area

The Dialog area is located on the right side of the Graphical User Interface. When you click a menu
item in the Navigation area, the Dialog area displays the corresponding dialog.

Updating the display

If a dialog remains opened for a longer time, then the values in the device have possibly changed
in the meantime.
 To update the display in the dialog, click the button. Unsaved information in the dialog is lost.

Saving the settings


 To transfer the changed settings to the volatile memory (RAM) of the device, click the button.
 To keep the changed settings, even after restarting the device, proceed as follows:
 Open the Basic Settings > Load/Save dialog.
 In the table, highlight the desired configuration profile.
 When in the Selected column the checkbox is unmarked, click the button and then the
Select item.
 Click the button and then the Save item.

Note: Unintentional changes to the settings can terminate the connection between your PC and the
device. To keep the device accessible, enable the Undo configuration modifications function in the
Basic Settings > Load/Save dialog, before changing any settings. Using the function, the device
continuously checks whether it can still be reached from the IP address of the user’s PC. If the
connection is lost, then the device loads the configuration profile saved in the non-volatile memory
(NVM) after the specified time. Afterwards, the device can be accessed again.

12 RM GUI EAGLE
Release 3.4 03/2020
Notes on the Graphical User Interface

Working with tables

The dialogs display numerous settings in table form.

When you modify a table cell, the table cell displays a red mark in its top-left corner. The red mark
indicates that your modifications are not yet transfered to the volatile memory (RAM) of the device.

You have the option of customizing the look of the tables to fit your needs. When you position the
mouse pointer over a column header, the column header displays a drop-down list button. When
you click this button, the drop-down list displays the following entries:
 Sort ascending
Sorts the table entries in ascending order based on the entries of the selected column.
You recognize sorted table entries by an arrow in the column header.
 Sort descending
Sorts the table entries in descending order based on the entries of the selected column.
You recognize sorted table entries by an arrow in the column header.
 Columns
Displays or hides columns.
You recognize hidden columns by an unmarked checkbox in the drop-down list.
 Filters
The table only displays the entries whose content matches the specified filter criteria of the
selected column.
You recognize filtered table entries by an emphasized column header.

You have the option of selecting multiple table entries simultaneously and subsequently applying
an action to them. This is useful when you are going to remove multiple table entries at the same
time.
 Select several consecutive table entries:
 Click the first desired table entry to highlight it.
 Press and hold the <SHIFT> key.
 Click the last desired table entry to highlight every desired table entry.
 Select multiple individual table entries:
 Click the first desired table entry to highlight it.
 Press and hold the <CTRL> key.
 Click the next desired table entry to highlight it.
Repeat until every desired table entry is highlighted.

Buttons

Here you find the description of the standard buttons. The special dialog-specific buttons are
described in the corresponding dialog help text.

Transfers the changes to the volatile memory (RAM) of the device and applies them to the device.
To save the changes in the non-volatile memory, proceed as follows:
 Open the Basic Settings > Load/Save dialog.
 In the table, highlight the desired configuration profile.
 When in the Selected column the checkbox is unmarked, click the button and then the Select
item.
 Click the button to save your current changes.

RM GUI EAGLE 13
Release 3.4 03/2020
Notes on the Graphical User Interface

Updates the fields with the values that are saved in the volatile memory (RAM) of the device.

Transfers the settings from the volatile memory (RAM) into the configuration profile designated as
“Selected” in the non-volatile memory (NVM).

When in the Basic Settings > External Memory dialog the checkbox in the Backup config when saving
column is marked, then the device generates a copy of the configuration profile in the external
memory.

Displays a submenu with menu items corresponding to the respective dialog.

Opens the Wizard dialog.

Adds a new table entry.

Removes the highlighted table entry.

Opens the online help.

14 RM GUI EAGLE
Release 3.4 03/2020
Basic Settings
[ Basic Settings > System ]

1 Basic Settings

The menu contains the following dialogs:


 System
 Network
 Software
 Load/Save
 External Memory
 Port
 Restart

1.1 System
[ Basic Settings > System ]

In this dialog, you monitor individual operating statuses.

Device status

The fields in this frame display the device status and inform you about alarms that have occurred.
When an alarm currently exists, the frame is highlighted.

You specify the parameters that the device monitors in the Diagnostics > Status Configuration > Device
Status dialog.

Note: If you connect only one power supply unit for the supply voltage to a device with a redundant
power supply unit, then the device reports an alarm. To help avoid this alarm, you deactivate the
monitoring of the missing power supply units in the Diagnostics > Status Configuration > Device Status
dialog.

Alarm counter
Displays the number of currently existing alarms.

When there is at least one currently existing alarm, the icon is visible.

When you position the mouse pointer over the icon, a tooltip displays the cause of the currently
existing alarms and the time at which the device triggered the alarm.

If a monitored parameter differs from the desired status, then the device triggers an alarm. The
Diagnostics > Status Configuration > Device Status dialog, Status tab displays an overview of the alarms.

RM GUI EAGLE 15
Release 3.4 03/2020
Basic Settings
[ Basic Settings > System ]

Security status

The fields in this frame display the security status and inform you about alarms that have occurred.
When an alarm currently exists, the frame is highlighted.

You specify the parameters that the device monitors in the Diagnostics > Status Configuration >
Security Status dialog.

Alarm counter
Displays the number of currently existing alarms.

When there is at least one currently existing alarm, the icon is visible.

When you position the mouse pointer over the icon, a tooltip displays the cause of the currently
existing alarms and the time at which the device triggered the alarm.

If a monitored parameter differs from the desired status, then the device triggers an alarm. The
Diagnostics > Status Configuration > Security Status dialog, Status tab displays an overview of the
alarms.

Signal contact status

The fields in this frame display the signal contact status and inform you about alarms that have
occurred. When an alarm currently exists, the frame is highlighted.

You specify the parameters that the device monitors in the Diagnostics > Status Configuration > Signal
Contact > Signal Contact 1/Signal Contact 2 dialog.

Alarm counter
Displays the number of currently existing alarms.

When there is at least one currently existing alarm, the icon is visible.

When you position the mouse pointer over the icon, a tooltip displays the cause of the currently
existing alarms and the time at which the device triggered the alarm.

If a monitored parameter differs from the desired status, then the device triggers an alarm. The
Diagnostics > Status Configuration > Signal Contact > Signal Contact 1/Signal Contact 2 dialog, Status tab
displays an overview of the alarms.

System data

The fields in this frame display operating data and information on the location of the device.

System name
Specifies the name for which the device is known in the network.

16 RM GUI EAGLE
Release 3.4 03/2020
Basic Settings
[ Basic Settings > System ]

Possible values:
 Alphanumeric ASCII character string with 0..255 characters
The following characters are allowed:
– 0..9
– a..z
– A..Z
– !#$%&'()*+,-./:;<=>?@[\\]^_`{}~
– <device name>-<MAC address> (default setting)

When creating HTTPS X.509 certificates, the application generating the certificate uses the
specified value as the domain name and common name.

The following functions use the specified value as a host name or FQDN (Fully Qualified Domain
Name). For compatibility, it is recommended to use only small letters, since not every system
compares the case in the FQDN. Verify that this name is unique in the whole network.
 Syslog

Location
Specifies the location of the device.

Possible values:
 Alphanumeric ASCII character string with 0..255 characters

Contact person
Specifies the contact person for this device.

Possible values:
 Alphanumeric ASCII character string with 0..255 characters

Device type
Displays the product name of the device.

Power supply 1
Power supply 2
Displays the status of the power supply unit on the relevant voltage supply connection.

Possible values:
 present
 defective
 not installed
 unknown

Uptime
Displays the time that has elapsed since this device was last restarted.

Possible values:
 Time in the format day(s), ...h ...m ...s

RM GUI EAGLE 17
Release 3.4 03/2020
Basic Settings
[ Basic Settings > System ]

Temperature [°C]
Displays the current temperature in the device in °C.

You activate the monitoring of the temperature thresholds in the Diagnostics > Status Configuration >
Device Status dialog.

Upper temp. limit [°C]


Specifies the upper temperature threshold in °C.

The “Installation” user manual contains detailed information about setting the temperature
thresholds.

Possible values:
 -99..99 (integer)
If the temperature in the device exceeds this value, then the device generates an alarm.

Lower temp. limit [°C]


Specifies the lower temperature threshold in °C.

The “Installation” user manual contains detailed information about setting the temperature
thresholds.

Possible values:
 -99..99 (integer)
If the temperature in the device falls below this value, then the device generates an alarm.

LED status

This frame displays the states of the device status LEDs at the time of the last update. The
“Installation” user manual contains detailed information about the device status LEDs.

Parameters Color Meaning


Status There is currently no device status alarm. The device status is OK.
There is currently at least one device status alarm. Therefore, see the
Device status frame above.
Power Device variant with 2 power supply units:
Only one supply voltage is active.
Device variant with 1 power supply unit:
The supply voltage is active.
Device variant with 2 power supply units:
Both supply voltages are active.
ACA No external memory connected.
The external memory is connected, but not ready for operation.
The external memory is connected and ready for operation.

18 RM GUI EAGLE
Release 3.4 03/2020
Basic Settings
[ Basic Settings > System ]

Port status

This frame displays a simplified view of the ports of the device at the time of the last update.

The icons represent the status of the individual ports. In some situations, the following icons
interfere with one another. When you position the mouse pointer over the appropriate port icon, a
tooltip displays a detailed information about the port state.

Parameters Statu Meaning


s
<Port number> The port is inactive.
The port does not send or receive any data.
The port is inactive.
The cable is connected. Active link.
The port is active.
No cable connected or no active link.
The port is active.
The cable is connected. Connection okay. Active link. Full-duplex mode
The half-duplex mode is enabled.
Verify the settings in the Basic Settings > Ports dialog, Configuration tab.
The port is in a blocking state due to a redundancy function.
The port operates as a router interface.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 19
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Network ]

1.2 Network
[ Basic Settings > Network ]

This dialog lets you specify the IP, VLAN and HiDiscovery settings required for the access to the
device management through the network.

Management interface

This frame lets you specify the following settings:


 VLAN in which the device management can be accessed

IP address assignment
Specifies the source from which the device management receives its IP parameters.

Possible values:
 Local
The device uses the IP parameters from the internal memory. You specify the settings for this
in the IP parameter frame.

VLAN ID
Specifies the VLAN in which the device management is accessible through the network. The device
management is accessible through ports that are members of this VLAN.

Possible values:
 1..4042 (default setting: 1)
The prerequisite is that the VLAN is already configured. See the Switching > VLAN > Configuration
dialog.

When you click the button after changing the value, the Information window opens. Select the
port, over which you connect to the device in the future. After clicking the Ok button, the new device
management VLAN settings are assigned to the port.
• After that the port is a member of the VLAN and transmits the data packets without a VLAN tag
(untagged). See the Switching > VLAN > Configuration dialog.
• The device assigns the port VLAN ID of the device management VLAN to the port. See the
Switching > VLAN > Port dialog.

After a short time the device is reachable over the new port in the new device management VLAN.

MAC address
Displays the MAC address of the device. The device management is accessible via the network
using the MAC address.

20 RM GUI EAGLE
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Network ]

HiDiscovery protocol v1/v2

This frame lets you specify settings for the access to the device using the HiDiscovery protocol.

On a PC, the HiDiscovery software displays the Hirschmann devices that can be accessed in the
network on which the HiDiscovery function is enabled. You can access these devices even if they
have invalid or no IP parameters assigned. The HiDiscovery software lets you assign or change the
IP parameters in the device.

Note: With the HiDiscovery software you access the device only through ports that are members
of the same VLAN as the device management. You specify which VLAN a certain port is assigned
to in the Switching > VLAN > Configuration dialog.

Operation
Enables/disables the HiDiscovery function in the device.

Possible values:
 On (default setting)
HiDiscovery is enabled.
You can use the HiDiscovery software to access the device from your PC.
 Off
HiDiscovery is disabled.

Access
Enables/disables the write access to the device using HiDiscovery.

Possible values:
 readWrite (default setting)
The HiDiscovery software is given write access to the device.
With this setting you can change the IP parameters in the device.
 readOnly
The HiDiscovery software is given read-only access to the device.
With this setting you can view the IP parameters in the device.

Recommendation: Change the setting to the value readOnly only after putting the device into
operation.

Signal
Activates/deactivates the flashing of the port LEDs as does the function of the same name in the
HiDiscovery software. The function lets you identify the device in the field.

Possible values:
 marked
The flashing of the port LEDs is active.
The port LEDs flash until you disable the function again.
 unmarked (default setting)
The flashing of the port LEDs is inactive.

RM GUI EAGLE 21
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Network ]

IP parameter

This frame lets you assign the IP parameters manually. If you have selected the Local radio button
in the Management interface frame, IP address assignment option list, then these fields can be edited.

IP address
Specifies the IP address under which the device management can be accessed through the
network.

Possible values:
 Valid IPv4 address

Verify that the IP subnet of the device management is not overlapping with any subnet connected
to another interface of the device:
• router interface
• loopback interface

Netmask
Specifies the netmask.

Possible values:
 Valid IPv4 netmask

Gateway address
Specifies the IP address of a router through which the device accesses other devices outside its
own network.

Possible values:
 Valid IPv4 address

If the device does not use the specified gateway, check whether another default gateway is
specified. The setting in the following dialog has precedence:
• Routing > Routing Table dialog, Next hop IP address column, if the value in the Network address
column and in the Netmask column is [Link]

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

22 RM GUI EAGLE
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Software ]

1.3 Software
[ Basic Settings > Software ]

This dialog lets you update the device software and display information about the device software.

You also have the option to restore a backup of the device software saved in the device.

Note: Before updating the device software, follow the version-specific notes in the Readme text file.

Version

Stored version
Displays the version number and creation date of the device software stored in the flash memory.
The device loads the device software during the next restart.

Running version
Displays the version number and creation date of the device software that the device loaded during
the last restart and is currently running.

Backup version
Displays the version number and creation date of the device software saved as a backup in the
flash memory. The device copied this device software into the backup memory during the last
software update or after you clicked the Restore button.

Restore
Restores the device software saved as a backup. In the process, the device changes the Stored
version and the Backup version of the device software.

Upon restart, the device loads the Stored version.

Bootcode
Displays the version number and creation date of the boot code.

Software update

Alternatively, when the image file is located in the external memory, the device lets you update the
device software by right-clicking in the table.

URL
Specifies the path and the file name of the image file with which you update the device software.

RM GUI EAGLE 23
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Software ]

The device gives you the following options for updating the device software:
 Software update from the PC
When the file is located on your PC or on a network drive, drag and drop the file in the area.
Alternatively click in the area to select the file.
You also have the option of transferring the file from your PC to the device through SFTP or
SCP:
 On your PC, open an SFTP or SCP client, for example WinSCP.
 Use the SFTP or SCP client to open a connection to the device.
 Transfer the file to the directory /upload/firmware in the device.
When the file transfer is complete, the device starts updating the device software. If the
update was successful, then the device creates an ok file in the directory /upload/firmware
and deletes the image file.
The device loads the device software during the next restart.

Start
Updates the device software.

The device installs the selected file in the flash memory, replacing the previously saved device
software. Upon restart, the device loads the installed device software.

The device copies the existing software into the backup memory.

To remain logged in to the device during the software update, move the mouse pointer
occasionally. Alternatively, specify a sufficiently high value in the Device Security > Management
Access > Web dialog, field Web interface session timeout [min] before the software update.

Table

File location
Displays the storage location of the device software.

Possible values:
 ram
Volatile memory of the device
 flash
Non-volatile memory (NVM) of the device
 usb
External USB memory (ACA21/ACA22)

Index
Displays the index of the device software.

For the device software in the flash memory, the index has the following meaning:
 1
Upon restart, the device loads this device software.
 2
The device copied this device software into the backup area during the last software update.

File name
Displays the device-internal file name of the device software.

24 RM GUI EAGLE
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Software ]

Firmware
Displays the version number and creation date of the device software.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 25
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Load/Save ]

1.4 Load/Save
[ Basic Settings > Load/Save ]

This dialog lets you save the device settings permanently in a configuration profile.

The device can hold several configuration profiles. When you activate an alternative configuration
profile, you change to other device settings. You have the option of exporting the configuration
profiles to your PC or to a server. You also have the option of importing the configuration profiles
from your PC or from a server to the device.

In the default setting, the device saves the configuration profiles unencrypted. If you enter a
password in the Configuration encryption frame, then the device saves both the current and the future
configuration profiles in an encrypted format.

Unintentional changes to the settings can terminate the connection between your PC and the
device. To keep the device accessible, enable the Undo configuration modifications function before
changing any settings. If the connection is lost, then the device loads the configuration profile saved
in the non-volatile memory (NVM) after the specified time.

External memory

Selected external memory


Displays the type of the external memory.

Possible values:
 usb
External USB memory (ACA21/ACA22)

Status
Displays the operating state of the external memory.

Possible values:
 notPresent
No external memory connected.
 removed
Someone has removed the external memory from the device during operation.
 ok
The external memory is connected and ready for operation.
 outOfMemory
The memory space is occupied in the external memory.
 genericErr
The device has detected an error.

Configuration encryption

Active
Displays whether the configuration encryption is active/inactive in the device.

26 RM GUI EAGLE
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Load/Save ]

Possible values:
 marked
The configuration encryption is active.
If the configuration profile is encrypted and the password matches the password stored in the
device, then the device loads a configuration profile from the non-volatile memory (NVM).
 unmarked
The configuration encryption is inactive.
If the configuration profile is unencrypted, then the device loads a configuration profile from the
non-volatile memory (NVM) only.

If in the Basic Settings > External Memory dialog, the Config priority column has the value first and
the configuration profile is unencrypted, then the Security status frame in the Basic Settings > System
dialog displays an alarm.

In the Diagnostics > Status Configuration > Security Status dialog, Global tab, Monitor column you specify
whether the device monitors the Load unencrypted config from external memory parameter.

Set password
Opens the Set password window that helps you to enter the password needed for the configuration
profile encryption. Encrypting the configuration profiles makes unauthorized access more difficult.
 When you are changing an existing password, enter the existing password in the Old password
field. To display the password in plain text instead of ***** (asterisks), mark the Display content
checkbox.
 In the New password field, enter the password.
To display the password in plain text instead of ***** (asterisks), mark the Display content
checkbox.
 Mark the Save configuration afterwards checkbox to use encryption also for the Selected
configuration profile in the non-volatile memory (NVM) and in the external memory.

Note: If a maximum of 1 configuration profile is stored in the non-volatile memory (NVM) of the
device, then use this function only. Before creating additional configuration profiles, decide for or
against permanently activated configuration encryption in the device. Save additional configuration
profiles either unencrypted or encrypted with the same password.

If you are replacing a device with an encrypted configuration profile, for example due to a defect,
then you proceed as follows:
 Restart the new device and assign the IP parameters.
 Open the Basic Settings > Load/Save dialog on the new device.
 Encrypt the configuration profile in the new device. See above. Enter the same password you
used in the defective device.
 Install the external memory from the defective device in the new device.
 Restart the new device.
When you restart the device, the device loads the configuration profile with the settings of the
defective device from the external memory. The device copies the settings into the volatile
memory (RAM) and into the non-volatile memory (NVM).

RM GUI EAGLE 27
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Load/Save ]

Delete
Opens the Delete window which helps you to cancel the configuration encryption in the device.
 In the Old password field, enter the existing password.
To display the password in plain text instead of ***** (asterisks), mark the Display content
checkbox.
 Mark the Save configuration afterwards checkbox to remove the encryption also for the Selected
configuration profile in the non-volatile memory (NVM) and in the external memory.

Note: If you keep additional encrypted configuration profiles in the memory, then the device helps
prevent you from activating or designating these configuration profiles as "Selected".

Information

NVM in sync with running config


Displays whether the configuration profile in the volatile memory (RAM) and the "Selected"
configuration profile in the non-volatile memory (NVM) are the same.

Possible values:
 marked
The configuration profiles are the same.
 unmarked
The configuration profiles differ.

External memory in sync with NVM


Displays whether the "Selected" configuration profile in the external memory and the "Selected"
configuration profile in the non-volatile memory (NVM) are the same.

Possible values:
 marked
The configuration profiles are the same.
 unmarked
The configuration profiles differ.
Possible causes:
– No external memory is connected to the device.
– In the Basic Settings > External Memory dialog, the Backup config when saving function is
disabled.

Backup config on a remote server when saving

Operation
Enables/disables the Backup config on a remote server when saving function.

28 RM GUI EAGLE
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Load/Save ]

Possible values:
 Enabled
The Backup config on a remote server when saving function is enabled.
When you save the configuration profile in the non-volatile memory (NVM), the device
automatically backs up the configuration profile on the remote server specified in the URL field.
 Disabled (default setting)
The Backup config on a remote server when saving function is disabled.

URL
Specifies path and file name of the backed up configuration profile on the remote server.

Possible values:
 Alphanumeric ASCII character string with 0..128 characters
Example: t[Link]
The device supports the following wildcards:
– %d
System date in the format YYYY-mm-dd
– %t
System time in the format HH_MM_SS
– %i
IP address of the device
– %m
MAC address of the device in the format AA-BB-CC-DD-EE-FF
– %p
Product name of the device

Set credentials
Opens the Credentials window which helps you to enter the credentials needed to authenticate on
the remote server.
 In the User name field, enter the user name.
To display the user name in plain text instead of ***** (asterisks), mark the Display content
checkbox.
Possible values:
– Alphanumeric ASCII character string with 1..32 characters
 In the Password field, enter the password.
To display the password in plain text instead of ***** (asterisks), mark the Display content
checkbox.
Possible values:
 Alphanumeric ASCII character string with 6..64 characters
The following characters are allowed:
a..z
A..Z
0..9
!#$%&'()*+,-./:;<=>?@[\\]^_`{}~

RM GUI EAGLE 29
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Load/Save ]

Undo configuration modifications

Operation
Enables/disables the Undo configuration modifications function. Using the function, the device
continuously checks whether it can still be reached from the IP address of the user’s PC. If the
connection is lost, after a specified time period the device loads the “Selected” configuration profile
from the non-volatile memory (NVM). Afterwards, the device can be accessed again.

Possible values:
 On
The function is enabled.
– You specify the time period between the interruption of the connection and the loading of the
configuration profile in the field Timeout [s] to recover after connection loss.
– When the non-volatile memory (NVM) contains multiple configuration profiles, the device
loads the configuration profile designated as “Selected”.
 Off (default setting)
The function is disabled.
Disable the function again before you close the Graphical User Interface. You thus help prevent
the device from restoring the configuration profile designated as “Selected”.

Note: Before you enable the function, save the settings in the configuration profile. Current
changes, that are saved temporarily, are therefore maintained in the device.

Timeout [s] to recover after connection loss


Specifies the time in seconds after which the device loads the “Selected” configuration profile from
the non-volatile memory (NVM) if the connection is lost.

Possible values:
 30..600 (default setting: 600)

Specify a sufficiently large value. Take into account the time when you are viewing the dialogs of
the Graphical User Interface without changing or updating them.

Watchdog IP address
Displays the IP address of the PC on which you have enabled the function.

Possible values:
 IPv4 address (default setting: [Link])

Table

Storage type
Displays the storage location of the configuration profile.

30 RM GUI EAGLE
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Load/Save ]

Possible values:
 RAM (volatile memory of the device)
In the volatile memory, the device stores the settings for the current operation.
 NVM (non-volatile memory of the device)
When applying the function Undo configuration modifications or during a restart, the device loads
the “Selected” configuration profile from the non-volatile memory.
The non-volatile memory provides space for multiple configuration profiles, depending on the
number of settings saved in the configuration profile. The device manages a maximum of 20
configuration profiles in the non-volatile memory.
You can load a configuration profile into the volatile memory (RAM):
 In the table, highlight the configuration profile.
 Click the button and then the Activate item.
 ENVM (external memory)
In the external memory, the device saves a backup copy of the “Selected” configuration profile.
The prerequisite is that in the Basic Settings > External Memory dialog you mark the Backup config
when saving checkbox.

Profile name
Displays the name of the configuration profile.

Possible values:
 running-config
Name of the configuration profile in the volatile memory (RAM).
 config
Name of the factory setting configuration profile in the non-volatile memory (NVM).
 User-defined name
The device lets you save a configuration profile with a user-specified name by highlighting an
existing configuration profile in the table, clicking the button and then the Save As.. item.

To export the configuration profile as an XML file on your PC, click the link. Then you select the
storage location and specify the file name.

To save the file on a remote server, click the button and then the Export... item.

Modification date (UTC)


Displays the time (UTC) at which a user last saved the configuration profile.

Selected
Displays whether the configuration profile is designated as “Selected”.

Possible values:
 marked
The configuration profile is designated as “Selected”.
– When applying the function Undo configuration modifications or during a restart, the device
loads the configuration profile into the volatile memory (RAM).
– When you click the button, the device saves the temporarily saved settings in this
configuration profile.
 unmarked
Another configuration profile is designated as “Selected”.

To designate another configuration profile as “Selected”, you highlight the desired configuration
profile in the table, click the button and then the Activate item.

RM GUI EAGLE 31
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Load/Save ]

Encrypted
Displays whether the configuration profile is encrypted.

Possible values:
 marked
The configuration profile is encrypted.
 unmarked
The configuration profile is unencrypted.

You activate/deactivate the encryption of the configuration profile in the Configuration encryption
frame.

Encryption verified
Displays whether the password of the encrypted configuration profile matches the password stored
in the device.

Possible values:
 marked
The passwords match. The device is able to unencrypt the configuration profile.
 unmarked
The passwords are different. The device is unable to unencrypt the configuration profile.

Software version
Displays the version number of the device software that the device ran while saving the
configuration profile.

Fingerprint
Displays the checksum saved in the configuration profile.

When saving the settings, the device calculates the checksum and inserts it into the configuration
profile.

Fingerprint verified
Displays whether the checksum saved in the configuration profile is valid.

The device calculates the checksum of the configuration profile marked as “Selected” and
compares it with the checksum saved in this configuration profile.

Possible values:
 marked
The calculated and the saved checksum match.
The saved settings are consistent.
 unmarked
For the configuration profile marked as “Selected” applies:
The calculated and the saved checksum are different.
The configuration profile contains modified settings.
Possible causes:
– The file is damaged.
– The file system in the external memory is inconsistent.
– A user has exported the configuration profile and changed the XML file outside the device.
For the other configuration profiles the device has not calculated the checksum.

32 RM GUI EAGLE
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Load/Save ]

The device verifies the checksum correctly only if the configuration profile has been saved before
as follows:
• on an identical device
• with the same software version, which the device is running

Note: This function identifies changes to the settings in the configuration profile. The function does
not provide protection against operating the device with modified settings.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Removes the configuration profile highlighted in the table from the non-volatile memory (NVM) or
from the external memory.

If the configuration profile is designated as "Selected", then the device helps prevent you from
removing the configuration profile.

Save As..
Copies the configuration profile highlighted in the table and saves it with a user-specified name in
the non-volatile memory (NVM). The device designates the new configuration profile as “Selected”.

Note: Before creating additional configuration profiles, decide for or against permanently activated
configuration encryption in the device. Save additional configuration profiles either unencrypted or
encrypted with the same password.

If in the Basic Settings > External Memory dialog the checkbox in the Backup config when saving column
is marked, then the device designates the configuration profile of the same name in the external
memory as “Selected”.

Activate
Loads the settings of the configuration profile highlighted in the table to the volatile memory (RAM).
 The device terminates the connection to the Graphical User Interface.
 Reload the Graphical User Interface.
 Login again.
 The device immediately uses the settings of the configuration profile on the fly.

Enable the Undo configuration modifications function before you activate another configuration profile.
If the connection is lost afterwards, then the device loads the last configuration profile designated
as “Selected” from the non-volatile memory (NVM). The device can then be accessed again.

If the configuration encryption is inactive, then the device loads an unencrypted configuration
profile. If the configuration encryption is active and the password matches the password stored in
the device, then the device loads an encrypted configuration profile.

When you activate an older configuration profile, the device takes over the settings of the functions
contained in this software version. The device sets the values of new functions to their default
value.

RM GUI EAGLE 33
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Load/Save ]

Select
Designates the configuration profile highlighted in the table as “Selected”. In the Selected column,
the checkbox is then marked.

When applying the function Undo configuration modifications or during a restart, the device loads the
settings of this configuration profile to the volatile memory (RAM).
 If the configuration encryption in the device is disabled, then designate an unencrypted
configuration profile only as “Selected”.
 If the configuration encryption in the device is enabled and the password of the configuration
profile matches the password saved in the device, then designate an encrypted configuration
profile only as “Selected”.

Otherwise, the device is unable to load and encrypt the settings in the configuration profile the next
time it restarts. For this case you specify in the Diagnostics > System > Selftest dialog whether the
device starts with the default settings or terminates the restart and stops.

Note: You only mark the configuration profiles saved in the non-volatile memory (NVM).

If in the Basic Settings > External Memory dialog the checkbox in the Backup config when saving column
is marked, then the device designates the configuration profile of the same name in the external
memory as “Selected”.

Import...
Opens the Import... window to import a configuration profile.

The prerequisite is that you have exported the configuration profile using the Export... button or
using the link in the Profile name column.
 In the Select source drop-down list, select from where the device imports the configuration profile.
 PC/URL
The device imports the configuration profile from the local PC or from a remote server.
 External memory
The device imports the configuration profile from the external memory.
 When PC/URL is selected above, in the Import profile from PC/URL frame you specify the
configuration profile file to be imported.
– Import from the PC
When the file is located on your PC or on a network drive, drag and drop the file in the
area. Alternatively click in the area to select the file.
You also have the option of transferring the file from your PC to the device through SFTP or
SCP:
On your PC, open an SFTP or SCP client, for example WinSCP.
Use the SFTP or SCP client to open a connection to the device.
Transfer the file to the directory /nv/cfg in the device.

34 RM GUI EAGLE
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Load/Save ]

 When External memory is selected above, in the Import profile from external memory frame you
specify the configuration profile file to be imported.
In the Profile name drop-down list, select the name of the configuration profile to be imported.
 In the Destination frame you specify where the device saves the imported configuration profile.
In the Profile name field you specify the name under which the device saves the configuration
profile.
In the Storage type field you specify the storage location for the configuration profile. The
prerequisite is that in the Select source drop-down list you have selected the value PC/URL.
 RAM
The device saves the configuration profile in the volatile memory (RAM) of the device. This
replaces the running-config, the device uses the settings of the imported configuration
profile immediately. The device terminates the connection to the Graphical User Interface.
Reload the Graphical User Interface. Login again.
 NVM
The device saves the configuration profile in the non-volatile memory (NVM) of the device.

When you import a configuration profile, the device takes over the settings as follows:
• If the configuration profile was exported on the same device or on an identically equipped device
of the same type, then:
The device takes over the settings completely.
• If the configuration profile was exported on an other device, then:
The device takes over the settings which it can interpret based on its hardware equipment and
software level.
The remaining settings the device takes over from its running-config configuration profile.

Regarding configuration profile encryption, also read the help text of the Configuration encryption
frame. The device imports a configuration profile under the following conditions:
• The configuration encryption of the device is inactive. The configuration profile is unencrypted.
• The configuration encryption of the device is active. The configuration profile is encrypted with
the same password that the device currently uses.

Export...
Exports the configuration profile highlighted in the table and saves it as an XML file on a remote
server.

To save the file on your PC, click the link in the Profile name column to select the storage location
and specify the file name.

The device gives you the following options for exporting a configuration profile:

Back to factory...
Resets the settings in the device to the default values.
 The device deletes the saved configuration profiles from the volatile memory (RAM) and from the
non-volatile memory (NVM).
 The device deletes the HTTPS certificate used by the web server in the device.
 The device deletes the RSA key (Host Key) used by the SSH server in the device.
 When an external memory is connected, the device deletes the configuration profiles saved in
the external memory.
 After a brief period, the device reboots and loads the default values.

RM GUI EAGLE 35
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Load/Save ]

Back to default
Deletes the current operating (running config) settings from the volatile memory (RAM) .

36 RM GUI EAGLE
Release 3.4 03/2020
Basic Settings
[ Basic Settings > External Memory ]

1.5 External Memory


[ Basic Settings > External Memory ]

This dialog lets you activate functions that the device automatically executes in combination with
the external memory. The dialog also displays the operating state and identifying characteristics of
the external memory.

Table

Type
Displays the type of the external memory.

Possible values:
 usb
External USB memory (ACA21/ACA22)

Status
Displays the operating state of the external memory.

Possible values:
 notPresent
No external memory connected.
 removed
Someone has removed the external memory from the device during operation.
 ok
The external memory is connected and ready for operation.
 outOfMemory
The memory space is occupied in the external memory.
 genericErr
The device has detected an error.

Writable
Displays whether the device has write access to the external memory.

Possible values:
 marked
The device has write access to the external memory.
 unmarked
The device has read-only access to the external memory. Possibly the write protection is
activated in the external memory.

Software auto update


Activates/deactivates the automatic device software update during the restart.

RM GUI EAGLE 37
Release 3.4 03/2020
Basic Settings
[ Basic Settings > External Memory ]

Possible values:
 marked (default setting)
The automatic device software update during the restart is activated. The device updates the
device software when the following files are located in the external memory:
– the image file of the device software
– a text file "[Link]" with the content autoUpdate=<image_file_name>.bin
 unmarked
The automatic device software update during the restart is deactivated.

Config priority
Specifies the memory from which the device loads the configuration profile upon reboot.

Possible values:
 disable
The device loads the configuration profile from the non-volatile memory (NVM).
 first
The device loads the configuration profile from the external memory.
When the device does not find a configuration profile in the external memory, it loads the
configuration profile from the non-volatile memory (NVM).

Note: When loading the configuration profile from the external memory (ENVM), the device
overwrites the settings of the Selected configuration profile in the non-volatile memory (NVM).

If the Config priority column has the value first and the configuration profile is unencrypted, then
the Security status frame in the Basic Settings > System dialog displays an alarm.

In the Diagnostics > Status Configuration > Security Status dialog, Global tab, Monitor column you specify
whether the device monitors the Load unencrypted config from external memory parameter.

Backup config when saving


Activates/deactivates creating a copy of the configuration profile in the external memory.

Possible values:
 marked (default setting)
Creating a copy is activated. When you click in the Basic Settings > Load/Save dialog the Save
button, the device generates a copy of the configuration profile on the active external memory.
 unmarked
Creating a copy is deactivated. The device does not generate a copy of the configuration profile.

Manufacturer ID
Displays the name of the memory manufacturer.

Revision
Displays the revision number specified by the memory manufacturer.

Version
Displays the version number specified by the memory manufacturer.

38 RM GUI EAGLE
Release 3.4 03/2020
Basic Settings
[ Basic Settings > External Memory ]

Name
Displays the product name specified by the memory manufacturer.

Serial number
Displays the serial number specified by the memory manufacturer.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 39
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Port ]

1.6 Port
[ Basic Settings > Port ]

This dialog lets you specify settings for the individual ports. The dialog also displays the operating
mode, connection status, bit rate and duplex mode for every port.

The dialog contains the following tabs:


 [Configuration]
 [Statistics]

[Configuration]

Table

Port
Displays the port number.

Name
Name of the port.

Possible values:
 Alphanumeric ASCII character string with 0..64 characters
The following characters are allowed:
– <space>
– 0..9
– a..z
– A..Z
– !#$%&'()*+,-./:;<=>?@[\\]^_`{}~

Port on
Activates/deactivates the port.

Possible values:
 marked (default setting)
The port is active.
 unmarked
The port is inactive. The port does not send or receive any data.

State
Displays whether the port is currently physically enabled or disabled.

Possible values:
 marked
The port is physically enabled.
 unmarked
The port is physically disabled.

40 RM GUI EAGLE
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Port ]

Power state (port off)


Specifies, whether the port is physically switched on or off when you deactivate the port with the
Port on function.

Possible values:
 marked
The port remains physically enabled. A connected device receives an active link.
 unmarked (default setting)
The port is physically disabled.

Auto power down


Specifies how the port behaves when no cable is connected.

Possible values:
 no-power-save (default setting)
The port remains activated.
 auto-power-down
The port changes to the energy-saving mode.
 unsupported
The port does not support this function and remains activated.

Automatic configuration
Activates/deactivates the automatic selection of the operating mode for the port.

Possible values:
 marked (default setting)
The automatic selection of the operating mode is active.
The port negotiates the operating mode independently using autonegotiation and detects the
devices connected to the TP port automatically (Auto Cable Crossing). This setting has priority
over the manual setting of the port.
Elapse several seconds until the port has set the operating mode.
 unmarked
The automatic selection of the operating mode is inactive.
The port operates with the values you specify in the Manual configuration column and in the
Manual cable crossing (Auto. conf. off) column.
 Grayed-out display
No automatic selection of the operating mode.

Manual configuration
Specifies the operating mode of the ports when the Automatic configuration function is disabled.

Possible values:
 10 Mbit/s HDX
Half duplex connection
 10 Mbit/s FDX
Full duplex connection
 100 Mbit/s HDX
Half duplex connection

RM GUI EAGLE 41
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Port ]

 100 Mbit/s FDX


Full duplex connection
 1000 Mbit/s FDX
Full duplex connection

Note: The operating modes of the port actually available depend on the device configuration.

Link/Current settings
Displays the operating mode which the port currently uses.

Possible values:
 –
No cable connected, no link.
 10 Mbit/s HDX
Half duplex connection
 10 Mbit/s FDX
Full duplex connection
 100 Mbit/s HDX
Half duplex connection
 100 Mbit/s FDX
Full duplex connection
 1000 Mbit/s FDX
Full duplex connection

Note: The operating modes of the port actually available depend on the device configuration.

Manual cable crossing (Auto. conf. off)


Specifies the devices connected to a TP port.

The prerequisite is that the Automatic configuration function is disabled.

Possible values:
 mdi
The device interchanges the send- and receive-line pairs on the port.
 mdix (default setting on TP ports)
The device helps prevent the interchange of the send- and receive-line pairs on the port.
 auto-mdix
The device detects the send and receive line pairs of the connected device and automatically
adapts to them.
Example: When you connect an end device with a crossed cable, the device automatically
resets the port from mdix to mdi.
 unsupported (default setting on optical ports or TP-SFP ports)
The port does not support this function.

Flow control
Activates/deactivates the flow control on the port.

42 RM GUI EAGLE
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Port ]

Possible values:
 marked (default setting)
The Flow control on the port is active.
The sending and evaluating of pause packets (full-duplex operation) or collisions (half-duplex
operation) is activated on the port.
 To enable the flow control in the device, also activate the Flow control function in the
Switching > Global dialog.
 Activate the flow control also on the port of the device that is connected to this port.
On an uplink port, activating the flow control can possibly cause undesired sending breaks in
the higher-level network segment (“wandering backpressure”).
 unmarked
The Flow control on the port is inactive.

If you are using a redundancy function, then you deactivate the flow control on the participating
ports. If the flow control and the redundancy function are active at the same time, it is possible that
the redundancy function operates differently than intended.

Send trap (Link up/down)


Activates/deactivates the sending of SNMP traps when the device detects changes in the link up/
down status for this port.

Possible values:
 marked (default setting)
The sending of SNMP traps is active.
When the device detects a link up/down status change, the device sends an SNMP trap.
 unmarked
The sending of SNMP traps is inactive.

The prerequisite for sending SNMP traps is that you enable the function in the Diagnostics > Status
Configuration > Alarms (Traps) dialog and specify at least 1 trap destination.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Clear port statistics


Resets the counter for the port statistics to 0.

[Statistics]

This tab displays the following overview per port:


 Number of data packets/bytes received in the device
– Received packets
– Received octets
– Received unicast packets
– Received multicast packets
– Received broadcast packets
 Number of data packets/bytes sent from the device
– Transmitted packets
– Transmitted octets
– Transmitted unicast packets

RM GUI EAGLE 43
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Port ]

– Transmitted multicast packets


– Transmitted broadcast packets
 Number of errors detected by the device
– Received fragments
– Detected CRC errors
– Detected collisions
 Number of data packets per size category received on the device
– Packets 64 bytes
– Packets 65 to 127 bytes
– Packets 128 to 255 bytes
– Packets 256 to 511 bytes
– Packets 512 to 1023 bytes
– Packets 1024 to 1518 bytes
 Number of data packets discarded by the device
– Received discards
– Transmitted discards

To sort the table by a specific criterion click the header of the corresponding row.

For example, to sort the table based on the number of received bytes in ascending order, click the
header of the Received octets column once. To sort in descending order, click the header again.

To reset the counter for the port statistics in the table to 0, proceed as follows:
 In the Basic Settings > Port dialog, click the button and then the Clear port statistics item.
or
 In the Basic Settings > Restart dialog, click the Clear port statistics button.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Clear port statistics


Resets the counter for the port statistics to 0.

44 RM GUI EAGLE
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Restart ]

1.7 Restart
[ Basic Settings > Restart ]

This dialog lets you restart the device, reset port counters and address tables, and delete log files.

Restart

Cold start...
Opens the Restart dialog to initiate a restart of the device.

If the configuration profile in the volatile memory (RAM) and the "Selected" configuration profile in
the non-volatile memory (NVM) differ, then the device displays the Warning dialog.
 To permanently save the changes, click the Yes button in the Warning dialog.
 To discard the changes, click the No button in the Warning dialog.

The device restarts and goes through the following phases:


 The device starts the device software that the Stored version field displays in the Basic Settings >
Software dialog.
 The device loads the settings from the "Selected" configuration profile. See the Basic Settings >
Load/Save dialog.

Note: During the restart, the device does not transfer any data. During this time, the device cannot
be accessed by the Graphical User Interface or other management systems.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Reset MAC address table


Removes the MAC addresses from the forwarding table that have in the Switching > Filter for MAC
Addresses dialog the value learned in the Status column.

Reset ARP table


Removes the dynamically set up addresses from the ARP table.

See the Diagnostics > System > ARP dialog.

Clear port statistics


Resets the counter for the port statistics to 0.

See the Basic Settings > Port dialog, Statistics tab.

RM GUI EAGLE 45
Release 3.4 03/2020
Basic Settings
[ Basic Settings > Restart ]

Delete log file


Removes the logged events from the log file.

See the Diagnostics > Report > System Log dialog.

Delete persistent log file


Removes the log files from the external memory.

See the Diagnostics > Report > Persistent Logging dialog.

Clear firewall table


Removes the information about open connections from the state table of the firewall. It is possible,
that the device interrupts open communication connections.

46 RM GUI EAGLE
Release 3.4 03/2020
Time
[ Time > Basic Settings ]

2 Time

The menu contains the following dialogs:


 Basic Settings
 NTP

2.1 Basic Settings


[ Time > Basic Settings ]

After a restart, the device initializes its clock to January 1, 00:00h. Reset the time if you disconnect
the device from the power supply or restart it. Alternatively you specify, that the device
automatically obtains the current time from an SNTP server or from a PTP clock.

In this dialog, you specify time-related settings independently of the time synchronization protocol
specified.

Configuration

System time (UTC)


Displays the current date and time with reference to Universal Time Coordinated (UTC).

Set time from PC


The device uses the time on the PC as the system time.

System time
Displays the current date and time with reference to the local time: System time = System time (UTC)
+ Local offset [min] + Daylight saving time

Time source
Displays the time source from which the device gets the time information.

The device automatically selects the available time source with the greatest accuracy.

Possible values:
 local
System clock of the device.
 ntp
The NTP client is activated and the device is synchronized by an NTP server.

Local offset [min]


Specifies the difference between the local time and System time (UTC) in minutes: Local offset [min] =
System time − System time (UTC)

RM GUI EAGLE 47
Release 3.4 03/2020
Time
[ Time > NTP ]

Possible values:
 -780..840 (default setting: 60)

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

2.2 NTP
[ Time > NTP ]

The device lets you synchronize the system time in the device and in the network using the Network
Time Protocol (NTP).

The Network Time Protocol (NTP) is a procedure described in RFC 5905 for time synchronization
in the network.

On the basis of a reference time source, NTP defines hierarchy levels for time servers and clients.
A hierarchy level is known as a “stratum”. Devices of the 1st level (stratum 1) synchronize
themselves directly with the reference time source and make the time information available to
clients of the 2nd level (stratum 2). A GPS receiver or a radio-controlled clock can serve as the
reference time source.

The NTP client in the device evaluates the time information of several servers and adjusts its own
clock continuously to attain a high level of accuracy. If you also configure the device as an NTP
server, then the device distributes time information to the clients in the subordinate network
segment.

The menu contains the following dialogs:


 Global
 Server
 NTP Multicast Groups

48 RM GUI EAGLE
Release 3.4 03/2020
Time
[ Time > NTP > Global ]

2.2.1 Global
[ Time > NTP > Global ]

In this dialog you determine whether the device functions as an NTP client and server or only as an
NTP client.
 As an NTP client, the device takes the coordinated world time (UTC) from one or more NTP
servers in the network.
 As an NTP server, the device distributes the coordinated world time (UTC) to NTP clients in the
subordinate network segment. The device takes the coordinated world time from one or more
NTP servers in the network, if these were previously specified.

Client only

The device transmits the time information without authentication in the VLAN of the device
management as well as in Layer 3 on the IP interfaces set up.

Client
Enables/disables the NTP client in the device.

Possible values:
 On
The NTP client is enabled.
The device obtains the time information from one or more NTP servers in the network.
 Off (default setting)
The NTP client is disabled.

Note: Before you enable the client, disable the Server function in the Client and server frame.

Mode
Specifies from where the NTP client takes the time information.

Possible values:
 unicast (default setting)
The NTP client takes the time information from unicast responses of the servers that are
indicated as active in the Time > NTP > Server dialog.
 broadcast
The NTP client takes the time information from broadcast messages or from multicast
messages of the servers that are indicated as active in the Time > NTP > Multicast Groups dialog.

Client and server

The device transmits the time information without authentication in the VLAN of the device
management as well as in Layer 3 on the IP interfaces set up.

Server
Enables/disables the NTP client and the NTP server in the device.

RM GUI EAGLE 49
Release 3.4 03/2020
Time
[ Time > NTP > Global ]

Possible values:
 On
The NTP client and the NTP server are enabled.
The NTP client obtains the time information from one or more NTP servers in the network. The
NTP server distributes the time information to the NTP clients in the subordinate network
segment.
 Off (default setting)
The NTP client and the NTP server are disabled.

Note: If you enable the NTP client and the NTP server, then the device disables the function in the
Client field in the Client only frame.

Mode
Specifies in which mode the NTP server works.

Possible values:
 client-server (default setting)
With this setting, the device obtains the time information from NTP servers in the network and
distributes it to NTP clients in the subordinate network segment.
– The NTP client takes the time information from the unicast responses of the servers that are
indicated as active in the Time > NTP > Server dialog.
– The NTP server distributes the time information via unicast to the requesting clients.
 symmetric
With this setting you integrate the device in a cluster of redundant NTP servers. The device
synchronizes the time information with the other NTP servers in the cluster at intervals of 64
seconds.
 In the Time > NTP > Server dialog, indicate the NTP servers participating in the cluster as
active.
 Specify a uniform value for the stratum for the NTP servers participating in the cluster.

Stratum
Specifies the hierarchical distance of the device to the referent time source.

Possible values:
 1..16 (default setting: 12)

Example: Devices of the first level (Stratum 1) synchronize themselves directly with the reference
time source and make the time information available to the clients of the second level (Stratum 2).

The device evaluates this value under the following circumstances:


 The NTP server in the device is working in symmetric mode.
or
 The device is using the local system clock as the time source. See the Time source field in the
Time > Basic Settings dialog.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

50 RM GUI EAGLE
Release 3.4 03/2020
Time
[ Time > NTP > Server ]

2.2.2 Server
[ Time > NTP > Server ]

In this dialog you specify the NTP servers.


 The NTP client of the device obtains the time information from the unicast responses of the
servers specified here.
 If the NTP server of the device is working in symmetric mode, then you specify the servers
participating in the cluster here.

Table

Index
Displays the index number to which the table entry relates.

Possible values:
 1..4

The device automatically assigns this number.

When you delete a table entry, this leaves a gap in the numbering. When you create a new table
entry, the device fills the first gap.

Address
Specifies the IP address of the NTP server.

Possible values:
 Valid IPv4 address (default setting: [Link])

Port
Displays the UDP Port on which the NTP server provides the time information.

Initial burst
Activates/deactivates the Initial burst mode.

During operation, the NTP client of the device only sends single data packets to request the time
information. If the NTP server is unreachable (Status column = notResponding),then the NTP client
of the device sends several data packets at once (burst) to synchronize as soon as possible.

Possible values:
 marked
The Initial burst mode is active.
– The device sends only once several data packets (burst) when the NTP server is
unreachable.
– Only use this setting if you use a private, non-public NTP server as reference time source.
– You use this setting with care to speed up the initial synchronization.
 unmarked (default setting)
The Initial burst mode is inactive.

RM GUI EAGLE 51
Release 3.4 03/2020
Time
[ Time > NTP > Server ]

Burst
Activates/deactivates the Burst mode.

During operation, the NTP client of the device only sends single data packets to request the time
information. In the Burst mode, the NTP client of the device sends several data packets at once
(burst) when the NTP server is reachable and ready for synchronization.

Possible values:
 marked
The Burst mode is active.
– For each polling interval, the device sends several data packets (burst) when the NTP server
is reachable.
– Only use this setting if you use a private, non-public NTP server as reference time source.
– You use this setting with care to improve precision when the connection to the NTP server
is unstable.
 unmarked (default setting)
The Burst mode is inactive.

Preferred
Marks the NTP server as preferred reference time source when multiple NTP servers are specified.

Without marking, the NTP client of the device uses standard algorithms to select the reference time
source.

Mark max. 1 sufficiently precise server as Preferred.

Possible values:
 marked
The device uses the NTP server as the preferred reference time source. You use this setting to
help prevent frequent connection changes between equal NTP servers.
 unmarked (default setting)
No preferred NTP server.

Status
Displays the synchronization status.

Possible values:
 disabled
No server available.
 protocolError

 notSynchronized
The server is available. The server itself is not synchronized.
 notResponding
The server is available. The device does not receive time information.
 synchronizing
The server is available. The device receives time information.
 synchronized
The server is available. The device has synchronized its clock with the server.
 genericError
Device-internal error.

52 RM GUI EAGLE
Release 3.4 03/2020
Time
[ Time > NTP > Server ]

Active
Activates/deactivates the connection to the NTP server.

Possible values:
 marked
The connection to the NTP server is activated.
– The NTP client of the device obtains the time information from the unicast responses of this
server.
– If the NTP server of the device is working in symmetric mode, then this server participates
in a cluster.
 unmarked
The connection to the NTP server is deactivated.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 53
Release 3.4 03/2020
Time
[ Time > NTP > Multicast Groups ]

2.2.3 NTP Multicast Groups


[ Time > NTP > Multicast Groups ]

In this dialog you specify the broadcast and multicast addresses.

In broadcast mode, the NTP client of the device obtains the time information from broadcast or
multicast messages from the addresses specified here.

Table

Index
Displays the index number to which the table entry relates.

When you delete a table entry, this leaves a gap in the numbering. When you create a new table
entry, the device fills the first gap.

Possible values:
 1..4

Address
Specifies the IP address of the broadcast or multicast.

Possible values:
 Valid IPv4 address (default setting: [Link])

Port
Specifies the UDP Port on which the broadcast or multicast provides the time information.

Possible values:
 1..65535 (default setting: 123)
Exception: Port 2222 is reserved for internal functions.

Status
Displays the synchronization status.

Possible values:
 disabled
No server available.
 notSynchronized
The server is available. The server itself is not synchronized.
 notResponding
The server is available. The device does not receive time information.
 synchronizing
The server is available. The device receives time information.
 synchronized
The server is available. The device has synchronized its clock with the server.
 genericError
Device-internal error.

54 RM GUI EAGLE
Release 3.4 03/2020
Time
[ Time > NTP > Multicast Groups ]

Active
Activates/deactivates the connection between the device and the broadcast or multicast server.

Possible values:
 marked
The connection to the broadcast or multicast is activated.
The NTP client of the device obtains the time information from the broadcast or multicast
messages of this IP address.
 unmarked
The connection to the broadcast or multicast is deactivated.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 55
Release 3.4 03/2020
Device Security
[ Device Security > User Management ]

3 Device Security

The menu contains the following dialogs:


 User Management
 Authentication List
 LDAP
 Management Access
 Pre-login Banner

3.1 User Management


[ Device Security > User Management ]

If users log in with valid login data, then the device lets them have access to its device
management.

In this dialog you manage the users of the local user management. You also specify the following
settings here:
 Settings for the login
 Settings for saving the passwords
 Specify policy for valid passwords

The methods that the device uses for the authentication you specify in the Device Security >
Authentication List dialog.

Configuration

This frame lets you specify settings for the login.

Login attempts
Number of login attempts possible.

Possible values:
 0..5 (default setting: 0)

If the user makes one more unsuccessful login attempt, then the device locks access for the user.

The device lets only users with the administrator authorization remove the lock.

The value 0 deactivates the lock. The user has unlimited attempts to login.

Login attempts period


Displays the time period before the device resets the counter in the Login attempts field.

Possible values:
 0..60 (default setting: 0)

56 RM GUI EAGLE
Release 3.4 03/2020
Device Security
[ Device Security > User Management ]

Min. password length


The device accepts the password if it contains at least the number of characters specified here.

The device checks the password according to this setting, regardless of the setting for the Policy
check checkbox.

Possible values:
 1..64 (default setting: 6)

Password policy

This frame lets you specify the policy for valid passwords. The device checks every new password
and password change according to this policy.

The settings effect the Password column. The prerequisite is that you mark the checkbox in the
Policy check column.

Upper-case characters (min.)


The device accepts the password if it contains at least as many upper-case letters as specified
here.

Possible values:
 0..16 (default setting: 1)

The value 0 deactivates this setting.

Lower-case characters (min.)


The device accepts the password if it contains at least as many lower-case letters as specified here.

Possible values:
 0..16 (default setting: 1)

The value 0 deactivates this setting.

Digits (min.)
The device accepts the password if it contains at least as many numbers as specified here.

Possible values:
 0..16 (default setting: 1)

The value 0 deactivates this setting.

Special characters (min.)


The device accepts the password if it contains at least as many special characters as specified
here.

RM GUI EAGLE 57
Release 3.4 03/2020
Device Security
[ Device Security > User Management ]

Possible values:
 0..16 (default setting: 1)

The value 0 deactivates this setting.

Table

Every user requires an active user account to gain access to the device management. The table
lets you set up and manage user accounts.

To change settings, click the desired parameter in the table and modify the value.

User name
Displays the name of the user account.

To create a new user account, click the button.

Active
Activates/deactivates the user account.

Possible values:
 marked
The user account is active. The device accepts the login of a user with this user name.
 unmarked (default setting)
The user account is inactive. The device rejects the login of a user with this user name.

When one user account exists with the administrator access role, this user account is constantly
active.

Password
Displays ***** (asterisks) instead of the password with which the user logs in. To change the
password, click the relevant field.

Possible values:
 Alphanumeric ASCII character string with 6..64 characters
The following characters are allowed:
– a..z
– A..Z
– 0..9
– !#$%&'()*+,-./:;<=>?@[\]^_`{}~

The minimum length of the password is specified in the Configuration frame. The device
differentiates between upper and lower case.

If the checkbox in the Policy check column is marked, then the device checks the password
according to the policy specified in the Password policy frame.

The device constantly checks the minimum length of the password, even if the checkbox in the
Policy check column is unmarked.

58 RM GUI EAGLE
Release 3.4 03/2020
Device Security
[ Device Security > User Management ]

Role
Specifies the user role that regulates the access of the user to the individual functions of the device.

Possible values:
 unauthorized
The user is blocked, and the device rejects the user log on.
Assign this value to temporarily lock the user account. If the device detects an error when
another role is being assigned, then the device assigns this role to the user account.
 guest (default setting)
The user is authorized to monitor the device.
 auditor
The user is authorized to monitor the device and to save the log file in the Diagnostics > Report >
Audit Trail dialog.
 operator
The user is authorized to monitor the device and to change the settings – with the exception of
security settings for device access.
 administrator
The user is authorized to monitor the device and to change the settings.

The device assigns the Service Type transferred in the response of a RADIUS server as follows to
a user role:
• Administrative-User: administrator
• Login-User: operator
• NAS-Prompt-User: guest

User locked
Unlocks the user account.

Possible values:
 marked
The user account is locked. The user has no access to the device management.
If the user makes too many unsuccessful log in attempts, then the device automatically locks
the user.
 unmarked (grayed out) (default setting)
The user account is unlocked. The user has access to the device management.

Policy check
Activates/deactivates the password check.

Possible values:
 marked
The password check is activated.
When you set up or change the password, the device checks the password according to the
policy specified in the Password policy frame.
 unmarked (default setting)
The password check is deactivated.

SNMP auth type


Specifies the authentication protocol that the device applies for user access via SNMPv3.

RM GUI EAGLE 59
Release 3.4 03/2020
Device Security
[ Device Security > User Management ]

Possible values:
 hmacmd5 (default value)
For this user account, the device uses protocol HMACMD5.
 hmacsha
For this user account, the device uses protocol HMACSHA.

SNMP encryption type


Specifies the encryption protocol that the device applies for user access via SNMPv3.

Possible values:
 none
No encryption.
 des (default value)
DES encryption
 aesCfb128
AES128 encryption

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Opens the Create window to add a new entry to the table.


 In the User name field, you specify the name of the user account.
Possible values:
– Alphanumeric ASCII character string with 1..32 characters

60 RM GUI EAGLE
Release 3.4 03/2020
Device Security
[ Device Security > Authentication List ]

3.2 Authentication List


[ Device Security > Authentication List ]

In this dialog you manage the authentication lists. In a authentication list you specify which method
the device uses for the authentication. You also have the option to assign pre-defined applications
to the authentication lists.

If users log in with valid login data, then the device lets them have access to its device
management. The device authenticates the users using the following methods:
 User management of the device
 LDAP
 RADIUS

In the default setting the following authentication lists are available:


 defaultLoginAuthList
 defaultV24AuthList

Table

Note: If the table does not contain a list, then the access to the device management is only possible
using the Command Line Interface through the serial interface of the device. In this case, the device
authenticates the user by using the local user management. See the Device Security > User
Management dialog.

Name
Displays the name of the list.

To create a new list, click the button.

Possible values:
 Alphanumeric ASCII character string with 1..32 characters

Policy 1
Policy 2
Policy 3
Policy 4
Policy 5
Specifies the authentication policy that the device uses for access using the application specified
in the Dedicated applications column.

The device gives you the option of a fall-back solution. For this, you specify another policy in each
of the policy fields. If the authentication with the specified policy is unsuccessful, then the device
can use the next policy, depending on the order of the values entered in each policy.

Possible values:
 local (default setting)
The device authenticates the users by using the local user management. See the Device
Security > User Management dialog.
You cannot assign this value to the authentication list defaultDot1x8021AuthList.
 radius
The device authenticates the users with a RADIUS server in the network. You specify the
RADIUS server in the Network Security > RADIUS > Authentication Server dialog.

RM GUI EAGLE 61
Release 3.4 03/2020
Device Security
[ Device Security > Authentication List ]

 reject
The device accepts or rejects the authentication depending on which policy you try first. The
following list contains authentication scenarios:
– If the first policy in the authentication list is local and the device accepts the credentials of
the user, then it logs the user in without attempting the other polices.
– If the first policy in the authentication list is local and the device denies the credentials of
the user, then it attempts to log the user in using the other polices in the order specified.
– If the first policy in the authentication list is radius or ldapand the device rejects a login, then
the login is immediately rejected without attempting to login the user using another policy.
If there is no response from the RADIUS or LDAP server, then the device attempts to
authenticate the user with the next policy.
– If the first policy in the authentication list is reject, then the devices immediately rejects the
user login without attempting another policy.
– Verify that the authentication list defaultV24AuthList contains at least one policy different
from reject.
 ldap
The device authenticates the users with authentication data and access role saved in a central
location. You specify the Active Directory server that the device uses in the Network Security >
LDAP > Configuration dialog.

Dedicated applications
Displays the dedicated applications. When users access the device with the relevant application,
the device uses the specified policies for the authentication.

To allocate another application to the list or remove the allocation, click the button and then the
Allocate applications item. The device lets you assign each application to exactly one list.

Active
Activates/deactivates the list.

Possible values:
 marked
The list is activated. The device uses the policies in this list when users access the device with
the relevant application.
 unmarked (default setting)
The list is deactivated.

62 RM GUI EAGLE
Release 3.4 03/2020
Device Security
[ Device Security > LDAP ]

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Allocate applications
Opens the Allocate applications window.
 The left field displays the applications that can be allocated to the highlighted list.
 The right field displays the applications that are allocated to the highlighted list.
 Buttons:
Moves every entry to the right field.
Moves the highlighted entries from the left field to the right field.
Moves the highlighted entries from the right field to the left field.
Moves every entry to the left field.

Note: When you move the entry WebInterface to the left field, the connection to the device is lost,
after you click the Ok button.

3.3 LDAP
[ Device Security > LDAP ]

The Lightweight Directory Access Protocol (LDAP) lets you authenticate and authorize the users at
a central point in the network. A widely used directory service accessible through LDAP is Active
Directory®.

The device forwards the log in data of the user to the authentication server using the LDAP protocol.
The authentication server decides whether the login data is valid and transfers the user’s
authorizations to the device.

Upon successful log on, the device saves the log on data temporarily in the cache. This speeds up
the logon process when users logon again. In this case, no complex LDAP search operation is
necessary.

The menu contains the following dialogs:


 LDAP Configuration
 LDAP Role Mapping

RM GUI EAGLE 63
Release 3.4 03/2020
Device Security
[ Device Security > LDAP > Configuration ]

3.3.1 LDAP Configuration


[ Device Security > LDAP > Configuration ]

This dialog lets you specify up to 4 authentication servers. An authentication server authenticates
and authorizes the users when the device forwards the login data to the server.

The device sends the log on data to the first authentication server. When no response comes from
this server, the device contacts the next server in the table.

Operation

Operation
Enables/disables the LDAP client.

If in the Device Security > Authentication List dialog you specify the value ldap in 1 of the rows Policy
1 to Policy 5, then the device uses the LDAP client. Prior to this, specify in the Device Security > LDAP >
Role Mapping dialog at least 1 Mapping for this role administrator. This provides you access to
the device as administrator after logging on through LDAP.

Possible values:
 On
The LDAP client is enabled.
 Off (default setting)
The LDAP client is disabled.

Configuration

Client cache timeout [min]


Specifies for how many minutes after successfully logging on the logon data of a user remain valid.
When a user logs on again within this time, no complex LDAP search operation is necessary. The
logon process is much faster.

Possible values:
 1..1440 (default setting: 10)

Bind user
Specifies the user ID in the form of the “Distinguished Name” (DN) with which the device logs on to
the LDAP server.

If the LDAP server requires a user ID in the form of the “Distinguished Name” (DN) for the log on,
then this information is necessary. In Active Directory environments, this information is
unnecessary.

The device logs on to the LDAP server with the user ID to find the “Distinguished Name” (DN) for
the users logging on. The device conducts the search according to the settings in the fields Base
DN and User name attribute.

64 RM GUI EAGLE
Release 3.4 03/2020
Device Security
[ Device Security > LDAP > Configuration ]

Possible values:
 Alphanumeric ASCII character string with 0..64 characters

Bind user password


Specifies the password which the device uses together with the user ID specified in the Bind user
field when logging on to the LDAP server.

Possible values:
 Alphanumeric ASCII character string with 0..64 characters

Base DN
Specifies the starting point for the search in the directory tree in the form of the “Distinguished
Name” (DN).

Possible values:
 Alphanumeric ASCII character string with 0..255 characters

User name attribute


Specifies the LDAP attribute which contains a biunique user name. Afterwards, the user uses the
user name contained in this attribute to log on.

Often the LDAP attributes userPrincipalName, mail, sAMAccountName and uid contain a unique
user name.

The device adds the character string specified in the Default domain field to the user name under the
following condition:
• The user name contained in the attribute does not contain the @ character.
• In the Default domain field, a domain name is specified.

Possible values:
 Alphanumeric ASCII character string with 0..64 characters
(default setting: userPrincipalName)

Default domain
Specifies the character string which the device adds to the user name of the users logging on if the
user name does not contain the @ character.

Possible values:
 Alphanumeric ASCII character string with 0..64 characters

CA certificate

URL
Specifies the path and file name of the certificate.

RM GUI EAGLE 65
Release 3.4 03/2020
Device Security
[ Device Security > LDAP > Configuration ]

The device accepts certificates with the following properties:


• X.509 format
• .PEM file name extension
• Base64-coded, enclosed by
-----BEGIN CERTIFICATE-----
and
-----END CERTIFICATE-----

For security reasons, we recommend to constantly use a certificate which is signed by a


certification authority.

The device gives you the following options for copying the certificate to the device:
 Import from the PC
When the certificate is located on your PC or on a network drive, drag and drop the certificate
in the area. Alternatively click in the area to select the certificate.
You also have the option of transferring the certificate from your PC to the device through SFTP
or SCP:
 On your PC, open an SFTP or SCP client, for example WinSCP.
 Use the SFTP or SCP client to open a connection to the device.
 Transfer the certificate file to the directory /upload/ldapcert in the device.
When the file transfer is complete, the device starts installing the certificate. If the installation
was successful, then the device creates an ok file in the directory /upload/ldapcert and
deletes the certificate file.

Start
Copies the certificate specified in the URL field to the device.

Table

Index
Displays the index number to which the table entry relates.

Description
Specifies the description.

You have the option to describe here the authentication server or note additional information.

Possible values:
 Alphanumeric ASCII character string with 0..255 characters

Address
Specifies the IP address or the DNS name of the server.

66 RM GUI EAGLE
Release 3.4 03/2020
Device Security
[ Device Security > LDAP > Configuration ]

Possible values:
 IPv4 address (default setting: [Link])
 DNS name in the format <domain>.<tld> or <host>.<domain>.<tld>
 _ldap._tcp.<domain>.<tld>
Using this DNS name, the device queries the LDAP server list (SRV Resource Record) from the
DNS server.

If in the Connection security row a value other than none is specified and the certificate contains only
DNS names of the server, then use a DNS name. Enable the Client function in the Advanced > DNS >
Client > Global dialog.

Destination TCP port


Specifies the TCP Port on which the server expects the requests.

If you have specified the value _ldap._tcp.[Link] in the Address column, then the device
ignores this value.

Possible values:
 0..65535 (default setting: 389)
Exception: Port 2222 is reserved for internal functions.

Frequently used TCP-Ports:


• LDAP: 389
• LDAP over SSL: 636
• Active Directory Global Catalogue: 3268
• Active Directory Global Catalogue SSL: 3269

Connection security
Specifies the protocol which encrypts the communication between the device and the
authentication server.

Possible values:
 none
No encryption.
The device establishes an LDAP connection to the server and transmits the communication
including the passwords in clear text.
 ssl
Encryption with SSL.
The device establishes a TLS connection to the server and tunnels the LDAP communication
over it.
 startTLS (default setting)
Encryption with startTLS extension.
The device establishes an LDAP connection to the server and encrypts the communication.

The prerequisite for encrypted communication is that the device uses the correct time. If the
certificate contains only the DNS names, then you specify the DNS name of the server in the
Address row. Enable the Client function in the Advanced > DNS > Client > Global dialog.

If the certificate contains the IP address of the server in the “Subject Alternative Name” field, then
the device is able to verify the identity of the server without the DNS configuration.

RM GUI EAGLE 67
Release 3.4 03/2020
Device Security
[ Device Security > LDAP > Configuration ]

Server status
Displays the connection status and the authentication with the authentication server.

Possible values:
 ok
The server is reachable.
If in the Connection security row a value other than none is specified, then the device has verified
the certificate of the server.
 unreachable
Server is unreachable.
 other
The device has not established a connection to the server yet.

Active
Activates/deactivates the use of the server.

Possible values:
 marked
The device uses the server.
 unmarked (default setting)
The device does not use the server.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Flush cache
Removes the cached log on data of the successfully logged on users.

68 RM GUI EAGLE
Release 3.4 03/2020
Device Security
[ Device Security > LDAP > Role Mapping ]

3.3.2 LDAP Role Mapping


[ Device Security > LDAP > Role Mapping ]

This dialog lets you create up to 64 mappings to assign a role to users.

In the table, you specify whether the device assigns a role to the user based on an attribute with a
specific value or based on the group membership.
 The device searches for the attribute and the attribute value within the user object.
 By evaluating the “Distinguished Name” (DN) contained in the member attributes, the device
checks group the membership.

When a user logs on, the device searches for the following information on the LDAP server:
 In the related user project, the device searches for attributes specified in the mappings.
 In the group objects of the groups specified in the mappings, the device searches for the
member attributes.

On this basis, the device checks any mapping.


• Does the user object contain the required attribute?
or
• Is the user member of the group?

If the device does not find a match, then the user does not get access to the device.

If the device finds more than 1 mapping that applies to a user, then the setting in the Matching policy
field decides. The user either obtains the role with the more extensive authorizations or the 1st role
in the table that applies.

Configuration

Matching policy
Specifies which role the device applies if more than 1 mapping applies to a user.

Possible values:
 highest (default setting)
The device applies the role with more extensive authorizations.
 first
The device applies the rule which has the lower value in the Index column to the user.

Table

Index
Displays the index number to which the table entry relates.

Role
Specifies the user role that regulates the access of the user to the individual functions of the device.

RM GUI EAGLE 69
Release 3.4 03/2020
Device Security
[ Device Security > LDAP > Role Mapping ]

Possible values:
 unauthorized
The user is blocked, and the device rejects the user log on.
Assign this value to temporarily lock the user account. If an error occurs when another role is
being assigned, then the device assigns this role to the user account.
 guest (default setting)
The user is authorized to monitor the device.
 auditor
The user is authorized to monitor the device and to save the log file in the Diagnostics > Report >
Audit Trail dialog.
 operator
The user is authorized to monitor the device and to change the settings – with the exception of
security settings for device access.
 administrator
The user is authorized to monitor the device and to change the settings.

Type
Specifies whether a group or an attribute with an attribute value is set in the Parameter column.

Possible values:
 attribute (default setting)
The Parameter column contains an attribute with an attribute value.
 group
The Parameter column contains the “Distinguished Name” (DN) of a group.

Parameter
Specifies a group or an attribute with an attribute value, depending on the setting in the Type
column.

Possible values:
 Alphanumeric ASCII character string with 0..255 characters
The device differentiates between upper and lower case.
– If in the Type column the value attribute is specified, then you specify the attribute in the
form of Attribute_name=Attribute_value.
Example: l=Germany
– If in the Type column the value group is specified, then you specify the “Distinguished Name”
(DN) of a group.
Example: CN=admin-users,OU=Groups,DC=example,DC=com

Active
Activates/deactivates the role mapping.

Possible values:
 marked (default setting)
The role mapping is active.
 unmarked
The role mapping is inactive.

70 RM GUI EAGLE
Release 3.4 03/2020
Device Security
[ Device Security > Management Access ]

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Opens the Create window to add a new entry to the table.


 In the Index field, you specify the index number.
Possible values:
– 1..64

3.4 Management Access


[ Device Security > Management Access ]

The menu contains the following dialogs:


 Server
 IP Access Restriction
 Web
 Command Line Interface
 SNMPv1/v2 Community

RM GUI EAGLE 71
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > Server ]

3.4.1 Server
[ Device Security > Management Access > Server ]

This dialog lets you set up the server services which enable users or applications to access the
management of the device.

The dialog contains the following tabs:


 [Information]
 [SNMP]
 [SSH]
 [HTTP]
 [HTTPS]

[Information]

This tab displays as an overview which server services are enabled.

Table

SNMPv1
Displays whether the server service is active or inactive, which authorizes access to the device
using SNMP version 1. See the SNMP tab.

Possible values:
 marked
Server service is active.
 unmarked
Server service is inactive.

SNMPv2
Displays whether the server service is active or inactive, which authorizes access to the device
using SNMP version 2. See the SNMP tab.

Possible values:
 marked
Server service is active.
 unmarked
Server service is inactive.

SNMPv3
Displays whether the server service is active or inactive, which authorizes access to the device
using SNMP version 3. See the SNMP tab.

72 RM GUI EAGLE
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > Server ]

Possible values:
 marked
Server service is active.
 unmarked
Server service is inactive.

Telnet server
Displays whether the server service is active or inactive, which authorizes access to the device
using Telnet. See the Telnet tab.

Possible values:
 marked
Server service is active.
 unmarked
Server service is inactive.

SSH server
Displays whether the server service is active or inactive, which authorizes access to the device
using Secure Shell. See the SSH tab.

Possible values:
 marked
Server service is active.
 unmarked
Server service is inactive.

HTTP server
Displays whether the server service is active or inactive, which authorizes access to the device
using the Graphical User Interface through HTTP. See the HTTP tab.

Possible values:
 marked
Server service is active.
 unmarked
Server service is inactive.

HTTPS server
Displays whether the server service is active or inactive, which authorizes access to the device
using the Graphical User Interface through HTTPS. See the HTTPS tab.

Possible values:
 marked
Server service is active.
 unmarked
Server service is inactive.

RM GUI EAGLE 73
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > Server ]

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

[SNMP]

This tab lets you specify settings for the SNMP agent of the device and to enable/disable access
to the device with different SNMP versions.

The SNMP agent enables access to the device management with SNMP-based applications.

Configuration

SNMPv1
Activates/deactivates the access to the device with SNMP version 1.

Possible values:
 marked
Access is activated.
 unmarked (default setting)
Access is deactivated.

You specify the community names in the Device Security > Management Access > SNMPv1/v2
Community dialog.

SNMPv2
Activates/deactivates the access to the device with SNMP version 2.

Possible values:
 marked
Access is activated.
 unmarked (default setting)
Access is deactivated.

You specify the community names in the Device Security > Management Access > SNMPv1/v2
Community dialog.

SNMPv3
Activates/deactivates the access to the device with SNMP version 3.

Possible values:
 marked (default setting)
Access is activated.
 unmarked
Access is deactivated.

Network management systems like Industrial HiVision use this protocol to communicate with the
device.

74 RM GUI EAGLE
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > Server ]

UDP port
Specifies the number of the UDP port on which the SNMP agent receives requests from clients.

Possible values:
 1..65535 (default setting: 161)
Exception: Port 2222 is reserved for internal functions.

To enable the SNMP agent to use the new port after a change, you proceed as follows:
 Click the button.
 Select in the Basic Settings > Load/Save dialog the active configuration profile.
 Click the button to save the current changes.
 Restart the device.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

[SSH]

This tab lets you enable/disable the SSH server in the device and specify its settings required for
SSH. The server works with SSH version 2.

The SSH server enables access to the device management remotely through the Command Line
Interface. SSH connections are encrypted.

To access the device and the connected external memory using SFTP or SCP, you also need
access to the SSH server. With an SFTP or SCP client, for example WinSCP, you have the option
of loading configuration files or a software update to the device.

The SSH server identifies itself to the clients using its public RSA key. When first setting up the
connection, the client program displays the user the fingerprint of this key. The fingerprint contains
a Base64-coded character sequence that is easy to check. When you make this character
sequence available to the users via a reliable channel, they have the option to compare both
fingerprints. If the character sequences match, then the client is connected to the correct server.

The device lets you create the private and public keys (host keys) required for RSA directly in the
device. Otherwise you have the option to copy your own keys to the device in PEM format.

As an alternative, the device lets you load the RSA key (host key) from an external memory upon
restart. You activate this function in the Basic Settings > External Memory dialog, SSH key auto upload
column.

Operation

Operation
Enables/disables the SSH server.

RM GUI EAGLE 75
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > Server ]

Possible values:
 On (default setting)
The SSH server is enabled.
The access to the device management is possible through the Command Line Interface using
an encrypted SSH connection.
You can start the server only if there is an RSA signature in the device.
 Off
The SSH server is disabled.
When you disable the SSH server, the existing connections remain established. However, the
device helps prevent new connections from being set up.

Note: If the Telnet server is disabled and you also disable SSH, then the access to the Command
Line Interface is only possible through the serial interface of the device.

Configuration

TCP port
Specifies the number of the TCP port on which the device receives SSH requests from clients.

Possible values:
 1..65535 (default setting: 22)
Exception: Port 2222 is reserved for internal functions.

The server restarts automatically after the port is changed. Existing connections remain in place.

Sessions
Displays how many SSH connections are currently established to the device.

Sessions (max.)
Specifies the maximum number of SSH connections to the device that can be set up
simultaneously.

When you access the device using Command Line Interface, SFTP or SCP, each of these
applications establishes a separate SSH connection to the device.

Possible values:
 1..5 (default setting: 5)

Session timeout [min]


Specifies the timeout in minutes. After the user logged on has been inactive for this time, the device
ends the connection.

A change in the value takes effect the next time a user logs on to the device.

Possible values:
 0
Deactivates the function. The connection remains established in the case of inactivity.
 1..160 (default setting: 5)

76 RM GUI EAGLE
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > Server ]

Fingerprint

The fingerprint is an easy to verify string that uniquely identifies the host key of the SSH server.

After importing a new host key, the device continues to display the existing fingerprint until you
restart the server.

Fingerprint type
Specifies which fingerprint the RSA Fingerprint field displays.

Possible values:
 md5
The RSA Fingerprint field displays the fingerprint as hexadecimal MD5 hash.
 sha256
The device does not support this setting. The RSA Fingerprint field retains the previous display.

RSA Fingerprint
Displays the fingerprint of the public host key of the SSH server.

When you change the settings in the Fingerprint type field, click afterwards the button and then
the button to update the display.

Signature

RSA present
Displays whether an RSA host key is present in the device.

Possible values:
 marked
A key is present.
 unmarked
No key is present.

Create
Generates a host key in the device. The prerequisite is that the SSH server is disabled.

Length of the key created:


 2048 bit (RSA)

To get the SSH server to use the generated host key, re-enable the SSH server.

Alternatively, you have the option to copy your own host key to the device in PEM format. See the
Key import frame.

Delete
Removes the host key from the device. The prerequisite is that the SSH server is disabled.

RM GUI EAGLE 77
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > Server ]

Oper status
Displays whether the device currently generates a host key.

It is possible that another user triggered this action.

Possible values:
 rsa
The device currently generates an RSA host key.
 none
The device does not generate a host key.

Key import

URL
Specifies the path and file name of your own RSA host key.

The device accepts the RSA key if it has the following key length:
• 2048 bit (RSA)

The device gives you the following options for copying the key to the device:
 Import from the PC
When the host key is located on your PC or on a network drive, drag and drop the file that
contains the key in the area. Alternatively click in the area to select the file.
You also have the option of transferring the key from your PC to the device through SFTP or
SCP:
 On your PC, open an SFTP or SCP client, for example WinSCP.
 Use the SFTP or SCP client to open a connection to the device.
 Transfer the file that contains the key to the directory /upload/ssh-key in the device.
When the file transfer is complete, the device starts installing the key. If the installation was
successful, then the device creates an ok file in directory /upload/ssh-key and deletes the
file that contains the key.
 To get the server to use this key, you restart the server.

Start
Copies the key specified in the URL field to the device.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

78 RM GUI EAGLE
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > Server ]

[HTTP]

This tab lets you enable/disable the HTTP protocol for the web server and specify the settings
required for HTTP.

The web server provides the Graphical User Interface via an unencrypted HTTP connection. For
security reasons, disable the HTTP protocol and use the HTTPS protocol instead.

The device supports up to 10 simultaneous connections using HTTP or HTTPS.

Note: If you change the settings in this tab and click the button, then the device ends the session
and disconnects every opened connection. To continue working with the Graphical User Interface,
login again.

Operation

Operation
Enables/disables the HTTP protocol for the web server.

Possible values:
 On (default setting)
The HTTP protocol is enabled.
The access to the device management is possible through an unencrypted HTTP connection.
When the HTTPS protocol is also enabled, the device automatically redirects the request for a
HTTP connection to an encrypted HTTPS connection.
 Off
The HTTP protocol is disabled.
When the HTTPS protocol is enabled, the access to the device management is possible through
an encrypted HTTPS connection.

Note: If the HTTP and HTTPS protocols are disabled, then you can enable the HTTP protocol using
the Command Line Interface command http server to get to the Graphical User Interface.

Configuration

TCP port
Specifies the number of the TCP port on which the web server receives HTTP requests from clients.

Possible values:
 1..65535 (default setting: 80)
Exception: Port 2222 is reserved for internal functions.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 79
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > Server ]

[HTTPS]

This tab lets you enable/disable the HTTPS protocol for the web server and specify the settings
required for HTTPS.

The web server provides the Graphical User Interface via an encrypted HTTP connection.

A digital certificate is required for the encryption of the HTTP connection. The device lets you create
this certificate yourself or to load an existing certificate onto the device.

The device supports up to 10 simultaneous connections using HTTP or HTTPS.

Note: If you change the settings in this tab and click the button, then the device ends the session
and disconnects every opened connection. To continue working with the Graphical User Interface,
login again.

Operation

Operation
Enables/disables the HTTPS protocol for the web server.

Possible values:
 On (default setting)
The HTTPS protocol is enabled.
The access to the device management is possible through an encrypted HTTPS connection.
When there is no digital certificate present, the device generates a digital certificate before it
enables the HTTPS protocol.
 Off
The HTTPS protocol is disabled.
When the HTTP protocol is enabled, the access to the device management is possible through
an unencrypted HTTP connection.

Note: If the HTTP and HTTPS protocols are disabled, then you can enable the HTTPS protocol using
the Command Line Interface command https server to get to the Graphical User Interface.

Configuration

TCP port
Specifies the number of the TCP port on which the web server receives HTTPS requests from
clients.

Possible values:
 1..65535 (default setting: 443)
Exception: Port 2222 is reserved for internal functions.

80 RM GUI EAGLE
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > Server ]

Fingerprint

The fingerprint is an easily verified hexadecimal number sequence that uniquely identifies the
digital certificate of the HTTPS server.

After importing a new digital certificate, the device displays the current fingerprint until you restart
the server.

Fingerprint type
Specifies which fingerprint the Fingerprint field displays.

Possible values:
 sha1
The Fingerprint field displays the SHA1 fingerprint of the certificate.
 sha256
The Fingerprint field displays the SHA256 fingerprint of the certificate.

Fingerprint
Character sequence of the digital certificate used by the server.

When you change the settings in the Fingerprint type field, click afterwards the button and then
the button to update the display.

Certificate

Note: If the device uses a certificate that is not signed by a certification authority, then the web
browser displays a message while loading the Graphical User Interface. To continue, add an
exception rule for the certificate in the web browser.

Present
Displays whether the digital certificate is present in the device.

Possible values:
 marked
The certificate is present.
 unmarked
The certificate has been removed.

Create
Generates a digital certificate in the device.

Until restarting the web server uses the previous certificate.

To get the web server to use the newly generated certificate, restart the web server. Restarting the
web server is possible only through the Command Line Interface.

Alternatively, you have the option of copying your own certificate to the device. See the Certificate
import frame.

RM GUI EAGLE 81
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > Server ]

Delete
Deletes the digital certificate.

Until restarting the web server uses the previous certificate.

Oper status
Displays whether the device currently generates or deletes a digital certificate.

It is possible that another user has triggered the action.

Possible values:
 none
The device does currently not generate or delete a certificate.
 delete
The device currently deletes a certificate.
 generate
The device currently generates a certificate.

Certificate import

URL
Specifies the path and file name of the certificate.

The device accepts certificates with the following properties:


• X.509 format
• .PEM file name extension
• Base64-coded, enclosed by
• -----BEGIN PRIVATE KEY-----
and
-----END PRIVATE KEY-----
as well as
• -----BEGIN CERTIFICATE-----
and
-----END CERTIFICATE-----
• RSA key with 2048 bit length

The device gives you the following options for copying the certificate to the device:
 Import from the PC
When the certificate is located on your PC or on a network drive, drag and drop the certificate
in the area. Alternatively click in the area to select the certificate.
You also have the option of transferring the certificate from your PC to the device through SFTP
or SCP:
 On your PC, open an SFTP or SCP client, for example WinSCP.
 Use the SFTP or SCP client to open a connection to the device.
 Transfer the certificate file to the directory /upload/https-cert in the device.
When the file transfer is complete, the device starts installing the certificate. If the installation
was successful, then the device creates an ok file in the directory /upload/https-cert and
deletes the certificate file.
 To get the web server to use this certificate, restart the web server. Restarting the web server
is possible only through the Command Line Interface.

82 RM GUI EAGLE
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > Server ]

Start
Copies the certificate specified in the URL field to the device.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 83
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > IP Access Restriction ]

3.4.2 IP Access Restriction


[ Device Security > Management Access > IP Access Restriction ]

This dialog enables you to restrict the access to the device management to specific IP address
ranges and selected IP-based applications.
 If the function is disabled, then the access to the device management is possible from any IP
address and using every application.
 If the function is enabled, then the access is restricted. You have access to the device
management only under the following conditions:
– At least one table entry is activated.
and
– You are accessing the device with a permitted application from a permitted IP address range.

Operation

Note: Before you enable the function, verify that at least one active entry in the table lets you
access. Otherwise, if you change the settings, then the connection to the device terminates. The
access to the device management is possible only using the Command Line Interface through the
serial interface.

Operation
Enables/disables the IP Access Restriction function.

Possible values:
 On
The IP Access Restriction function is enabled.
The access to the device management is restricted.
 Off (default setting)
The IP Access Restriction function is disabled.

Table

You have the option of defining up to 16 table entries and activating them separately.

Index
Displays the index number to which the table entry relates.

When you delete a table entry, this leaves a gap in the numbering. When you create a new table
entry, the device fills the first gap.

Possible values:
 1..16

Address
Specifies the IP address of the network from which you allow the access to the device
management. You specify the network range in the Netmask column.

84 RM GUI EAGLE
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > IP Access Restriction ]

Possible values:
 Valid IPv4 address (default setting: [Link])

Netmask
Specifies the range of the network specified in the Address column.

Possible values:
 Valid netmask (default setting: [Link])

HTTP
Activates/deactivates the HTTP access.

Possible values:
 marked (default setting)
Access is activated for the adjacent IP address range.
 unmarked
Access is deactivated.

HTTPS
Activates/deactivates the HTTPS access.

Possible values:
 marked (default setting)
Access is activated for the adjacent IP address range.
 unmarked
Access is deactivated.

SNMP
Activates/deactivates the SNMP access.

Possible values:
 marked (default setting)
Access is activated for the adjacent IP address range.
 unmarked
Access is deactivated.

SSH
Activates/deactivates the SSH access.

Possible values:
 marked (default setting)
Access is activated for the adjacent IP address range.
 unmarked
Access is deactivated.

Active
Activates/deactivates the table entry.

RM GUI EAGLE 85
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > IP Access Restriction ]

Possible values:
 marked (default setting)
Table entry is activated. The device restricts the access to the device management to the
adjacent IP address range and the selected IP-based applications.
 unmarked
Table entry is deactivated.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

86 RM GUI EAGLE
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > Web ]

3.4.3 Web
[ Device Security > Management Access > Web ]

In this dialog, you specify settings for the Graphical User Interface.

Configuration

Web interface session timeout [min]


Specifies the timeout in minutes. After the device has been inactive for this time it ends the session
for the user logged on.

Possible values:
 0..160 (default setting: 5)

The value 0 deactivates the function, and the user remains logged on when inactive.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 87
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > CLI ]

3.4.4 Command Line Interface


[ Device Security > Management Access > CLI ]

In this dialog, you specify settings for the Command Line Interface. You find detailed information
about the Command Line Interface in the “Command Line Interface” reference manual.

The dialog contains the following tabs:


 [Global]
 [Login banner]

[Global]

This tab lets you change the prompt in the Command Line Interface and specify the automatic
closing of sessions through the serial interface when they have been inactive.

The device has the following serial interfaces.


 V.24 interface

Configuration

Login prompt
Specifies the character string that the device displays in the Command Line Interface at the start of
every command line.

Possible values:
 Alphanumeric ASCII character string with 0..128 characters
(0x20..0x7E) including space characters
Wildcards
– %d date
– %i IP address
– %m MAC address
– %p product name
– %t time
Default setting: (EAGLE)

Changes to this setting are immediately effective in the active Command Line Interface session.

Serial interface timeout [min]


Specifies the time in minutes after which the device automatically closes the session of a logged
on user in the Command Line Interface via the serial interface when it has been inactive.

Possible values:
 0..160 (default setting: 5)
The value 0 deactivates the function, and the user remains logged on when inactive.

A change in the value takes effect the next time a user logs on to the device.

For Telnet and SSH, you specify the timeout in the Device Security > Management Access > Server
dialog.

88 RM GUI EAGLE
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > CLI ]

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

[Login banner]

In this tab, you replace the start screen of the Command Line Interface with your own text.

In the default setting, the start screen displays information about the device, such as the software
version and the device settings. With the function in this tab, you deactivate this information and
replace it with an individually specified text.

To display your own text in the Command Line Interface and in the Graphical User Interface before
the login, you use the Device Security > Pre-login Banner dialog.

Operation

Operation
Enables/disables the Login banner function.

Possible values:
 On
The Login banner function is enabled.
The device displays the text information specified in the Banner text field to the users that login
to the device using the Command Line Interface.
 Off (default setting)
The Login banner function is disabled.
The start screen displays information about the device. The text information in the Banner text
field is kept.

Banner text

Banner text
Specifies the character string that the device displays in the Command Line Interface at the start of
every session.

Possible values:
 Alphanumeric ASCII character string with 0..1024 characters
(0x20..0x7E) including space characters
 <Tab>
 <Line break>

Remaining characters
Displays how many characters are still remaining in the Banner text field for the text information.

RM GUI EAGLE 89
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > CLI ]

Possible values:
 1024..0

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

90 RM GUI EAGLE
Release 3.4 03/2020
Device Security
[ Device Security > Management Access > SNMPv1/v2 Community ]

3.4.5 SNMPv1/v2 Community


[ Device Security > Management Access > SNMPv1/v2 Community ]

In this dialog, you specify the community name for SNMPv1/v2 applications.

Applications send requests via SNMPv1/v2 with a community name in the SNMP data packet
header. Depending on the community name, the application gets read authorization or read and
write authorization for the device.

You activate the access to the device via SNMPv1/v2 in the Device Security > Management Access >
Server dialog.

Table

Community
Displays the authorization for SNMPv1/v2 applications to the device:
 Write
For requests with the community name entered, the application receives read and write
authorization for the device.
 Read
For requests with the community name entered, the application receives read authorization for
the device.

Name
Specifies the community name for the adjacent authorization.

Possible values:
 Alphanumeric ASCII character string with 0..32 characters
private (default setting for read and write authorizations)
public (default setting for read authorization)

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 91
Release 3.4 03/2020
Device Security
[ Device Security > Pre-login Banner ]

3.5 Pre-login Banner


[ Device Security > Pre-login Banner ]

This dialog lets you display a greeting or information text to users before they login to the device.

The users see this text in the login dialog of the Graphical User Interface and of the Command Line
Interface. Users logging in with SSH see the text - regardless of the client used - before or during
the login.

To display the text only in the Command Line Interface, use the settings in the Device Security >
Management Access > CLI dialog.

Operation

Operation
Enables/disables the Pre-login Banner function.

Using the Pre-login Banner function, the device displays a greeting or information text in the login
dialog of the Graphical User Interface and of the Command Line Interface.

Possible values:
 On
The Pre-login Banner function is enabled.
The device displays the text specified in the Banner text field in the login dialog.
 Off (default setting)
The Pre-login Banner function is disabled.
The device does not display a text in the login dialog. When you enter a text in the Banner text
field, this text is saved in the device.

Banner text

Banner text
Specifies information text that the device displays in the Login dialog of the Graphical User Interface
and of the Command Line Interface.

Possible values:
 Alphanumeric ASCII character string with 0..512 characters
(0x20..0x7E) including space characters
 <Tab>
 <Line break>

Remaining characters
Displays how many characters are still remaining in the Banner text field.

Possible values:
 512..0

92 RM GUI EAGLE
Release 3.4 03/2020
Device Security
[ Device Security > Pre-login Banner ]

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 93
Release 3.4 03/2020
Network Security
[ Network Security > Overview ]

4 Network Security

The menu contains the following dialogs:


 Network Security Overview
 RADIUS
 Packet Filter
 Deep Packet Inspection
 DoS

4.1 Network Security Overview


[ Network Security > Overview ]

This dialog displays the network security rules used in the device.

Parameter

Port/VLAN
Specifies whether the device displays VLAN- and/or port-based rules.

Possible values:
 All (default setting)
The device displays the VLAN- and port-based rules specified by you.
 Port: <Port Number>
The device displays port-based rules for a specific port. This selection is available, when you
specified one or more rules for this port.
 VLAN: <VLAN ID>
The device displays VLAN-based rules for a specific VLAN. This selection is available, when
you specified one or more rules for this VLAN.

Packet filter
Displays the Packet Filter rules in the overview.

You edit Packet Filter rules in the Network Security > Packet Filter dialog.

DNAT
Displays the Destination NAT rules in the overview.

You edit Destination NAT rules in the Routing > NAT > Destination NAT dialog.

Double NAT
Displays the Double NAT rules in the overview.

You edit Double NAT rules in the Routing > NAT > Double NAT dialog.

94 RM GUI EAGLE
Release 3.4 03/2020
Network Security
[ Network Security > RADIUS ]

Masquerading NAT
Displays the Masquerading NAT rules in the overview.

You edit Masquerading NAT rules in the Routing > NAT > Masquerading NAT dialog.

1:1 NAT
Displays the 1:1 NAT rules in the overview.

You edit 1:1 NAT rules in the Routing > NAT > 1:1 NAT dialog.

All
Marks the adjacent checkboxes. The device displays the related rules in the overview.

None
Unmarks the adjacent checkboxes. The device does not display any rules in the overview.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

4.2 RADIUS
[ Network Security > RADIUS ]

With its factory settings, the device authenticates users based on the local user management.
However, as the size of a network increases, it becomes more difficult to keep the login data of the
users consistent across the devices.

RADIUS (Remote Authentication Dial-In User Service) lets you authenticate and authorize the
users at a central point in the network. A RADIUS server performs the following tasks here:
 Authentication
The authentication server authenticates the users when the RADIUS client at the access point
forwards the login data of the users to the server.
 Authorization
The authentication server authorizes logged in users for selected services by assigning various
parameters for the relevant end device to the RADIUS client at the access point.

If you assign the radius policy to an application in the Device Security > Authentication List dialog,
then the device operates in the role of the RADIUS client. The device forwards the users’ login data
to the primary authentication server. The authentication server decides whether the login data is
valid and transfers the user’s authorizations to the device.

The device assigns the Service Type transferred in the response of a RADIUS server as follows to
a user role existing in the device:
• Administrative-User: administrator
• Login-User: operator
• NAS-Prompt-User: guest

RM GUI EAGLE 95
Release 3.4 03/2020
Network Security
[ Network Security > RADIUS ]

The menu contains the following dialogs:


 RADIUS Global
 RADIUS Authentication Server
 RADIUS Authentication Statistics

96 RM GUI EAGLE
Release 3.4 03/2020
Network Security
[ Network Security > RADIUS > Global ]

4.2.1 RADIUS Global


[ Network Security > RADIUS > Global ]

This dialog lets you specify basic settings for RADIUS.

RADIUS configuration

Retransmits (max.)
Specifies how many times the device retransmits an unanswered request to the authentication
server before the device sends the request to an alternative authentication server.

Possible values:
 1..15 (default setting: 4)

Timeout [s]
Specifies how many seconds the device waits for a response after a request to an authentication
server before it retransmits the request.

Possible values:
 1..30 (default setting: 5)

Accounting
Activates/deactivates the accounting.

Possible values:
 marked
Accounting is active.
The device sends the traffic data to an accounting server specified in the Network Security >
RADIUS > Accounting Server dialog.
 unmarked (default setting)
Accounting is inactive.

NAS IP address (attribute 4)


Specifies the IP address that the device transfers to the authentication server as attribute 4. Specify
the IP address of the device or another available address.

Possible values:
 Valid IPv4 address (default setting: [Link])

In many cases, there is a firewall between the device and the authentication server. In the Network
Address Translation (NAT) in the firewall changes the original IP address, and the authentication
server receives the translated IP address of the device.

The device transfers the IP address in this field unchanged across the Network Address Translation
(NAT).

RM GUI EAGLE 97
Release 3.4 03/2020
Network Security
[ Network Security > RADIUS > Global ]

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Reset
Deletes the statistics in the Network Security > RADIUS > Authentication Statistics dialog.

98 RM GUI EAGLE
Release 3.4 03/2020
Network Security
[ Network Security > RADIUS > Authentication Server ]

4.2.2 RADIUS Authentication Server


[ Network Security > RADIUS > Authentication Server ]

This dialog lets you specify up to 8 authentication servers. An authentication server authenticates
and authorizes the users when the device forwards the login data to the server.

The device sends the login data to the specified primary authentication server. When the server
does not respond, the device contacts the specified authentication server that is highest in the
table. When no response comes from this server either, the device contacts the next server in the
table.

Table

Index
Displays the index number to which the table entry relates.

Name
Displays the name of the server.

To change the value, click the relevant field.

Possible values:
 Alphanumeric ASCII character string with 1..32 characters
(default setting: Default-RADIUS-Server)

Address
Specifies the IP address of the server.

Possible values:
 Valid IPv4 address

Destination UDP port


Specifies the number of the UDP port on which the server receives requests.

Possible values:
 0..65535 (default setting: 1812)
Exception: Port 2222 is reserved for internal functions.

Secret
Displays ****** (asterisks) when you specify a password with which the device logs in to the server.
To change the password, click the relevant field.

Possible values:
 Alphanumeric ASCII character string with 1..64 characters

You get the password from the administrator of the authentication server.

RM GUI EAGLE 99
Release 3.4 03/2020
Network Security
[ Network Security > RADIUS > Authentication Server ]

Primary server
Specifies the authentication server as primary or secondary.

Possible values:
 marked
The server is specified as the primary authentication server. The device sends the login data for
authenticating the users to this authentication server.
When you activate multiple servers, the device specifies the last server activated as the primary
authentication server.
 unmarked (default setting)
The server is the secondary authentication server. When the device does not receive a
response from the primary authentication server, the device sends the login data to the
secondary authentication server.

Active
Activates/deactivates the connection to the server.

The device uses the server, if you specify in the Device Security > Authentication List dialog the value
radius in one of the rows Policy 1 to Policy 5.

Possible values:
 marked (default setting)
The connection is active. The device sends the login data for authenticating the users to this
server if the preconditions named above are fulfilled.
 unmarked
The connection is inactive. The device does not send any login data to this server.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Opens the Create window to add a new entry to the table.


 In the Index field, you specify the index number.
 In the Address field, you specify the IP address of the server.

100 RM GUI EAGLE


Release 3.4 03/2020
Network Security
[ Network Security > RADIUS > Authentication Statistics ]

4.2.3 RADIUS Authentication Statistics


[ Network Security > RADIUS > Authentication Statistics ]

This dialog displays information about the communication between the device and the
authentication server. The table displays the information for each server in a separate row.

To delete the statistic, click in the Network Security > RADIUS > Global dialog the Clear RADIUS
statistics? button.

Table

Name
Displays the name of the server.

Address
Displays the IP address of the server.

Round trip time


Displays the time interval in hundredths of a second between the last response received from the
server (Access Reply/Access Challenge) and the corresponding data packet sent (Access
Request).

Access requests
Displays the number of access data packets that the device sent to the server. This value does not
take repetitions into account.

Retransmitted access-request packets


Displays the number of access data packets that the device retransmitted to the server.

Access accepts
Displays the number of access accept data packets that the device received from the server.

Access rejects
Displays the number of access reject data packets that the device received from the server.

Access challenges
Displays the number of access challenge data packets that the device received from the server.

Malformed access responses


Displays the number of malformed access response data packets that the device received from the
server (including data packets with an invalid length).

RM GUI EAGLE 101


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter ]

Bad authenticators
Displays the number of access response data packets with an invalid authenticator that the device
received from the server.

Pending requests
Displays the number of access request data packets that the device sent to the server to which it
has not yet received a response from the server.

Timeouts
Displays how many times no response to the server was received before the specified waiting time
elapsed.

Unknown types
Displays the number data packets with an unknown data type that the device received from the
server on the authentication port.

Packets dropped
Displays the number of data packets that the device received from the server on the authentication
port and then discarded them.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

4.3 Packet Filter


[ Network Security > Packet Filter ]

In this menu, you specify the settings for the packet filters. The packet filter contains rules which
the device applies successively to the data stream on its router interfaces. The packet filter
evaluates the data stream status-oriented and filters undesired data packets selectively. The
device considers the status of the connection, thus also determining data packets that belong to a
specific connection (Stateful Packet Inspection).

If a data packet complies with the criteria of one or more rules, then the device applies the action
specified in the first rule that applies to the data stream. The device ignores the rules following.

If no rule applies, then the packet filter applies the standard rule. In the default setting, the standard
rule has the value accept. You have the option of changing the standard rule in the Network
Security > Packet Filter > Global dialog.

The device provides a multi-step approach for setting up and applying the Packet Filter rules:
 Create rule.
 Assign rule to a router interface.
Up to this step, changes have no effect on the behavior of the device and the data stream.
 Apply the rule to the data stream. To do this, in the Network Security > Packet Filter > Global dialog,
click the button and then the Commit item.

102 RM GUI EAGLE


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter ]

Comparing packet filters to ACLs:


 Packet filters process data traffic using software, resulting in slower transient times.
 Packet filters provide fine filtering.
 Packet filters process data traffic after ACL processing.
 You assign Packet filters to a router interface.

The data packets go through the filter functions of the device in the following sequence:

Operating System

Destination Address Modification Ingress Egress Source Address Modification


1:1 NAT Packet Policy Routing Packet Masquerading NAT
Destination NAT Filter Filter Double NAT
Double NAT

MAC-based ACL

IP-based ACL

DoS
Switching Chip

Network 1 Network 2

Figure 1: Processing sequence of the data packets in the device

The menu contains the following dialogs:


 Packet Filter Global
 Firewall Learning Mode
 Packet Filter Rule
 Packet Filter Assignment
 Packet Filter Overview

RM GUI EAGLE 103


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter > Global ]

4.3.1 Packet Filter Global


[ Network Security > Packet Filter > Global ]

In this dialog, you specify the global settings for the packet filter.

Configuration

Allowed rules for L3 firewalling (max.)


Displays the maximum number of allowed firewall rules for data packets.

Default policy
Specifies how the firewall processes data packets if no rule applies.

Possible values:
 accept (default setting)
The device accepts incoming data packets.
 drop
The device discards incoming data packets.
 reject
The device discards incoming data packet and sends an ICMP Admin Prohibited message to
the sender.

Validate checksum
Specifies how the firewall handles connection tracking on the basis of data packet checksum.

Possible values:
 marked (default setting)
The device does not consider the defective checksum packets for connection tracking.
 unmarked
The device considers the defective checksum packets for connection tracking.

Information

Uncommitted changes present


Displays whether the packet filter rules used in the data stream differ from the packet filter rules
saved in the device.

Possible values:
 marked
At least one of the packet filter rules saved in the device contains modified settings. By clicking
the Commit button, you apply the packet filter rules to the data stream.
 unmarked
The device applies the saved Packet Filter rules to the data stream.

104 RM GUI EAGLE


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter > Global ]

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Commit
Applies the rules saved in the device to the data stream.

In the process, the device also removes the state information from the packet filter. This includes
potential DCE RPC information of the OPC Enforcer. In the process, the device interrupts open
communication connections.

Note: While the device is activating the saved rules, the establishment of any new communication
connections is impossible.

RM GUI EAGLE 105


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter > FLM ]

4.3.2 Firewall Learning Mode


[ Network Security > Packet Filter > FLM ]

The FLM function helps you to specify which connections you allow to have access to your network.

The maximum number of rules that you can configure using the FLM function depends on the
number of rules already configured in the Packet Filter Rule dialog. The device lets you configure up
to a total of 2048 rules.

The FLM function only applies to packets that pass through the device matching the FORWARD
chain. The packets that the device receives on the INPUT chain, and those that the device creates
on the OUTPUT chain traverse the device unrestricted. During the learning phase the device
retains SSH, SNMP, and GUI access.

The FLM function requires you to configure and select at least 2 router interfaces in the device.

The maximum number of connections that the FLM function can learn is 65535.

Note: During the learning phase your network is temporarily exposed, because Firewall Learning
Mode configures rules to accept every data packet on the selected ports.

Note: If you enable the VRRP function on a router interface, then the FLM function is ineffective on
this router interface.

The dialog contains the following tabs:


 [Configuration]
 [Rules]

[Configuration]

The tab lets you enable the FLM function. The device monitors up to 4 interfaces to discover what
type of data traverses the port into you network.

Operation

Operation
Enables/disables the FLM function.

Possible values:
 On
The FLM function is enabled.
 Off (default setting)
The FLM function is disabled.

106 RM GUI EAGLE


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter > FLM ]

Information

Status
Displays the state of the running Firewall Learning Mode application.

Possible values:
 off
The function is inactive.
 stopped-data-notpresent
 stopped-data-present
The device stopped the learning mode. Check the Rule tab for learned data.
 learning
The device is learning data.
 pending
The device is busy processing learned data.

Information
Displays the status of Firewall Learning Mode application memory.

Additional information
Displays a special status message.

Learned entries
Displays the number of Layer 3 entries in the connection table.

Free memory for learning data [%]


Displays the percentage of free memory available for learning data.

Configuration

Available Interfaces
Displays the interfaces that are available for the FLM function.

Selected Interfaces
Specifies the interfaces that the FLM function is actively monitoring. The maximum number of
interfaces that the device can monitor is 4.

RM GUI EAGLE 107


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter > FLM ]

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Moves the entries highlighted in the Available Interfaces field to the Selected Interfaces field. For the
FLM function, you can only select active router interfaces.

Moves the entries highlighted in the Selected Interfaces field to the Available Interfaces field.

Start
Starts the learning phase. The device filters the data packets on the active interfaces.

Stop
Stops the learning phase.

Continue
Continues the learning phase from a previous session, without clearing the memory.

Clear
Clears the memory. Learned data can be cleared only when the FLM function is stopped.

[Rules]

This tab displays the type of data that is traversing the selected ports. This lets you create rules to
manage the data stream traversing the device. Using the data displayed in the Learned entries frame
you can accept or reject data as required.

The tab is active after the device forwards 1 data packet and the FLM function is disabled again.

Learned entries

Source address
Displays the source address of the packets.

Destination address
Displays the destination address of the packet.

Destination port
Displays the destination port of the packet.

108 RM GUI EAGLE


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter > FLM ]

Ingress interface
Displays the interface that received the packet.

Egress interface
Displays the interface that sent the packet.

Protocol
Displays the IP protocol, based on RFC 791, for protocol filtering.

First Occurence
Displays the first time that the device has determined the packet.

Connections by Rule Set


Displays the number of connections that match the rules set in the table below.

Connections by Selection
Displays the number of connections that match the selections in the table below.

Packetfilter Rules

Rule index
Displays the sequential number of the Packet Filter rule. The device automatically assigns this
number.

Source address
Specifies the source address of the data packets to which the device applies the Packet Filter rule.

Possible values:
 any (default setting)
The device applies the Packet Filter rule to data packets with any source address.
 Valid IPv4 address
The device applies the rule to data packets with the specified source address.
 Valid IPv4 address and netmask in CIDR notation
The device applies the rule to data packets with the specified source address in the specified
subnet.
 An exclamation mark (!) preceding the IP address reverses the expression into its opposite. The
device applies the rule to data packets which do not contain the source address specified here.

Destination address
Specifies the destination address of the data packets to which the device applies the Packet Filter
rule.

RM GUI EAGLE 109


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter > FLM ]

Possible values:
 any (default setting)
The device applies the Packet Filter rule to data packets with any destination address.
 Valid IPv4 address
The device applies the rule to data packets with the specified destination address.
 Valid IPv4 address and netmask in CIDR notation
The device applies the rule to data packets with the specified destination address in the
specified subnet.
 An exclamation mark (!) preceding the IP address reverses the expression into its opposite. The
device applies the rule to data packets which do not contain the destination address specified
here.

Protocol
Specifies the protocol type of the data packets to which the device applies the rule.

Possible values:
 any (default setting)
The device applies the rule to every data packet without considering the protocol.
 icmp
Internet Control Message Protocol (RFC 792)
 igmp
Internet Group Management Protocol
 ipip
IP in IP tunneling (RFC 2003)
 tcp
Transmission Control Protocol (RFC 793)
 udp
User Datagram Protocol (RFC 768)
 esp
IPsec Encapsulated Security Payload (RFC 2406)
 ah
IPsec Authentication Header (RFC 2402)
 icmpv6
Internet Control Message Protocol for IPv6

Destination port
Specifies the destination port of the data packets to which the device applies the Packet Filter rule.

Possible values:
 any (default setting)
The device applies the Packet Filter rule to every data packet without considering the destination
port.
 1..65535
The device applies the Packet Filter rule only to data packets containing the specified destination
port.
The field lets you specify the following options:
– You specify a port with a single numerical value, for example 21.
– You specify multiple individual ports with numerical values separated by commas, for
example 21,80,110.

110 RM GUI EAGLE


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter > FLM ]

– You specify a port range with numerical values connected by dashes, for example 2000-
3000.
– You can also combine ports and port ranges, for example 21,2000-3000,65535.
The field lets you specify up to 15 numerical values. When you enter 21,2000-3000,65535,
for example, you use 4 of 15 numerical values.

Action
Specifies how the device handles received data packets when the device applies the rule.

Possible values:
 accept (default setting)
The device accepts the data packets according to the ingress rules. Afterwards, the device
applies the egress rules before sending the data packets.
 drop
The device discards the data packet without informing the sender.
 reject
The device discards the data packet and informs the sender.
 enforce-modbus
The device applies the rule specified in the DPI profile index column to the data packets.
 enforce-opc
The device applies the rule specified in the DPI profile index column to the data packets.

Description
Specifies a name or description for the rule.

Possible values:
 Alphanumeric ASCII character string with 0..64 characters

Ingress interface
Displays whether the device applies the Packet Filter rule to data packets received or sent on an
interface.

Possible values:
 ingress
The device applies the Packet Filter rule to data packets received on the router interface.
 egress
The device applies the Packet Filter rule to data packets sent on the router interface.

Active
Activates/deactivates the rule.

Possible values:
 marked (default setting)
The rule is active.
 unmarked
The rule is inactive.

RM GUI EAGLE 111


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter > FLM ]

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Create
Creates a new rule when the Learned entries frame displays at least an entry. The newly created rule
is then displayed in the Packetfilter Rules frame.

Edit
Lets you edit the rule highlighted in the Packetfilter Rules frame.

Delete
Deletes the rule highlighted in the Packetfilter Rules frame.

112 RM GUI EAGLE


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter > Rule ]

4.3.3 Packet Filter Rule


[ Network Security > Packet Filter > Rule ]

This dialog lets you configure rules for the packet filter. You assign the rules specified here to the
desired ports in the Network Security > Packet Filter > Assignment dialog.

Table

Rule index
Displays the sequential number of the Packet Filter rule. The device automatically assigns this
number.

Description
Specifies a name or description for the rule.

Possible values:
 Alphanumeric ASCII character string with 0..64 characters

Source address
Specifies the source address of the data packets to which the device applies the Packet Filter rule.

Possible values:
 any (default setting)
The device applies the Packet Filter rule to data packets with any source address.
 Valid IPv4 address
The device applies the rule to data packets with the specified source address.
 Valid IPv4 address and netmask in CIDR notation
The device applies the rule to data packets with the specified source address in the specified
subnet.
 An exclamation mark (!) preceding the IP address reverses the expression into its opposite. The
device applies the rule to data packets which do not contain the source address specified here.

Destination address
Specifies the destination address of the data packets to which the device applies the Packet Filter
rule.

Possible values:
 any (default setting)
The device applies the Packet Filter rule to data packets with any destination address.
 Valid IPv4 address
The device applies the rule to data packets with the specified destination address.
 Valid IPv4 address and netmask in CIDR notation
The device applies the rule to data packets with the specified destination address in the
specified subnet.
 An exclamation mark (!) preceding the IP address reverses the expression into its opposite. The
device applies the rule to data packets which do not contain the destination address specified
here.

RM GUI EAGLE 113


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter > Rule ]

Protocol
Specifies the protocol type of the data packets to which the device applies the rule.

Possible values:
 any (default setting)
The device applies the rule to every data packet without considering the protocol.
 icmp
Internet Control Message Protocol (RFC 792)
 igmp
Internet Group Management Protocol
 ipip
IP in IP tunneling (RFC 2003)
 tcp
Transmission Control Protocol (RFC 793)
 udp
User Datagram Protocol (RFC 768)
 esp
IPsec Encapsulated Security Payload (RFC 2406)
 ah
IPsec Authentication Header (RFC 2402)
 icmpv6
Internet Control Message Protocol for IPv6

Source port
Specifies the source port of the data packets to which the device applies the Packet Filter rule.

Possible values:
 any (default setting)
The device applies the Packet Filter rule to every data packet without considering the source port.
 1..65535
The device applies the Packet Filter rule only to data packets containing the specified source port.
The field lets you specify the following options:
– You specify a port with a single numerical value, for example 21.
– You specify multiple individual ports with numerical values separated by commas, for
example 21,80,110.
– You specify a port range with numerical values connected by dashes, for example 2000-
3000.
– You can also combine ports and port ranges, for example 21,2000-3000,65535.
The field lets you specify up to 15 numerical values. When you enter 21,2000-3000,65535,
for example, you use 4 of 15 numerical values.

Destination port
Specifies the destination port of the data packets to which the device applies the Packet Filter rule.

114 RM GUI EAGLE


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter > Rule ]

Possible values:
 any (default setting)
The device applies the Packet Filter rule to every data packet without considering the destination
port.
 1..65535
The device applies the Packet Filter rule only to data packets containing the specified destination
port.
The field lets you specify the following options:
– You specify a port with a single numerical value, for example 21.
– You specify multiple individual ports with numerical values separated by commas, for
example 21,80,110.
– You specify a port range with numerical values connected by dashes, for example 2000-
3000.
– You can also combine ports and port ranges, for example 21,2000-3000,65535.
The field lets you specify up to 15 numerical values. When you enter 21,2000-3000,65535,
for example, you use 4 of 15 numerical values.

Parameters
Specifies additional parameters for this rule.

Enter parameters in the form <param>=<val>. If you enter multiple parameters, then separate them
using a comma. If you enter multiple values, then separate them using a vertical bar.

Some parameters are valid when you use a specific protocol. Exception: the value mac is valid
independently of the protocol. You also have the option of entering a combination of valid rules and
protocol-specific rules.

Possible values:
 none (default setting)
You have not specified any additional parameters for this rule.
 mac=de:ad:de:ad:be:ef
This rule applies to packets with the source MAC address de:ad:de:ad:be:ef.
 type=<0..255>
This rule applies to packets with a specific ICMP type. Enter exactly one value (for the meaning
of these values see RFC 792).
 code=<0..255>
This rule applies to packets with a specific ICMP code. Enter exactly one value (for the meaning
of these values see RFC 792).
 frags=<true|false>
When true, this rule applies to fragmented packets for which you set specific rules.
 flags=<syn|ack|fin>
This rule applies to packets for which you set specific flags.
 flags=syn
This rule applies to packets for which you set the syn flag.
 flags=syn|ack|fin
This rule applies to packets for which you set the syn, ack, or fin flag.
 mac=de:ad:de:ad:be:ef,state=new|rel,flags=syn
This rule applies to packets that come from the de:ad:de:ad:be:ef MAC address, are in a new
or relative connection, and for which you set the syn flag.

Action
Specifies how the device processes received data packets when it applies the rule.

RM GUI EAGLE 115


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter > Rule ]

Possible values:
 accept (default setting)
The device accepts the data packets according to the ingress rules. Afterwards, the device
applies the egress rules before transmitting the data packets.
 drop
The device discards the data packet without informing the sender.
 reject
The device discards the data packet and informs the sender.
 enforce-modbus
The device applies the rule specified in the DPI profile index column to the data packets.
The value is only available in the device variant MB or 01. Refer to the Software level
characteristic value in the product code.
 enforce-opc
The value is only available in the device variant OP or 01. Refer to the Software level
characteristic value in the product code.

To apply the changes to the data stream, click the button, then the button and then the
Commit item in the Network Security > Packet Filter > Global dialog or in the Network Security > Packet
Filter > Assignment dialog.

Log
Activates/deactivates the logging in the log file.

Possible values:
 marked
Logging is activated.
When the device applies the Packet Filter rule to a data packet, the device places an entry in the
log file. See the Diagnostics > Report > System Log dialog.
 unmarked (default setting)
Logging is deactivated.

Trap
Activates/deactivates the sending of SNMP traps when the Packet Filter rule is applied to data
packets.

Possible values:
 marked
If the device applies the Packet Filter rule to a data packet, then the device sends an SNMP trap.
 unmarked (default setting)
The sending of SNMP traps is deactivated.

The prerequisite for sending SNMP traps is that you enable the function in the Diagnostics > Status
Configuration > Alarms (Traps) dialog and specify at least 1 trap destination.

DPI profile index


Displays which Modbus Enforcer or OPC Enforcer rule the device applies to the data packets.

The column is only available in the device variant MB, OP or 01. Refer to the Software level
characteristic value in the product code.

The prerequisite for changing the value is that you specify the value enforce-modbus or enforce-
opc in the Action column and click the button.

116 RM GUI EAGLE


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter > Rule ]

Possible values:
 0 (default setting)
The device does not apply any rule to the data packets.
 1..32
When you click the field, a drop-down list opens. Select a value from the drop-down list.
– If the enforce-modbus value is specified in the Action column, see the Index and Description
fields of the rules specified in the Network Security > DPI > Modbus Enforcer dialog.
– If the enforce-opc value is specified in the Action column, see the Index and Description fields
of the rules specified in the Network Security > DPI > OPC Enforcer dialog.

To apply changes to the data stream, click the button.

Active
Activates/deactivates the rule.

Possible values:
 marked (default setting)
The rule is active.
 unmarked
The rule is inactive.

To apply the changes to the data stream, click the button, then the button and then the
Commit item in the Network Security > Packet Filter > Global dialog or in the Network Security > Packet
Filter > Assignment dialog.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 117


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter > Assignment ]

4.3.4 Packet Filter Assignment


[ Network Security > Packet Filter > Assignment ]

This dialog lets you assign one or more packet filter rules to router interfaces of the device.

You set up router interfaces in the Routing > Interfaces > Configuration dialog.

Information

Assignments
Displays how many rules are active for the ports.

Uncommitted changes present


Displays whether the packet filter rules used in the data stream differ from the packet filter rules
saved in the device.

Possible values:
 marked
At least one of the packet filter rules saved in the device contains modified settings. By clicking
the Commit button, you apply the packet filter rules to the data stream.
 unmarked
The device applies the saved Packet Filter rules to the data stream.

Table

Description
Displays the name or description of the rule. You specify the description in the Network Security >
Packet Filter > Rule dialog.

Rule index
Displays the sequential number of the Packet Filter rule. You specify the index by clicking on the
Create entry button.

Interface
Displays the interface on which the device uses the rule. You specify the interface by clicking on
the Create entry button. The device displays ports on which you enable the Routing function.

Direction
Displays whether the device applies the Packet Filter rule to data packets received or sent.

118 RM GUI EAGLE


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter > Assignment ]

Possible values:
 ingress
The device applies the Packet Filter rule to data packets received on the router interface.
 egress
The device applies the Packet Filter rule to data packets sent on the router interface.

Priority
Specifies the priority of the Packet Filter rule.

Using the priority, you specify the sequence in which the device applies the rules to the data stream.
The device applies rules in ascending order starting with priority 0.

Possible values:
 0..4294967295

Active
Activates/deactivates the rule.

Possible values:
 marked (default setting)
The rule is active.
 unmarked
The rule is inactive.

To apply the changes to the data stream, click the button, then the button and then the
Commit item.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Opens the Create dialog to assign a rule to a router interface.


 In the Interface field, you specify the router interface to which the device applies the rule.
 In the Direction field, you specify the data packets to which the device applies the rule.
 In the Rule index field, you specify rule which you assign to the router interface.

Commit
Applies the rules saved in the device to the data stream.

In the process, the device also removes the state information from the packet filter. This includes
potential DCE RPC information of the OPC Enforcer. In the process, the device interrupts open
communication connections.

Note: While the device is activating the saved rules, the establishment of any new communication
connections is impossible.

RM GUI EAGLE 119


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter > Overview ]

4.3.5 Packet Filter Overview


[ Network Security > Packet Filter > Overview ]

This dialog gives you an overview of the specified packet filter rules.

Table

Description
Displays the name or description of the rule. You specify the description in the Network Security >
Packet Filter > Rule dialog.

Rule index
Displays the sequential number of the Packet Filter rule.

Interface
Displays the interface on which the device uses the rule.

Direction
Displays whether the device applies the Packet Filter rule to data packets received or sent.

Possible values:
 ingress
The device applies the Packet Filter rule to data packets received on the router interface.
 egress
The device applies the Packet Filter rule to data packets sent on the router interface.

Priority
Displays the priority of the Packet Filter rule.

The device applies rules to the data stream in ascending order starting with priority 1.

Source address
Displays the source address of the data packets to which the device applies the rule.

Possible values:
 any
The device applies the Packet Filter rule to data packets with any source address.
 Valid IPv4 address
The device applies the Packet Filter rule only to data packets containing the source address
specified here.
 Valid IPv4 address and netmask in CIDR notation
The device applies the Packet Filter rule only to data packets containing a source address in the
subnet specified here.
 An exclamation mark (!) preceding the IP address reverses the expression into its opposite. The
device applies the rule to data packets which do not contain the source address specified here.

120 RM GUI EAGLE


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter > Overview ]

Source port
Displays the source port of the data packets to which the device applies the rule.

Possible values:
 any
The device applies the Packet Filter rule to every data packet without considering the source port.
 1..65535
The device applies the Packet Filter rule only to data packets containing the specified source port.

Destination address
Specifies the destination address of the data packets to which the device applies the Packet Filter
rule.

Possible values:
 any (default setting)
The device applies the Packet Filter rule to data packets with any destination address.
 Valid IPv4 address
The device applies the rule to data packets with the specified destination address.
 Valid IPv4 address and netmask in CIDR notation
The device applies the rule to data packets with the specified destination address in the
specified subnet.
 An exclamation mark (!) preceding the IP address reverses the expression into its opposite. The
device applies the rule to data packets which do not contain the destination address specified
here.

Destination port
Displays the destination port of the data packets to which the device applies the Packet Filter rule.

Possible values:
 any
The device applies the Packet Filter rule to every data packet without considering the destination
port.
 1..65535
The device applies the Packet Filter rule only to data packets containing the specified destination
port.

Protocol
Displays the IP protocol to which the Packet Filter rule is restricted. The device applies the Packet
Filter rule only to packets of the specified IP protocol.

Possible values:
 icmp
Internet Control Message Protocol (RFC 792)
 igmp
Internet Group Management Protocol
 ipip
IP in IP tunneling (RFC 1853)
 tcp
Transmission Control Protocol (RFC 793)
 udp
User Datagram Protocol (RFC 768)

RM GUI EAGLE 121


Release 3.4 03/2020
Network Security
[ Network Security > Packet Filter > Overview ]

 esp
IPsec Encapsulated Security Payload (RFC 2406)
 ah
IPsec Authentication Header (RFC 2402)
 icmpv6
Internet Control Message Protocol for IPv6
 any
The device applies the Packet Filter rule to every data packet without considering the IP protocol.

Parameters
Displays additional parameters for this rule.

Possible values:
 none (default setting)
You have not specified any additional parameters for this rule.
 mac=de:ad:de:ad:be:ef
This rule applies to packets with the source MAC address de:ad:de:ad:be:ef.
 type=<0..255>
This rule applies to packets with a specific ICMP type. Enter exactly one value (for the meaning
of these values see RFC 792).
 code=<0..255>
This rule applies to packets with a specific ICMP code. Enter exactly one value (for the meaning
of these values see RFC 792).
 frags=<true|false>
When true, this rule applies to fragmented packets for which you set specific rules.
 flags=<syn|ack|fin>
This rule applies to packets for which you set specific flags.
 flags=syn
This rule applies to packets for which you set the syn flag.
 flags=syn|ack|fin
This rule applies to packets for which you set the syn, ack, or fin flag.
 mac=de:ad:de:ad:be:ef,state=new|rel,flags=syn
This rule applies to packets that come from the de:ad:de:ad:be:ef MAC address, are in a new
or relative connection, and for which you set the syn flag.

Action
Displays how the device processes received data packets.

Possible values:
 accept
The device accepts the data packets.
 drop
The device drops the data packets.
 reject
The device rejects the data packets.

Log
Displays whether the device places an entry in the log file when the device applies the rule to a data
packet.

122 RM GUI EAGLE


Release 3.4 03/2020
Network Security
[ Network Security > DPI ]

Possible values:
 marked
When the device applies the Packet Filter rule to a data packet, the device places an entry in the
log file. See the Diagnostics > Report > System Log dialog.
 unmarked
Logging is disabled.

Trap
Displays whether the device sends an SNMP trap when the device applies the rule to a data packet.

Possible values:
 marked
The device sends an SNMP trap.
 unmarked
The device does not send an SNMP trap.

The prerequisite for sending SNMP traps is that you enable the function in the Diagnostics > Status
Configuration > Alarms (Traps) dialog and specify at least 1 trap destination.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

4.4 Deep Packet Inspection


[ Network Security > DPI ]

The DPI function lets you monitor and filter data packets. The function supports you in protecting
your network from undesirable content, such as spam or viruses.

The DPI function inspects data packets for undesirable characteristics and protocol violations. The
protocol inspects the header and the payload of the data packets.

This dialog lets you specify the settings for the DPI function. The device blocks data packets that
violate the specified rules. If a violation occurs, then the device terminates the data connection on
request.

The menu contains the following dialogs:


 Deep Packet Inspection - Modbus Enforcer
 Deep Packet Inspection - OPC Enforcer

RM GUI EAGLE 123


Release 3.4 03/2020
Network Security
[ Network Security > DPI > Modbus Enforcer ]

4.4.1 Deep Packet Inspection - Modbus Enforcer


[ Network Security > DPI > Modbus Enforcer ]

This dialog lets you specify the Modbus Enforcer settings and define Modbus TCP-specific rules. The
rules specify Modbus TCP function codes and register or coil addresses. The function code in the
Modbus TCP protocol specifies the purpose of the data transfer. The device blocks data packets that
violate the specified rules. If an error is detected, then the device terminates the Modbus TCP or TCP
connection on request. The predefined Modbus TCP function code lists and the function code
generator support you when defining the Modbus TCP function codes.

Operation

Uncommitted changes present


Displays whether the Modbus Enforcer rules applied to the data stream differ from the rules saved in
the device.

Possible values:
 marked
At least one of the Modbus Enforcer rules saved in the device contains modified settings.
When you click the button and then the Commit item, the device applies the specified Modbus
Enforcer rules and refreshes the display in the Function code column.
 unmarked
The device applies the saved Modbus Enforcer rules to the data stream.

Table

Index
Displays the number of the rule to which the table entry relates.

Description
Specifies the name for the entry.

Possible values:
 Alphanumeric ASCII character string with 0..64 characters
(default setting: modbus)
The device differentiates between upper and lower case.

Function type
Specifies the function type for the Modbus Enforcer rule.

124 RM GUI EAGLE


Release 3.4 03/2020
Network Security
[ Network Security > DPI > Modbus Enforcer ]

Possible values:
 readOnly (default setting)
The device enters only function codes from read functions of the Modbus TCP protocol in the
Function code column: 1,2,3,4,7,11,12,17,20,24.
 readWrite
The device enters only function codes from read/write functions of the Modbus TCP protocol in
the Function code column: 1,2,3,4,5,6,7,11,12,15,16,17,20,21,22,23,24.
 programming
The device enters only function codes from programming functions of the Modbus TCP protocol
in the Function code column: 1,2,3,4,5,6,7,11,12,15,16,17,20,21,22,23,24,40,42,90,
125,126.
 all
The device enters every function code of the Modbus TCP protocol in the Function code column:
1,2,..,255:
 advanced
Lets you enter or delete manual values in the Function code column.

Note: If you have specified advanced for the value, then for your own security the device does not
allow any subsequent changes to be made to the value. The device helps prevent a change to
readOnly, readWrite or programming. This helps avoid overwriting the manually specified values
in the Function code column.

To specify an entry with the readOnly, readWrite or programming function type, you create a new
entry using the Create button with the desired value in the Function type column.

To apply the changes, click the button and then the Commit changes item. The device enters the
specified function code list in the Function code column.

Function code
Displays the function code list for the Modbus Enforcer rule.

When the value advanced is specified in the Function type column, you can edit the values.

When the profile is active, the device applies the Modbus Enforcer rules to the data stream. The
device permits data packets with the function codes specified in the function code list. Data packets
containing different function codes are rejected by the device. You activate the profile in the Profile
active column.

The device lets you specify multiple function codes (a function code list) and for specific function
codes additional values (address ranges). The device gives you the following options to specify the
function code list:
 Specify the value readOnly, readWrite or programming in the Function type column. The device
enters the related function codes of the Modbus TCP protocol in the Function code column.
 Click the Edit button to open the Edit dialog.
When a value other than advanced is specified in the Function type column, the Modbus Enforcer
function changes the value to advanced. The prerequisite is that the function type of the entry
is advanced.
Otherwise, the device displays a message. Confirm that you agree with changing the function
type to the value advanced.
 Specify the value advanced in the Function type column. Enter one or more values in the Function
code column.

RM GUI EAGLE 125


Release 3.4 03/2020
Network Security
[ Network Security > DPI > Modbus Enforcer ]

Possible values:
 <1,2,..,255>|<0..65535>|<0..65535>
The device permits data packets with the following properties:
Function codes <1,2,..,255>, read address range <0..65535> and write address range
<0..65535>.
– You separate multiple function codes with a comma.
Example: 1,2,3
The device permits data packets with the following function codes: 1 (Read Coils), 2
(Read Discrete Inputs and 3 (Read Holding Registers).
– You separate additional values (address ranges) with vertical lines.
Example: 23|128-255|512-1023
The device permits data packets with the following properties:
Function code 23 (Read/Write Multiple Registers, read address range 128..255, write
address range 512..1023

 1,2,3,4,7,11,12,17,20,24
(default setting for Function code = readOnly)
 1,2,3,4,5,6,7,11,12,15,16,17,20,21,22,23,24
(default setting for Function code = readWrite)
 1,2,3,4,5,6,7,11,12,15,16,17,20,21,22,23,24,40,42,90,125, 126 (default setting for
Function code = programming)
 1,2,..,255 (default setting for Function code = all)

You can find the meaning of the Function code numbers in section“Meaning of the Function code
values” on page 130.

Unit identifier
Specifies the Modbus TCP identification unit for the Modbus Enforcer rule.

Possible values:
 none (default setting)
The device permits data packets without an identification unit.
 0..255
The device permits data packets with the specified identification unit.
The device lets you specify multiple values separated by commas.

Sanity check
Activates/deactivates the plausibility check for data packets.

Possible values:
 marked (default setting)
The plausibility check is activated.
The device checks the plausibility of data packets in regards to format and specification.
 unmarked
The plausibility verification is deactivated.

Exception
Activates/deactivates the sending of an Exception response in case of a protocol violation or if the
plausibility check leads to errors.

126 RM GUI EAGLE


Release 3.4 03/2020
Network Security
[ Network Security > DPI > Modbus Enforcer ]

Possible values:
 marked
The sending of an Exception response is active.
If the device identifies a protocol violation or a plausibility check error, then the device sends an
Exception response to the end points and terminates the Modbus TCP connection.
 unmarked (default setting)
The sending of an Exception response is inactive. The Modbus TCP connection remains
established.

Reset
Activates/deactivates the resetting of the TCP connection in case of a protocol violation or if the
plausibility check leads to errors.

Possible values:
 marked (default setting)
The resetting of the TCP connection is active.
If the device identifies a protocol violation or a plausibility check error, then the device terminates
the TCP connection.
 unmarked
The resetting of the TCP connection is inactive. The TCP connection remains established.

Profile active
Activates/deactivates the rules.

Possible values:
 marked (default setting)
The rule is active.
The device applies the Modbus Enforcer rules specified in this table entry to the data packets.
 unmarked
The rule is inactive.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Opens the Create window to add a new entry to the table.


 In the Index field, you specify the number of the rule.
Possible values:
– 1..32
When you click the Ok button, the device creates the new table entry and assigns the number
specified in the Index field to the entry.

Removes the highlighted rule from the table. To save the changes in the non-volatile memory (NVM),
proceed as follows:
 Open the Basic Settings > Load/Save dialog.
 In the table, highlight the desired configuration profile.

RM GUI EAGLE 127


Release 3.4 03/2020
Network Security
[ Network Security > DPI > Modbus Enforcer ]

 When in the Selected column the checkbox is unmarked, click the button and then the Select
item.
 Click the Save button.

If you mark the Profile active checkbox for the rule, then the device stops you from removing the rule.

Copy
Opens the Create dialog to copy an existing table entry.

The prerequisite is that the table entry for the rule to be copied is marked.
 In the Index field, you specify the number of the rule.
Possible values:
– 1..32
The device creates the new table entry and assigns the number specified in the Index field to
the entry.

Edit
Opens the Edit window for specifying the function code list.

The prerequisite is that a table entry is marked.

When a value other than advanced is specified in the Function type column, the Modbus Enforcer
function changes the value to advanced.

Commit changes
The device applies the specified rules to the data stream.

If you changed the value in the Function type field, then the device applies the change to the Function
code list and refreshes the display in the Function code column.

[Edit]

Function type
Specifies the function type for the Modbus Enforcer rule.

Possible values:
 readOnly (default setting)
The device enters only function codes from read functions of the Modbus TCP protocol in the
Function code column: 1,2,3,4,7,11,12,17,20,24.
 readWrite
The device enters only function codes from read/write functions of the Modbus TCP protocol in
the Function code column: 1,2,3,4,5,6,7,11,12,15,16,17,20,21,22,23,24.
 programming
The device enters only function codes from programming functions of the Modbus TCP protocol
in the Function code column: 1,2,3,4,5,6,7,11,12,15,16,17,20,21,22,23,24,40,42,90,
125,126.

128 RM GUI EAGLE


Release 3.4 03/2020
Network Security
[ Network Security > DPI > Modbus Enforcer ]

 all
The device enters every function code of the Modbus TCP protocol in the Function code column:
1,2,..,255:
 advanced
Lets you enter or delete values manually in the Function code column.
– To add or delete a Function code, use the buttons.
– The device lets you select and deselect arbitrary addresses from the respective (left or right)
Function code columns.
– To assign the Function code list to the rule, click the Ok button.

Function code
Displays the number (#) and the meaning of the available function codes for the Modbus Enforcer
rule.

Possible values:
 <1,2,..,255>
You can find the meaning of the Function code numbers in section “Meaning of the Function code
values” on page 130.

Range
Specifies the register or coil address range for the function codes 1,2,3,4,5,6,7,8,11,12,
13,14,15,16,17,20,21,22,23,24,40,42,43,48,66,67,90,100,125.

Possible values:
 <0..65535>
For Function code = 23, you specify the address range for read and write as follows:
<0..65535>|<0..65535>
You can find the meaning of the Function code numbers in section “Meaning of the Function code
values” on page 130.

Buttons

Buttons Meaning
>> Moves all entries to the right column.
> Moves the highlighted entries to the right column.
< Moves the highlighted entries to the left column.
<< Moves all entries to the left column.
Ok Closes the Edit window and transfers the changes to the volatile memory
(ram) of the device.
Cancel Closes the Edit window without saving the changes.

RM GUI EAGLE 129


Release 3.4 03/2020
Network Security
[ Network Security > DPI > Modbus Enforcer ]

Meaning of the Function code values

# Meaning Address Address


range range
1 Read Coils <0..65535> -
2 Read Discrete Inputs <0..65535> -
3 Read Holding Registers <0..65535> -
4 Read Input Registers <0..65535> -
5 Write Single Coil <0..65535> -
6 Write Single Register <0..65535> -
7 Read Exception Status - -
8 Diagnostic - -
11 Get Comm Event Counter - -
12 Get Comm Event Log - -
13 Program (584/984) - -
14 Poll (584/984) - -
15 Write Multiple Coils <0..65535> -
16 Write Multiple Registers <0..65535> -
17 Report Slave ID - -
20 Read File Record - -
21 Write File Record - -
22 Mask Write Register <0..65535> -
23 Read/Write Multiple Registers <0..65535> <0..65535>
24 Read FIFO Queue <0..65535> -
40 Program (Concept) - -
42 Concept Symbol Table - -
43 Encapsulated Interface Transport - -
48 Advantech Co. Ltd. - Management Functions - -
66 Scan Data Inc. - Expanded Read Holding Registers - -
67 Scan Data Inc. - Expanded Write Holding Registers - -
90 Unity Programming/OFS - -
100 Scattered Register Read - -
125 Schneider Electric - Firmware - -

130 RM GUI EAGLE


Release 3.4 03/2020
Network Security
[ Network Security > DPI > OPC Enforcer ]

4.4.2 Deep Packet Inspection - OPC Enforcer


[ Network Security > DPI > OPC Enforcer ]

This dialog lets you specify the settings for the OPC Content Inspector.

OPC is an integration protocol for industrial environments. The OPC Enforcer is a function that
supports the network security. The device blocks data packets that violate the specified rules. Upon
request, the device verifies the data packets for their plausibility and their fragment characteristics.
The device verifies and observes OPC data connections and helps protect against invalid or fake
data packets. The function dynamically activates TCP ports for each data connection. When
requested by an OPC server, the device sets up the data connection only between the OPC server
and the related OPC client.

Note: When applying the rules saved in the device to the data stream and when activating/
deactivating the Routing function on a router interface, the device removes the state information
from the packet filter. This includes potential DCE RPC information of the OPC Enforcer. In the
process, the device interrupts open communication connections.

Operation

Uncommitted changes present


Displays whether the OPC Enforcer rules applied to the data stream differ from the rules saved in
the device.

Possible values:
 marked
At least one of the OPC Enforcer rules saved in the device contains modified settings.
When you click the button and then the Commit changes item, the device applies the specified
OPC Enforcer rules.
 unmarked
The device applies the saved OPC Enforcer rules to the data stream.

Table

Index
Displays the number of the rule to which the table entry relates.

Description
Specifies the name for the entry.

Possible values:
 Alphanumeric ASCII character string with 0..64 characters
(default setting: opc)
The device differentiates between upper and lower case.

RM GUI EAGLE 131


Release 3.4 03/2020
Network Security
[ Network Security > DPI > OPC Enforcer ]

Sanity check
Activates/deactivates the plausibility verification for data packets.

Possible values:
 marked (default setting)
The plausibility check is activated.
The device verifies the plausibility of the data packets as regards format and specification.
 unmarked
The plausibility verification is deactivated.

Fragment check
Activates/deactivates the fragment verification for data packets.

Possible values:
 marked (default setting)
The fragment verification is activated.
The device verifies the data packets for fragment characteristics.
 unmarked
The fragment verification is deactivated.

Timeout at connect
Specifies the period in seconds after which the device terminates the OPC data connection.

Possible values:
 1..60 (default setting: 5)
 0
The value 0 deactivates the function. The OPC data connection remains set up without a time
limit.

Profile active
Activates/deactivates the rules.

Possible values:
 marked (default setting)
The rule is active.
The device applies the rule to the data packets.
 unmarked
The rule is inactive.

132 RM GUI EAGLE


Release 3.4 03/2020
Network Security
[ Network Security > DoS ]

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Opens the Create window to add a new entry to the table.


 In the Index field, you specify the number of the rule.
Possible values:
– 1..32
When you click the Ok button, the device creates the new table entry and assigns the number
specified in the Index field to the entry.

Removes the highlighted rule from the table.

To save the changes in the non-volatile memory (NVM), proceed as follows:


 Open the Basic Settings > Load/Save dialog.
 In the table, highlight the desired configuration profile.
 When in the Selected column the checkbox is unmarked, click the Select button.
 Click the Save button.

If you mark the Profile active checkbox for the rule, then the device stops you from removing the rule.

Copy
Opens the Create dialog to copy an existing table entry.

The prerequisite is that the table entry for the rule to be copied is marked.
 In the Index field, you specify the number of the rule.
Possible values:
– 1..32
The device creates the new table entry and assigns the number specified in the Index field to
the entry.

Commit changes
The device applies the specified rules to the data stream.

4.5 DoS
[ Network Security > DoS ]

Denial of Service (DoS) is a cyber-attack that aims to bring down specific services or devices. In
this dialog you can set up several filters to help protect the device itself and other devices in the
network from DoS attacks.

The menu contains the following dialogs:


 DoS Global

RM GUI EAGLE 133


Release 3.4 03/2020
Network Security
[ Network Security > DoS > Global ]

4.5.1 DoS Global


[ Network Security > DoS > Global ]

In this dialog, you specify the DoS settings for the TCP/UDP, IP and ICMP protocols.

TCP/UDP

A scanner uses port scans to prepare network attacks. The scanner uses different techniques to
determine running devices and open ports. This frame lets you activate filters for specific scanning
techniques.

The device supports the detection of the following scan types:


 Null scans
 Xmas scans
 SYN/FIN scans
 TCP Offset attacks
 TCP SYN attacks
 L4 Port attacks
 Minimal Header scans

Null Scan filter


Activates/deactivates the Null Scan filter.

The Null Scan filter detects incoming data packets with no TCP flags set and discards them.

Possible values:
 marked
The filter is active.
 unmarked (default setting)
The filter is inactive.

Xmas filter
Activates/deactivates the Xmas filter.

The Xmas filter detects incoming data packets with the TCP flags FIN, URG and PUSH set
simultaneously and discards them.

Possible values:
 marked
The filter is active.
 unmarked (default setting)
The filter is inactive.

SYN/FIN filter
Activates/deactivates the SYN/FIN filter.

The SYN/FIN filter detects incoming data packets with the TCP flags SYN and FIN set
simultaneously and discards them.

134 RM GUI EAGLE


Release 3.4 03/2020
Network Security
[ Network Security > DoS > Global ]

Possible values:
 marked
The filter is active.
 unmarked (default setting)
The filter is inactive.

TCP Offset protection


Activates/deactivates the TCP Offset protection.

The TCP Offset protection detects incoming TCP data packets whose fragment offset field of the
IP header is equal to 1 and discards them.

The TCP Offset protection accepts UDP and ICMP packets whose fragment offset field of the IP
header is equal to 1.

Possible values:
 marked
The protection is active.
 unmarked (default setting)
The protection is inactive.

TCP SYN protection


Activates/deactivates the TCP SYN protection.

The TCP SYN protection detects incoming data packets with the TCP flag SYN set and a L4 source
port <1024 and discards them.

Possible values:
 marked
The protection is active.
 unmarked (default setting)
The protection is inactive.

L4 Port protection
Activates/deactivates the L4 Port protection.

The L4 Port protection detects incoming TCP and UDP data packets whose source port number
and destination port number are identical and discards them.

Possible values:
 marked
The protection is active.
 unmarked (default setting)
The protection is inactive.

Min. Header Size filter


Activates/deactivates the Minimal Header filter.

The Minimal Header filter compares the TCP header of incoming data packets. If the data offset
value multiplied by 4 is smaller than the minimum TCP header size, then the filter discards the data
packet.

RM GUI EAGLE 135


Release 3.4 03/2020
Network Security
[ Network Security > DoS > Global ]

Possible values:
 marked
The filter is active.
 unmarked (default setting)
The filter is inactive.

Min. TCP header size


Displays the minimum size of a valid TCP header.

IP

This frame lets you activate or deactivate the Land Attack filter. With the land attack method, the
attacking station sends data packets whose source and destination addresses are identical to
those of the recipient. When you activate this filter, the device detects data packets with identical
source and destination addresses and discards these data packets.

Land Attack filter


Activates/deactivates the Land Attack filter.

The Land Attack filter detects incoming IP data packets whose source and destination IP address
are identical and discards them.

Possible values:
 marked
The filter is active.
 unmarked (default setting)
The filter is inactive.

ICMP

This dialog provides you with filter options for the following ICMP parameters:
 Fragmented data packets
 ICMP packets from a specific size upwards

Filter fragmented packets


Activates/deactivates the filter for fragmented ICMP packets.

The filter detects fragmented ICMP packets and discards them.

Possible values:
 marked
The filter is active.
 unmarked (default setting)
The filter is inactive.

Filter by packet size


Activates/deactivates the filter for incoming ICMP packets.

136 RM GUI EAGLE


Release 3.4 03/2020
Network Security
[ Network Security > DoS > Global ]

The filter detects ICMP packets whose payload size exceeds the size specified in the Allowed
payload size [byte] field and discards them.

Possible values:
 marked
The filter is active.
 unmarked (default setting)
The filter is inactive.

Allowed payload size [byte]


Specifies the maximum allowed payload size of ICMP packets in bytes.

Possible values:
 0..1472 (default setting: 512)

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 137


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Overview ]

5 Virtual Private Network

The menu contains the following dialogs:


 VPN Overview
 VPN Certificates
 VPN Connections

5.1 VPN Overview


[ Virtual Private Network > Overview ]

Virtual Private Networks (VPN) provide secure communications for remote users or branch offices,
allowing them to connect to servers within other branch offices, or even other companies using
public networks. Even though the VPN tunnel uses a public network, it has the same behavior as
a private network.

VPN tunnels provide secure communications to support the current trend of increased
telecommuting and global business operations. In such cases, remote users or branch offices are
able to connect to each other and central resources.

To provide secure communications, VPNs use IP Security (IPSec). IPSec has 2 functions for
providing confidentiality namely, data encryption and data integrity. To provide authentication and
integrity of the source with encryption, the device uses the IPSec Encapsulating Security Payload
(ESP). Only the sender and receiver know the security key.

The device also uses the Negotiated Security Association method. The first packet received
initiates a negotiation, between the sender and receiver, for which security association (SA)
parameters the devices are going to use. The devices use the Internet Key Exchange (IKE) for the
negotiation process. When negotiating the parameters, the sending and receiving devices agree
on the authentication and data-security methods. The devices also perform mutual authentication,
and then generate a shared key. The devices use the shared key to encrypt the data contained in
each packet.

The VPN LED is green if at least one VPN tunnel is active and established. The LED is a separate
LED for VPN and as such is non-configurable for this device. The VPN LED only displays the status
of the VPN tunnels.

The dialog contains tabs which display the current VPN tunnels and statuses.

The Connection errors tab displays detected errors that are helpful when troubleshooting a VPN
tunnel.

The dialog contains the following tabs:


 [Overview]
 [Diagnostics]
 [Connection errors]

138 RM GUI EAGLE


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Overview ]

Connection

Connections (max.)
Displays the maximum number of VPN tunnels supported. The device limits maximum number of
active VPN tunnels to the amount set in Max. active connections.

Max. active connections


Displays the maximum number of active VPN tunnels supported.

[Overview]

Table

VPN index
Displays the row index for unique identification of a VPN tunnel.

VPN description
Displays the user-defined name for the VPN tunnel.

VPN active
Displays whether the VPN tunnel is active/inactive.

The device limits the maximum number of configured VPN tunnels to the value displayed in
Connections (max.). The device also limits the maximum number of active VPN tunnels to the value
specified in the Max. active connections column.

Possible values:
 marked
The VPN tunnel is active.
 unmarked
The VPN tunnel is inactive.

Used IKE version


Displays the version of the IKE protocol that the VPN tunnel uses.

Possible values:
 ikev1
The device uses the IKE version 1 (ISAKMP) protocol.
 ikev2
The device uses the IKE version 2 protocol.

Startup
Displays the starting role for mediating the key exchange for VPN tunnel.

RM GUI EAGLE 139


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Overview ]

Possible values:
 initiator
If you specify the role of the device as an initiator for the VPN tunnel, then the device actively
initiates the Internet Key Exchange (IKE) and parameter negotiation.
 responder
If you specify the role of the device as a responder for the VPN tunnel, then the device waits for
the initiator to begin a key exchange (IKE) and connection parameter negotiation.

Operational status
Displays the current status of the VPN tunnel.

Possible values:
 up
The Internet Key Exchange-Security Association (IKE-SA) and every Internet Protocol Security-
Security Association (IPsec-SA) is up.
 down
The IKE-SA and IPsec-SAs are down.
 negotiation
If you specify the VPN tunnel for this device as the initiator, then the value indicates that the key
exchange and negotiation algorithm is in progress. If the VPN tunnel for this device is the
responder, then the value indicates that the VPN tunnel is waiting for the process to begin.
 constructing
The IKE-SA is up. However, the device has detected at least one unestablished IPsec-SA for
this instance.
 dormant
The device is waiting for you to complete the configuration before starting the VPN tunnel setup.
For example, the device has an unsuccessful hostname resolution.
 re-keying
The key exchange is in progress. The device displays the value after the expiration of either the
IKE or the IPSEC lifetime timer.

Connection established [s]


Displays the time, in seconds, since the device established the VPN tunnel for this device. The
device updates the value after every IKE re-authentication.

Local host
Displays the name and/or IP address of the local host that the device detected using IKE.

Possible values:
 Alphanumeric ASCII character string with 1..128 characters

Remote host
Displays the name and/or IP address of the remote host that the device detected using IKE.

Possible values:
 Alphanumeric ASCII character string with 1..128 characters

IKE proposal
Displays the algorithms that IKE uses for the key exchange.

140 RM GUI EAGLE


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Overview ]

The device displays a combination of the IKE key agreement, IKE integrity (MAC) and IKE encryption
parameters.

If you configure an IKE algorithm for the device in the VPN Connections dialog, and the remote
endpoint has a more secure algorithm configured, then it is possible that both the local and remote
devices use the remote algorithm.

The device displays the current cipher suite used for the connection.

IPsec proposal
Displays the algorithms that IPsec uses for data communication.

The device displays a combination of the IPsec key agreement, IPsec integrity (MAC) and IPsec
encryption parameters.

If you configure an IPsec algorithm for the instance in the VPN Connections dialog, and the remote
endpoint has a better, more secure algorithm configured, then it is possible that both the local and
remote devices use the better algorithm.

The device displays the current cipher suite used for the connection.

Tunnels
Displays the number of IPsec tunnels within the VPN network.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

[Diagnostics]

Table

VPN index
Displays the row index for unique identification of a VPN tunnel.

VPN description
Displays the user-defined name for the VPN tunnel.

VPN active
Displays whether the VPN tunnel is active/inactive.

The device limits the maximum number of configured VPN tunnels to the value displayed in
Connections (max.). The device also limits the maximum number of active VPN tunnels to the value
specified in the Max. active connections column.

RM GUI EAGLE 141


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Overview ]

Possible values:
 marked
The VPN tunnel is active.
 unmarked
The VPN tunnel is inactive.

Tunnel index
Displays the index value that, together with the value in the VPN index column, identifies the entry
in the connection tunnel info table.

Traffic selector index


Displays the index value that, together with the value in the VPN index column, identifies the entry
in the traffic selector table which is mapped into the IPsec tunnel.

Possible values:
 0
The traffic selector index is unknown.
 1..16

Operational status
Displays the current status of the VPN tunnel.

Possible values:
 up
The Internet Key Exchange-Security Association (IKE-SA) and every Internet Protocol Security-
Security Association (IPsec-SA) is up.
 down
The IKE-SA and IPsec-SAs are down.
 negotiation
If you specify the VPN tunnel for this instance as the initiator, then the value indicates that the
key exchange and negotiation algorithm is in progress. If the VPN tunnel for this instance is the
responder, then the value indicates that the VPN tunnel is waiting for the process to begin.
 constructing
The IKE-SA is up. However, the device has detected at least one unestablished IPsec-SA for
this instance.
 dormant
The device is waiting for you to complete the configuration before starting the VPN tunnel setup.
For example, the device has an unsuccessful hostname resolution.
 re-keying
The key exchange is in progress. The device displays the value after the expiration of either the
IKE or the IPSEC lifetime timer.

IKE re-authentication [s]


Displays the remaining time, in seconds, before the next IKE re-authentication. The value 0
indicates that re-authentication is unconfigured.

Next IKE re-keying [s]


Displays the remaining time, in seconds, before the next IKE re-key. The value 0 indicates that re-
keying is unconfigured.

142 RM GUI EAGLE


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Overview ]

IKE initiator SPI


Displays the Security Parameter Index (SPI) of the IKE initiator, depending which device you
specify as the initiator. For example, when you specify this device as the initiator, then this value is
the SPI of the local device.

IKE responder SPI


Displays the SPI of the IKE responder, depending which device you specify as the initiator. For
example, when you specify this device as the initiator, then this value is the SPI of the remote
device.

Local traffic selector


Displays the local traffic selector for this IPsec tunnel. As a result of the negotiation process
between the peers, the local traffic selector can be different from the configured traffic selector.

Remote traffic selector


Displays the remote traffic selector for this IPsec tunnel. As a result of the negotiation process
between the peers, the traffic selector can be different from the configured traffic selector.

Tunnel status
Displays the current operational status of the IPsec tunnel.

Possible values:
 unknown
The IPsec proposal is in progress. No traffic selectors or security parameters have been
negotiated for this IPsec-SA.
 created
The key exchange and the negotiation algorithm is finished for this IPsec-SA, but the tunnel is
inactive.
 routed
The encryption policies for the data stream are established, but the negotiation process has not
started.
 installing
The peer authentication is established, but the IPsec proposal for this tunnel is still in progress.
 installed
The IPsec-SA is installed.
 updating
The device updates the security associations.
 re-keying
The key exchange is in progress for this IPsec-SA. The device displays the value after the
expiration of the IPsec lifetime timer.
 re-keyed
The key exchange for this IPsec-SA is finished and the device creates a new tunnel. The tunnel
is active after the expiration of the previous IPsec proposal.
 re-trying
The key exchange for this IPsec-SA failed. The device will automatically try to initiate a new key
exchange.

RM GUI EAGLE 143


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Overview ]

 deleting
The device replaces the IPsec tunnel during re-keying. The device keeps the tunnel open till the
processing of delayed packets, which is default set to 5 seconds. After the IPsec lifetime timer
has expired, the device deletes the tunnel.
 destroying
The IPsec lifetime timer has expired. The device deletes the tunnel.

IPsec input SPI


Displays IPSec Security Parameter Index (SPI) that the device applies to the data it receives from
the VPN tunnel. The SPI lets the device select the SA under which it processes a received packet.

IPsec output SPI


Displays IPSec Security Parameter Index (SPI) that the device applies to the data it transmits to
the VPN tunnel.

Next IPsec re-keying [s]


Displays the remaining time, in seconds, before the next re-keying starts for this IPsec tunnel.

IPsec tunnel input [byte]


Displays the number of bytes received into this VPN tunnel.

IPsec-tunnel input [packets]


Displays the number of packets received into this VPN tunnel.

Last IPsec data received [s]


Displays the time, in seconds, since the VPN tunnel has received the last time data.

IPsec tunnel output [byte]


Displays the number of bytes sent into this VPN tunnel.

IPsec tunnel output [packets]


Displays the number of packets sent into this VPN tunnel.

Last IPsec data transmitted [s]


Displays the time, in seconds, since the VPN tunnel has sent the last time data.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

144 RM GUI EAGLE


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Overview ]

[Connection errors]

Table

VPN index
Displays the row index for unique identification of a VPN tunnel.

VPN description
Displays the user-defined name for the VPN tunnel.

VPN active
Displays whether the VPN tunnel is active/inactive.

The device limits the maximum number of configured VPN tunnels to the value displayed in
Connections (max.). The device also limits the maximum number of active VPN tunnels to the value
specified in the Max. active connections column.

Possible values:
 marked
The VPN tunnel is active.
 unmarked
The VPN tunnel is inactive.

Last connection error


Displays the last error notification that occurred for this VPN tunnel.

When the connection remains in the down state, this value is useful to help you isolate detected
errors. This value helps you determine if a detected error occurred in the proposal exchange or
during tunnel establishment.

Possible values:
 Alphanumeric ASCII character string with 1..512 characters

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 145


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Certificates ]

5.2 VPN Certificates


[ Virtual Private Network > Certificates ]

A Certificate Authority (CA) issues certificates to authenticate the identity of devices requesting a
VPN tunnel. You configure the devices that form a VPN tunnel to trust the CA that signed the
certificate. When a trusted CA issues a certificate, the device considers it to be valid. Using a
trusted CA, lets you add, renew, and change the certificates loaded in the device without affecting
the VPN. The prerequisite is, that the actual identity information is correct.

Using certificates also lets you reduce the required maintenance work. The reason for this is
because you change certificates less often as you change pre-shared keys. The CA creates
certificates with commence and expiration date. The certificate is only valid during this time. When
a certificate expires, the device requires a new certificate.

You create a self signed certificate using the strongSwan application in conjunction with the Linux
Operating System.

Note: RC2 certificate encryption algorithms are unsupported, for example PKCS12 containers with
RC2 encryption or passphrase protection.

Table

Index
Displays the row index of the certificate entry.

Possible values:
 1..100

File name
Displays the name of the file uploaded to the device.

Possible values:
 Alphanumeric ASCII character string with 1..64 characters

Subject
Displays the subject field of certificate.

The subject field of the certificate is a combination of the following items the country (C), state (ST),
organization (O), organizational unit (OU), common name (CN), and email address of the recipient
(emailAddress).

Possible values:
 Alphanumeric ASCII character string with 0..64 characters

Issuer
Displays the issuer of the certificate.

Possible values:
 Alphanumeric ASCII character string with 0..64 characters

146 RM GUI EAGLE


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Certificates ]

Valid from
Displays the certificate commencement time and date.

Possible values:
 Date and time stamp

Valid until
Displays the certificate expiration time and date.

Possible values:
 Date and time stamp

Type
Displays the type of the container file used.

Possible values:
 ca
The value indicates that the uploaded file is a certificate authority.
 peer
The value indicates that the uploaded file is a peer certificate.
 pkcs12
The value indicates that the uploaded file is a p12 bundle.
 encrypted key
The value indicates that the uploaded file is a key file with password encryption.
 encrypted pkcs12
The value indicates that the uploaded file is a p12 bundle with password encryption.

Upload date
Displays the time and date of the last certificate upload.

Possible values:
 Date and time stamp

Private key status


Displays the status of the private key in the peer certificate. A peer certificate is unusable without a
private key.

Possible values:
 none
The peer certificate does not contain a private key.
 present
The device has located and extracted the private key from the peer certificate.
 notFound
The device has located a private key. However, the key is missing the passphrase and the
device has suspended the transfer.

Private key file


Displays the name of the private key file.

RM GUI EAGLE 147


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Certificates ]

The device lets you enter alphanumeric characters plus hyphens, underscores and dots.

Possible values:
 Alphanumeric ASCII character string with 0..64 characters

Active connections
Displays the number of active connections that are using this certificate.

The device lets you delete the certificate only when the value is 0.

Possible values:
 0..256

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Upload
Opens the Upload certificate window to add another certificate to the table.
 In the Pass Phrase (Private Key) field, you enter the passphrase used with this certificate.
Possible values:
– Alphanumeric ASCII character string with 0..128 characters
 In the File field, you enter the certificate file path.
When the certificate is located on your PC or on a network drive, click the area to select the
file that contains the certificate.

148 RM GUI EAGLE


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

5.3 VPN Connections


[ Virtual Private Network > Connections ]

This dialog lets you create, delete and edit VPN tunnels.

Note: The device uses software for des and AES-Galois/Counter Mode (GCM) encryption.

Table

VPN description
Specifies the user-defined name for the VPN tunnel.

Possible values:
 Alphanumeric ASCII character string with 1..128 characters

Traffic selector index


Displays the index value that, together with the value in the VPN index column, identifies the entry
in the traffic selector table.

Possible values:
 1..16
The device lets you specify any available value within the given range.

VPN active
VPN active

Activates/deactivates the VPN tunnel.

The device limits the maximum number of configured VPN tunnels to the value displayed in
Connections (max.). The device also limits the maximum number of active VPN tunnels to the value
displayed in Max. active connections.

Possible values:
 marked
The VPN tunnel is active.
The device does not let you change any value, including active traffic selectors.
 unmarked (default setting)
The VPN tunnel is inactive.
The device lets you change values.

Traffic selector active

Activates/deactivates the table entry.

RM GUI EAGLE 149


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

Possible values:
 marked
The table entry is active.
The device filters the data stream according to the parameters specified in the traffic selector
only when the table entry is active.
 unmarked (default setting)
The table entry is inactive.
The device lets you edit the traffic selector parameters only when the table entry is inactive.

Traffic selector description


Specifies the name of the traffic selector.

Possible values:
 Alphanumeric ASCII character string with 0..128 characters

Source address (CIDR)


Specifies the IP address and netmask of the source host. When the device forwards packets
containing this source IP address over a VPN tunnel, the device applies the settings specified in
this row. Furthermore, the device applies the associated IPsec and IKE-SA settings, to every IP
packet it forwards containing this address.

Possible values:
 Valid IPv4 address and netmask in CIDR notation
 any (default setting)
TThe device applies the settings in this row to every packet it forwards.

Source restrictions
Specifies the optional source restrictions using names or numbers entered as <protocol/port>.
The device sends only the type of data specified through the VPN tunnel.

Example:

tcp/http is equal to 6/80

udp is equal to udp/any

/53 is equal to any/53

Possible values:
 <empty> (default setting)
The device uses any/any as the restriction.
 Alphanumeric ASCII character string with 0..32 characters

Destination address (CIDR)


Specifies the IP address and netmask of the destination. When the device forwards packets
containing this destination IP address over a VPN tunnel, the device applies the settings specified
in this row. Furthermore, for every IP packet the device forwards containing this address, it applies
the associated IPsec and IKE-SA settings.

150 RM GUI EAGLE


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

Possible values:
 Valid IPv4 address and netmask in CIDR notation
 any (default setting)
The device applies the settings in this row to every packet it forwards.

Destination restrictions
Specifies the optional destination restrictions using names or numbers entered as <protocol/
port>. The device accepts only the type of data specified from the VPN tunnel.

Example:

tcp/http is equal to 6/80

udp is equal to udp/any

/53 is equal to any/53

Possible values:
 <empty> (default setting)
The device uses any/any as the restriction.
 Alphanumeric ASCII character string with 0..32 characters

Version
Specifies the version of the IKE protocol for the VPN connection.

Possible values:
 auto (default setting)
The VPN starts with protocol IKEv2 as the initiator and accepts IKEv1/v2 as the responder.
 ikev1
The VPN starts with the IKEv1 (ISAKMP) protocol.
 ikev2
The VPN starts with the IKEv2 protocol.

Startup
Specifies if the device starts this instance as a responder or initiator.

If you specify the local peer as the responder, and the remote peer sends traffic to a specific
selector, then the device attempts to establish the connection as the responder. Establishing a
connection as a responder depends upon other settings for this connection. For example, if you
specify the Remote endpoint as any, then it is not possible to initiate the connection.

Possible values:
 initiator
If you specify that the device starts as an initiator, then the device begins an IKE with the
responder.
 responder
If you specify that the device starts as a responder, then the device waits for the initiator to start
the IKE and parameter negotiation.

RM GUI EAGLE 151


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

DPD timeout [s]


Specifies the timeout, in seconds, before the local peer declares the remote peer dead, if the
remote peer is unresponsive.

Possible values:
 0..86400 (default setting: 120)
The value 0 disables this feature. The default setting is 2 minutes. The maximum setting is 24
hours.

IKE lifetime [s]


Specifies the lifetime, in seconds, of the IKE security association between two network devices to
support secure communication. The devices establish a security association after exchanging a set
of pre-defined keys.

Possible values:
 300..86400 (default setting: 28800)
The default setting is 8 hours. The maximum setting is 24 hours.

IKE exchange mode


Specifies the use of the phase 1 exchange mode for IKEv1.

The purpose of IKE phase 1 is to establish a secure authenticated communication channel. The
device uses the Diffie-Hellman key exchange algorithm to generate a shared secret key. The
device then uses the shared secret key to further encrypt IKE communications.

Possible values:
 main (default setting)
The main mode for phase 1 provides identity protection.
 aggressive
You use the aggressive mode to reduce round trips.

Authentication type
Specifies the type of authentication that the device uses.

Possible values:
 psk (default setting)
Select this value for the device to use a key that was previously created and saved on both the
remote and local devices.
 individualx509
Select this value for the device to use an X509 certificate.
Use a separate certificate for CA and local identification.
 pkcs12
Select this value for the device to use a PKCS12 container with the needed certificates, which
also includes the CA.

Pre-shared key
Specifies the pre-shared key.

The device also lets you create pre-shared secrets as hexadecimal or Base64 encoded binary
values. The device interprets a character sequence beginning with 0x as sequence with
hexadecimal digits. Similarly, the device also interprets a character sequence beginning with
multiple 0s as Base64 encoded binary data.

152 RM GUI EAGLE


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

The prerequisite for using this parameter is that you specify in the Authentication type column the
value psk.

Possible values:
 Alphanumeric ASCII character string with 0..128 characters
excluding new line and double-quote characters

IKE auth. cert. CA


Specifies the Certificate Authority certificate file names. The device uses this certificate for
signature verification of the local and remote certificates.

The prerequisite for using this parameter is that you specify in the Authentication type column the
value individualx509.

Possible values:
 Alphanumeric ASCII character string with 0..128 characters

IKE auth. cert. local


Specifies the file name of the certificate the local device uses. The device uses this certificate for
authentication of the local peer on the remote side.

If you specify in the Authentication type column the value individualx509, then the certificate binds
the identity of local peer to the specified public key, that the certification authority (CA) signed in IKE
auth. cert. CA.

If you specify in the Authentication type column the value pkcs12, then the certificate in the pkcs
bundle binds the identity of local peer to the specified public key. This is done independently of the
certificate displayed in the IKE auth. cert. CA column.

Possible values:
 Alphanumeric ASCII character string with 0..128 characters

IKE auth. cert. remote


Specifies the file name of the certificate the remote device uses. The device uses this certificate
authentication of the remote peer on the local side. This certificate binds the identity of remote peer
to the specified public key.

The value is optional, because the remote peer typically sends the certificate and the device only
checks the validity of the certificate.

The prerequisite for using this parameter is that you specify in the Authentication type column the
value individualx509.

Possible values:
 Alphanumeric ASCII character string with 0..128 characters

Encrypted private key


Specifies the private key file name. This value is only the file name of the private key. Enter the
passphrase in Encrypted key/PKCS12 passphrase.

The prerequisite for using this parameter is that you specify in the Authentication type column the
value individualx509 and you encrypt the key saved in the device with a passphrase. If you
encrypt the key saved on the device, then the key and the certificate remain unmatched.

RM GUI EAGLE 153


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

Possible values:
 Alphanumeric ASCII character string with 0..128 characters

Encrypted key/PKCS12 passphrase


Specifies the passphrase to use for the decryption of the private key in Encrypted private key or
pkcs12 certificate container.

Possible values:
 Alphanumeric ASCII character string with 0..128 characters

IKE local identifier type


Specifies the type of local peer identifier that the device uses for the IKE local ID parameter.

Possible values:
 default (default setting)
If in the Authentication type column the value psk is specified, then the device uses the IP address
specified in the Local endpoint column as the local identifier.
If in the Authentication type column the value individualx509 or pkcs12 is specified, then the
device uses the distinguished name (DN) contained in the local IKE auth. cert. local certificate.
 address
Use the local IP address or DNS name from the Local endpoint column as the IKE local ID.
 id
The device identifies the value specified in the IKE local ID column as one of the following types:
– An IPv4 address or DNS host name
– A key identifier specifying data that the device uses to pass vendor-specific information. The
device uses the information to identify which pre-shared key it uses for aggressive mode
authentication during negotiations.
– A Fully Qualified Domain Name web address, for example, [Link]
– An email address
– The ASN.1 X.500 Distinguished Name (DN) contained within the IKE auth. cert. remote
column. The local and remote devices exchange their certificates to establish the SA.

IKE local ID
Specifies the local peer identifier that the device sends to the remote device in the ID payload
during phase 1 negotiations. The devices use the ID payload to identify the initiator of the security
association (SA). The responder uses the identity to determine the correct host system policy
requirement for the security association.

The formats for this parameter depend on the type specified in the IKE local identifier type column.

Possible values:
 <empty> (default setting)
 When you specify the value id in the IKE local identifier type column, the following values are
possible:
– An IPv4 address or DNS host name
– A previously specified key identifier, specifying data that the device uses to pass vendor-
specific information.
– A Fully Qualified Domain Name web address, for example, [Link]
– An email address
– A typical X.500 distinguished name

154 RM GUI EAGLE


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

Remote identifier type


Specifies the type of remote peer identifier that the device uses for the Remote ID parameter.

Possible values:
 any (default setting)
The device accepts every received remote identifier as unverified.
 address
In the Remote ID column, use the IP address or the DNS name from the Remote endpoint column.
 id
The device identifies the value specified in the Remote ID column as one of the following types:
– An IPv4 address or DNS host name
– A key identifier specifying data that the device uses to pass vendor-specific information. The
device uses the information to identify which pre-shared key it uses for aggressive mode
authentication during negotiations.
– A Fully Qualified Domain Name web address, for example, [Link]
– An email address
– The ASN.1 X.500 Distinguished Name (DN) contained within the IKE auth. cert. remote
column. The local and remote devices exchange their certificates to establish the SA.

Remote ID
Specifies the remote peer identifier which the device compares with the value in the ID payload
during phase 1 negotiations. The device uses the ID payload to identify the initiator of the security
association. The responder uses the identity to determine the correct host system policy
requirement for the security association.

The formats for this parameter depend on the type specified in the Remote identifier type column.

Possible values:
 <empty>
 When you specify the value id in the Remote identifier type column, the following values are
possible:
– An IPv4 address or DNS host name
– A previously specified key identifier, specifying data that the device uses to pass vendor-
specific information.
– A Fully Qualified Domain Name web address, for example, [Link]
– An email address
– A typical X.500 distinguished name

IKE key agreement


Specifies which Diffie-Hellman key agreement algorithm the device uses for establishing the IKE-
SA session key establishment.

Possible values:
 any
The device accepts every algorithm when specified as the responder.
 modp1024 (default setting)
1024 bits modulus which is DH Group 2.
 modp1536
1536 bits modulus which is DH Group 5.
 modp2048
2048 bits modulus which is DH Group 14.

RM GUI EAGLE 155


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

 modp3072
3072 bits modulus which is DH Group 15.
 modp4096
4096 bits modulus which is DH Group 16.

IKE integrity (MAC)


Specifies which IKEv2 Integrity (MAC) algorithm the device uses.

In order to help keep the information on the VPN secure, the Hash-based Message Authentication
Code (HMAC) process mixes (hashes) a shared secret key with the message data. The device
mixes the results (hash value) with the secret key again, and then applies the hash function a
second time.

Possible values:
 any
When you specify the device as the responder, the device accepts every algorithm. When you
specify the device as the initiator, the device uses various pre-defined algorithms.
 hmacmd5
The device uses the Message Digest Algorithm 5 (MD5) for the hash function calculation.
 hmacsha1 (default setting)
The device uses the Secure Hash Algorithm version 1 (SHA-1) for the hash function calculation.
 hmacsha256
The device uses SHA-256, part of the version 2 family, for the hash function calculation which
the device computes with 32-bit words.
 hmacsha384
The device uses SHA-384, part of the version 2 family, for hash function calculation which the
device computes using a shorter version of SHA-512.
 hmacsha512
The device uses SHA-512, part of the version 2 family, for hash function calculation which the
device computes with 64 bit words.

IKE encryption
Specifies the encryption algorithm that the device uses for IKE.

Possible values:
 any
When you specify the device as the responder, the device accepts every algorithm. When you
specify the device as the initiator, the device uses various pre-defined algorithms.
 des
The device uses the Data Encryption Standard (DES) block cipher for encryption of message
data with a 56-bit key.
 des3
The device uses the Triple DES block cipher for encryption of message data which applies the
56-bit key, from DES, 3 times to each block.
 aes128 (default setting)
The device uses the Advanced Encryption Standard (AES) with a block size of 128 bits, and a
key length of 128 key bits.
 aes192
The device uses the Advanced Encryption Standard (AES) with a block size of 128 bits, and a
key length of 192 key bits.
 aes256
The device uses the Advanced Encryption Standard (AES) with a block size of 128 bits, and a
key length of 256 key bits.

156 RM GUI EAGLE


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

Local endpoint
Specifies the hostname or IP address of the local security gateway.

Possible values:
 any (default setting)
The device uses the IP address of the interface the device uses to forward data to the remote
endpoint.
 Valid IPv4 address and netmask
 hostname
Alphanumeric ASCII character string with 0..128 characters
If you specify a hostname, then the device delays the VPN tunnel until it receives an IP address
for the hostname.

Remote endpoint
Specifies the hostname or IP address of the remote security gateway.

Possible values:
 any (default setting)
The device accepts any IP address when establishing an IKE-SA as a VPN responder.
 Valid IPv4 address and netmask
If you specify that the device is a responder for this VPN tunnel, then the device accepts a
network in CIDR notation, during IKE-SA establishment.
 hostname
Alphanumeric ASCII character string with 0..128 characters
If you specify a hostname, then the device delays the VPN tunnel until it receives an IP address
for the hostname.

Re-authentication
Activates/deactivates peer re-authentication after an IKE-SA re-key.

If you specify in the Version column the value IKEv1, then the device constantly re-authenticates the
VPN tunnel, even when you unmark the checkbox.

Possible values:
 marked
The device creates a new IKE-SA and attempts to recreate the IPsec SAs.
 unmarked (default setting)
When using IKEv2, the device re-keys the VPN tunnel and retains the IPsec SAs.

IPsec key agreement


Specifies which Diffie-Hellman key agreement algorithm the device uses for establishing the IPsec-
SA session key establishment.

Possible values:
 any
When you specify the device as the responder, the device accepts every algorithm. When you
specify the device as the initiator, the device uses various pre-defined algorithms.
 modp1024 (default setting)
The value represents a Rivest, Shamir, and Adleman (RSA) algorithm with 1024 bits modulus
which is Diffie-Hellman Group 2.
 modp1536
The value represents an RSA with 1536 bits modulus which is Diffie-Hellman Group 5.

RM GUI EAGLE 157


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

 modp2048
The value represents an RSA with 2048 bits modulus which is Diffie-Hellman Group 14.
 modp3072
The value represents an RSA with 3072 bits modulus which is Diffie-Hellman Group 15.
 modp4096
The value represents an RSA with 4096 bits modulus which is Diffie-Hellman Group 16.
 none
The value disables Perfect Forward Secrecy (PFS). With PFS enabled, if a compromise of a
single key occurs, then the integrity remains for subsequently generated keys.

IPsec integrity (MAC)


Specifies what the device uses for the IPsec Integrity (MAC) algorithm.

In order to help keep the information on the VPN secure, the Hash-based Message Authentication
Code (HMAC) process mixes (hashes) a shared secret key with the message data. The device
mixes the results (hash value) with the secret key again, and then applies the hash function a
second time.

Possible values:
 any
When you specify the device as the responder, the device accepts every algorithm. When you
specify the device as the initiator, the device uses various pre-defined algorithms.
 hmacmd5
The device uses the Message Digest Algorithm 5 (MD5) for the hash function calculation.
 hmacsha1 (default setting)
The device uses the Secure Hash Algorithm version 1 (SHA-1) for the hash function calculation.
 hmacsha256
The device uses SHA-256, part of the version 2 family, for the hash function calculation which
the device computes with 32-bit words.
 hmacsha384
The device uses SHA-384, part of the version 2 family, for hash function calculation which the
device computes using a shorter version of SHA-512.
 hmacsha512
The device uses SHA-512, part of the version 2 family, for hash function calculation which the
device computes with 64 bit words.

IPsec encryption
Specifies the algorithm that the device uses for IPsec encryption.

Possible values:
 any
When you specify the device as the responder, the device accepts every algorithm. When you
specify the device as the initiator, the device uses various pre-defined algorithms.
 des
The device uses the Data Encryption Standard (DES) block cipher for encryption of message
data with a 56-bit key.
 des3
The device uses the Triple DES block cipher for encryption of message data which applies the
56-bit key, from DES, 3 times to each block.
 aes128 (default setting)
The device uses the Advanced Encryption Standard (AES) with a block size of 128 bits, and a
key length of 128 key bits.

158 RM GUI EAGLE


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

 aes192
The device uses the AES with a block size of 128 bits, and a key length of 192 key bits.
 aes256
The device uses the AES with a block size of 128 bits, and a key length of 256 key bits.
 aes128gcm64
The device uses the AES-Galois/Counter Mode (GCM) with a 64 bit Integrity Check Value (ICV)
and 128 key bits.
 aes128gcm96
AES-GCM with a 96 bit ICV and 128 key bits.
 aes128gcm128
AES-GCM with a 128 bit ICV and 128 key bits.
 aes192gcm64
AES-GCM with a 64 bit ICV and 192 key bits.
 aes192gcm96
AES-GCM with a 96 bit ICV and 192 key bits.
 aes192gcm128
AES-GCM with a 128 bit ICV and 192 key bits.
 aes256gcm64
AES-GCM with a 64 bit ICV and 256 key bits.
 aes256gcm96
AES-GCM with a 96 bit ICV and 256 key bits.
 aes256gcm128
AES-GCM with a 128 bit ICV and 256 key bits.

IPsec lifetime [s]


Specifies the lifetime, in seconds, of the IPsec security association between two network devices
to support secure communication. The devices establish a security association after exchanging a
set of pre-defined keys.

Possible values:
 300..28800 (default setting: 3600)
The default setting is 1 hour. The maximum setting is 8 hours.

Margin time [s]


Specifies the period in seconds, before IKE lifetime [s] and IPsec lifetime [s] expire, in which the device
attempts to negotiate a new key.

Possible values:
 1..1800 (default setting: 150)
The default setting is equal to 2.5 minutes. The maximum value is half an hour.

Log informational entries


Activates/deactivates event log entries for debugging proposes only.

Possible values:
 marked
The device receives and processes the informational messages for this VPN tunnel, and enters
the message in the event log.
 unmarked (default setting)
The device receives and processes the informational messages for this connection, without an
event log entry.

RM GUI EAGLE 159


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

Log unhandled messages


Activates/deactivates message handling for messages unknown to strongSwan for debugging
proposes only.

Possible values:
 marked
The device enters the non-strongSwan messages received for this connection, in the event log.
 unmarked (default setting)
The device ignores the non-strongSwan messages received for this connection.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Create entry
Opens the Create entry window to add a entry for VPN description and traffic selector index.
 In the VPN description field, you specify the user-defined description.
Possible values:
– Alphanumeric ASCII character string with 0..128 characters
 In the Traffic selector index field, you specify the index of the VPN tunnel traffic selector.
Possible values:
– 1..16

[VPN configuration (Wizard)]

The device provides you with an assistant for setting up a VPN tunnel. The assistant takes you
through the configuration of a VPN tunnel step-by-step and selects the next step for you, depending
on the settings you have already made.

The device also lets you create or change a VPN tunnel directly in the dialog.

After closing the Wizard window, click the button to save your settings.

[VPN configuration (Wizard) – Create or select entry]

Create or select entry – Table

VPN index
Displays the row index for unique identification of a VPN tunnel.

VPN description
Displays the user-defined name for the VPN tunnel.

160 RM GUI EAGLE


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

Remote host
Displays the name and/or IP address of the remote host that the device detected using IKE.

Possible values:
 Alphanumeric ASCII character string with 1..128 characters

Operational status
Displays the current status of the VPN tunnel.

Possible values:
 up
The Internet Key Exchange-Security Association (IKE-SA) and every Internet Protocol Security-
Security Association (IPsec-SA) is up.
 down
The IKE-SA and IPsec-SAs are down.
 negotiation
If you specify the VPN tunnel for this device as the initiator, then the value indicates that the key
exchange and negotiation algorithm is in progress. If the VPN tunnel for this device is the
responder, then the value indicates that the VPN tunnel is waiting for the process to begin.
 constructing
The IKE-SA is up. However, the device has detected at least one unestablished IPsec-SA for
this instance.
 dormant
The device is waiting for you to complete the configuration before starting the VPN tunnel setup.
For example, the device has an unsuccessful hostname resolution.
 re-keying
The key exchange is in progress. The device displays the value after the expiration of either the
IKE or the IPSEC lifetime timer.

Startup
Displays the starting role for mediating the key exchange for VPN tunnel.

Possible values:
 initiator
If you specify the role of the device as the initiator for the VPN tunnel, then the device actively
initiates the Internet Key Exchange (IKE) and parameter negotiation.
 responder
If you specify the role of the device as a responder for the VPN tunnel, then the device waits for
the initiator to begin a key exchange (IKE) and connection parameter negotiation.

Authentication type
Displays the type of authentication that the device uses.

RM GUI EAGLE 161


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

Possible values:
 psk (default setting)
Select this value for the device to use a key that was previously created and saved on both the
remote and local devices.
 individualx509
Select this value for the device to use an X509 certificate.
Use a separate certificate for CA and local identification.
 pkcs12
Select this value for the device to use a PKCS12 container with the needed certificates, which
also includes the CA.

VPN active
Displays whether the VPN tunnel is active/inactive.

The device limits the maximum number of configured VPN tunnels to the value displayed in
Connections (max.). The device also limits the maximum number of active VPN tunnels to the value
specified in the Max. active connections column.

Possible values:
 marked
The VPN tunnel is active.
 unmarked
The VPN tunnel is inactive.

Create or select entry – Text fields

VPN index
Specifies the index of the VPN tunnel.

Possible values:
 0..256
The value 0 indicates that only assigned entries are available.

VPN description
Specifies the user-defined description for the VPN tunnel.

Possible values:
 Alphanumeric ASCII character string with 1..128 characters

162 RM GUI EAGLE


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

[VPN configuration (Wizard) – Authentication]

Authentication type

Authentication type
Specifies the type of authentication that the device uses.

Possible values:
 psk (default setting)
Select this value for the device to use a key that was previously created and saved on both the
remote and local devices.
 individualx509
Select this value for the device to use an X509 certificate.
Use a separate certificate for CA and local identification.
 pkcs12
Select this value for the device to use a PKCS12 container with the needed certificates, which
also includes the CA.

Pre-shared key (PSK)

Pre-shared key (PSK)


Specifies the pre-shared key.

The device also lets you create pre-shared secrets as hexadecimal or Base64 encoded binary
values. The device interprets a character sequence beginning with 0x as sequence with
hexadecimal digits. Similarly, the device also interprets a character sequence beginning with
multiple 0s as Base64 encoded binary data.

The prerequisite for using this parameter is that you specify in the Authentication type column the
value psk.

Possible values:
 Alphanumeric ASCII character string with 0..128 characters
excluding new line and double-quote characters

Confirm
Specify the same key you specified in the Pre-shared key field for confirmation. If the key is different
from the value you entered in the Pre-shared key field, then the Next button remains gray.

The prerequisite for using this parameter is that you select the value Pre-shared key (PSK) from the
Authentication type drop-down list and mark the Change checkbox.

Possible values:
 Alphanumeric ASCII character string with 1..128 characters

RM GUI EAGLE 163


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

Change
Activates/deactivates the Pre-shared key and Confirm fields, allowing you to enter and confirm the
pre-shared key.

Possible values:
 marked (default setting for new entries)
Activates the Pre-shared key and Confirm fields which lets you enter and confirm a new key.
 unmarked (default setting for pre-existing entries)
The Pre-shared key and Confirm fields are inactive.

Certificate

Local Certificate
Displays the name of the local peer identified in the certificate.

The device uses this certificate for authentication of the local peer on the remote side. The
certificate binds the identity of the local peer to its public key, which the CA signed. You select the
file using the Choose... button.

The prerequisite for activating the Choose... button is that you select the value individualx509 or
pkcs12 from the Authentication type drop-down list.

Possible values:
 Alphanumeric ASCII character string with 1..128 characters

Encrypted Private Key


Specifies the private key file name.

This value is only the file name of the private key. The key requires that you specify the passphrase
in the Pass Phrase (Private Key) field.

The prerequisite for using this parameter is that you select the value individualx509 from the
Authentication type drop-down list and you encrypt the key saved in the device with a passphrase. If
you encrypt the key saved on the device, then the key and the certificate remain unmatched. You
select the file using the Choose... button.

The prerequisite for activating the Choose... button is that you select the value individualx509 from
the Authentication type drop-down list.

Possible values:
 Alphanumeric ASCII character string with 0..128 characters

Certificate Authority
Displays the name of the certificate authority (CA) which issued the certificate.

The device uses this certificate for signature verification of the local and remote certificates. You
select the file using the Choose... button.

The prerequisite for activating the Choose... button is that you select the value individualx509 from
the Authentication type drop-down list.

164 RM GUI EAGLE


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

Possible values:
 Alphanumeric ASCII character string with 1..128 characters

Pass Phrase (Private Key)


Specifies the passphrase that the device uses for decryption of the private key from Encrypted
Private Key.

The prerequisite for using this parameter is that you select the value individualx509 or pkcs12 from
the Authentication type drop-down list and mark the Change checkbox.

Possible values:
 Alphanumeric ASCII character string with 0..128 characters

Confirm
Enter the same key you entered in the Pass Phrase (Private Key) field for confirmation.

The prerequisite for using this parameter is that you select the value individualx509 or pkcs12 from
the Authentication type drop-down list and mark the Change checkbox.

Possible values:
 Alphanumeric ASCII character string with 1..128 characters

Change
Activates/deactivates the Pass Phrase (Private Key) and Confirm fields.

The prerequisite for using this parameter is that you select the value individualx509 or pkcs12 from
the Authentication type drop-down list.

Possible values:
 marked (default setting)
Activates the Pass Phrase (Private Key) and Confirm fields allowing you to enter and confirm a
passphrase.
 unmarked
The Pass Phrase (Private Key) and Confirm fields are inactive.

[VPN configuration (Wizard) – Endpoint and traffic selectors]

Endpoints

Remote endpoint
Specifies the hostname or IP address of the remote IPsec VPN tunnel endpoint.

RM GUI EAGLE 165


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

Possible values:
 any (default setting)
The device accepts any IP address when establishing an IKE-SA as a VPN responder.
 Valid IPv4 address and netmask
If you specify that the device is a responder for this VPN tunnel, then the device accepts a
network in CIDR notation, during IKE-SA establishment.
 hostname
Alphanumeric ASCII character string with 0..128 characters
When you enter a hostname, the device lets you use CR LF or CR NUL in the character string.
If you specify a hostname, then the device delays the creation of the VPN tunnel until it receives
an IP address for the hostname.

Local endpoint
Specifies the hostname or IP address of the local IPsec VPN tunnel endpoint.

Possible values:
 any (default setting)
The device uses the IP address of the interface the device uses to forward data to the remote
endpoint.
 Valid IPv4 address and netmask
 hostname
Alphanumeric ASCII character string with 0..128 characters
When you enter a hostname, the device lets you use CR LF or CR NUL in the character string. If
you specify a hostname, then the device delays the creation of the VPN tunnel until it receives
an IP address for the hostname.

Add traffic selector

Traffic selector index


Displays the traffic selector index of the VPN tunnel. The device lets you specify any available
number within the given range.

Possible values:
 1..16

Traffic selector description


Displays the user-defined description for the traffic selector.

Possible values:
 Alphanumeric ASCII character string with 1..128 characters

Source address (CIDR)


Displays the IP address and netmask of the source host. When the device forwards packets
containing this source IP address over a VPN tunnel, the device applies the settings specified in
this row. Furthermore, the device applies the associated IPsec and IKE-SA settings, to every IP
packet it forwards containing this address.

166 RM GUI EAGLE


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

Possible values:
 Valid IPv4 address and netmask in CIDR notation
 any (default setting)
TThe device applies the settings in this row to every packet it forwards.

Source restrictions
Displays the optional source restrictions using names or numbers entered as <protocol/port>.
The device sends only the type of data specified through the VPN tunnel.

Example:

tcp/http is equal to 6/80

udp is equal to udp/any

/53 is equal to any/53

Possible values:
 <empty> (default setting)
The device uses any/any as the restriction.
 Alphanumeric ASCII character string with 0..32 characters

Destination address (CIDR)


Displays the IP address and netmask of the destination. When the device forwards packets
containing this destination IP address over a VPN tunnel, the device applies the settings specified
in this row. Furthermore, for every IP packet the device forwards containing this address, it applies
the associated IPsec and IKE-SA settings.

Possible values:
 Valid IPv4 address and netmask in CIDR notation
 any (default setting)
TThe device applies the settings in this row to every packet it forwards.

Destination restrictions
Displays the optional destination restrictions using names or numbers entered as <protocol/
port>. The device accepts only the type of data specified from the VPN tunnel.

Example:

tcp/http is equal to 6/80

udp is equal to udp/any

/53 is equal to any/53

Possible values:
 <empty> (default setting)
The device uses any/any as the restriction.
 Alphanumeric ASCII character string with 0..32 characters

RM GUI EAGLE 167


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Add
Opens the Add traffic selector dialog to add another selector to the VPN connection.
 In the Traffic selector index field, you specify the traffic selector index.
Possible values:
– 1..16
 In the Traffic selector description field, you specify the user-defined description.
Possible values:
– Alphanumeric ASCII character string with 0..128 characters
 In the Source address (CIDR) field, you specify the IP address of the source host.
Possible values:
– Valid IPv4 address and netmask in CIDR notation
 In the Source restrictions field, you specify the optional source restrictions.
Possible values:
– Alphanumeric ASCII character string with 0..32 characters
 In the Destination address (CIDR) field, you specify the IP address of the destination.
Possible values:
– Valid IPv4 address and netmask in CIDR notation
 In the Destination restrictions field, you specify the optional destination restrictions.
Possible values:
– Alphanumeric ASCII character string with 0..32 characters

Remove
Removes the highlighted entry from the table.

[VPN configuration (Wizard) – Advanced configuration]

General

Margin time [s]


Specifies the time, in seconds, remaining before the connection or the keying channel expires.
Afterwards, the device attempts to negotiate a replacement.

Possible values:
 1..1800 (default setting: 540)
The default setting is equal to 9 minutes. The maximum value is half an hour.

IKE/Key-exchange

Version
Specifies the version of the IKE protocol for the VPN connection.

168 RM GUI EAGLE


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

Possible values:
 auto (default setting)
The VPN starts with protocol IKEv2 as the initiator and accepts IKEv1/v2 as the responder.
 ikev1
The VPN starts with the IKEv1 (ISAKMP) protocol.
 ikev2
The VPN starts with the IKEv2 protocol.

Startup
Specifies if the device starts this instance as a responder or initiator.

If you specify the local peer as the responder, and the remote peer sends traffic to a specific
selector, then the device attempts to establish the connection as the responder. Establishing a
connection as a responder depends upon other settings for this connection. For example, if you
specify the Remote endpoint as any, then it is not possible to initiate the connection.

Possible values:
 initiator
If you specify that the device starts as an initiator, then the device begins an IKE with the
responder.
 responder
If you specify that the device starts as a responder, then the device waits for the initiator to start
the IKE and parameter negotiation.

IKE local identifier type


Specifies the type of local peer identifier that the device uses for the IKE local ID parameter.

Possible values:
 default (default setting)
If in the Authentication type column the value psk is specified, then the device uses the IP address
specified in the Local endpoint field as the local identifier.
If in the Authentication type column the value individualx509 or pkcs12 is specified, then the
device uses the distinguished name (DN) contained in the local IKE auth. cert. local certificate.
 address
In the IKE local ID column, use the IP address or the DNS name from the Local endpoint field.
 id
The device identifies the value specified in the IKE local ID column as one of the following types:
– An IPv4 address or DNS host name
– A key identifier specifying data that the device uses to pass vendor-specific information. The
device uses the information to identify which pre-shared key it uses for aggressive mode
authentication during negotiations.
– A Fully Qualified Domain Name web address, for example, [Link]
– An email address
– The ASN.1 X.500 Distinguished Name (DN) contained within the IKE auth. cert. remote
column. The local and remote devices exchange their certificates to establish the SA.

IKE local ID
Specifies the local peer identifier that the device sends to the remote device in the ID payload
during phase 1 negotiations. The devices use the ID payload to identify the initiator of the security
association (SA). The responder uses the identity to determine the correct host system policy
requirement for the security association.

The formats for this parameter depend on the type specified in the IKE local identifier type column.

RM GUI EAGLE 169


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

Possible values:
 <empty> (default setting)
 When you specify the value id in the IKE local identifier type column, the following values are
possible:
– An IPv4 address or DNS host name
– A previously specified key identifier, specifying data that the device uses to pass vendor-
specific information.
– A Fully Qualified Domain Name web address, for example, [Link]
– An email address
– A typical X.500 distinguished name

Remote identifier type


Specifies the type of remote peer identifier that the device uses for the Remote ID parameter.

Possible values:
 any (default setting)
The device accepts every received remote identifier as unverified.
 address
In the Remote ID column, use the IP address or the DNS name from the Remote endpoint field.
 id
The device identifies the value specified in the Remote ID column as one of the following types:
– An IPv4 address or DNS host name
– A key identifier specifying data that the device uses to pass vendor-specific information. The
device uses the information to identify which pre-shared key it uses for aggressive mode
authentication during negotiations.
– A Fully Qualified Domain Name web address, for example, [Link]
– An email address
– The ASN.1 X.500 Distinguished Name (DN) contained within the IKE auth. cert. remote
column. The local and remote devices exchange their certificates to establish the SA.

Remote ID
Specifies the remote peer identifier which the device compares with the value in the ID payload
during phase 1 negotiations. The device uses the ID payload to identify the initiator of the security
association. The responder uses the identity to determine the correct host system policy
requirement for the security association.

The formats for this parameter depend on the type specified in the Remote identifier type column.

Possible values:
 <empty>
 When you specify the value id in the Remote identifier type column, the following values are
possible:
– An IPv4 address or DNS host name
– A previously specified key identifier, specifying data that the device uses to pass vendor-
specific information.
– A Fully Qualified Domain Name web address, for example, [Link]
– An email address
– A typical X.500 distinguished name

IKE exchange mode


Specifies the use of the phase 1 exchange mode for IKEv1.

170 RM GUI EAGLE


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

The purpose of IKE phase 1 is to establish a secure authenticated communication channel. The
device uses the Diffie-Hellman key exchange algorithm to generate a shared secret key. The
device then uses the shared secret key to further encrypt IKE communications.

Possible values:
 main (default setting)
The main mode for phase 1 provides identity protection.
 aggressive
You use the aggressive mode to reduce round trips.

IKE key agreement


Specifies which Diffie-Hellman key agreement algorithm the device uses for establishing the IKE-
SA session key establishment.

Possible values:
 any
With this value selected the device accepts every algorithm when specified as the responder.
 modp1024 (default setting)
The value represents an RSA with 1024 bits modulus which is DH Group 2.
 modp1536
The value represents an RSA with 1536 bits modulus which is DH Group 5.
 modp2048
The value represents an RSA with 2048 bits modulus which is DH Group 14.
 modp3072
The value represents an RSA with 3072 bits modulus which is DH Group 15.
 modp4096
The value represents an RSA with 4096 bits modulus which is DH Group 16.

IKE integrity (MAC)


Specifies which IKE Integrity (MAC) algorithm the device uses.

In order to help keep the information on the VPN secure, the Hash-based Message Authentication
Code (HMAC) process mixes (hashes) a shared secret key with the message data. The device
mixes the results (hash value) with the secret key again, and then applies the hash function a
second time.

Possible values:
 any
When you specify the device as the responder, the device accepts every algorithm. When you
specify the device as the initiator, the device uses various pre-defined algorithms.
 hmacmd5
The device uses the Message Digest Algorithm 5 (MD5) for the hash function calculation.
 hmacsha1 (default setting)
The device uses the Secure Hash Algorithm version 1 (SHA-1) for the hash function calculation.
 hmacsha256
The device uses SHA-256, part of the version 2 family, for the hash function calculation which
the device computes with 32-bit words.
 hmacsha384
The device uses SHA-384, part of the version 2 family, for hash function calculation which the
device computes using a shorter version of SHA-512.
 hmacsha512
The device uses SHA-512, part of the version 2 family, for hash function calculation which the
device computes with 64 bit words.

RM GUI EAGLE 171


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

IKE encryption
Specifies the IKE encryption algorithm that the device uses.

Possible values:
 any
When you specify the device as the responder, the device accepts every algorithm. When you
specify the device as the initiator, the device uses various pre-defined algorithms.
 des
The device uses the Data Encryption Standard (DES) block cipher for encryption of message
data with a 56-bit key.
 des3
The device uses the Triple DES block cipher for encryption of message data which applies the
56-bit key, from DES, 3 times to each block.
 aes128 (default setting)
The device uses the Advanced Encryption Standard (AES) with a block size of 128 bits, and a
key length of 128 key bits.
 aes192
The device uses the Advanced Encryption Standard (AES) with a block size of 128 bits, and a
key length of 192 key bits.
 aes192
The device uses the Advanced Encryption Standard (AES) with a block size of 128 bits, and a
key length of 256 key bits.

DPD timeout [s]


Specifies the timeout, in seconds, before the local peer declares the remote peer dead, if the
remote peer is unresponsive.

Possible values:
 0..86400 (default setting: 120)
The value 0 disables this feature. The default setting is 2 minutes. The maximum setting is 24
hours.

IKE lifetime [s]


Specifies the lifetime, in seconds, of the IKE security association between two network devices to
support secure communication. The device establishes a security association after exchanging a
set of pre-defined keys.

Possible values:
 300..86400 (default setting: 28800)
The default setting is 8 hours. The maximum setting is 24 hours.

IPSec/Data-exchange

IPsec key agreement


Specifies which Diffie-Hellman key agreement algorithm the device uses for establishing the IPsec-
SA session key establishment.

172 RM GUI EAGLE


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

Possible values:
 any
When you specify the device as the responder, the device accepts every algorithm. When you
specify the device as the initiator, the device uses various pre-defined algorithms.
 modp1024 (default setting)
The value represents an Rivest, Shamir, and Adleman (RSA) algorithm with 1024 bits modulus.
This value is Diffie-Hellman Group 2.
 modp1536
The value represents an RSA with 1536 bits modulus which is Diffie-Hellman Group 5.
 modp2048
The value represents an RSA with 2048 bits modulus which is Diffie-Hellman Group 14.
 modp3072
The value represents an RSA with 3072 bits modulus which is Diffie-Hellman Group 15.
 modp4096
The value represents an RSA with 4096 bits modulus which is Diffie-Hellman Group 16.
 none
The value disables Perfect Forward Secrecy (PFS). With PFS enabled, if a compromise of a
single key occurs, then the integrity remains for subsequently generated keys.

IPsec lifetime [s]


Specifies the lifetime, in seconds, of the IPsec security association between two network devices
to support secure communication. The device establishes a security association after exchanging
a set of pre-defined keys.

Possible values:
 300..28800 (default setting: 3600)
The default setting is 1 hour. The maximum setting is 8 hours.

IPsec integrity (MAC)


Specifies which IPsec Integrity (MAC) algorithm the device uses for the instance.

In order to help keep the information on the VPN secure, the Hash-based Message Authentication
Code (HMAC) process mixes (hashes) a shared secret key with the message data. The device
mixes the results (hash value) with the secret key again, and then applies the hash function a
second time.

Possible values:
 any
When you specify the device as the responder, the device accepts every algorithm. When you
specify the device as the initiator, the device uses various pre-defined algorithms.
 hmacmd5
The device uses the Message Digest Algorithm 5 (MD5) for the hash function calculation.
 hmacsha1 (default setting)
The device uses the Secure Hash Algorithm version 1 (SHA-1) for the hash function calculation.
 hmacsha256
The device uses SHA-256, part of the version 2 family, for the hash function calculation which
the device computes with 32-bit words.
 hmacsha384
The device uses SHA-384, part of the version 2 family, for hash function calculation which the
device computes using a shorter version of SHA-512.
 hmacsha512
The device uses SHA-512, part of the version 2 family, for hash function calculation which the
device computes with 64 bit words.

RM GUI EAGLE 173


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

IPsec encryption
Specifies the IPsec encryption algorithm that the device uses.

Possible values:
 any
When you specify the device as the responder, the device accepts every algorithm. When you
specify the device as the initiator, the device uses various pre-defined algorithms.
 des
The device uses the Data Encryption Standard (DES) block cipher for encryption of message
data with a 56-bit key.
 des3
The device uses the Triple DES block cipher for encryption of message data which applies the
56-bit key, from DES, 3 times to each block.
 aes128 (default setting)
The device uses the Advanced Encryption Standard (AES) with a block size of 128 bits, and a
key length of 128 key bits.
 aes192
The device uses the AES with a block size of 128 bits, and a key length of 192 key bits.
 aes256
The device uses the AES with a block size of 128 bits, and a key length of 256 key bits.
 aes128gcm64
The device uses the AES-Galois/Counter Mode (GCM) with a 64 bit Integrity Check Value (ICV)
and 128 key bits.
 aes128gcm96
AES-GCM with a 96 bit ICV and 128 key bits.
 aes128gcm128
AES-GCM with a 128 bit ICV and 128 key bits.
 aes192gcm64
AES-GCM with a 64 bit ICV and 192 key bits.
 aes192gcm96
AES-GCM with a 96 bit ICV and 192 key bits.
 aes192gcm128
AES-GCM with a 128 bit ICV and 192 key bits.
 aes256gcm64
AES-GCM with a 64 bit ICV and 256 key bits.
 aes256gcm96
AES-GCM with a 96 bit ICV and 256 key bits.
 aes256gcm128
AES-GCM with a 128 bit ICV and 256 key bits.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Back
Displays the previous page. Changes are lost.

Next
Saves the changes and displays the next page.

174 RM GUI EAGLE


Release 3.4 03/2020
Virtual Private Network
[ Virtual Private Network > Connections ]

Finish
Saves the changes and closes the wizard.

Cancel
Closes the Wizard. Changes are lost.

RM GUI EAGLE 175


Release 3.4 03/2020
Switching
[ Switching > Global ]

6 Switching

The menu contains the following dialogs:


 Switching Global
 Rate Limiter
 Filter for MAC Addresses

6.1 Switching Global


[ Switching > Global ]

This dialog lets you specify the following settings:


 Change the Aging time of the address table
 Enable the flow control in the device

If a large number of data packets are received in the priority queue of a port at the same time, then
this can cause the port memory to overflow. This happens, for example, when the device receives
data on a Gigabit port and forwards it to a port with a lower bandwidth. The device discards surplus
data packets.

The flow control mechanism described in standard IEEE 802.3 helps ensure that no data packets
are lost due to a port memory overflowing. Shortly before a port memory is completely full, the
device signals to the connected devices that it is not accepting any more data packets from them.
 In full-duplex mode, the device sends a pause data packet.
 In half-duplex mode, the device simulates a collision.

Then the connected devices do not send any more data packets for as long as the signaling takes.
On uplink ports, this can possibly cause undesired sending breaks in the higher-level network
segment (“wandering backpressure”).

Configuration

MAC address
Displays the MAC address of the device.

Aging time [s]


Specifies the aging time in seconds.

Possible values:
 10..500000 (default setting: 30)

The device monitors the age of the learned unicast MAC addresses. The device deletes address
entries that exceed a particular age (aging time) from its address table.

You find the address table in the Switching > Filter for MAC Addresses dialog.

In connection with the router redundancy, specify a time ≥ 30 s.

176 RM GUI EAGLE


Release 3.4 03/2020
Switching
[ Switching > Global ]

Flow control
Activates/deactivates the flow control in the device.

Possible values:
 marked
The flow control is active in the device.
Additionally activate the flow control on the required ports. See the Basic Settings > Port dialog,
Configuration tab, checkbox in the Flow control column.
 unmarked (default setting)
The flow control is inactive in the device.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 177


Release 3.4 03/2020
Switching
[ Switching > Rate Limiter ]

6.2 Rate Limiter


[ Switching > Rate Limiter ]

The device lets you limit the traffic on the ports in order to help provide stable operation even with
a large traffic volume. If the traffic on a port exceeds the traffic value entered, then the device
discards the excess traffic on this port.

The rate limiter function operates only on Layer 2, and is used to limit the effects of storms of data
packets that flood the device (typically Broadcasts).

The rate limiter function ignores protocol information on higher levels, such as IP or TCP.

The dialog contains the following tabs:


 [Ingress]

[Ingress]

In this tab, you enable the Rate Limiter function. The threshold value specifies the maximum amount
of traffic the port receives. If the traffic on this port exceeds the threshold value, then the device
discards the excess traffic on this port.

Table

Port
Displays the port number.

Threshold unit
Specifies the unit for the threshold value:

Possible values:
 percent (default setting)
Specifies the threshold value as a percentage of the data rate of the port.
 pps
Specifies the threshold value in data packets per second.

Broadcast mode
Activates/deactivates the rate limiter function for received broadcast data packets.

Possible values:
 marked
 unmarked (default setting)

If the threshold value is exceeded, then the device discards the excess broadcast data packets on
this port.

Activates/deactivates the rate limiter function for received multicast data packets.

178 RM GUI EAGLE


Release 3.4 03/2020
Switching
[ Switching > Rate Limiter ]

Possible values:
 marked
 unmarked (default setting)

If the threshold value is exceeded, then the device discards the excess multicast data packets on
this port.

Activates/deactivates the rate limiter function for received unicast data packets with an unknown
destination address.

Possible values:
 marked
 unmarked (default setting)

If the threshold value is exceeded, then the device discards the excess unicast data packets on this
port.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 179


Release 3.4 03/2020
Switching
[ Switching > Filter for MAC Addresses ]

6.3 Filter for MAC Addresses


[ Switching > Filter for MAC Addresses ]

This dialog lets you display and edit address filters for the address table. Address filters specify the
way the data packets are forwarded in the device based on the destination MAC address.

Each row in the table represents one filter. The device automatically sets up the filters. The device
lets you set up additional filters manually.

The device transmits the data packets as follows:


 When the table contains an entry for the destination address of a data packet, the device
transmits the data packet from the receiving port to the port specified in the table entry.
 When there is no table entry for the destination address, the device transmits the data packet
from the receiving port to every other port.

Table

To delete the learned MAC addresses from the address table, click in the Basic Settings > Restart
dialog the Reset MAC address table button.

Address
Displays the destination MAC address to which the table entry applies.

VLAN ID
Displays the ID of the VLAN to which the table entry applies.

The device learns the MAC addresses for every VLAN separately (independent VLAN learning).

Status
Displays how the device has set up the address filter.

Possible values:
 learned
Address filter set up automatically by the device based on received data packets.
 permanent
Address filter set up manually. The address filter stays set up permanently.
 mgmt
MAC address of the device. The address filter is protected against changes.

<Port number>
Displays how the corresponding port transmits data packets which it directs to the adjacent
destination address.

Possible values:
 –
The port does not transmit any data packets to the destination address.
 learned
The port transmits data packets to the destination address. The device created the filter
automatically based on received data packets.

180 RM GUI EAGLE


Release 3.4 03/2020
Switching
[ Switching > Filter for MAC Addresses ]

 unicast static
The port transmits data packets to the destination address. A user created the filter.
 multicast static
The port transmits data packets to the destination address. A user created the filter.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Opens the Create window to add a new entry to the table.


 In the Address field, you specify the destination MAC address.
 In the VLAN ID field, you specify the ID of the VLAN.
 In the Port field, you specify the port.
– Select one port if the destination MAC address is a unicast address.
– Select one or more ports if the destination MAC address is a multicast address.
– Select no port to create a discard filter. The device discards data packets with the destination
MAC address specified in the table entry.

Reset MAC address table


Removes the MAC addresses from the forwarding table that have the value learned in the Status
column.

RM GUI EAGLE 181


Release 3.4 03/2020
Routing
[ Routing > Global ]

7 Routing

The menu contains the following dialogs:


 Routing Global
 Routing Interfaces
 ARP
 Open Shortest Path First
 Routing Table
 Tracking
 L3 Relay
 Loopback Interface
 L3-Redundancy
 NAT

7.1 Routing Global


[ Routing > Global ]

The Routing menu lets you specify the Routing functions settings for transmitting data on Layer 3 of
the ISO/OSI layer model.

For security reasons, the following functions are permanently disabled in the device:
 Source Routing
With source routing, the data packet contains the routing information and overwrites the settings
in the router with it.
 ICMP Redirects
ICMP redirect data packets are able to modify the routing table. The device generally ignores
received ICMP redirect data packets. The settings in the Routing > Interfaces > Configuration
dialog, column ICMP redirects, have an effect only on the sending of ICMP redirect data packets.

In accordance with RFC 2644, the device does not exchange any broadcast data packets from
external networks in a local network. This behavior supports you in protecting the devices in the
local network against overloading, for example due to so-called smurf attacks.

This dialog lets you enable the routing function in the device and to specify further settings.

Operation

Operation
Enables/disables the Routing function in the device.

Possible values:
 On
The Routing function is enabled.
Also activate the routing function on the router interfaces. See the Routing > Interfaces >
Configuration dialog.
 Off (default setting)
The Routing function is disabled.

182 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > Global ]

ICMP filter

In the ICMP filter frame, you have the option of limiting the transmission of ICMP messages on the
set up router interfaces. A limitation is meaningful for several reasons:
• A large number of “ICMP Error” messages influences the router performance and reduces the
available network bandwidth.
• Malicious senders use “ICMP Redirect” messages to perform man-in-the-middle attacks or to
divert data packets through “black hole” for the purpose of supervision or denial-of-service
(DoS).
• “ICMP Echo Reply” messages are ping responses which can be misused to discover vulnerable
devices and routers in the network.

Send echo reply


Activates/deactivates the responding to pings on the router interfaces.

Possible values:
 marked (default setting)
Responding to pings is active.
The device reacts to received “IPv4 Echo Requests” and responds with an “ICMP Echo Reply”
message.
 unmarked
Responding to pings is inactive.

Send redirects
Activates/deactivates the sending of “ICMP Redirect” messages on the router interfaces.

Possible values:
 marked (default setting)
The sending of “ICMP Redirect” messages is active.
In the Routing > Interfaces > Configuration dialog, you have the option of individually activating the
sending on every router interface. See the ICMP redirects function.
 unmarked
The sending of “ICMP Redirect” messages is inactive.
This setting helps prevent the multiplication of data packets, if both hardware and software
functions of the device forward a copy of the same data packet.

Rate limit interval [ms]


Specifies the average minimum time in milliseconds between sending ICMP packets. The device
sends existing ICMP packets to each receiver using a token bucket algorithm.
• In periods without sending ICMP packets, the device accumulates tokens to allow bursts.
• In the case of bursts, the interval is shorter than specified here.

Possible values:
 0..2147483647 (default setting: 1000)

Rate limit burst size


Displays the maximum number of ICMP packets, the device sends during a burst to each receiver.

Possible values:
 6

RM GUI EAGLE 183


Release 3.4 03/2020
Routing
[ Routing > Interfaces ]

Information

Default TTL
Displays the fixed TTL value 64 which the device adds to IP packets that the device management
sends.

TTL (Time To Live, also known as “Hop Count”) identifies the maximum number of steps an IP
packet is allowed to perform on the way from the sender to the receiver. Every router on the
transmission path reduces the value in the IP packet by 1. If a router receives a data packet with
the TTL value 1, then the router discards the IP packet. The router reports to the source that it has
discarded the IP packet.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

7.2 Routing Interfaces


[ Routing > Interfaces ]

This menu lets you specify the settings for the router interfaces.

The menu contains the following dialogs:


 Routing Interfaces Configuration
 Routing Interfaces Secondary Interface Addresses

184 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > Interfaces > Configuration ]

7.2.1 Routing Interfaces Configuration


[ Routing > Interfaces > Configuration ]

This dialog lets you specify the settings for the router interfaces.

To set up a port-based router interface, edit the table entries. To set up a VLAN-based router
interface, use the Wizard window.

Table

Port
Displays the number of the port or VLAN belonging to the router interface.

Name
Name of the port.

Possible values:
 Alphanumeric ASCII character string with 0..64 characters
The following characters are allowed:
– <space>
– 0..9
– a..z
– A..Z
– !#$%&'()*+,-./:;<=>?@[\\]^_`{}~

Port on
Activates/deactivates the port.

Possible values:
 marked (default setting)
The port is active.
 unmarked
The port is inactive. The port does not send or receive any data.

Port status
Displays the operating state of the port.

Possible values:
 marked
The port is enabled.
 unmarked
The port is disabled.

IP address
Specifies the IP address for the router interface.

RM GUI EAGLE 185


Release 3.4 03/2020
Routing
[ Routing > Interfaces > Configuration ]

Possible values:
 Valid IPv4 address (default setting: [Link])

Verify that the IP subnet of the router interface is not overlapping with any subnet connected to
another interface of the device:
• management port
• router interface
• loopback interface

Netmask
Specifies the netmask for the router interface.

Possible values:
 Valid IPv4 netmask (default setting: [Link])

Routing
Activates/deactivates the Routing function on the router interface.

In the process, the device removes the state information from the packet filter. This includes
potential DCE RPC information of the OPC enforcer. In the process, the device interrupts open
communication connections.

Possible values:
 marked
The Routing function is active.
– With port-based routing, the device transforms the port into a router interface.
Enabling the Routing function removes the port from the VLANs in which it was previously a
member. Disabling the Routing function does NOT reestablish the assignment; the port is not
a member of any VLAN.
– With VLAN-based routing, the device forwards the data packets in the related VLAN.
 unmarked (default setting)
The Routing function is inactive.
With VLAN-based routing, the device is still reachable through the router interface if the IP
address and netmask have been configured for the router interface.

Proxy ARP
Activates/deactivates the Proxy ARP function on the router interface. This feature lets you connect
devices from other networks as if these devices could be reached in the same network.

Possible values:
 marked
The Proxy ARP function is active.
The device responds to ARP requests from end devices that are located in other networks.
 unmarked (default setting)
The Proxy ARP function is inactive.

MTU value
Specifies the maximum allowed size of IP packets on the router interface in bytes.

186 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > Interfaces > Configuration ]

Possible values:
 0
Restores the default value (1500).
 68..1500 (default setting: 1500)
The prerequisite is that on the ports belonging to the router interface you specify the maximum
allowed size of Ethernet packets at least 18 bytes larger than specified here. See the Basic
Settings > Port dialog, MTU column.

ICMP unreachables
Displays whether the sending of “ICMP Destination Unreachable” messages is activated on the
router interface.

Possible values:
 marked
The router interface sends “ICMP Destination Unreachable” messages.
 unmarked (default setting)
The router interface does not send “ICMP Destination Unreachable” messages.

ICMP redirects
Displays whether the sending of “ICMP Redirect” messages is activated on the router interface.

Possible values:
 marked
The router interface sends “ICMP Redirect” messages.
 unmarked (default setting)
The router interface does not send “ICMP Redirect” messages.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Opens the Create window to add a new entry to the table.

In the VLAN ID field, you specify the ID of the VLAN.

[Configure VLAN router interface (Wizard)]

This Wizard window lets you set up a VLAN-based router interface.


 To set up a router interface from a VLAN already set up, highlight a VLAN in the table.
 To set up a router interface from a new VLAN, specify at the bottom of the VLAN ID field the ID
of the new VLAN.

After closing the Wizard window, click the button to save your settings.

RM GUI EAGLE 187


Release 3.4 03/2020
Routing
[ Routing > Interfaces > Configuration ]

[Configure VLAN router interface (Wizard) – Create or select VLAN]

Table

VLAN ID
Displays the ID of the VLANs set up in the device.

Name
Displays the name of the VLANs set up in the device.

Area under the table

VLAN ID
Specifies the ID of a VLAN that the Wizard window specifies for you.

Possible values:
 1..4042

[Configure VLAN router interface (Wizard) – Setup VLAN]

Area above the table

VLAN ID
Displays the ID of the VLAN that you have marked or specified on the Create or select VLAN page.

Name
Specifies the name of the VLAN.

Possible values:
 Alphanumeric ASCII character string with 1..32 characters
(0x20..0x7E) including space characters

This setting overwrites the setting specified for the port in the Switching > VLAN > Configuration dialog.

Table

Port
Displays the port number.

188 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > Interfaces > Configuration ]

Member
Activates/deactivates the VLAN membership of the port.

As a VLAN member the port belongs to router interface to be set up. This setting overwrites the
setting for the port specified in the Switching > VLAN > Configuration dialog.

Possible values:
 marked
The port is a member of the VLAN.
 unmarked
The port is not a member of the VLAN.

Untagged
Activates/deactivates the transmission of data packets with a VLAN tag on the port. This setting
overwrites the setting for the port specified in the Switching > VLAN > Configuration dialog.

Possible values:
 marked
The port transmits the data packets without a VLAN tag.
Use this setting if the connected device does not evaluate any VLAN tags, for example on end
ports.
 unmarked
The port transmits the data packets with a VLAN tag.

Port-VLAN ID
Specifies the ID of the VLAN which the devices assigns to data packets without a VLAN tag. This
setting overwrites the setting for the port specified in the Switching > VLAN > Port dialog, column Port-
VLAN ID.

Possible values:
 ID of a VLAN you set up (default setting: 1)

[Configure VLAN router interface (Wizard) – Setup virtual router port]

The device lets you specify up to 2 IP addresses (1 primary, 1 secondary) for a router interface and
a total of up to 64 IP addresses.

When you assign ports to the router interface that already transmit data packets in other VLANs,
the device displays a message upon closing the Wizard window:
 If you click the Yes button, then the related ports transmit the data packets from now on only in
the router VLAN.
In the Switching > VLAN > Configuration dialog, the related ports in the row of the router VLAN have
the value U or T, in the rows of other VLANs the value –.
 If you click the No button, then the related ports transmit the data packets in the router VLAN
and in other VLANs. This setting possibly causes undesired behavior.

RM GUI EAGLE 189


Release 3.4 03/2020
Routing
[ Routing > Interfaces > Configuration ]

Primary address

Address
Specifies the primary IP address for the router interface.

Possible values:
 Valid IPv4 address (default setting: [Link])

Netmask
Specifies the primary netmask for the router interface.

Possible values:
 Valid IPv4 netmask (default setting: [Link])

Secondary addresses

Address
Specifies a further IP address for the router interface (Multinetting).

Possible values:
 Valid IPv4 address (default setting: [Link])

Specify an IP address which is different from the primary IP address of the router interface.

Netmask
Specifies the netmask for the belonging further IP address.

Possible values:
 Valid IPv4 netmask (default setting: [Link])

190 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > Interfaces > Secondary Interface Addresses ]

7.2.2 Routing Interfaces Secondary Interface Addresses


[ Routing > Interfaces > Secondary Interface Addresses ]

This dialog lets you assign further IP addresses to the router interfaces. You use this function to
connect a router interface to several subnets.

The device lets you specify up to 2 IP addresses (1 primary, 1 secondary) for a router interface and
a total of up to 64 IP addresses.

Table

Port
Displays the number of the port or VLAN belonging to the router interface.

IP address
Displays the primary IP address of the router interface. See the Routing > Interfaces > Configuration
dialog.

Netmask
Displays the primary netmask of the router interface. See the Routing > Interfaces > Configuration
dialog.

Secondary IP Address/Netmask
Displays further IP addresses and netmasks assigned to the router interface.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Opens the Create window to add another IP address to the router interface highlighted in the table.
 In the Port drop-down list, you select the port number or VLAN ID belonging to the router
interface.
 In the Additional IP address field, you specify the IP address.
Possible values:
– Valid IPv4 address
 In the Additional netmask field, you specify the netmask.
Possible values:
– Valid IPv4 netmask

Verify that the IP subnet of the router interface is not overlapping with any subnet connected to
another interface of the device:
• management port
• router interface
• loopback interface

RM GUI EAGLE 191


Release 3.4 03/2020
Routing
[ Routing > ARP ]

7.3 ARP
[ Routing > ARP ]

The Address Resolution Protocol (ARP) learns the MAC address that belongs to an IP address.

The menu contains the following dialogs:


 ARP Global
 ARP Current
 ARP Static

192 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > ARP > Global ]

7.3.1 ARP Global


[ Routing > ARP > Global ]

This dialog lets you set the ARP parameters and view statistical values.

Configuration

Aging time [s]


Specifies the average time in seconds, after which the device removes an entry from the ARP table.
The device actually removes an entry after a randomly determined time in the range (0.5 to 1.5 )×
of the value defined here.

When there is data exchange with the associated device within this time period, the time measuring
begins from the start again.

Possible values:
 15..21600 (default setting: 1200)

Response timeout [s]


Specifies the time in seconds, that the device waits for a response before the query is seen as a
failure.

Possible values:
 1..10 (default setting: 1)

Retries
Specifies how many times the device repeats a failed query before it discards the query to this
address.

Possible values:
 0..10 (default setting: 4)

Information

Current entries total


Displays the number of entries that the ARP table currently contains.

This includes:
 Addresses of the devices which are connected to the router interfaces. See the Routing > ARP >
Current dialog.
 Addresses of the devices which are connected to the device management. See the Diagnostics >
System > ARP dialog.

Entries (max.)
Displays how many entries the ARP table can contain at a maximum.

RM GUI EAGLE 193


Release 3.4 03/2020
Routing
[ Routing > ARP > Global ]

Total entry peaks


Displays how many entries the ARP table has already contained at a maximum.

When you reset the ARP table, the counter is reset to the value 0. See the Reset ARP table button
in the Routing > ARP > Current dialog.

Current static entries


Displays the number of statically configured entries the ARP table currently contains. See the
Routing > ARP > Static dialog.

Static entries (max.)


Displays the number of statically configured entries the ARP table can contain at a maximum.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

194 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > ARP > Current ]

7.3.2 ARP Current


[ Routing > ARP > Current ]

This dialog lets you view the ARP table and delete the dynamically configured entries.

Table

Port
Displays the router interface on which the device has learned the IP/MAC address assignment.

IP address
Displays the IP address of the device that responded to an ARP query on this router interface.

MAC address
Displays the MAC address of the device that responded to an ARP query on this router interface.

Last updated
Displays the time in seconds since the current settings of the entry were registered in the ARP
table.

Type
Displays the way in which the ARP entry was set up.

Possible values:
 dynamic
Dynamically configured entry.
When no traffic with the associated device takes place by the end of the aging time, the device
removes this entry from the ARP table.
You specify the aging time in the Routing > ARP > Global dialog, field Aging time [s].
 static
Statically configured entry.
When you remove the dynamically configured addresses from the ARP table using the Reset
ARP table button, the entry remains.
 local
Identifies the IP/MAC address assignment of the router interface.
 invalid
Invalid entry.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Reset ARP table


Removes the dynamically set up addresses from the ARP table.

RM GUI EAGLE 195


Release 3.4 03/2020
Routing
[ Routing > ARP > Static ]

7.3.3 ARP Static


[ Routing > ARP > Static ]

This dialog lets you add to the ARP table IP/MAC address assignments that you have specified
yourself.

Table

IP address
Displays the IP address that the device assigns to the adjacent MAC address.

MAC address
Displays the MAC address that the device assigns to the adjacent IP address.

Port
Displays the router interface to which the device applies the IP/MAC address assignment.

Possible values:
 <Router interface>
The device applies the IP/MAC address assignment to this router interface.
 no port
The IP/MAC address assignment is currently not assigned to a router interface.

Active
Displays whether the IP/MAC address assignment is active or inactive.

Possible values:
 marked
The IP/MAC address assignment is active. The ARP table of the device contains the IP/MAC
address assignment as a static entry.
 unmarked (default setting)
The IP/MAC address assignment is inactive.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Opens the Create window to add a new entry to the table.

In the IP address field, you specify the IP address that the device assigns to the adjacent MAC
address.

196 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > OSPF ]

[ARP (Wizard)]

The Wizard window lets you add to the ARP table IP/MAC address assignments that you have
specified yourself. The prerequisite is that at least one router interface is set up.

[ARP (Wizard) – Edit ARP table]


 In the fields under the table, specify the IP address and the associated MAC address.
 To insert the IP/MAC address assignment into the table on the top, click the Add button.
 After closing the Wizard window, specify in the Port column the router interface. Then enable in
the Active column the IP/MAC address assignment.

After closing the Wizard window, click the button to save your settings.

Table

IP address
Specifies the IP address.

Possible values:
 Valid IPv4 address

MAC address
Specifies the MAC address.

Possible values:
 Valid MAC address

7.4 Open Shortest Path First


[ Routing > OSPF ]

Open Shortest Path First (OSPF) version 2, is a routing protocol described in RFC 2328, which is
applicable to networks with many routers.

In contrast to the hop count based distance-vector routing protocols such as RIP, OSPF provides
a link state algorithm. OSPF bases its link state algorithm on link cost meaning that the criteria for
the routing decisions are the path costs instead of hop counts. The path cost is calculated as
(100 Mbit/s) / (bandwidth in Mbit/s). OSPF also supports Variable Length Subnet Masking (VLSM)
or Classless Inter-Domain Routing (CIDR) networks.

OSPF convergence of the entire network is slow. However, after implementation the protocol is
quick in reacting to topology changes. The convergence time for OSPF is 5 to 15 seconds,
depending on the size of the network.

RM GUI EAGLE 197


Release 3.4 03/2020
Routing
[ Routing > OSPF ]

OSPF supports networks grouped to "Areas" and thus reduces the administrative effort when
maintaining the overall network (OSPF domain). The routers participating in the network know and
only manage their own "Area" by flooding Link State Advertisements (LSAs) into the area. Using
the LSAs each router builds its own topology database.
 The Area Border Routers (ABR) flood LSAs in an "Area" informing the local networks about
destinations in other areas within the OSPF domain. The Designated Routers (DR) transmit
LSAs informing about destinations in other areas.
 With Hello packets, neighboring routers periodically identify themselves and signal their
availability. If a router misses the Hello packets of another router, then after the expiration of the
dead-interval timer, the router considers this router as unreachable.

The device lets you use the md5 algorithm for data transmission. If you use the md5 mode, then
specify the same values in the devices in the same area. Specify the area relevant values
connected to the ABRs and ASBRs.

OSPF divides routers into the following roles:


 Designated Router (DR)
 Backup Designated Router (BDR)
 Area Border Router (ABR)
 Autonomous System Boundary Router (ASBR)

The menu contains the following dialogs:


 OSPF Global
 OSPF Areas
 OSPF Stub Areas
 OSPF Not So Stubby Areas
 OSPF Interfaces
 OSPF Virtual Links
 OSPF Ranges
 OSPF Diagnostics

198 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > OSPF > Global ]

7.4.1 OSPF Global


[ Routing > OSPF > Global ]

This dialog lets you specify the basic OSPF settings.

The menu contains the following dialogs:


 [General]
 [Configuration]
 [Redistribution]

[General]

This tab lets you enable OSPF in the device and to specify network parameters.

Operation

Operation
Enables/disables the OSPF function in the device.

Possible values:
 On
The OSPF function is enabled.
 Off (default setting)
The OSPF function is disabled.

Configuration

Router ID
Specifies the unique identifier for the router in the Autonomous System (AS). It influences the
election of the Designated Router (DR) and the Backup Designated Router (BDR). Ideally, you use
the IP address of a router interface in the device.

Possible values:
 <IP address of an interface> (default setting: [Link])

External LSDB limit


Specifies the maximum number of entries, non-default AS-external-LSAs, that the device saves in
the link state database. When this limit is reached, the router enters the overflow state.

Possible values:
 -1 (default setting)
The router continues to save entries until the memory is full.
 0..2147483647
The device saves up to the specified number of entries.
Specify the same value in the routers on the OSPF backbone and in any regular OSPF area.

RM GUI EAGLE 199


Release 3.4 03/2020
Routing
[ Routing > OSPF > Global ]

External LSAs
Displays the current number of entries, non-default AS-external-LSAs, that the device currently
holds in the link state database.

Autocost reference bandwidth


Specifies a reference for router interface bandwidth calculations, in Mbps. You use this value for
metric calculations.

Possible values:
 1..4294967 (default setting: 100)

Paths (max.)
Specifies the maximum number of ECMP routes that OSPF adds to the routing table when multiple
routes exist for a subnet with same path costs, but different next hops.

Possible values:
 1..4 (default setting: 4)
 5..16
Available when the ipv4DataCenter routing profile is currently applied. See the Routing profile
frame in the Routing > Global dialog.

Default metric
Specifies the default metric value for OSPF.

Possible values:
 0 (default setting)
OSPF automatically assigns a cost of 20 for routes learned from external sources (static or
directly connected).
 1..16777214

Send trap
Activates/deactivates the sending of SNMP traps when the device detects a OSPF parameter
change.

Possible values:
 marked
The sending of SNMP traps is active.
If the device detects changes in the OSPF parameters, then the device sends an SNMP trap.
 unmarked (default setting)
The sending of SNMP traps is inactive.

The prerequisite for sending SNMP traps is that you enable the function in the Diagnostics > Status
Configuration > Alarms (Traps) dialog and specify at least 1 trap destination.

200 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > OSPF > Global ]

Shortest path first

Delay time [s]


Specifies the delay time, in seconds, between when the router receives a topology change and
when it starts an SPF calculation.

Possible values:
 0..65535 (default setting: 5)
The value 0 means that the router immediately begins the SPF calculation after receiving the
topology change.

Hold time [s]


Specifies the minimum time, in seconds, between consecutive SPF calculations.

Possible values:
 0..65535 (default setting: 10)
The value 0 means that after the router completes an SPF calculation it immediately begins the
next consecutive SPF calculation.

Exit overflow interval [s]


Specifies the number of seconds, after entering the overflow state, that a router attempts to leave
the overflow state. When the router leaves the overflow state, the router transmits new non-default
AS-external-LSAs.

Possible values:
 0..2147483647 (default setting: 0)
The value 0 means that the router remains in the Overflow-State until restarted.

Information

ASBR status
Displays whether the device operates as an Autonomous System Boundary Router (ASBR).

Possible values:
 marked
The router is an ASBR.
 unmarked
The router functions in a role other than the role of an ASBR.

ABR status
Displays whether the device operates as an Area Border Router (ABR).

Possible values:
 marked
The router is a ABR.
 unmarked
The router functions in a role other than the role of an ABR.

RM GUI EAGLE 201


Release 3.4 03/2020
Routing
[ Routing > OSPF > Global ]

External LSA checksum


Displays the link state checksums of the external LSAs contained in the link state database. This
value helps to determine when changes occur in a link state database of the router, and to compare
the link state database to other routers.

New LSA originated


Displays the number of new link state advertisements originated on this router. The router
increments this number each time it originates a new Link State Advertisement (LSA).

LSAs received
Displays the number of LSAs received that the router determined to be new instances. This number
also excludes newer instances of self-originated LSAs.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

[Configuration]

This dialog lets you specify the following settings:


 the manner in which the device calculates the path costs
 how OSPF handles default routes
 the type of route OSPF uses for the path-cost calculation

RFC 1583 compatibility

The Network Working Group is continually developing the OSPF function improving and adding
parameters. This router provides parameters in accordance with RFC 2328. With parameters in
this dialog, you make the router compatible with routers developed under RFC 1583. Activating the
compatibility function lets you install this device in a network containing routers developed under
RFC 1583.

RFC 1583 compatibility


Enables/disabled the device to be compatible with routers developed under RFC 1583.

In order to minimize the chance of routing loops, set this function to the same value on the OSPF
enabled routers in an OSPF domain.

Possible values:
 On (default setting)
Enable the function when routers are present in the domain without software containing the
external path preference functionality described in RFC 2328.
 Off
Disable the function when every router present in the domain has software containing the
external path preference functionality described in RFC 2328.

202 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > OSPF > Global ]

Preferences

The preferences in this dialog are metrics values which the device uses as a tie breaker between
identical routes with different distance types. For example, when a route is inside the local area
(intra-area) and the other is outside the local area (inter-area or external). If the metric values are
the same for intra, inter and external, then the order of preference is intra, inter then external.

OSPF considers routes specified with a preference value of 255 as unreachable.

Preference (intra)
Specifies the "administrative distance" between routers within the same area (intra-area OSPF
routes).

Possible values:
 1..255 (default setting: 110)

Preference (inter)
Specifies the "administrative distance" between routers in different areas (inter-area OSPF routes).

Possible values:
 1..255 (default setting: 110)

Preference (external)
Specifies the "administrative distance" between routers external to the areas (external OSPF
routes).

Possible values:
 1..255 (default setting: 110)

Default route

Advertise
Activates/deactivates OSPF advertisements of default routes learned from other protocols.

For example, area border routers of stub areas advertise a default route into the stub area through
summary link advertisements. When you configure the router as an AS boundary router, it
advertises the default route in AS external link advertisements.

Possible values:
 marked
The router advertises default routes.
 unmarked (default setting)
The router suppresses advertisements of default routes.

Advertise always
Displays whether the router constantly advertises [Link]/0 as the default route.

RM GUI EAGLE 203


Release 3.4 03/2020
Routing
[ Routing > OSPF > Global ]

When routers forward an IP packet, the router constantly forwards the packet to the best matching
destination address. A default route with a destination address of [Link] and a mask of [Link]
is a match for every IP destination address. Matching every IP destination address lets an AS
boundary router operate as a gateway for destinations outside of the AS.

Possible values:
 marked
The router constantly advertises [Link]/0 as the default route.
 unmarked (default setting)
The device uses the settings specified in the Advertise parameter.

Metric
Specifies the metric of the default route, which OSPF advertises when learned from other protocols.

Possible values:
 0
The device uses the value specified in the Default metric field.
 1..16777214

Metric type
Displays the metric type of the default route which OSPF advertises when learned from another
protocol.

Possible values:
 externalType1
Includes both the external path cost from the ABR to the ASBR that originated the route plus the
internal path cost to the ABR that advertised the route in the local area.
 externalType2 (default setting)
Includes only the external path cost.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

[Redistribution]

A router with a disabled OSPF function on a routed interface does not propagate the network of this
interface on its other interfaces. Thus, the network cannot be reached. To propagate such
networks, enable the Redistribution for "connected" networks.

Redistribution is helpful in cases where multiple network administrators manage different


departments, or in multi-vendor networks with multiple protocols. OSPF redistribution lets you
convert route information such as cost and distance to a destination from other protocols into
OSPF.

204 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > OSPF > Global ]

To help prevent routes from double redistribution and thus preventing a possible loop, use the Tag
function. This function marks the routes redistributed from other protocols into OSPF. Then on the
other routers in the network, create an ACL active to deny the tagged number. To specify exactly
which routes the device distributes in OSPF, create ACL permit rules.

The number of routes that the device learns through OSPF is limited to the size of the routing table.

Table

Source
Displays the source protocol, from which OSPF redistributes routes. This object also acts as the
identifier for the table entry.

Activating a row lets the device redistribute routes from the specific source protocol into OSPF.

Possible values:
 connected
The router is directly connected to the route.
 static
A network administrator has specified the route in the router.

Active
Activates/deactivates route redistribution from the source protocol into OSPF.

Possible values:
 marked
Redistribution of routes learned from the source protocol is active.
 unmarked (default setting)
OSPF route redistribution is inactive.

Metric
Specifies the metric value for routes redistributed from this protocol.

Possible values:
 0 (default setting)
The device uses the value specified in the Default metric field.
 1..16777214

Metric type
Specifies the route metric type which OSPF redistributes from other source protocols.

Possible values:
 externalType1
This metric type includes both the external path cost from the ABR to the ASBR that originated
the route plus the internal path cost to the ABR that advertised the route in the local area.
 externalType2 (default setting)
This metric type is only that of the external path cost.

RM GUI EAGLE 205


Release 3.4 03/2020
Routing
[ Routing > OSPF > Global ]

Tag
Specifies a tag for routes redistributed into OSPF.

When you set a route tag, OSPF assigns the value to every redistributed route from this source
protocol. This function is useful when 2 or more border routers connect an autonomous system to
an external network. To help prevent double redistribution, specify the same value in every border
router when redistributing the same protocol.

Possible values:
 0..4294967295 (default setting: 0)

Subnets
Activates/deactivates subnet route redistribution into OSPF.

OSPF only redistributes classful routes into the OSPF domain. In order to redistribute subnet routes
into OSPF activate the subnet parameter.

Possible values:
 marked (default setting)
The router redistributes classful and subnet routes into OSPF.
 unmarked
The router redistributes only classful routes into OSPF.

ACL group name


Specifies the name of the Access Control List created to filter routes received from the specified
source protocol.

To help prevent double redistribution and eventual loops, create an access list denying
redistribution of routes originating in another protocol. Specify the access list ID, then activate the
function in the ACL active column. When filtering redistributed routes, the device uses the source
address.

Possible values:
 - (default setting)
No Access Control List assigned.
 <Group name> (IPv4)
You specify the Access Control Lists in the Network Security > ACL > IPv4 Rule dialog.

ACL active
Activates/deactivates Access Control List filtering for this source protocol.

Possible values:
 marked
The router filters redistribution of routes according to the specified Access Control List.
 unmarked (default setting)
The router ignores Access Control List filtering for this source protocol.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

206 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > OSPF > Areas ]

7.4.2 OSPF Areas


[ Routing > OSPF > Areas ]

OSPF supports networks divided into "Areas" and thus reduces the administrative effort when
maintaining the network. The routers participating in the network know and only manage their own
"Area" by flooding Link State Advertisements (LSAs) into the area. Using the LSAs each router
builds its own topology database.

The device lets you specify up to a total of 64 OSPF Areas.

Table

Area ID
Displays the area ID.

Area type
Specifies the import policy of AS external LSAs for the area which determines the Area Type.

OSPF import policies apply to external routes only. An external route is a route that is outside the
OSPF autonomous system.

Possible values:
 area (default setting)
The router imports type 5 AS external LSAs into the area.
 stub area
The router ignores type 5 AS external LSAs.
 nssa
The router translates type 7AS external LSAs into type 5 NSSA summary LSAs and imports
them into the area.

SPF runs
Displays the number of times that the router calculated the intra-area routing table using the link
state database of this area. The router uses Dijkstra's algorithm for route calculation.

Area border router


Displays the total number of ABRs reachable within this area. The number of reachable routers is
initially 0. OSPF calculates the number in each SPF Pass.

AS boundary router
Displays the total number of ASBRs reachable within this area. The number of reachable ASBRs
is initially 0. OSPF calculates the number in each SPF Pass.

Area LSAs
Displays the total number of link state advertisements in the link state database of this area,
excluding AS External LSAs.

RM GUI EAGLE 207


Release 3.4 03/2020
Routing
[ Routing > OSPF > Areas ]

Area LSA checksum


Displays the total number of LS checksums contained in the LS database of this area. This sum
excludes type 5 external LSAs. You use the sum to determine if there has been a change in an LS
database of a router, and to compare the LS database to other routers.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Opens the Create window to add a new entry to the table.


 In the Area ID field you specify the area ID for the new table entry.
Possible values:
– Octet value displayed like an IPv4 address

208 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > OSPF > Stub Areas ]

7.4.3 OSPF Stub Areas


[ Routing > OSPF > Stub Areas ]

OSPF lets you specify certain areas as stub areas. The Area Border Router (ABR) of a stub area
enters the information learned from AS external LSAs in its database without flooding the AS
external LSAs across the stub area. The ABR instead sends a summary LSA into the stub area
advertising a default route. The default route advertised in the summary LSA pertains only to the
particular stub area. When forwarding data to AS external destinations, the routers in a stub area
use the default ABR only. Sending a summary LSA containing the default route instead of AS
external LSAs reduces the link state database size, and therefore the memory requirements for an
internal router of a stub area.

The device gives you the following options for creating a Stub Area:
 Converting an Area to a Stub Area
 In the Routing > OSPF > Areas dialog, change the value in the Area type column to Stub Area.
 Creating a new Stub Area
 In the Routing > OSPF > Areas dialog, create an entry in the table.
 Change the value in the Area type column to stub area.

Table

Area ID
Displays the area ID for the stub area.

Default cost
Specifies the external metric value for the metric type.

Possible values:
 0..16777215
The router sets the default value to equal the lower cost within the area for the metric type.

Metric type
Specifies the type of metric used for the default route advertised into the area.

The border router of a stub area advertises a default route as a network summary LSA.

Possible values:
 OSPF metric (default setting)
The ABR advertises the metric as OSPF internal, which is the cost of an intra-area route to the
ABR.
 External type 1
The ABR advertises the metric as External type 1, which is the cost of the OSPF internal
metric plus external metric to the ASBR.
 External type 2
The ABR advertises the metric as External type 2, which is the cost of the external metric to
the ASBR. You use this value for NSSAs.

Totally stub
Activates/deactivates the import of summary LSAs into stub areas.

RM GUI EAGLE 209


Release 3.4 03/2020
Routing
[ Routing > OSPF > Stub Areas ]

Possible values:
 marked
The router does not import area summaries. The stub area relies entirely on the default route.
This makes the default route a Totally Stub Area.
 unmarked (default setting)
The router both summarizes and propagates summary LSAs into the stub area.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

210 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > OSPF > NSSA ]

7.4.4 OSPF Not So Stubby Areas


[ Routing > OSPF > NSSA ]

NSSAs are similar to the OSPF stub area. However, NSSAs have the additional capability of
importing limited AS external routes. The ABR sends external routes out of the NSSA by converting
type 7 AS external LSAs into type 5 AS external LSAs. The ASBR in an NSSA originates type 7
LSAs. The only difference between the type 5 and type 7 LSAs is that the router sets the “N“ bit for
NSSAs. Both NSSA neighbors have the "N" bit set. This forms the OSPF neighbor adjacency.

Beside the internal data traffic, NSSAs act like transit areas by transport data coming from external
sources to other areas within the OSPF domain.

The device gives you the following options for creating an NSSA:
 Converting an Area to an NSSA
 In the Routing > OSPF > Areas dialog, change the value in the Area type column to nssa.
 Creating a new NSSA
 In the Routing > OSPF > Areas dialog, create an entry in the table.
 Change the value in the Area type column to nssa.

Table

Area ID
Displays the area ID to which the table entries apply.

Redistribute
Activates/deactivates external route redistribution into the NSSA.

Possible values:
 marked (default setting)
The NSSA ASBRs suppress external route redistribution into the NSSA. Furthermore, the ASBR
stops to create type 7 external LSAs for external routes.
 unmarked
The NSSA ASBRs redistribute external routes into the NSSA.

Originate default info


Activates/deactivates the creation of type 7 default LSAs.

The prerequisite for the creation of type 7 default LSAs is that the router is an NSSA ABR or ASBR.

Possible values:
 marked
The router creates type 7 default LSAs and sends then into the NSSA.
 unmarked (default setting)
The router suppresses type 7 default LSAs.

Default metric
Specifies the metric value advertised in the type 7 default LSA.

RM GUI EAGLE 211


Release 3.4 03/2020
Routing
[ Routing > OSPF > NSSA ]

Possible values:
 1..16777214 (default setting: 10)

Default metric type


Specifies the metric type advertised in the type 7 default LSA.

Possible values:
 ospfMetric
The router advertises the metric as OSPF internal, which is the cost of an intra-area route to the
ABR.
 comparable
The router advertises the metric as external type 1, which is the cost of the OSPF internal metric
plus external metric to the ASBR.
 nonComparable
The router advertises the metric as external type 2, which is the cost of the external metric to
the ASBR.

Translator role
Specifies the ability of an NSSA border router to perform translation of type-7 LSAs into type-5
LSAs.

NSSA Area Border Routers receive type-5 LSAs containing information about external routes. The
NSSA border routers block the type-5 LSAs from entering into the NSSA. However, using type-7
LSAs the border routers inform each other about external routes. The ABRs then translate the type-
7 LSAs to type-5 external LSAs and flood the information to the rest of the OSPF network.

Possible values:
 always
The router translates type-7 LSAs to type-5 LSAs.
When the router receives a type-5 LSAs from another router with a router ID higher then its own,
it flushes its type-5 LSAs.
 candidate (default setting)
The router translates type-7 LSAs to type-5 LSAs.
To help prevent routing loops, OSPF performs a translator election. When multiple candidates
exist, OSPF elects the router with the higher router ID as the translator.

Translator status
Displays if and how the router is translating type-7 LSAs into type-5 LSAs.

Possible values:
 enabled
The Translator role of the router is set to always.
 elected
As a candidate, the NSSA Border router is translating type-7 LSAs into type-5.
 disabled
Another NSSA border router is translating type-7 LSAs into type-5 LSAs.

Translator stability interval [s]


Specifies the number of seconds after the router loses a translation election that it continues to
translate type-7 LSAs into type-5 LSAs.

212 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > OSPF > NSSA ]

Possible values:
 0..65535 (default setting: 40)

Translator events
Displays the number of translator status changes that have occurred since the last boot-up.

Discontinuities in the value of this counter occur while OSPF is disabled and can occur during re-
initialization of the management system.

Totally NSSA
Activates/deactivates importation of summary routes into the NSSA as type 3 summary LSAs.

Possible values:
 marked
The router suppresses summary route importation making the area a Totally NSSA.
 unmarked (default setting)
The router imports summary routes into the NSSA as type 3 summary LSAs.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 213


Release 3.4 03/2020
Routing
[ Routing > OSPF > Interfaces ]

7.4.5 OSPF Interfaces


[ Routing > OSPF > Interfaces ]

This dialog lets you specify, activate, and display OSPF parameters on the router interfaces.

The device lets you activate up to 64 OSPF router interfaces.

The device uses the OSPF routing protocol to exchange reachability information between the
routers. The device uses routing information learned from peers to determine the next hop towards
the destination. To route traffic correctly, the router authenticates OSPF protocol exchanges to help
prevent malicious or incorrect routing information from getting introduced into the routing table.

OSPF supports multiple types of authentication. You configure the type of authentication in use on
a per interface basis. The cryptographic authentication option md5, helps protect your network
against passive attacks and helps provide significant protection against active attacks. When using
the cryptographic authentication option, each router appends a "message digest" to its transmitted
OSPF packets. Receivers then use the shared secret key and received digest to verify that each
received OSPF packet is authentic.

Table

Port
Displays the interface to which the table entry applies.

IP address
Displays the IP address of this OSPF interface.

Active
Activates/deactivates the OSPF administrative status of the interface.

Possible values:
 marked
The router advertises the values specified on the interface, and the interface as an OSPF
internal route.
 unmarked (default setting)
The interface is external to OSPF.

Area ID
Specifies the area ID of the domain to which the interface connects.

Possible values:
 <Area ID>
You specify the area IDs in the Routing > OSPF > Areas dialog.

Priority
Specifies the priority of this interface.

214 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > OSPF > Interfaces ]

In multi-access networks, the router uses the value in the Designated Router election algorithm.
When a tie occurs, the routers use their router ID as a tie breaker. The highest router ID wins.

Possible values:
 0
The router is unable to become the Designated Router on this particular network.
 1..255 (default setting: 1)

Transmit delay [s]


Specifies the estimated number of seconds it takes to transmit a link state update packet over this
interface.

This setting is useful for low speed links. The timer increases the age of the LS updates to
compensate for estimated delays on the interface. Increasing the packet age too much results in a
reply that is younger than the original packet.

Possible values:
 0..3600 (default setting: 1)

Retrans interval [s]


Specifies the number of seconds between link state advertisement retransmissions for adjacencies
belonging to this interface.

You also use this value when retransmitting database description and link state request packets.

Possible values:
 0..3600 (default setting: 5)

Hello interval [s]


Specifies the number of seconds between Hello packet transmissions on the interface.

Set this value the same for the routers attached to a common network. Verify that every router in
an area has the same value.

Possible values:
 1..65535 (default setting: 10)

Dead interval [s]


Specifies the number of seconds between received Hello packets before a router declares the
neighbor router down.

Specify the value to a multiple of the Hello interval [s]. Specify the same value for the router interfaces
within the same area.

Possible values:
 1..65535 (default setting: 40)
Specify a lower value to get a faster detection of a neighbor in a down state.

Note: Lower values are prone to interoperability issues.

RM GUI EAGLE 215


Release 3.4 03/2020
Routing
[ Routing > OSPF > Interfaces ]

Status
Displays the OSPF interface state.

Possible values:
 down (default setting)
The interface is in the initial state and is blocking traffic.
 loopback
The interface is a loopback interface of the device. Although packets are not sent out on the
loopback interface, the router LSAs continue to advertise the interface address.
 waiting
Applies only to interfaces connected to broadcast and Non-broadcast Multi-access (NBMA)
network types. While in this state, the router attempts to identify the state of the network DR and
BDR by sending and receiving Hello packets. The wait timer causes the interface to exit the
waiting state and select a DR. The period of this timer is the same as the value in the Dead
interval [s] field.
 pointToPoint
Applies only to interfaces connected to point-to-point, point-to-multipoint, and virtual link
network types. While in this state the interface sends Hello packets every Hello interval [s] and
establishes an adjacency with its neighbor.
 designatedRouter
The router is the DR for the multi-access network and establishes adjacencies with the other
network routers.
 backupDesignatedRouter
The router is the BDR for the multi-access network and establishes adjacencies with the other
network routers.
 otherDesignatedRouter
The router is only a network participant. The router establishes adjacencies only with the DR
and BDR and tracks its network neighbors.

Designated router
Displays the IP address of the Designated Router.

Possible values:
 Valid IPv4 address (default setting: [Link])

Backup designated router


Displays the IP address of the Backup Designated Router.

Possible values:
 Valid IPv4 address (default setting: [Link])

Events
Displays the number of times this OSPF interface changed its state, or the router detected an error.

Network type
Specifies the OSPF network type of the autonomous system.

216 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > OSPF > Interfaces ]

Possible values:
 broadcast
Use this value for broadcast networks, such as Ethernet and IEEE 802.5. OSPF performs a DR
and BDR election with which the non-designated routers form an adjacency.
 nbma
Use this value for non-broadcast multi-access networks such as X.25 and similar technologies.
OSPF performs a DR and BDR election to limit the number of adjacencies formed.
 pointToPoint
Use this value for networks that link only 2 interfaces.
 pointToMultipoint
Use this value when you collect several point-to-point links into a non-broadcast network. Every
router in the network transmits Hello packets to other routers in the network, but without having
a DR and BDR election.

Auth type
Specifies the authentication type for an interface.

If you specify simple or MD5, then this router requires other routers to pass an authentication
process before this router accepts the other routers as neighbors.

If you use authentication to help protect your network, then use the same type and key for every
router in your autonomous system.

Possible values:
 none (default setting)
Network authentication is inactive.
 simple
The router uses clear text authentication. In this case, routers transmit the passwords as clear
text.
 MD5
The router uses the message-digest algorithm MD5 authentication. This type of authentication
helps make your network more secure.

Auth key
Specifies the authentication key.

After entering the field displays ***** (asterisk) instead of the authentication key.

Possible values:
 Alphanumeric ASCII character string with 16 characters
– with 8 characters if in the Auth type drop-down list the value simple is selected
– with 16 characters if in the Auth type drop-down list the value MD5 is selected
If you specify a shorter authentication key, then the device fills in the remaining characters
with 0.

Auth key ID
Specifies the MD5 authentication key ID value.

The cryptographic authentication option MD5, helps protect your network against passive attacks
and helps provide significant protection against active attacks.

The prerequisite for changing the value is that, in the Auth type column, you specify the value MD5.

RM GUI EAGLE 217


Release 3.4 03/2020
Routing
[ Routing > OSPF > Interfaces ]

Possible values:
 0..255 (default setting: 0)

Cost
Specifies the internal metric.

OSPF uses link cost as the metric. OSPF also uses the cost of a link to calculate the SPF routes.
OSPF prefers the route with the smaller value.

The formula to calculate cost is reference bandwidth divided by interface bandwidth. Reference
bandwidth is specified in the Autocost reference bandwidth field and is set to 100 Mbit/s by default.
See the Routing > OSPF > Global dialog, General tab.

Example:

The interface bandwidth is 10 Mbit/s.

The metric is 100 Mbit/s divided by 10 Mbit/s = 10.

Possible values:
 auto (default setting)
OSPF calculates the metric and automatically adjusts the value when the interface bandwidth
changes.
 1..65535
OSPF uses the value specified here as metric.

Calculated cost
Displays the metric value which OSPF currently uses for this interface.

MTU ignore
Activates/deactivates the IP maximum transmission unit (MTU) mismatch detection on this OSPF
interface.

Possible values:
 marked
Disables the IP MTU check and makes adjacencies possible when the MTU value differs on the
interfaces.
 unmarked (default setting)
The router checks if neighbors are using the same MTU value on the interfaces.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

218 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > OSPF > Virtual Links ]

7.4.6 OSPF Virtual Links


[ Routing > OSPF > Virtual Links ]

OSPF requires that you link every area to the backbone area. The physical location of routers often
prohibits a direct link to the backbone. Virtual links allow you to connect physically separated areas
to the backbone through a transit area. You specify both routers on the endpoints of a virtual link
as ABRs on a point-to-point link.
 To enter a virtual link in the table, click the button.

Table

Area ID
Displays the area ID for the transit area that the virtual link traverses.

Neighbor ID
Displays the router ID of the virtual neighbor.

The router learns this value from Hello packets received from the virtual neighbor. The value is a
static value for virtual adjacencies.

Transmit delay [s]


Specifies the estimated number of seconds it takes to transmit an LS update packet over this
interface.

This setting is useful for low speed links. The timer increases the age of the LS updates to
compensate for estimated delays on the interface. Increasing the packet age too much results in a
reply that is younger than the original packet.

Possible values:
 0..3600 (default setting: 1)

Retrans interval [s]


Specifies the number of seconds between the LS advertisement retransmissions for adjacencies
belonging to this interface.

You also use this value when retransmitting Database Description (DD) and LS Request packets.

Possible values:
 0..3600 (default setting: 5)

Dead interval [s]


Specifies the number of seconds between received Hello packets before a router declares the
neighbor router down.

Specify the value to a multiple of the Hello interval [s]. Specify the same value for the router interfaces
within the same area.

RM GUI EAGLE 219


Release 3.4 03/2020
Routing
[ Routing > OSPF > Virtual Links ]

Possible values:
 1..65535 (default setting: 40)
Specify a lower value to get a faster detection of a neighbor in a down state.

Note: Lower values are prone to interoperability issues.

Hello interval [s]


Specifies the number of seconds between Hello packet transmissions on the interface.

Set this value the same for the routers attached to a common network.

Possible values:
 1..65535 (default setting: 10)

Status
Displays the OSPF virtual interface state.

Possible values:
 down (default setting)
The interface is in the initial state and is blocking traffic.
 pointToPoint
Applies only to interfaces connected to point-to-point, point-to-multipoint, and virtual link
network types. While in this state the interface sends Hello packets every Hello interval [s] and
establishes an adjacency with its neighbor.

Events
Displays the number of times this interface changed its state due to a received event.

Auth type
Specifies the authentication type for a virtual link.

If you specify simple or MD5, then this router requires other routers to pass an authentication
process before this router accepts the other routers as neighbors.

If you use authentication to help protect your network, then use the same type and key for every
router in your autonomous system.

Possible values:
 none (default setting)
Network authentication is inactive.
 simple
The router uses clear text authentication. In this case, routers transmit the passwords as clear
text.
 MD5
The router uses the message-digest algorithm MD5 authentication. This type of authentication
helps make your network more secure.

Auth key
Specifies the authentication key.

After entering the field displays ***** (asterisk) instead of the authentication key.

220 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > OSPF > Virtual Links ]

Possible values:
 Alphanumeric ASCII character string with 16 characters
– with 8 characters if in the Auth type drop-down list the value simple is selected
– with 16 characters if in the Auth type drop-down list the value MD5 is selected
If you specify a shorter authentication key, then the device fills in the remaining characters
with 0.

Auth key ID
Specifies the MD5 authentication key ID value.

The cryptographic authentication option md5, helps protect your network against passive attacks
and helps provide significant protection against active attacks.

The prerequisite for specifying this value is that you specify in the Auth type column the value MD5.

Possible values:
 0..255 (default setting: 0)

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Opens the Create window to add a new entry to the table.


 In the Area ID drop-down list you select the area ID for the new table entry.
 In the Neighbor ID field you specify the router ID of the virtual neighbor.

RM GUI EAGLE 221


Release 3.4 03/2020
Routing
[ Routing > OSPF > Ranges ]

7.4.7 OSPF Ranges


[ Routing > OSPF > Ranges ]

In large areas, OSPF messages flooded across the network reduce available bandwidth and
increase the size of the routing table. A large routing table increases the amount of CPU processing
that the router requires to enter the information into the routing table. A large routing table also
reduces available memory. To decrease the number of OSPF messages flooded across the
network, OSPF lets you create several smaller subnets within a large area.

In order to summarize routing information into and out of a subnet, the Area Border Router (ABR)
specifies the subnet as a single address range. The ABR advertises each address range as a single
route to the external area. The IP address that the ABR advertises for the subnet is an address and
mask pair. Unadvertised ranges allow you to hide the existence of subnets from other areas.

The router specifies cost of the advertised route as the greater cost in the set component subnets.
 To enter an address range into the table, click the button.

Table

Area ID
Displays the area ID of the address range.

LSDB type
Displays the route information aggregated by the address range.

Possible values:
 summaryLink
The area range aggregates type 5 route information.
 nssaExternalLink
The area range aggregates type 7 route information.

Network
Displays the IP address of the subnet of the range.

Netmask
Displays the netmask of the subnet of the range.

Effect
Specifies the external advertisement of the subnet ranges.

Possible values:
 advertiseMatching (default setting)
The router advertises the range in other areas.
 doNotAdvertiseMatching
The router withholds range advertisement to other external areas.

222 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > OSPF > Ranges ]

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Opens the Create window to add a new entry to the table.


 In the Area ID drop-down list you select the area ID of the address range.
 In the LSDB type drop-down list you select the route information aggregated by the address
range.
Possible values:
– summaryLink
The area range aggregates type 5 route information.
– nssaExternalLink
The area range aggregates type 7 route information.
 In the Network field you specify the IP address for the area subnet.
 In the Netmask field you specify the netmask for the area subnet.

RM GUI EAGLE 223


Release 3.4 03/2020
Routing
[ Routing > OSPF > Diagnostics ]

7.4.8 OSPF Diagnostics


[ Routing > OSPF > Diagnostics ]

To function properly, OSPF relies on 2 basic processes.


 forming adjacencies
 after forming adjacencies, the neighboring routers exchange information and update their
routing table

The statistics displayed in the tabs help you to analyze the OSPF processes.

The dialog contains the following tabs:


 [Statistics]
 [Link state database]
 [Neighbors]
 [Virtual neighbors]
 [External link state database]
 [Route]

[Statistics]

In order to accomplish the 2 basic processes, OSPF routers send and receive various messages
containing information to form adjacencies, and update routing tables. The counters in the tab
indicate the amount of message traffic transmitted and received on the OSPF interfaces.
 Link State Acknowledgments (LSAcks) provide a response to a Link State Update (LS update)
request as part of the link state exchange process.
 The Hello messages allow a router to discover other OSPF routers in the area and to establish
adjacencies between the neighboring devices. After establishing adjacencies, the routers
advertise their credentials for establishing a role as either a Designated Router (DR), a Backup
Designated Router (BDR), or only as a participant in the OSPF network. The routers then use
the Hello messages to exchange information about the OSPF configuration in the Autonomous
System (AS).
 Database Description (DD) messages contain descriptions of the AS or area topology. The
messages also propagate the contents of the link state database for the AS or area from a router
to other routers in the area.
 Link State Requests (LS Request) messages provide a means of requesting updated
information about a portion of the Link State Database (LSDB). The message specifies the link
or links for which the requesting router requires current information.
 LS Update messages contain updated information about the state of certain links on the LSDB.
The router sends the updates as a response to an LS Request message. The router also
broadcast or multicast messages periodically. The router uses the message contents to update
the information in the LSDBs of routers that receive them.
 LSAs contain the local routing information for the OSPF area. The router transmits the LSAs to
other routers in an OSPF area and only on interfaces connecting the router to the specific OSPF
area.
 Type 1 LSAs are router LSAs. Each router in an area originates a router-LSA. A single router
LSA describes the state and cost of every link in the area. The router floods type 1 LSAs only
across its own area.
 Type 2 LSAs are network LSAs. The DR creates a network LSA from information received in the
type 1 LSAs. The DR originates in its own area a network LSA for each broadcast and NBMA
network it is connected to. The LSA describes every router attached to the network, including
the DR itself. The router floods type 2 LSAs only across its own area.

224 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > OSPF > Diagnostics ]

 Type 3 LSAs are network summary LSAs. An Area Border Router (ABR) creates a single
network summary LSA from information contained in the type 1 and type 2 LSAs received from
the DRs. The ABR transmits network summary LSAs describing inter-area destinations. The
router floods type 3 LSAs across every area connected to it. Except this is the area for which it
generated the Type 3 LSA.
 Type 4 LSAs are Autonomous System Boundary Router (ASBR) summary LSAs. An ABR
creates a single ASBR summary LSA from information contained in the type 1 and type 2 LSAs
received from the DRs. The ABR transmits type 4 LSAs to areas different than the area it resides
in, to describe the ASBRs from which the ABR received type 5 LSAs. The router floods type 4
LSAs across every area connected to it. Except this is the area for which it generated the Type
4 LSA.
 Type 5 LSAs are AS external LSAs. The AS boundary routers create the AS external LSAs
describing destinations external to the AS. The type 5 LSAs contain information redistributed
into OSPF from other routing processes. The router floods type 5 LSAs to every area except
stub and NSSA areas.

Global

LSA retransmitted
Displays the total number of LSAs retransmitted since resetting the counters. When the router
transmits the same LSA to multiple neighbors, the router increments the count for each neighbor.

Hello packets received


Displays the total number of OSPFv2 Hello packets received since resetting the counters.

Hello packets transmitted


Displays the total number of OSPFv2 Hello packets transmitted since resetting the counters.

DB description packets received


Displays the total number of OSPFv2 Database Description packets received since resetting the
counters.

DB description packets transmitted


Displays the total number of OSPFv2 Database Description packets transmitted since resetting the
counters.

LS request packets received


Displays the total number of OSPFv2 Link State Request packets received since resetting the
counters.

LS request packets transmitted


Displays the total number of OSPFv2 Link State Request packets transmitted since resetting the
counters.

LS update packets received


Displays the total number of OSPFv2 LS Update packets received since resetting the counters.

RM GUI EAGLE 225


Release 3.4 03/2020
Routing
[ Routing > OSPF > Diagnostics ]

LS update packets transmitted


Displays the total number of OSPFv2 LS Update packets transmitted since resetting the counters.

LS ack update packets received


Displays the total number of OSPFv2 LS Acknowledgement packets received since resetting the
counters.

LS ack update packets transmitted


Displays the total number of OSPFv2 LS Acknowledgement packets transmitted since resetting the
counters.

Max. rate of LSU received in any 5sec


Displays the maximum rate of OSPFv2 LS Update packets received over any 5-second interval
since resetting the counters. The field displays the rate in packets per second. For example, the
number of packets received during the 5-second interval, divided by 5.

Max. rate of LSU transmitted in any 5sec


Displays the maximum rate of OSPFv2 LS Update packets transmitted over any 5-second interval
since resetting the counters. The field displays the rate in packets per second. For example, the
number of packets transmitted during the 5-second interval, divided by 5.

Type-1 (Router) LSAs received


Displays the number of type 1 router LSAs received since resetting the counters.

Type-2 (Network) LSAs received


Displays the number of type 2 network LSAs received since resetting the counters.

Type-3 (Summary) LSAs received


Displays the number of type 3 network summary LSAs received since resetting the counters.

Type-4 (ASBR) LSAs received


Displays the number of type 4 ASBR summary LSAs received since resetting the counters.

Type-5 (External) LSAs received


Displays the number of type 5 external LSAs received since resetting the counters.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

226 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > OSPF > Diagnostics ]

[Link state database]

A router maintains a separate link state database for every area to which it belongs.

The router adds LSAs to the database in the following cases:


 When the router receives an LSA, for example during the flooding process.
 When the router originates the LSA.

When a router deletes an LSA from the database, it also removes the LSA from the link state
retransmission lists of the other routers in the network. A router deletes an LSA from its database
in the following cases:
 A newer instance overwrites the LSA during the flooding process.
 The router originates a newer instance of a self-originated LSA.
 The LSA ages out and the router flushes the LSA from the routing domain.

Table

Area ID
Displays the area ID from which router received the LSA.

Type
Displays the type of the LSAs received.

Each LSA type has a separate advertisement format.

Possible values:
 routerLink
The router received the information from another router in the same area. Routers announce
their existence and list the links to other routers within the same area using a type 1 LSA. The
link state ID is the originating router ID.
 networkLink
The router received the information from a DR on a broadcast segment using a type 2 LSA. The
DR compiles the information received in type 1 LSAs and lists the routers linked together by the
segment. The link state ID is the IP interface address of the DR.
 summaryLink
The router received the information from an ABR using a type 3 LSA describing routes to
networks. ABRs compile information learned from type 1 and type 2 LSAs received from the
attached areas before sending the routing information to the other areas. The link state ID is the
destination network number which is the results of the summarization process.
 asSummaryLink
The router received the information from an ABR using a type 4 LSA describing routes to
ASBRs. ABRs compile information learned from type 1 and type 2 LSAs received from the
attached areas before sending the routing information to the other areas. The link state ID is the
destination network number.
 asExternalLink
The router received the information from an ASBR using a type 5 LSA describing routes to
another AS. The link state ID is the router id of the ASBR.
 nssaExternalLink
The router received the information from a router in a NSSA using a type 7 LSA.

RM GUI EAGLE 227


Release 3.4 03/2020
Routing
[ Routing > OSPF > Diagnostics ]

LSID
Displays the Link State ID (LSID) value received in the LSA.

The LSID is a field located in the LSA header. The field contains either a router ID or an IP address
according to the LSA type.

Possible values:
 <Router ID>
 Valid IPv4 address

Router ID
Displays the router ID uniquely identifying the originating router.

Sequence
Displays the value of the sequence field in an LSA.

The router examines the contents or the LS checksum field whenever the LS sequence number
field indicates that 2 instances of an LSA are the same. When there is a difference, the router
considers the instance with the larger LS checksum to be most recent.

Age
Displays the age of the link state advertisement in seconds.

When the router creates the LSA, the router sets the LS age to the value 0. As the routers transmit
the LSA across the network they increment the value by the value specified in the Transmit delay [s]
column.

If a router receives 2 LSAs for the same segment having identical LS sequence numbers and LS
checksums, then the router examines the age of the LSAs.
• The router immediately discards LSA with MaxAge.
• Otherwise, the router discards the LSA with the smaller age.

Checksum
Displays the contents of the checksum.

The field is a checksum of the complete contents of the LSA, except for the age field. The age field
of the advertisement increases as the routers transmit the message across the network. Excluding
the age field lets routers transmit the message without needing to update the checksum field.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

228 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > OSPF > Diagnostics ]

[Neighbors]

The Hello Protocol is responsible for neighbor acquisition, maintenance, and for 2-way
communication between neighbors.

During the acquisition process, the routers on a segment compare their configurations for
compatibility. If the routers are compatible, then the routers form adjacencies. The routers discover
their master or slave status using information provided in the Hello packets.

After the routers discover their roles, they exchange routing information to synchronize their routing
databases. When the routers finish updating their databases, the neighbors are fully adjacent and
the LSA lists the adjacency.

Table

Neighbor ID
Displays the router ID of the neighboring router.

The router learns this value from Hello packets received from the neighbor. The value is a static
value for virtual adjacencies.

IP address
Displays the IP address of the neighboring router interface attached to the port.

When sending unicast protocol packets on this adjacency, the router uses the value as the
destination IP address. When the neighboring router is the DR, the router is also used in router
LSAs as the link ID for the attached network. The router learns the neighbor IP address when it
receives Hello packets from the neighbor. For virtual links, the router learns the neighbor IP address
while building the routing table.

Interface
Displays the interface to which the entries in this row refer.

Status
Displays the state of the relationship with the neighbor listed in this instance.

An event invokes each state change, such as a received Hello packet. This event produces
different effects, depending on the current state of the neighbor. Also, depending on the state of
neighbor change, the routers initiate a DR election.

Possible values:
 down (default setting)
The initial state of a neighbor conversation or a router terminated the conversation due to
expiration of the Dead interval [s] timer.
 attempt
The state is only valid for neighbors attached to NBMA networks. The information from the
neighbor remains unresolved. The router actively attempts to contact the neighbor by sending
the neighbor Hello packets in the interval specified in Hello interval [s].

RM GUI EAGLE 229


Release 3.4 03/2020
Routing
[ Routing > OSPF > Diagnostics ]

 init
The router has recently seen a Hello packet from the neighbor. However, the router has only
established uni-directional communication with the neighbor. For example, the router ID of this
router is missing from the Hello packet of the neighbor. When sending Hello packets, the
associated interface lists neighbors in this state or higher.
 twoWay
Communication between the 2 routers is bidirectional. The router verifies the operation by
examining the contents of the Hello packet. The routers elect a DR and BDR from the set of
neighbors while in or after the 2-way state.
 exchangeStart
The first step in creating an adjacency between the 2 neighboring routers. The goal of this step
is to decide which router is the master and to decide upon the initial Sequence number.
 exchange
The router is announcing its entire link state database by sending Database Description (DD)
packets to the neighbor. The router explicitly acknowledges each DD packet. Each packet has
a sequence number. The adjacencies only allow 1 DD packet to be outstanding at any time. In
this state, the router sends LS Request packets asking for up-to-date database information. The
adjacencies are fully capable of transmitting and receiving OSPF routing protocol packets.
 loading
The router sends LS Request packets to the neighbor inquiring about the outstanding database
updates sent in the exchange state.
 full
The neighboring routers are fully adjacent. The adjacencies now appear in router LSAs and
network LSAs.

Dead time
Displays the amount of time remaining before the router declares the neighbor status as down. The
timer initiates the count down after the router receives a Hello packet.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

[Virtual neighbors]

OSPF requires a continuous connection of the Autonomous System backbone area. OSPF also
requires that every area has a connection to the backbone area. The physical location of routers
often prohibits an area from directly connecting to the backbone area. Virtual links allow you to
connect physically separated areas to the backbone area.

The ABRs of the backbone area and the physically separated area form a point-to-point link through
a transit area. When the ABRs establish an adjacency, the backbone router LSAs include the link
and OSPF packets flow over the virtual link. Furthermore, the routing database of each endpoint
router includes the link state information of the other endpoint router.

Note: The OSPF lets you specify virtual links through every type of area except for stub areas.

230 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > OSPF > Diagnostics ]

Table

Area ID
Displays the transit area ID of the virtual link.

Router ID
Displays the router ID of the other virtual endpoint ABR.

After virtual adjacencies form, the virtual link carries OSPF packets such as Hello packets and LS
update packets containing database information. The prerequisite is that the LSAs of the neighbor
router contain the router ID of the local router.

IP address
Displays the IP address of the virtual neighbor.

The router uses the IP address to send OSPF packets across the transit network to the virtual
neighbor.

Options
Displays the information contained in the options field of the LSA. This value indicates the
capabilities of virtual neighbor.

The options field used in the Hello packets allow routers to identify their optional capabilities, and
to communicate the capabilities to other routers. This mechanism lets you mix routers of different
capabilities within a routing domain.

The router supports 4 options by setting the following bits in the options field either high or low
depending on the capabilities of the router. The field displays the value by adding the following
option bits together. You read the fields from least significant bit to most significant bit.
• The routers advertise the ability to process TOS 0 in AS external routes when it sets the E-bit
high. The E-bit is the second bit in the options field and represents the value 2^1 or 2.
• The routers advertise the ability to process multicast routes when it sets the MC-bit high. The
MC-bit is the third bit in the options field and represents the value 2^2 or 4.
• The routers advertise the ability to process AS external routes in an NSSA summary with type
7 LSAs when it sets the N/P-bit high. The N/P-bit is the fourth bit in the options field and
represents the value 2^3 or 8.
• The routers advertise the ability to process demand circuits when it sets the DC-bit high. The
DC-bit is the sixth bit in the options field and represents the value 25 or 32.

In a special case, the router sets the E-bit low.


• The routers advertise the ability to process TOS metrics other than TOS 0 when it sets the E-bit
low. The E-bit is the second bit in the options field and when set low, the bit represents the value
0.

Possible values:
 2,6,10,14,34,38,42,46
The values indicate that the virtual neighbor supports Type of Service metric (TOS) 0 in AS
external LSAs.
 0,4,8,12,32,36,40,44
The values indicate that the virtual neighbor supports TOS metrics other than TOS 0.

RM GUI EAGLE 231


Release 3.4 03/2020
Routing
[ Routing > OSPF > Diagnostics ]

 4,6,12,14,36,38,44,46
The values indicate that the virtual neighbor supports multicast routing.
 8,10,12,14,40,42,44,46
The values indicate that the virtual neighbor supports type 7 LSAs.
 32,34,36,38,40,42,44,46
The values indicate that the virtual neighbor supports demand circuits.

Status
Displays the state of the relationship with the neighbor listed in this instance.

An event invokes each state change, such as a received Hello packet. This event produces
different effects, depending on the current state of the neighbor. Also, depending on the state of
neighbor change, the routers initiate a DR election.

Possible values:
 down (default setting)
The initial state of a neighbor conversation or a router terminated the conversation due to
expiration of the Dead interval [s] timer.
 attempt
The state is only valid for neighbors attached to NBMA networks. Information from the neighbor
remains unresolved. The router actively attempts to contact the neighbor by sending the
neighbor Hello packets in the interval specified in Hello interval [s].
 init
The router has recently seen a Hello packet from the neighbor. However, the router has only
established uni-directional communication with the neighbor. For example, the router ID of this
router is missing from the Hello packet of the neighbor. When sending Hello packets, the
associated interface lists neighbors in this state or higher.
 twoWay
Communication between the 2 routers is bidirectional. The router verifies the operation by
examining the contents of the Hello packet. The routers elect a DR and BDR from the set of
neighbors while in or after the 2-way state.
 exchangeStart
The first step in creating an adjacency between the 2 neighboring routers. The goal of this step
is to decide which router is the master and to decide upon the initial Sequence number.
 exchange
The router is announcing its entire link state database by sending Database Description (DD)
packets to the neighbor. The router explicitly acknowledges each DD packet. Each packet has
a sequence number. The adjacencies only allow 1 DD packet to be outstanding at any time. In
this state, the router sends LS Request packets asking for up-to-date database information. The
adjacencies are fully capable of transmitting and receiving OSPF routing protocol packets.
 loading
The router sends LS Request packets to the neighbor inquiring about the outstanding database
updates sent in the exchange state.
 full
The neighboring routers are fully adjacent. The adjacencies now appear in router LSAs and
network LSAs.

Events
Displays the number of times this interface changed its state due to a received event such as
HelloReceived or 2-way.

232 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > OSPF > Diagnostics ]

Length of retransmission queue


Displays the length of the retransmission list.

In order to flood LSAs out of an interface to the neighbor, the router places the LSAs on the link
state retransmission list of the adjacency. To validate LSA flooding, the router retransmits the LSAs
until the neighbor acknowledges the LSA reception. You configure the length of time between
retransmissions in the Routing > OSPF > Interfaces dialog in the Retrans interval [s] column.

Suppressed Hellos
Displays whether the router is suppressing Hello packets to the neighbor.

Suppressing Hello packet transmission to the neighbor lets demand circuits close, on point-to-point
links, during periods of inactivity. In NBMA networks, the periodic transmission of LSAs causes the
circuit to remain open.

Possible values:
 marked
The router suppresses Hello packets.
 unmarked
The router transmits Hello packets.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

[External link state database]

The table displays the contents of the external link state database, with an entry for each unique
link state ID. External links allow the area to connect to destinations outside of the autonomous
system. Routers pass information about the external links throughout the network as link state
updates.

Table

Type
Displays the type of the link state advertisement. When the router detects an external link state
advertisement, the router enters the information in the table.

Possible values:
 asExternalLink

LSID
Displays the Link State ID is an LS type-specific field containing either a router ID or an IP address.
The value identifies the routing domain described in the advertisement.

RM GUI EAGLE 233


Release 3.4 03/2020
Routing
[ Routing > OSPF > Diagnostics ]

Router ID
Displays the router ID uniquely identifying the originating router.

Sequence
Displays the value of the sequence field in an LSA.

The router examines the contents or the LS checksum field whenever the LS sequence number
field indicates that 2 instances of an LSA are the same. When there is a difference, the router
considers the instance with the larger LS checksum to be most recent.

Age
Displays the age of the link state advertisement in seconds.

When the router creates the LSA, the router sets the LS age to the value 0. As the routers transmit
the LSA across the network they increment the value by the value specified in the Transmit delay [s]
column.

If a router receives 2 LSAs for the same segment having identical LS sequence numbers and LS
checksums, then the router examines the age of the LSAs.
• The router immediately discards LSA with MaxAge.
• Otherwise, the router discards the LSA with the smaller age.

Checksum
Displays the contents of the checksum.

The field is a checksum of the complete contents of the LSA, except for the age field. The age field
of the advertisement increases as the routers transmit the message across the network. Excluding
the age field lets routers transmit the message without needing to update the checksum field.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

[Route]

The dialog displays the OSPF route information learned from the Link State Advertisements (LSA).

Table

IP address
Displays the IP address of the network or subnet for the route.

Netmask
Displays the netmask for the network or subnet.

234 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > Routing Table ]

Metric
Displays the route cost, calculated in the SPF algorithm, to reach the network.

Type
Displays the type of route that was learned from OSPF.

Possible values:
 intra
Entry for routes from the OSPF protocol within an area.
 inter
Entry for routes from the OSPF protocol between areas.
 ext-type1
These routes were imported from an Autonomous System Boundary Router (ASBR) into the
OSPF area. These routes use the costs relating to the connection between the ASBR and the
route costs includes this device.
 ext-type2
These routes were imported from an Autonomous System Boundary Router (ASBR) into the
OSPF area. These routes do not use the costs relating to the connection between the ASBR
and the route costs includes this device.
 nssa-type1
These routes were imported from an Autonomous System Boundary Router (ASBR) into the
Not-So-Stub Area. These routes use the costs relating to the connection between the ASBR and
the route costs includes this device.
 nssa-type2
These routes were imported from an Autonomous System Boundary Router (ASBR) into the
Not-So-Stub Area. These routes do not use the costs relating to the connection between the
ASBR and the route costs includes this device.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

7.5 Routing Table


[ Routing > Routing Table ]

This dialog displays the routing table with the routes configured in the device. Using the routing
table, the device learns the router interface through which it transfers IP packets that are addressed
to recipients in a different network.

Configuration

Preference
Specifies the preference number that the device assigns by default to the newly configured, static
routes.

RM GUI EAGLE 235


Release 3.4 03/2020
Routing
[ Routing > Routing Table ]

Possible values:
 1..255 (default setting: 1)
Routes with a value of 255 will be ignored by the device in the routing decision.

Table

Port
Displays the router interface through which the device is currently transmitting IP packets
addressed to the destination network.

Possible values:
 <Router interface>
The device uses this router interface to transfer IP packets addressed to the destination
network.
 no port
The static route is currently not assigned to a router interface.

Network address
Displays the address of the destination network.

Netmask
Displays the netmask.

Next hop IP address


Displays the IP address of the next router on the path to the destination network.

Type
Displays the type of the route.

Possible values:
 local
The router interface is directly connected to the destination network.
 remote
The router interface is connected to the destination network through a router (Next hop IP
address).
 reject
The device discards IP packets addressed to the destination network and informs the sender.
 other
The route is inactive. See the Active checkbox.

Protocol
Displays the origin of this route.

236 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > Routing Table ]

Possible values:
 local
The device created this route when setting up the router interface. See the Routing > Interfaces >
Configuration dialog.
 netmgmt
A user created this static route with the button.

Note: You can make static routes with the same destination and preference, but with different next
hops. The device uses Equal Cost Multi Path (ECMP) forwarding mechanism to help ensure load
sharing and redundancy over the network. Depending on the selected routing profile in the Routing >
Global dialog, ECMP can use up to 4 routes. If you select the ipv4DataCenter routing profile, then
ECMP can use up to 16 routes.

 ospf
The OSPF function created this route. See the Routing > OSPF dialog.

Preference
Specifies the "administrative distance" of the route.

The device uses this value instead of the metric, when the metric of the routes is incomparable.

Possible values:
 0
Reserved for routes that the device creates when setting up the router interfaces. These routes
have the value local in the Protocol column.
 1..254
In routing decisions, the device gives preference to the route with the smallest value.
 255
In routing decisions, the device ignores the route.

The "administrative distance" can be set for static routes created using the button.

Metric
Displays the metric of the route.

The device transmits the data packets using the route with the smallest value.

Last update [s]


Displays the time in seconds, since the current settings of the route were entered in the routing
table.

Track name
Specifies the tracking object with which the device links the route.

The device automatically activates or deactivates static routes – depending on the link status of an
interface or the reachability of a remote router or end device.

You set up tracking objects in the Routing > Tracking > Configuration dialog.

RM GUI EAGLE 237


Release 3.4 03/2020
Routing
[ Routing > Routing Table ]

Possible values:
 Name of the tracking object, made up of Type and Track ID.
 –
No tracking object selected.

This function is used only for static routes. (Column Protocol = netmgmt)

Active
Displays whether the route is active or inactive.

Possible values:
 marked
The route is active; the device uses the route.
 unmarked
The route is inactive.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Opens the Create dialog to create a static route.


 In the Network address field, you specify the address of the destination network.
Possible values:
– Valid IPv4 address
If you specify a default route ([Link]), then you specify a default gateway in the Next hop IP
address field. This setting takes precendence over the setting in the following dialog:
– Basic Settings > Network dialog, Gateway address field
 In the Netmask field, you specify the netmask that identifies the network prefix in the address of
the destination network.
Possible values:
– Valid IPv4 netmask
 In the Next hop IP address field, you specify the IP address of the next router on the path to the
destination network.
Possible values:
– Valid IPv4 address
To make a reject type route, specify the value [Link] in this field. With this route, the
device discards IP packets addressed to the destination network and informs the sender.
 In the Preference field, you specify the preference number that the device uses to decide which
of several existing routes to the destination network it will use.
Possible values:
– 1..255
In routing decisions, the device gives preference to the route with the smallest value. The
default setting is the value specified in the Configuration frame, field Preference.
 In the Track name field, you specify the tracking object with which the device links the route.
Possible values:
– –
No tracking object selected.
– Name of the tracking object, made up of Type and Track ID.

238 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > Tracking ]

7.6 Tracking
[ Routing > Tracking ]

The tracking function lets you monitor what are known as tracking objects. Examples of monitored
tracking objects are the link status of an interface or the reachability of a remote router or end
device.

The device forwards status changes of the tracking objects to the registered applications, for
example to the routing table or to a VRRP instance. The applications then react to the status
changes:
• In the routing table, the device activates/deactivates the route linked to the tracking object.
• The VRRP instance linked to the tracking object reduces the priority of the virtual router so that
a backup router takes over the role of the master.

If you set up the tracking objects in the Tracking Configuration dialog, then you can link applications
with the tracking objects:
• You link static routes with a tracking object in the Routing > Routing Table dialog, Track name
column.
• You link virtual routers with a tracking object in the Routing > L3-Redundancy > VRRP > Tracking
dialog. Click the button to open the Create window and select the tracking object in the Track
name drop-down list.

The menu contains the following dialogs:


 Tracking Configuration
 Tracking Applications

RM GUI EAGLE 239


Release 3.4 03/2020
Routing
[ Routing > Tracking > Configuration ]

7.6.1 Tracking Configuration


[ Routing > Tracking > Configuration ]

In this dialog, you set up the tracking objects.

Table

Type
Specifies the type of the tracking object.

Possible values:
 interface
The device monitors the link status of its physical ports or of its link aggregation, LRE or VLAN
router interface.
 ping
The device monitors the route to a remote router or end device by means of periodic ping
requests.
 logical
The device monitors tracking objects logically linked to each other and thus enables complex
monitoring tasks.

Track ID
Specifies the identification number of the tracking object.

Possible values:
 1..256
This range is available to every type (interface, ping and logical).

Track name
Displays the name of the tracking object made up of Type and Track ID.

Active
Activates/deactivates the monitoring of the tracking object.

Possible values:
 marked
Monitoring is active. The device monitors the tracking object.
 unmarked (default setting)
Monitoring is inactive.

Description
Specifies the description.

Here you describe what the device uses the tracking object for.

Possible values:
 Alphanumeric ASCII character string with 0..255 characters

240 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > Tracking > Configuration ]

Status
Displays the monitoring result of the tracking object.

Possible values:
 up
The monitoring result is positive:
– The link status is active.
or
– The remote router or end device is reachable.
or
– The result of the logical link is TRUE.
 down
The monitoring result is negative:
– The link status is inactive.
or
– The remote router or end device is not reachable.
or
– The result of the logical link is FALSE.
 notReady
The monitoring of the tracking object is inactive. You activate the monitoring in the Active
column.

Changes
Displays the number of status changes since the tracking object has been activated.

Last changed
Displays the time of the last status change.

Send trap
Activates/deactivates the sending of an SNMP trap when someone activates or deactivates the
tracking object.

Possible values:
 marked
If someone activates or deactivates the tracking object in the Active column, then the device
sends an SNMP trap.
 unmarked (default setting)
The device does not send an SNMP trap.

Port
Specifies the interface to be monitored for tracking objects of the interface type.

Possible values:
 <Interface number>
Number of the physical ports or of the link aggregation, LRE or VLAN router interface.
 no Port
No tracking object of the interface type.

RM GUI EAGLE 241


Release 3.4 03/2020
Routing
[ Routing > Tracking > Configuration ]

Link up delay [s]


Specifies the period in seconds after which the device evaluates the monitoring result as positive.
If the link has been active on the interface for longer than the period specified here, then the Status
column displays the value up.

Possible values:
 0..255
 –
No tracking object of the logical type.

Link down delay [s]


Specifies the period in seconds after which the device evaluates the monitoring result as negative.
If the link has been inactive on the interface for longer than the period specified here, then the Status
column displays the value down.

Possible values:
 0..255
 –
No tracking object of the interface type.

If the link to every aggregated port is interrupted, then Link aggregation, LRE and VLAN router
interfaces have a negative monitoring result.

If the link to every physical port and link-aggregation interface which is a member of the VLAN is
interrupted, then a VLAN router interface has a negative monitoring result.

Ping port
Specifies the router interface for tracking objects of the ping type through which the device sends
the ping request packets.

Possible values:
 <Interface number>
Number of the router interface.
 noName
No router interface assigned.
 –
No tracking object of the ping type.

IP address
Specifies the IP address of the remote router or end device to be monitored.

Possible values:
 Valid IPv4 address
 –
No tracking object of the ping type.

Ping interval [ms]


Specifies the interval in milliseconds at which the device periodically sends ping request packets.

242 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > Tracking > Configuration ]

Possible values:
 100..20000 (default setting: 1000)
If you specify a value <1000, then you can set up a maximum of 16 tracking objects of the ping
type.
 –
No tracking object of the ping type.

Ping replies to lose


Specifies the number of missed responses from the device after which the device evaluates the
monitoring result as negative. If the device does not receive a response to its sent ping request
packets for the number of times specified here in a row, then the Status column displays the value
down.

Possible values:
 1..10 (default setting: 3)
 –
No tracking object of the ping type.

Ping replies to receive


Specifies the number of received responses from the device after which the device evaluates the
monitoring result as positive. If the device receives a response to its sent ping request packets for
the number of times specified here in a row, then the Status column displays the value up.

Possible values:
 1..10 (default setting: 2)
 –
No tracking object of the ping type.

Ping timeout [ms]


Specifies the period in milliseconds for which the device waits for a response. If the device does
not receive a response within this period, then the device evaluates this as a missed response. See
the Ping replies to lose column.

Possible values:
 10..10000 (default setting: 100)
If a large number of ping tracking objects is set up in the device, then specify a sufficiently large
value. If more than 100 instances are present, then specify at least 200 ms.
 –
No tracking object of the ping type.

Ping TTL
Specifies the TTL value in the IP header with which the device sends the ping request packets.

TTL (Time To Live, also known as “Hop Count”) identifies the maximum number of steps an IP
packet is allowed to perform on the way from the sender to the receiver.

Possible values:
 –
No tracking object of the ping type.
 1..255 (default setting: 128)

RM GUI EAGLE 243


Release 3.4 03/2020
Routing
[ Routing > Tracking > Configuration ]

Best route
Displays the number of the router interface through which the best route leads to the monitoring
router or end device.

Possible values:
 <Port number>
Number of the router interface.
 no Port
No route exists.
 –
No tracking object of the ping type.

Logical operand A
Specifies the first operand of the logical link for tracking objects of the logical type.

Possible values:
 Tracking objects set up
 –
No tracking object of the logical type.

Logical operand B
Specifies the second operand of the logical link for tracking objects of the logical type.

Possible values:
 Tracking objects set up
 –
No tracking object of the logical type.

Operator
Links the tracking objects specified in the Logical operand A and Logical operand B fields.

Possible values:
 and
Logical AND link
 or
Logical OR link
 –
No tracking object of the logical type.

244 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > Tracking > Configuration ]

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Opens the Create window to add a new entry to the table.


 In the Type field, you specify the type of the tracking object.
Possible values:
– interface
The device monitors the link status of its physical ports or of its link aggregation, LRE or
VLAN router interface.
– ping
The device monitors the route to a remote router or end device by means of periodic ping
requests.
– logical
The device monitors tracking objects logically linked to each other and thus enables complex
monitoring tasks.
 In the Track ID field, you specify the identification number of the tracking object.
Possible values:
– 1..2147483647

RM GUI EAGLE 245


Release 3.4 03/2020
Routing
[ Routing > Tracking > Applications ]

7.6.2 Tracking Applications


[ Routing > Tracking > Applications ]

In this dialog, you see which applications are linked with the tracking objects.

The following applications can be linked with tracking objects:


• You link static routes with a tracking object in the Routing > Routing Table dialog, Track name
column.
• You link virtual routers with a tracking object in the Routing > L3-Redundancy > VRRP > Tracking
dialog. Click the button top open the Create window and select the tracking object in the Track
name drop-down list.

Table

Type
Displays the type of the tracking object.

Track ID
Displays the identification number of the tracking object.

Application
Displays the name of the application that is linked with the tracking object.

Possible values:
 Tracking objects of the logical type
 Static routes
 Virtual router of a VRRP instance

Track name
Displays the name of the tracking object made up of Type and Track ID.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

246 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > L3 Relay ]

7.7 L3 Relay
[ Routing > L3 Relay ]

Clients in a subnet send BOOTP/DHCP broadcasts messages to DHCP servers requesting


configuration information such as IP addresses. Routers provide a border for broadcast domains
so that BOOTP/DHCP requests remain in the local subnet. The Layer 3 Relay (L3 Relay) function
acts as a proxy for clients that require information from a BOOTP/DHCP server in another network.

When you configure this device to retrieve IP addresses from a DHCP server located in another
subnet, the L3 Relay function lets you forward requests across multiple hops to a server located in
another network.

Using IP helper addresses and UDP helper ports the L3 Relay forwards DHCP packets between
the clients and servers. The IP helper address is the DHCP server IP address. Clients use the UDP
helper port to request a type of information such as DNS information on UDP port 53, or DHCP
information on UDP port 67.

The L3 Relay function provides you the follow advantages over the standard BOOTP/DHCP function:
 redundancy, when you specify multiple severs to process client requests.
 load balancing, when you specify multiple interfaces to relay broadcast packets from the client
to the servers.
 central management, useful in large networks. The administrator saves the device
configurations on a centrally located server which responds to client requests in multiple
subnets.
 diversity, this function lets you specify up to 512 entries.

Operation

Operation
Enables/disables the L3 Relay function.

Possible values:
 On
The L3 Relay function is globally enabled.
 Off (default setting)
The L3 Relay function is globally disabled.

Configuration

Circuit ID
Activates/deactivates the BOOTP/DHCP Circuit ID Option Mode.

The device sends circuit ID suboption information, identifying the local agent, to the DHCP server.
The DHCP server uses the suboption information to send responses back to the proper agent.

RM GUI EAGLE 247


Release 3.4 03/2020
Routing
[ Routing > L3 Relay ]

Possible values:
 marked
The device adds the circuit ID of the DHCP relay agent to the suboptions for client requests.
 unmarked (default setting)
The device removes the DHCP relay agent circuit ID suboptions from client requests.

BOOTP/DHCP wait time (min.)


Specifies the minimum amount of time that the device delays forwarding the BOOTP/DHCP
request.

The end devices send broadcast request on the local network. This setting lest a local server
respond to the client request before the router forwards the client request through the interfaces.

Possible values:
 0..100 (default setting: 0)
If a local server is absent from the network, then set the value to 0.

BOOTP/DHCP hops (max.)


Specifies the maximum number of cascaded devices allowed to forward the BOOTP/DHCP
request.

If the hop count exceeds the maximum number of hops specified in this field, then the device drops
BOOTP requests.

Possible values:
 0..16 (default setting: 4)

Information

DHCP client messages received


Displays the number of DHCP requests received from the clients.

DHCP client messages relayed


Displays the number of DHCP requests forwarded to the servers specified in the table.

DHCP server messages received


Displays the number of DHCP offers received from the servers specified in the table.

DHCP server messages relayed


Displays the number of DHCP offers forwarded to the clients from the servers specified in the table.

UDP messages received


Displays the number of UDP requests received from the clients.

248 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > L3 Relay ]

UDP messages relayed


Displays the number of UDP requests forwarded to the servers specified in the table.

Packets with expired TTL


Displays the number of UDP packets received with an expired TTL value.

Discarded packets
Displays the number of UDP packets that device discarded, because the packet matched an active
table entry.

Table

Port
Displays the interface to which the table entry applies.

UDP port
Displays the UDP port for client messages received on this interface for this table entry. The device
forwards client DHCP messages matching the UDP port criteria to the IP helper address specified
in this table entry.

IP address
Displays the IP helper address associated with this table entry.

Hits
Displays the current number of packets that the interface forwards for the specified UDP port in this
table entry.

Active
Activates/deactivates the table entry.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Reset statistics
Resets the table statistics.

Create

Port
Specifies the interface to which the entry applies.

RM GUI EAGLE 249


Release 3.4 03/2020
Routing
[ Routing > L3 Relay ]

Interface configurations take priority over global configurations. If the destination UDP port for a
packet matches any entry on an ingress interface, then the device handles the packet according to
the interface configuration. If none of the interface entries match the packet, then the device
handles the packet according to the global configuration.

Possible values:
 All (default setting)
Relay entries with this port value specify a global configuration.
 <available interfaces>
Used to specify interface configurations.

UDP port
Specifies the helper UDP port criteria for packets received on this interface for this entry. When
active, the device forwards packets received with this destination UDP port value to the IP address
specified in this entry.

Possible values:
 default (default setting)
Equal to UDP port 0.
An entry with a UDP port specified as 0 enables the dhcp, time, nameserver, tacacs, dns, tftp,
netbios-ns, and netbios-dgm entries.
 dhcp
Equal to UDP port 67.
The device forwards DHCP requests for IP address assignment and networking parameters.
 domain
Equal to UDP port 53.
The device forwards DNS requests for host name to IP address conversion.
 isakmp
Equal to UDP port 500.
The device forwards Internet Security Association and Key Management Protocol requests. The
requests specifies procedures and packet formats which establish, negotiate, modify and delete
Security Associations.
 mobile-ip
Equal to UDP port 434.
The device forwards Home Agent Registration requests. Use this value when you install the
device in a network other than the home network.
 nameserver
Equal to UDP port 42.
The device forwards Windows Internet Name Service requests. You use the port to copy the
NetBIOS name table from 1 Windows server to another.
 netbios-dgm
Equal to UDP port 138.
The device forwards NetBIOS Datagram Service requests. The datagram service provides the
ability to send a message to a unique name or to a group name.
 netbios-ns
Equal to UDP port 137.
The device forwards NetBIOS Name Service requests for name registration and resolution.
 ntp
Equal to UDP port 123.
The device forwards Network Time Protocol requests. Use this value for peer-to-peer
synchronization where both peers consider the other to be a time source.

250 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > L3 Relay ]

 pim-auto-rp
Equal to UDP port 496.
The device forwards Protocol Independent Multicast-Automatic-Rendezvous Point requests.
The Rendezvous Point (RP) serves as the root of the shared multicast delivery tree and is
responsible for gathering multicast data from different sources, then forwarding the data to the
clients.
 rip
Equal to UDP port 520.
The device forwards RIP requests and RIP response messages.
 tacacs
Equal to UDP port 49.
The device forwards TACACS Login Host Protocol requests for remote authentication and
related services for networked access control through a centralized server.
 tftp
Equal to UDP port 69.
The device forwards Trivial File Transfer Protocol requests and responses.
 time
Equal to UDP port 37.
The device forwards Time Protocol requests. The device forwards client requests to a server
that supports the time protocol. The server then responds with a message containing an integer
representing the number of seconds since 00:00 1 January, 1900 GMT, and closes the data link.
 0..65535
When you know the UDP port number, the device lets you specify the port number directly.

IP address
Specifies the IP helper address for packets received on this interface.

Possible values:
 Valid IP address
An address of [Link] identifies the entry as a discard entry. The device drops packets that
match a discard entry. You specify discard entries only on the interfaces.

RM GUI EAGLE 251


Release 3.4 03/2020
Routing
[ Routing > Loopback Interface ]

7.8 Loopback Interface


[ Routing > Loopback Interface ]

A loopback interface is a virtual network interface without reference to a physical port. Loopback
interfaces are constantly available while the device is in operation.

The device lets you create router interfaces on the basis of loopback interfaces. Using such a router
interface, the device is constantly available, even during periods of inactivity of individual router
interfaces.

Up to 8 loopback interfaces can be set up in the device.

Table

Index
Displays the number that uniquely identifies the loopback interface.

Port
Displays the name of the loopback interface.

IP address
Specifies the IP address for the loopback interface.

Possible values:
 Valid IPv4 address (default setting: [Link])

Subnet mask
Specifies the netmask for the loopback interface.

Possible values:
 Valid IPv4 netmask (default setting: [Link])
Example: [Link]

Active
Displays whether the loopback interface is active or inactive.

Possible values:
 marked (default setting)
The loopback interface is active.
When sending SNMP traps, the device uses the IP address of the first loopback interface as the
sender.
 unmarked
The loopback interface is inactive.

252 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > Loopback Interface ]

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Opens the Create dialog to create a loopback interface.


 In the Index field, you specify the number that uniquely identifies the loopback interface.
Possible values:
– 1..8

RM GUI EAGLE 253


Release 3.4 03/2020
Routing
[ Routing > L3-Redundancy ]

7.9 L3-Redundancy
[ Routing > L3-Redundancy ]

The menu contains the following dialogs:


 VRRP

7.9.1 VRRP
[ Routing > L3-Redundancy > VRRP ]

The Virtual Router Redundancy Protocol (VRRP) is a procedure that lets the system react to the
failure of a router.

You use VRRP in networks with end devices that support 1 entry for the default gateway. If the
default gateway fails, then VRRP helps ensure that the end devices find a redundant gateway.

Note: You find detailed information on VRRP in the “Configuration” user manual.

The menu contains the following dialogs:


 VRRP Configuration
 VRRP Statistics
 VRRP Tracking

254 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > L3-Redundancy > VRRP > Configuration ]

[Link] VRRP Configuration


[ Routing > L3-Redundancy > VRRP > Configuration ]

This dialog lets you specify the following settings:


 up to 8 virtual routers per router interface
 up to 2 addresses per virtual router

Operation

Operation
Enables/disables the VRRP redundancy in the device.

Possible values:
 On
The VRRP function is enabled.
 Off (default setting)
The VRRP function is disabled.

Information + Configuration

Version
Specifies the VRRP version.

Send trap (VRRP master)


Activates/deactivates the sending of SNMP traps when the device is the VRRP master.

Possible values:
 marked
The sending of SNMP traps is active.
If the device is the VRRP master, then the device sends an SNMP trap.
 unmarked (default setting)
The sending of SNMP traps is inactive.

The prerequisite for sending SNMP traps is that you enable the function in the Diagnostics > Status
Configuration > Alarms (Traps) dialog and specify at least 1 trap destination.

Send trap (VRRP authentication failure)


Activates/deactivates the sending of SNMP traps when the device receives a VRRP packet
including authentication information.

Note: The device supports only VRRP packets without authentication information. In order for the
device to operate in conjunction with other devices that support VRRP authentication, verify that on
those devices the VRRP authentication is not applied.

RM GUI EAGLE 255


Release 3.4 03/2020
Routing
[ Routing > L3-Redundancy > VRRP > Configuration ]

Possible values:
 marked
The sending of SNMP traps is active.
If the device receives a VRRP packet including authentication information, then the device
sends an SNMP trap.
 unmarked (default setting)
The sending of SNMP traps is inactive.

The prerequisite for sending SNMP traps is that you enable the function in the Diagnostics > Status
Configuration > Alarms (Traps) dialog and specify at least 1 trap destination.

Table

Port
Displays the port number to which the table entry relates.

VRID
Displays the Virtual Router IDentifier.

Active
Activates/deactivates the VRRP instance specified in this row.

Possible values:
 marked
The VRRP instance is active.
 unmarked (default setting)
The VRRP instance is inactive.

Oper status
Specifies the row status. The operational state of the related virtual router controls the row status
of a currently active row in the table.

Possible values:
 active
The instance is available for use.
 notInService
The instance exists in the device, but necessary information is missing and it is unavailable for
use.
 notReady
The instance exists in the device, but necessary information is missing and it is unavailable for
use.

State
Displays the VRRP state.

256 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > L3-Redundancy > VRRP > Configuration ]

Possible values:
 initialize
VRRP is in the initialization phase, the function is inactive, or the master router is still unnamed.
 backup
The router sees the possibility of becoming the master router.
 master
The router is the master router.

Base priority
Specifies the priority of the virtual router. The value differs from Priority if tracked objects are down
or the virtual router is the IP address owner.

Possible values:
 1..254 (default setting: 100)

When you configure multiple VRRP routers in a single instance, distribute the priority values
uniformly on the routers. For example, assign the priority value of 50 to the primary router, the value
of 100 to the next router. Repeat the steps with the value 150, and so on.

Priority
Specifies the VRRP priority value.

The router with the higher priority value takes over the master router role. If the virtual router IP
address is the same as an IP address of a router interface, then the router is the “owner” of the IP
address. If an IP address owner exists, then VRRP assigns the IP address owner the VRRP priority
255 and declares the router as the master router.

Possible values:
 1..255 (default setting: 100)

When you plan to remove a master router from the network, lower the priority number to force an
election, thus reducing the black hole period.

Virtual IP address
Displays the virtual IP address in the subnet of the primary IP address on the interface. If no match
is found, then the device returns an unspecified virtual address. If no virtual address is configured,
then [Link] is returned.

Possible values:
 Valid IPv4 address

Preempt mode
Activates/deactivates the preempt mode. This setting specifies whether this router, as a backup
router, takes over the master router role when the master router has a lower VRRP priority.

RM GUI EAGLE 257


Release 3.4 03/2020
Routing
[ Routing > L3-Redundancy > VRRP > Configuration ]

Possible values:
 marked (default setting)
When you enable the preempt mode, this router takes the master router role from a router with
a lower VRRP priority without waiting for an election.
 unmarked
When you disable the Preempt mode, this router assumes the role of a backup router and listens
for master router advertisements. After the master down interval expires, without receiving
advertisements from the master router, this router participates in the master router election
process.

VRRP master candidate


Specifies the primary virtual router IP address.

When the interface has several specified IP addresses, the parameter lets the user select an IP
address as the Master IP address.

Possible values:
 Valid IPv4 address (default setting: [Link])
The default setting [Link] indicates that the router is using the lower IP address as the Master
IP address.

Master IP address
Displays the current master router interface IP address.

Possible values:
 Valid IPv4 address (default setting: [Link])

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Opens the Create window to add a new entry to the table.


 In the Port field, you specify the router interface.
 In the VRID field, you specify the Virtual Route Identifier (VRID).

Setting up the VRRP router instance

The device lets you set up to 8 virtual routers per router interface.

Before you set up a VRRP instance, verify that network routing functions properly and set the IP
addresses on the router interfaces used for the VRRP instances.

258 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > L3-Redundancy > VRRP > Configuration ]

Perform the following steps:


 In the Routing > L3-Redundancy > VRRP > Configuration dialog, open the Wizard window.
 In the Wizard window, open the Create or select entry page.
– Select a router interface from the Port drop-down list.
– Specify the Virtual Router IDentifier in the VRID column.
 In the Wizard window, open the Edit entry page.
– In the Configuration frame, specify the values for the following parameters:
Priority
Preempt mode
Advertisement interval [s]
Ping answer
Select the VRRP master candidate IP address from the drop-down list.
– VRRP advert address (IP address of the partner HiVRRP router)
– VRRP advert interval [ms]
– Link-down notify address (IP address of the second router to which the device sends link-down
notifications)
You use this function when the virtual router consists of 2 VRRP routers.
– Domain ID
– Domain role
 To transfer the settings to the VRRP router interface table, click the Finish button.
 In the Routing > L3-Redundancy > VRRP > Configuration dialog, select the On radio button in the
Operation frame. Then click the button.

Editing an existing VRRP router instance


 In the Routing > L3-Redundancy > VRRP > Configuration dialog, highlight a row in the table and click
the button to edit it.
 As an alternative, double-click a field in the table and edit the entry directly. Or right-click a field
and select a value.

Deleting a VRRP router instance


 In the Routing > L3-Redundancy > VRRP > Configuration dialog, highlight a row and click the
button.

[VRRP configuration (Wizard)]

The Wizard window helps you to create a VRRP router instance.

Prerequisites:
 Network routing is functioning correctly.
 On the interfaces used in the VRRP instance the IP addresses are specified.

After closing the Wizard window, click the button to save your settings.

RM GUI EAGLE 259


Release 3.4 03/2020
Routing
[ Routing > L3-Redundancy > VRRP > Configuration ]

[VRRP configuration (Wizard) – Create or select entry]

Table

Port
Displays the router interface number to which the table entry relates.

VRID
Displays the Virtual Router IDentifier.

IP address
Displays the primary IP address of the router interface.

You specify this address in the Routing > Interfaces > Configuration dialog.

Netmask
Displays the netmask of primary IP address.

You specify this subnet mask in the Routing > Interfaces > Configuration dialog.

Area under the table

Port
Specifies the router interface number to which the table entry relates.

Possible values:
 <Available router interfaces>

VRID
Specifies the Virtual Router IDentifier.

A virtual router uses 00-00-5E-00-01-XX as its MAC address. The value specified here replaces
the last octet (XX) in the MAC address. Assign a unique value to every physical router within a virtual
router instance. The device changes the effective priority value to 255 for a physical router with the
same IP address as the virtual router.

Possible values:
 1..255

260 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > L3-Redundancy > VRRP > Configuration ]

[VRRP configuration (Wizard) – Edit entry – VRRP]

Operation

Operation
Enables/disables the VRRP redundancy in the device.

Possible values:
 On
The VRRP function is enabled.
 Off (default setting)
The VRRP function is disabled.

Information

Port
Displays the router interface number to which the table entry relates.

VRID
Displays the Virtual Router IDentifier.

Configuration

Base priority
Specifies the priority of the virtual router. The value differs from Priority if tracked objects are down
or the virtual router is the IP address owner.

Possible values:
 1..254 (default setting: 100)

When you configure multiple VRRP routers in a single instance, distribute the priority values
uniformly on the routers. For example, assign the priority value of 50 to the primary router, the value
of 100 to the next router. Repeat the steps with the value 150, and so on.

Priority
Specifies the VRRP priority value.

The router with the higher priority value takes over the master router role. If the virtual router IP
address is the same as an IP address of a router interface, then the router is the “owner” of the IP
address. If an IP address owner exists, then the VRRP function assigns the IP address owner the
priority value 255 and declares the router as the master router.

RM GUI EAGLE 261


Release 3.4 03/2020
Routing
[ Routing > L3-Redundancy > VRRP > Configuration ]

Possible values:
 1..255 (default setting: 100)

Disabling or removing an VRRP router, which is in the master role, forces the instance to send an
advertisement with priority value 0. This lets the other backup routers know that the master is not
participating. Sending a priority value 0 forces a new election.

Preempt mode
Activates/deactivates the preempt mode. This setting specifies whether this router, as a backup
router, takes over the master router role when the master router has a lower VRRP priority.

Possible values:
 marked (default setting)
When you enable the Preempt mode, this router takes the master router role from a router with a
lower VRRP priority without waiting for an election.
 unmarked
When you disable the Preempt mode, this router assumes the role of a backup router and listens
for master router advertisements. After the master down interval expires, without receiving
advertisements from the master router, this router participates in the master router election
process.

Advertisement interval [s]


Specifies the interval between master router advertisements in seconds.

Possible values:
 1..255 (default setting: 1)

Note: The longer the advertisement interval, the longer the time for which backup routers wait for
a message from the master router before starting a new election process (master down interval).
Also, specify the same value on every participant in a given virtual router instance.

Ping answer
Activates/deactivates the ping answer function in the device. You use the VRRP ping for
connectivity analyses.

The prerequisite for allowing the device to answer ping requests from the interfaces is that you
activate the Send echo reply function globally. In the Routing > Global dialog, ICMP filter frame, mark
the Send echo reply checkbox.

Possible values:
 marked (default setting)
The Ping answer function in the device is active.
The device answers ICMP ping requests.
 unmarked
The Ping answer function in the device is inactive.
The device ignores ICMP ping requests.

VRRP master candidate


Primary virtual router IP address.

262 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > L3-Redundancy > VRRP > Configuration ]

Physical routers within a virtual router instance use the VRRP IP address to communication with
themselves. If the virtual router IP address is the same as an IP address of a router interface, then
the router is the “owner” of the IP address and the master router.

Possible values:
 Valid IP address (default setting: [Link])

[VRRP configuration (Wizard) – Tracking]

Current track entries

Type
Displays the type of the tracking object.

Possible values:
 interface
The device monitors the link status of its physical ports or of its link aggregation, LRE or VLAN
router interface.
 ping
The device monitors the route to a remote router or end device by means of periodic ping
requests.
 logical
The device monitors tracking objects logically linked to each other and thus enables complex
monitoring tasks.

Track ID
Displays the identification number of the tracking object.

Track name
Displays the name of the tracking object made up of Type and Track ID.

Assigned track entries

Track name
Displays the name of the tracking object to which the virtual router is linked.

If the result for a tracking object is negative, then the VRRP instance reduces the priority of the
virtual router. The tracking object is negative for example, if the monitored interface is inactive or
the monitored router cannot be reached.

RM GUI EAGLE 263


Release 3.4 03/2020
Routing
[ Routing > L3-Redundancy > VRRP > Configuration ]

Possible values:
 Name of the tracking object, made up of Type and Track ID.
 Logical trackers, which combine multiple trackers
 –
No tracking object selected.

You set up tracking objects in the Routing > Tracking > Configuration dialog.

Decrement
Specifies the value by which the VRRP instance reduces the priority of the virtual router when the
monitoring result is negative.

Possible values:
 1..253 (default setting: 20)

Note: If in the Routing > L3-Redundancy > VRRP > Configuration dialog the value in the Priority column
is 255, then the virtual router is the owner of the IP address. In this case the priority of the virtual
router remains unchanged.

[VRRP configuration (Wizard) – Virtual IP addresses]

Information

IP address
Displays the primary IP address of the router interface.

Multinetting

Additional IP address
Displays the secondary IP addresses of the router interface.

The device lets you specify 1 primary and 1 secondary multinetting addresses per router interface.

Additional netmask
Displays the subnet mask of the secondary IP addresses.

Virtual IP addresses

IP address
Displays the assigned IP address of the master router within a virtual router.

264 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > L3-Redundancy > VRRP > Configuration ]

Virtual IP addresses
Specifies the virtual IP address to be assigned.

To insert the IP address in the IP address table, click the Add button.

RM GUI EAGLE 265


Release 3.4 03/2020
Routing
[ Routing > L3-Redundancy > VRRP > Statistics ]

[Link] VRRP Statistics


[ Routing > L3-Redundancy > VRRP > Statistics ]

This dialog displays the number of counters that count events relevant to the VRRP function.

Information

Checksum errors
Displays the number of VRRP messages received with the wrong checksum.

Version errors
Displays the number of VRRP messages received with an unknown or unsupported version
number.

VRID errors
Displays the number of VRRP messages received with an invalid Virtual Router IDentifier for this
virtual router.

Table

Port
Displays the router interface number to which the table entry relates.

VRID
Displays the Virtual Router IDentifier.

Become master
Displays the number of times that the device has taken the master role. This entry helps you to
analyze the network. When this number is low, your network is relatively stable.

Advertise received
Displays the number of VRRP advertisements received.

Advertise interval errors


Displays the number of VRRP advertisements received by the router outside the advertisement
interval. The value lets you determine if the routers have the same advertise interval specified
across the virtual router instance.

Authentication failures
Displays the number of VRRP advertisements received with authentication errors.

266 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > L3-Redundancy > VRRP > Statistics ]

IP TTL errors
Displays the number of VRRP advertisements received with an IP TTL not equal to 255.

Priority zero packets received


Displays the number of VRRP advertisements received with priority 0.

Priority zero packets sent


Displays the number of VRRP advertisements that the device sent with priority 0.

Invalid type packets received


Displays the number of VRRP advertisements received with an invalid type.

Address list errors


Displays the number of VRRP advertisements received for which the address list does not match
the address list configured locally for the virtual router.

Invalid authentication type


Displays the number of VRRP advertisements received with an invalid authentication type.

Authentication type mismatch


Displays the number of VRRP advertisements received with an incorrect authentication type.

Packet length errors


Displays the number of VRRP advertisements received with an incorrect packet length.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 267


Release 3.4 03/2020
Routing
[ Routing > L3-Redundancy > VRRP > Tracking ]

[Link] VRRP Tracking


[ Routing > L3-Redundancy > VRRP > Tracking ]

VRRP tracking lets you follow the operation of specific object and react to a change in the object
status. The function is periodically notified about the tracked object and displays the changes in the
table. The table displays the object statuses as either up, down or notReady.
 To enter a track object in the table, click the button.

Table

Port
Displays the router interface number of the virtual router.

VRID
Displays the virtual router ID for this virtual router.

Track name
Displays the name of the tracking object to which the virtual router is linked.

If the result for a tracking object is negative, then the VRRP instance reduces the priority of the
virtual router. The tracking object is negative for example, if the monitored interface is inactive or
the monitored router cannot be reached.

Possible values:
 Name of the tracking object, made up of Type and Track ID.
 Logical trackers, which combine multiple trackers
 –
No tracking object selected.

You set up tracking objects in the Routing > Tracking > Configuration dialog.

Decrement
Specifies the value by which the VRRP instance reduces the priority of the virtual router when the
monitoring result is negative.

Possible values:
 1..253 (default setting: 20)

Note: If in the Routing > L3-Redundancy > VRRP > Configuration dialog the value in the Priority column
is 255, then the virtual router is the owner of the IP address. In this case the priority of the virtual
router remains unchanged.

Status
Displays the monitoring result of the tracking object.

268 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > NAT ]

Possible values:
 notReady
The tracking object is not operating.
 up
The monitoring result is positive:
– The link status is active.
or
– The remote router or end device is reachable.
 down
The monitoring result is negative:
– The link status is inactive.
or
– The remote router or end device is not reachable.
 A combination of the up and down trackers.

Active
Displays whether the monitoring of the tracking object is active or inactive.

Possible values:
 active
The monitoring of the tracking object is active.
 notReady
The monitoring of the tracking object is inactive. You activate the monitoring in the Routing >
Tracking > Configuration dialog, Active column.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Opens the Create window to add a new entry to the table.


 In the Port VRID drop-down list, you select the interface and router ID of a virtual router that has
been set up.

 In the Track name drop-down list, you select the tracking object with which the device links the
virtual router.

7.10 NAT
[ Routing > NAT ]

The menu contains the following dialogs:


 NAT Global
 1:1 NAT
 Destination NAT
 Masquerading NAT
 Double NAT

RM GUI EAGLE 269


Release 3.4 03/2020
Routing
[ Routing > NAT > NAT Global ]

7.10.1 NAT Global


[ Routing > NAT > NAT Global ]

Network Address Translation (NAT) contains several procedures which automatically change the
IP address information in the data packet. When configured in the device, the NAT function enables
communication links between devices in different networks.

The device provides a multi-step approach for setting up and applying the NAT rules:
 Create rule.
 Assign rule to a router interface.
Up to this step, changes have no effect on the behavior of the device and the data stream.
 Apply the rule to the data stream; to do this, click in the Routing > NAT > NAT Global dialog the
Commit changes button.

This dialog displays how many NAT rules can be set up for the individual NAT processes and
indicates changes to the active NAT rules. By clicking the Commit changes button, you apply the NAT
rules configured to the data stream.

Information

1:1 NAT rules (max.)


Displays how many rules can be configured in the device for the 1:1 NAT function.

Destination NAT rules (max.)


Displays how many rules can be configured in the device for the Destination NAT function.

Masquerading NAT rules (max.)


Displays how many rules can be configured in the device for the Masquerading NAT function.

Double NAT rules (max.)


Displays how many rules can be configured in the device for the Double NAT function.

1:1 NAT pending actions


Displays whether the 1:1 NAT rules used in the data stream differ from the saved 1:1 NAT rules.

Possible values:
 marked
At least one saved 1:1 NAT rule contains modified settings. To apply the changes to the data
stream, click the button and then the Commit changes item.
 unmarked
The device applies the saved 1:1 NAT rules to the data stream.

Destination NAT pending actions


Displays whether the Destination NAT rules used in the data stream differ from the saved Destination
NAT rules.

270 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > NAT > NAT Global ]

Possible values:
 marked
At least one saved Destination NAT rule contains modified settings. To apply the changes to the
data stream, click the button and then the Commit changes item.
 unmarked
The device applies the saved Destination NAT rules to the data stream.

Masquerading NAT pending actions


Displays whether the Masquerading NAT rules used in the data stream differ from the saved
Masquerading NAT rules.

Possible values:
 marked
At least one saved Masquerading NAT rule contains modified settings. To apply the changes to
the data stream, click the button and then the Commit changes item.
 unmarked
The device applies the saved Masquerading NAT rules to the data stream.

Double NAT pending actions


Displays whether the Double NAT rules used in the data stream differ from the saved Double NAT
rules.

Possible values:
 marked
At least one saved Double NAT rule contains modified settings. To apply the changes to the data
stream, click the button and then the Commit changes item.
 unmarked
The device applies the saved Double NAT rules to the data stream.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Commit changes
Applies the rules saved in the device to the data stream.

In the process, the device also removes the state information from the packet filter. This includes
potential DCE RPC information of the OPC enforcer. In the process, the device interrupts open
communication connections.

Note: While the device is activating the saved rules, the establishment of any new communication
connections is impossible.

RM GUI EAGLE 271


Release 3.4 03/2020
Routing
[ Routing > NAT > 1:1 NAT ]

7.10.2 1:1 NAT


[ Routing > NAT > 1:1 NAT ]

The 1:1 NAT function lets you establish communication links within a local network to devices that
are located in other networks. The NAT router virtually “shifts” the devices into the public network.
To do this, the NAT router replaces the virtual with the actual IP address in the data packet while
sending it. A typical application is connecting some identically structured production cells with the
same IP address to a server farm.

The prerequisite for the 1:1 NAT process is that the NAT router itself responds to ARP requests. To
make this happen, turn on the Proxy ARP function on the ingress interface.

1:1 NAT
Zieladresse Neue Zieladresse
Destination Address New Destination Address
Ingress Egress
Interface Interface
[Link] [Link]
Proxy ARP

[Link]/24
[Link]/24
Regel

dest [Link]
Rule

new dest [Link]

[Link]

Figure 2: How the 1:1 NAT function works

 To use the NAT function, set up a router interface for each network and turn on the routing
function in the device.

Note: If you enable the VRRP function on a router interface, then the 1:1 NAT function is ineffective
on this router interface.

The data packets go through the filter functions of the device in the following sequence:

Operating System

Destination Address Modification Ingress Egress Source Address Modification


1:1 NAT Packet Policy Routing Packet Masquerading NAT
Destination NAT Filter Filter Double NAT
Double NAT

MAC-based ACL

IP-based ACL

DoS
Switching Chip

Network 1 Network 2

Figure 3: Processing sequence of the data packets in the device

The menu contains the following dialogs:


 1:1 NAT Rule

272 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > NAT > 1:1 NAT > Rule ]

[Link] 1:1 NAT Rule


[ Routing > NAT > 1:1 NAT > Rule ]

In this dialog, you generate and edit the 1:1 NAT rules and assign router interfaces to which the
device applies the 1:1 NAT rules.

Table

Index
Displays the index number to which the table entry relates.

Possible values:
 1..255

Rule name
Displays the name of the 1:1 NAT rule. To change the name, click the relevant field.

Possible values:
 Alphanumeric ASCII character string with 0..32 characters

Priority
Specifies the priority of the 1:1 NAT rule.

Using the priority, you specify the order in which the device applies several rules to the data stream.
The device applies the rules in ascending order starting with priority 1.

Possible values:
 1..6500 (default setting: 1)

Ingress interface
Assigns the 1:1 NAT rule to the router interface on which the device receives data packets. The 1:1
NAT rule makes the destination device virtually accessible in the network connected here.

Possible values:
 <Interface number>
The device applies the 1:1 NAT rule to this router interface, and only to data packets addressed
to the IP address specified in the Destination address column.
 no Port
No router interface is assigned to the 1:1 NAT rule. Someone removed the router interface after
the last edit of the 1:1 NAT rule.

You enable on the ARP proxy function on this router interface in the Routing > Interfaces >
Configuration dialog.

Destination address
Specifies the destination address of the data packets to which the device applies the 1:1 NAT rule.
The device sends data packets with this destination address to the destination address specified in
the New destination address column.

RM GUI EAGLE 273


Release 3.4 03/2020
Routing
[ Routing > NAT > 1:1 NAT > Rule ]

Possible values:
 Valid IPv4 address
The device applies the 1:1 NAT rule only to data packets containing the destination address
specified here.
 Valid IPv4 address and netmask in CIDR notation
The device applies the 1:1 NAT rule only to data packets containing a destination address in the
subnet specified here.

Egress interface
Assigns the 1:1 NAT rule to the router interface on which the device forwards the modified data
packets. The destination device can actually be reached in the network connected here.

Possible values:
 <Interface number>
The device forwards the modified data packets on this router interface.
 no Port
No router interface is assigned to the 1:1 NAT rule. Someone removed the router interface after
the last edit of the 1:1 NAT rule.

New destination address


Specifies the actual IP address of the destination device. The device sends data packets to the
destination address specified here.

Possible values:
 Valid IPv4 address
The device replaces the destination address in the data packet with this new destination
address.
 Valid IPv4 address and netmask in CIDR notation
The device replaces the destination address in the data packet with a destination address in the
subnet specified here.

Trap
Activates/deactivates the sending of SNMP traps when the 1:1 NAT rule is applied to data packets.

Possible values:
 marked
If the device applies the 1:1 NAT rule to a data packet, then the device sends an SNMP trap.
 unmarked (default setting)
The sending of SNMP traps is deactivated.

The prerequisite for sending SNMP traps is that you enable the function in the Diagnostics > Status
Configuration > Alarms (Traps) dialog and specify at least 1 trap destination.

Log
Activates/deactivates the logging in the log file. See the Diagnostics > Report > System Log dialog.

274 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > NAT > Destination NAT ]

Possible values:
 marked
Logging is activated.
When the device applies the 1:1 NAT rule to a data packet, the device places an entry in the log
file.
 unmarked (default setting)
Logging is deactivated.

Active
Activates/deactivates the 1:1 NAT rule.

Possible values:
 marked
The rule is active.
 unmarked (default setting)
The rule is inactive.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

7.10.3 Destination NAT


[ Routing > NAT > Destination NAT ]

The Destination NAT function lets you divert the data stream of outgoing communication links to or
through a server in a local network.

A special form of the Destination NAT function is port forwarding. You use port forwarding to hide the
structure of a network from the outside while still allowing communication links from the outside into
the network. A typical application is remote control of a PC in a production cell. The maintenance
station establishes the communication link to the NAT router, and the Destination NAT function takes
care of the routing to the production cell.

RM GUI EAGLE 275


Release 3.4 03/2020
Routing
[ Routing > NAT > Destination NAT ]

src <any>
dest <any> Destination NAT

Regel
Rule
new dest [Link]
proto tcp
dest port 80,20,21
[Link]/24
Zieladresse
Destination Address
<any>
[Link] Ingress
Interface
Quelladresse DMZ
Source Address

[Link]

Neue Zieladresse
New Destination Address

(Port Forwarding)

Ingress [Link]/24
Interface

[Link]:80
[Link]:8080
Zieladresse Neue Zieladresse
Destination Address New Destination Address

Figure 4: How the Destination NAT function works

 To use the NAT function, set up a router interface for each network and turn on the routing
function in the device.

Note: If you enable the VRRP function on a router interface, then the Destination NAT function is
ineffective on this router interface.

The data packets go through the filter functions of the device in the following sequence:

Operating System

Destination Address Modification Ingress Egress Source Address Modification


1:1 NAT Packet Policy Routing Packet Masquerading NAT
Destination NAT Filter Filter Double NAT
Double NAT

MAC-based ACL

IP-based ACL

DoS
Switching Chip

Network 1 Network 2

Figure 5: Processing sequence of the data packets in the device

The menu contains the following dialogs:


 Destination NAT Rule
 Destination NAT Mapping
 Destination NAT Overview

276 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > NAT > Destination NAT > Rule ]

[Link] Destination NAT Rule


[ Routing > NAT > Destination NAT > Rule ]

In this dialog you create and edit the Destination NAT rules.

You assign a router interface to the affected Destination NAT rule in the Routing > NAT > Destination
NAT > Mapping dialog.

An overview of which Destination NAT rule is to be assigned to which router interface can be found
in the Routing > NAT > Destination NAT > Overview dialog.

Table

Index
Displays the index number to which the table entry relates.

Possible values:
 1..255

Rule name
Displays the name of the Destination NAT rule. To change the name, click the relevant field.

Possible values:
 Alphanumeric ASCII character string with 0..32 characters

Source address
Specifies the source address of the data packets to which the device applies the Destination NAT
rule.

Possible values:
 any (default setting)
The device applies the Destination NAT rule to data packets with any source address.
 Valid IPv4 address
The device applies the Destination NAT rule only to data packets containing the source address
specified here.
 Valid IPv4 address and netmask in CIDR notation
The device applies the Destination NAT rule only to data packets containing a source address in
the subnet specified here.
 An exclamation mark (!) preceding the IP address reverses the expression into its opposite. The
device applies the Destination NAT rule to data packets NOT containing the source address
specified here.

Source port
Specifies the source port of the data packets to which the device applies the Destination NAT rule.

The prerequisite for specifying a source port is that, in the Protocol field, you specify the value TCP
or UDP.

RM GUI EAGLE 277


Release 3.4 03/2020
Routing
[ Routing > NAT > Destination NAT > Rule ]

Possible values:
 any (default setting)
The device applies the Destination NAT rule to every data packet without considering the source
port.
 1..65535
The device applies the Destination NAT rule only to data packets containing the specified source
port.
The field lets you specify the following options:
– You specify a port with a single numerical value, for example 21.
– You specify multiple individual ports with numerical values separated by commas, for
example 21,80,110.
– You specify a port range with numerical values connected by dashes, for example 2000-
3000.
– You can also combine ports and port ranges, for example 21,2000-3000,65535.
The column lets you specify up to 15 numerical values. When you enter 21,2000-
3000,65535, for example, you use 4 of 15 numerical values.

Destination address
Specifies the destination address of the data packets to which the device applies the Destination NAT
rule. The device sends data packets with this destination address to the destination address
specified in the New destination address column.

Possible values:
 any
The device applies the Destination NAT rule to data packets with any destination address.
 Valid IPv4 address
The device applies the Destination NAT rule only to data packets containing the destination
address specified here.
 Valid IPv4 address and netmask in CIDR notation
The device applies the Destination NAT rule only to data packets containing a destination address
in the subnet specified here.
 An exclamation mark (!) preceding the IP address reverses the expression into its opposite. The
device applies the Destination NAT rule to data packets NOT containing the destination address
specified here.

Destination port
Specifies the destination port of the data packets to which the device applies the Destination NAT
rule.

Possible values:
 any (default setting)
The device applies the Destination NAT rule to every data packet without considering the
destination port.
 1..65535
The device applies the Destination NAT rule only to data packets containing the specified
destination port.
The field lets you specify the following options:
– You specify a port with a single numerical value, for example 21.
– You specify multiple individual ports with numerical values separated by commas, for
example 21,80,110.

278 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > NAT > Destination NAT > Rule ]

– You specify a port range with numerical values connected by dashes, for example 2000-
3000.
– You can also combine ports and port ranges, for example 21,2000-3000,65535.
The column lets you specify up to 15 numerical values. When you enter 21,2000-
3000,65535, for example, you use 4 of 15 numerical values.

New destination address


Specifies the actual IP address of the destination device. The device sends data packets to the
destination address specified here.

Possible values:
 Valid IPv4 address
The device replaces the destination address in the data packet with this new destination
address.

New destination port


Specifies the port of the destination device. The device forwards data packets to the destination
port specified here.

Possible values:
 any
The device retains the original destination port in the data packet.
 1..65535
The device replaces the destination port in the packet with this new destination port.

Protocol
Restricts the Destination NAT rule to an IP protocol. The device applies the Destination NAT rule only
to packets of the specified IP protocol.

Possible values:
 icmp
Internet Control Message Protocol (RFC 792)
 igmp
Internet Group Management Protocol
 ipip
IP in IP tunneling (RFC 1853)
 tcp
Transmission Control Protocol (RFC 793)
 udp
User Datagram Protocol (RFC 768)
 esp
IPsec Encapsulated Security Payload (RFC 2406)
 ah
IPsec Authentication Header (RFC 2402)
 icmpv6
Internet Control Message Protocol for IPv6
 any (default setting)
The device applies the Destination NAT rule to every data packet without considering the IP
protocol.

RM GUI EAGLE 279


Release 3.4 03/2020
Routing
[ Routing > NAT > Destination NAT > Rule ]

Log
Activates/deactivates the logging in the log file. See the Diagnostics > Report > System Log dialog.

Possible values:
 marked
Logging is activated.
When the device applies the Destination NAT rule to a data packet, the device places an entry in
the log file.
 unmarked (default setting)
Logging is deactivated.

Trap
Activates/deactivates the sending of SNMP traps when the Destination NAT rule is applied to data
packets.

Possible values:
 marked
If the device applies the Destination NAT rule to a data packet, then the device sends an SNMP
trap.
 unmarked (default setting)
The sending of SNMP traps is deactivated.

The prerequisite for sending SNMP traps is that you enable the function in the Diagnostics > Status
Configuration > Alarms (Traps) dialog and specify at least 1 trap destination.

Active
Activates/deactivates the Destination NAT rule.

Possible values:
 marked
The rule is active.
 unmarked (default setting)
The rule is inactive.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

280 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > NAT > Destination NAT > Mapping ]

[Link] Destination NAT Mapping


[ Routing > NAT > Destination NAT > Mapping ]

In this dialog you assign the Destination NAT rules to a router interface. To do this, click the button
and then the Assign item.

You create and edit the Destination NAT rules in the Routing > NAT > Destination NAT > Rule.

An overview of which Destination NAT rule is to be assigned to which router interface can be found
in the Routing > NAT > Destination NAT > Overview dialog.

Table

Port
Displays the number of the router interface on which the device applies the Destination NAT rule.

Rule index
Displays the sequential number of the Destination NAT rule. See the Index column in the Routing >
NAT > Destination NAT > Rule dialog.

Rule name
Displays the name of the Destination NAT rule. See the Rule name column in the Routing > NAT >
Destination NAT > Rule dialog.

Direction
Displays whether the device applies the Destination NAT rule to data packets received or sent.

Possible values:
 ingress
The device applies the Destination NAT rule to data packets received on the router interface.

Priority
Specifies the priority of the Destination NAT rule.

Using the priority, you specify the order in which the device applies several rules to the data stream.
The device applies the rules in ascending order starting with priority 1.

Possible values:
 1..6500 (default setting: 1)

Active
Activates/deactivates the Destination NAT rule.

RM GUI EAGLE 281


Release 3.4 03/2020
Routing
[ Routing > NAT > Destination NAT > Mapping ]

Possible values:
 marked
The rule is active.
 unmarked (default setting)
The rule is inactive.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Assign
Opens the Assign dialog. In this dialog, you assign a configured router interface of an existing
Destination NAT rule.

282 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > NAT > Destination NAT > Overview ]

[Link] Destination NAT Overview


[ Routing > NAT > Destination NAT > Overview ]

In this dialog you will find an overview of which Destination NAT rule is assigned to which router
interface.

You create and edit the Destination NAT rules in the Routing > NAT > Destination NAT > Rule.

You assign a router interface to the affected Destination NAT rule in the Routing > NAT > Destination
NAT > Mapping dialog.

Table

Port
Displays the number of the router interface on which the device applies the Destination NAT rule.

Rule index
Displays the sequential number of the Destination NAT rule. See the Index column in the Routing >
NAT > Destination NAT > Rule dialog.

Rule name
Displays the name of the Destination NAT rule. See the Rule name column in the Routing > NAT >
Destination NAT > Rule dialog.

Destination address
Displays the destination address of the data packets to which the device applies the Destination NAT
rule. The device sends data packets with this destination address to the destination address
specified in the New destination address column.

New destination address


Displays the actual IP address of the destination device. The device sends data packets to the
destination address specified here.

Trap
Displays whether the device sends an SNTP trap when it applies the Destination NAT rule to a data
packet.

Possible values:
 marked
The device sends an SNMP trap.
 unmarked
The device does not send an SNMP trap.

The prerequisite for sending SNMP traps is that you enable the function in the Diagnostics > Status
Configuration > Alarms (Traps) dialog and specify at least 1 trap destination.

RM GUI EAGLE 283


Release 3.4 03/2020
Routing
[ Routing > NAT > Destination NAT > Overview ]

Log
Displays whether the device places an entry in the log file when it applies the Destination NAT rule
to a data packet.

Possible values:
 marked
When the device applies the Destination NAT rule to a data packet, the device places an entry in
the log file. See the Diagnostics > Report > System Log dialog.
 unmarked
Logging is disabled.

Direction
Displays whether the device applies the Destination NAT rule to data packets received or sent.

Possible values:
 ingress
The device applies the Destination NAT rule to data packets received on the router interface.

Priority
Displays the priority of the Destination NAT rule.

The device applies rules to the data stream in ascending order starting with priority 1.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

284 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > NAT > Masquerading NAT ]

7.10.4 Masquerading NAT


[ Routing > NAT > Masquerading NAT ]

The Masquerading NAT function hides any number of devices behind the IP address of the NAT
router and thus hides the structure of a network from other networks. To do this, the NAT router
replaces the sender address in the data packet with its own IP address. Also, the NAT router
replaces the source port in the data packet with its own value to send the response data packets
back to the original sender later on.

Quelladresse
Source Address

Masquerading NAT
[Link]
[Link]/24

[Link]

[Link]/24 [Link]
Egress
[Link] Interface

Figure 6: How the Masquerading NAT function works

 To use the NAT function, set up a router interface for each network and turn on the routing
function in the device.

Note: If you enable the VRRP function on a router interface, then the Masquerading NAT function is
ineffective on this router interface.

The data packets go through the filter functions of the device in the following sequence:

Operating System

Destination Address Modification Ingress Egress Source Address Modification


1:1 NAT Packet Policy Routing Packet Masquerading NAT
Destination NAT Filter Filter Double NAT
Double NAT

MAC-based ACL

IP-based ACL

DoS
Switching Chip

Network 1 Network 2

Figure 7: Processing sequence of the data packets in the device

The menu contains the following dialogs:


 Masquerading NAT Rule
 Masquerading NAT Mapping
 Masquerading NAT Overview

RM GUI EAGLE 285


Release 3.4 03/2020
Routing
[ Routing > NAT > Masquerading NAT > Rule ]

[Link] Masquerading NAT Rule


[ Routing > NAT > Masquerading NAT > Rule ]

In this dialog you create and edit the Masquerading NAT rules.

You assign a router interface to the affected Masquerading NAT rule in the Routing > NAT >
Masquerading NAT > Mapping dialog.

An overview of which Masquerading NAT rule is to be assigned to which router interface can be found
in the Routing > NAT > Masquerading NAT > Overview dialog.

Table

Index
Displays the index number to which the table entry relates.

Possible values:
 1..128

Rule name
Displays the name of the Masquerading NAT rule. To change the name, click the relevant field.

Possible values:
 Alphanumeric ASCII character string with 0..32 characters

Source address
Specifies the source address of the data packets to which the device applies the Masquerading NAT
rule.

Possible values:
 any
The device applies the Masquerading NAT rule to data packets with any source address.
 Valid IPv4 address
The device applies the Masquerading NAT rule only to data packets containing the source
address specified here.
 Valid IPv4 address and netmask in CIDR notation
The device applies the Masquerading NAT rule only to data packets containing a source address
in the subnet specified here.
 An exclamation mark (!) preceding the IP address reverses the expression into its opposite. The
device applies the Masquerading NAT rule to data packets NOT containing the source address
specified here.

Source port
Specifies the source port of the data packets to which the device applies the Masquerading NAT rule.

286 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > NAT > Masquerading NAT > Rule ]

Possible values:
 any (default setting)
The device applies the Masquerading NAT rule to every data packet without considering the
source port.
 1..65535
The device applies the Masquerading NAT rule only to data packets containing the specified
source port.
The field lets you specify the following options:
– You specify a port with a single numerical value, for example 21.
– You specify multiple individual ports with numerical values separated by commas, for
example 21,80,110.
– You specify a port range with numerical values connected by dashes, for example 2000-
3000.
– You can also combine ports and port ranges, for example 21,2000-3000,65535.
The column lets you specify up to 15 numerical values. When you enter 21,2000-
3000,65535, for example, you use 4 of 15 numerical values.

Protocol
Restricts the Masquerading NAT rule to an IP protocol. The device applies the Masquerading NAT rule
only to packets of the specified IP protocol.

Possible values:
 tcp
Transmission Control Protocol (RFC 793)
 udp
User Datagram Protocol (RFC 768)
 any (default setting)
The device applies the Masquerading NAT rule to every data packet without considering the IP
protocol.

Log
Activates/deactivates the logging in the log file. See the Diagnostics > Report > System Log dialog.

Possible values:
 marked
Logging is activated.
When the device applies the Masquerading NAT rule to a data packet, the device places an entry
in the log file.
 unmarked (default setting)
Logging is deactivated.

Trap
Activates/deactivates the sending of SNMP traps when the Masquerading NAT rule is applied to data
packets.

RM GUI EAGLE 287


Release 3.4 03/2020
Routing
[ Routing > NAT > Masquerading NAT > Rule ]

Possible values:
 marked
If the device applies the Masquerading NAT rule to a data packet, then the device sends an SNMP
trap.
 unmarked (default setting)
The sending of SNMP traps is deactivated.

The prerequisite for sending SNMP traps is that you enable the function in the Diagnostics > Status
Configuration > Alarms (Traps) dialog and specify at least 1 trap destination.

IPsec exempt
Activates/deactivates applying the Masquerading NAT rule to IPsec data packets.

Possible values:
 marked
The device does not apply the Masquerading NAT rule to the IPsec data packets. The device
transmits IPsec data packets through the VPN tunnel without any modification.
 unmarked (default setting)
The device applies the Masquerading NAT rule to the IPsec data packets. The device transmits
IPsec data packets through the VPN tunnel depending on the settings of the Traffic Selector in
the Source address (CIDR) and Source restrictions columns. See the Virtual Private Network >
Connections dialog.

Active
Activates/deactivates the Masquerading NAT rule.

Possible values:
 marked
The rule is active.
 unmarked (default setting)
The rule is inactive.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

288 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > NAT > Masquerading NAT > Mapping ]

[Link] Masquerading NAT Mapping


[ Routing > NAT > Masquerading NAT > Mapping ]

In this dialog you assign the Masquerading NAT rules to a router interface. To do this, click the
button and then the Assign item.

You create and edit the Masquerading NAT rules in the Routing > NAT > Masquerading NAT > Rule.

An overview of which Masquerading NAT rule is to be assigned to which router interface can be found
in the Routing > NAT > Masquerading NAT > Overview dialog.

Table

Port
Displays the number of the router interface on which the device applies the Masquerading NAT rule.

Rule index
Displays the sequential number of the Masquerading NAT rule. See the Index column in the Routing >
NAT > Masquerading NAT > Rule dialog.

Rule name
Displays the name of the Masquerading NAT rule. See the Rule name column in the Routing > NAT >
Masquerading NAT > Rule dialog.

Direction
Displays whether the device applies the Masquerading NAT rule to data packets received or sent.

Possible values:
 egress
The device applies the Masquerading NAT rule to data packets sent on the router interface.

Priority
Specifies the priority of the Masquerading NAT rule.

Using the priority, you specify the order in which the device applies several rules to the data stream.
The device applies the rules in ascending order starting with priority 1.

Possible values:
 1..6500 (default setting: 1)

Active
Activates/deactivates the Masquerading NAT rule.

RM GUI EAGLE 289


Release 3.4 03/2020
Routing
[ Routing > NAT > Masquerading NAT > Mapping ]

Possible values:
 marked
The rule is active.
 unmarked (default setting)
The rule is inactive.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Assign
Opens the Assign dialog. In this dialog, you assign a configured router interface of an existing
Masquerading NAT rule.

290 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > NAT > Masquerading NAT > Overview ]

[Link] Masquerading NAT Overview


[ Routing > NAT > Masquerading NAT > Overview ]

In this dialog you will find an overview of which Masquerading NAT rule is assigned to which router
interface.

You create and edit the Masquerading NAT rules in the Routing > NAT > Masquerading NAT > Rule.

You assign a router interface to the affected Masquerading NAT rule in the Routing > NAT >
Masquerading NAT > Mapping dialog.

Table

Port
Displays the number of the router interface on which the device applies the Masquerading NAT rule.

Rule index
Displays the sequential number of the Masquerading NAT rule. See the Index column in the Routing >
NAT > Masquerading NAT > Rule dialog.

Rule name
Displays the name of the Masquerading NAT rule. See the Rule name column in the Routing > NAT >
Masquerading NAT > Rule dialog.

Trap
Displays whether the device sends an SNTP trap when it applies the Masquerading NAT rule to a
data packet.

Possible values:
 marked
The device sends an SNMP trap.
 unmarked
The device does not send an SNMP trap.

The prerequisite for sending SNMP traps is that you enable the function in the Diagnostics > Status
Configuration > Alarms (Traps) dialog and specify at least 1 trap destination.

Log
Displays whether the device places an entry in the log file when it applies the Masquerading NAT rule
to a data packet.

Possible values:
 marked
When the device applies the Masquerading NAT rule to a data packet, the device places an entry
in the log file. See the Diagnostics > Report > System Log dialog.
 unmarked
Logging is disabled.

RM GUI EAGLE 291


Release 3.4 03/2020
Routing
[ Routing > NAT > Double NAT ]

Direction
Displays whether the device applies the Masquerading NAT rule to data packets received or sent.

Possible values:
 egress
The device applies the Masquerading NAT rule to data packets sent on the router interface.

Priority
Displays the priority of the Masquerading NAT rule.

The device applies rules to the data stream in ascending order starting with priority 1.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

7.10.5 Double NAT


[ Routing > NAT > Double NAT ]

The Double NAT function lets you establish communication links between end devices located in
different IP networks, which have no way to specify a default gateway or default route. The NAT
router virtually “shifts” the devices into the other network. To do this, the NAT router replaces the
source address and the destination address in the data packet during sending. A typical application
is the linking of controllers located in different networks.

The prerequisite for the Double NAT function is that the NAT router itself responds to ARP requests
from the respective network. To make this happen, turn on the ARP proxy function on the ingress
interface and on the egress interface.

Lokale interne IP-Adresse Lokale externe IP-Adresse


Local Internal IP Address Local External IP Address

Double NAT
[Link] [Link]
Proxy ARP
Egress
Interface

Ingress
[Link]/24 [Link]/24
Interface
[Link] Proxy ARP [Link]

Entfernte externe IP-Adresse Entfernte interne IP-Adresse


Remote External IP Address Remote Internal IP Address

Figure 8: How the Double NAT function works

 To use the NAT function, set up a router interface for each network and turn on the routing
function in the device.

Note: If you enable the VRRP function on a router interface, then the Double NAT function is
ineffective on this router interface.

292 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > NAT > Double NAT ]

The data packets go through the filter functions of the device in the following sequence:

Operating System

Destination Address Modification Ingress Egress Source Address Modification


1:1 NAT Packet Policy Routing Packet Masquerading NAT
Destination NAT Filter Filter Double NAT
Double NAT

MAC-based ACL

IP-based ACL

DoS
Switching Chip

Network 1 Network 2

Figure 9: Processing sequence of the data packets in the device

The menu contains the following dialogs:


 Double NAT Rule
 Double NAT Mapping
 Double NAT Overview

RM GUI EAGLE 293


Release 3.4 03/2020
Routing
[ Routing > NAT > Double NAT > Rule ]

[Link] Double NAT Rule


[ Routing > NAT > Double NAT > Rule ]

In this dialog you create and edit the Double NAT rules.

You assign the router interfaces to the related Double NAT rule in the Routing > NAT > Double NAT >
Mapping dialog.

An overview of which Double NAT rule is assigned to which router interfaces you find in the Routing >
NAT > Double NAT > Overview dialog.

Table

Index
Displays the index number to which the table entry relates.

Possible values:
 1..255

Rule name
Displays the name of the Double NAT rule. To change the name, click the relevant field.

Possible values:
 Alphanumeric ASCII character string with 0..32 characters

Local internal IP address


Specifies the actual IP address for the device placed in the first network.

Possible values:
 Valid IPv4 address
The device applies the Double NAT rule only to data packets containing the source address
specified here.

Local external IP address


Specifies the virtual IP address in the second network for the device placed in the first network.

Possible values:
 Valid IPv4 address
The device applies the Double NAT rule only to data packets containing the source address
specified here.

Remote internal IP address


Specifies the actual IP address for the device placed in the second network.

Possible values:
 Valid IPv4 address
The device applies the Double NAT rule only to data packets containing the source address
specified here.

294 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > NAT > Double NAT > Rule ]

Remote external IP address


Specifies the virtual IP address in the first network for the device placed in the second network.

Possible values:
 Valid IPv4 address
The device applies the Double NAT rule only to data packets containing the source address
specified here.

Log
Activates/deactivates the logging in the log file. See the Diagnostics > Report > System Log dialog.

Possible values:
 marked
Logging is activated.
The device places an entry in the log file when it applies the Double NAT rule to a data packet.
 unmarked (default setting)
Logging is deactivated.

Trap
Activates/deactivates the sending of SNMP traps when the Double NAT rule is applied to data
packets.

Possible values:
 marked
If the device applies the Double NAT rule to a data packet, then the device sends an SNMP trap.
 unmarked (default setting)
The sending of SNMP traps is deactivated.

The prerequisite for sending SNMP traps is that you enable the function in the Diagnostics > Status
Configuration > Alarms (Traps) dialog and specify at least 1 trap destination.

Active
Activates/deactivates the Double NAT rule.

Possible values:
 marked
The rule is active.
 unmarked (default setting)
The rule is inactive.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 295


Release 3.4 03/2020
Routing
[ Routing > NAT > Double NAT > Mapping ]

[Link] Double NAT Mapping


[ Routing > NAT > Double NAT > Mapping ]

In this dialog you assign the Double NAT rules to a router interface. To do this, click the button
and then the Assign item.

You create and edit the Double NAT rules in the Routing > NAT > Double NAT > Rule.

An overview of which Double NAT rule is assigned to which router interfaces you find in the Routing >
NAT > Double NAT > Overview dialog.

Table

Port
Displays the number of the router interface on which the device applies the Double NAT rule.

Rule index
Displays the sequential number of the Double NAT rule. See the Index column in the Routing > NAT >
Double NAT > Rule dialog.

Rule name
Displays the name of the Double NAT rule. See the Rule name column in the Routing > NAT > Double
NAT > Rule dialog.

Direction
Displays whether the device applies the Double NAT rule to data packets received or sent.

Possible values:
 ingress
The device applies the Double NAT rule to data packets received on the router interface.
 egress
The device applies the Double NAT rule to data packets sent on the router interface.
 both
The device applies the Double NAT rule to data packets received or sent on the router interface.

You can change the value when you click the button and then the Assign item.

Priority
Specifies the priority of the Double NAT rule.

Using the priority, you specify the order in which the device applies several rules to the data stream.
The device applies the rules in ascending order starting with priority 1.

Possible values:
 1..6500 (default setting: 1)

296 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > NAT > Double NAT > Mapping ]

Active
Activates/deactivates the Double NAT rule.

Possible values:
 marked
The rule is active.
 unmarked (default setting)
The rule is inactive.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Assign
Opens the Assign dialog. In this dialog, you assign a configured router interface of an existing Double
NAT rule.

RM GUI EAGLE 297


Release 3.4 03/2020
Routing
[ Routing > NAT > Double NAT > Overview ]

[Link] Double NAT Overview


[ Routing > NAT > Double NAT > Overview ]

In this dialog you will find an overview of which Double NAT rule is assigned to which router interface.

You create and edit the Double NAT rules in the Routing > NAT > Double NAT > Rule.

You assign the router interfaces to the related Double NAT rule in the Routing > NAT > Double NAT >
Mapping dialog.

Table

Port
Displays the number of the router interface on which the device applies the Double NAT rule.

Rule index
Displays the sequential number of the Double NAT rule. See the Index column in the Routing > NAT >
Double NAT > Rule dialog.

Rule name
Displays the name of the Double NAT rule. See the Rule name column in the Routing > NAT > Double
NAT > Rule dialog.

Local internal IP address


Displays the actual IP address for the device placed in the first network.

Local external IP address


Displays the virtual IP address in the second network for the device placed in the first network.

Remote internal IP address


Displays the actual IP address for the device placed in the second network.

Remote external IP address


Displays the virtual IP address in the first network for the device placed in the second network.

Trap
Displays whether the device sends an SNTP trap when it applies the Double NAT rule to a data
packet.

298 RM GUI EAGLE


Release 3.4 03/2020
Routing
[ Routing > NAT > Double NAT > Overview ]

Possible values:
 marked
The device sends an SNMP trap.
 unmarked
The device does not send an SNMP trap.

The prerequisite for sending SNMP traps is that you enable the function in the Diagnostics > Status
Configuration > Alarms (Traps) dialog and specify at least 1 trap destination.

Log
Displays whether the device places an entry in the log file when it applies the Double NAT rule to a
data packet.

Possible values:
 marked
When the device applies the Double NAT rule to a data packet, the device places an entry in the
log file. See the Diagnostics > Report > System Log dialog.
 unmarked
Logging is disabled.

Direction
Displays whether the device applies the Double NAT rule to data packets received or sent.

Possible values:
 ingress
The device applies the Double NAT rule to data packets received on the router interface.
 egress
The device applies the Double NAT rule to data packets sent on the router interface.
 both
The device applies the Double NAT rule to data packets received or sent on the router interface.

Priority
Displays the priority of the Double NAT rule.

The device applies rules to the data stream in ascending order starting with priority 1.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 299


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Status Configuration ]

8 Diagnostics

The menu contains the following dialogs:


 Status Configuration
 System
 Syslog
 Ports
 LLDP
 Report

8.1 Status Configuration


[ Diagnostics > Status Configuration ]

The menu contains the following dialogs:


 Device Status
 Security Status
 Signal Contact
 Alarms (Traps)

300 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Status Configuration > Device Status ]

8.1.1 Device Status


[ Diagnostics > Status Configuration > Device Status ]

The device status provides an overview of the overall condition of the device. Many process
visualization systems record the device status for a device in order to present its condition in
graphic form.

The device displays its current status as error or ok in the Device status frame. The device
determines this status from the individual monitoring results.

The device displays detected faults in the Status tab and also in the Basic Settings > System dialog,
Device Status frame.

The dialog contains the following tabs:


 [Global]
 [Port]
 [Status]

[Global]

Device status

Device status
Displays the current status of the device. The device determines the status from the individual
monitored parameters.

Possible values:
 error
The device displays this value to indicate a detected error in one of the monitored parameters.
 ok

Traps

Send trap
Activates/deactivates the sending of SNMP traps when the device detects changes in the
monitored functions.

Possible values:
 marked
The sending of SNMP traps is active.
If the device detects a change in the monitored functions, then the device sends an SNMP trap.
 unmarked (default setting)
The sending of SNMP traps is inactive.

The prerequisite for sending SNMP traps is that you enable the function in the Diagnostics > Status
Configuration > Alarms (Traps) dialog and specify at least 1 trap destination.

RM GUI EAGLE 301


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Status Configuration > Device Status ]

Table

Temperature
Activates/deactivates the monitoring of the temperature in the device.

Possible values:
 marked (default setting)
Monitoring is active.
If the temperature exceeds or falls below the specified limit, then in the Device status frame, the
value changes to error.
 unmarked
Monitoring is inactive.

You specify the temperature thresholds in the Basic Settings > System dialog, Upper temp. limit [°C]
field and Lower temp. limit [°C] field.

Connection errors
Activates/deactivates the monitoring of the link status of the port/interface.

Possible values:
 marked
Monitoring is active.
If the link interrupts on a monitored port/interface, then in the Device status frame, the value
changes to error.
In the Port tab, you have the option of selecting the ports/interfaces to be monitored individually.
 unmarked (default setting)
Monitoring is inactive.

External memory removal


Activates/deactivates the monitoring of the active external memory.

Possible values:
 marked
Monitoring is active.
If you remove the active external memory from the device, then in the Device status frame, the
value changes to error.
 unmarked (default setting)
Monitoring is inactive.

External memory not in sync


Activates/deactivates the monitoring of the configuration profile in the device and in the external
memory.

Possible values:
 marked
Monitoring is active.
In the Device status frame, the value changes to error in the following situations:
– The configuration profile only exists in the device.
– The configuration profile in the device differs from the configuration profile in the external
memory.
 unmarked (default setting)
Monitoring is inactive.

302 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Status Configuration > Device Status ]

Power supply
Activates/deactivates the monitoring of the power supply unit.

Possible values:
 marked (default setting)
Monitoring is active.
If the device has a detected power supply fault, then in the Device status frame, the value
changes to error.
 unmarked
Monitoring is inactive.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

[Port]

Table

Port
Displays the port number.

Propagate connection error


Activates/deactivates the monitoring of the link on the port/interface.

Possible values:
 marked
Monitoring is active.
If the link on the selected port/interface is interrupted, then in the Device status frame, the value
changes to error.
 unmarked (default setting)
Monitoring is inactive.

This setting takes effect when you mark the Connection errors checkbox in the Global tab.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 303


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Status Configuration > Device Status ]

[Status]

Table

Timestamp
Displays the date and time of the event in the format, Month Day, Year hh:mm:ss AM/PM.

Cause
Displays the event which caused the SNMP trap.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

304 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Status Configuration > Security Status ]

8.1.2 Security Status


[ Diagnostics > Status Configuration > Security Status ]

This dialog gives you an overview of the status of the safety-relevant settings in the device.

The device displays its current status as error or ok in the Security status frame. The device
determines this status from the individual monitoring results.

The device displays detected faults in the Status tab and also in the Basic Settings > System dialog,
Security status frame.

The dialog contains the following tabs:


 [Global]
 [Port]
 [Status]

[Global]

Security status

Security status
Displays the current status of the security-relevant settings in the device. The device determines
the status from the individual monitored parameters.

Possible values:
 error
The device displays this value to indicate a detected error in one of the monitored parameters.
 ok

Traps

Send trap
Activates/deactivates the sending of SNMP traps when the device detects changes in the
monitored functions.

Possible values:
 marked
The sending of SNMP traps is active.
If the device detects a change in the monitored functions, then the device sends an SNMP trap.
 unmarked (default setting)
The sending of SNMP traps is inactive.

The prerequisite for sending SNMP traps is that you enable the function in the Diagnostics > Status
Configuration > Alarms (Traps) dialog and specify at least 1 trap destination.

RM GUI EAGLE 305


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Status Configuration > Security Status ]

Table

Password default settings unchanged


Activates/deactivates the monitoring of the password for the locally set up user accounts user and
admin.

Possible values:
 marked (default setting)
Monitoring is active.
If the password is set to the default setting for the user or admin user accounts, then in the
Security status frame, the value changes to error.
 unmarked
Monitoring is inactive.

You set the password in the Device Security > User Management dialog.

Min. password length < 8


Activates/deactivates the monitoring of the Min. password length policy.

Possible values:
 marked (default setting)
Monitoring is active.
If the value for the Min. password length policy is less than 8, then in the Security status frame, the
value changes to error.
 unmarked
Monitoring is inactive.

You specify the Min. password length policy in the Device Security > User Management dialog in the
Configuration frame.

Password policy settings deactivated


Activates/deactivates the monitoring of the Password policies settings.

Possible values:
 marked (default setting)
Monitoring is active.
If the value for at least one of the following policies is less than 1, then in the Security status frame,
the value changes to error.
– Upper-case characters (min.)
– Lower-case characters (min.)
– Digits (min.)
– Special characters (min.)
 unmarked
Monitoring is inactive.

You specify the policy settings in the Device Security > User Management dialog in the Password policy
frame.

User account password policy check deactivated


Activates/deactivates the monitoring of the Policy check function.

306 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Status Configuration > Security Status ]

Possible values:
 marked
Monitoring is active.
If the Policy check function is inactive for at least 1 user account, then in the Security status frame,
the value changes to error.
 unmarked (default setting)
Monitoring is inactive.

You activate the Policy check function in the Device Security > User Management dialog.

HTTP server active


Activates/deactivates the monitoring of the HTTP server.

Possible values:
 marked (default setting)
Monitoring is active.
If you enable the HTTP server, then in the Security status frame, the value changes to error.
 unmarked
Monitoring is inactive.

You enable/disable the HTTP server in the Device Security > Management Access > Server dialog,
HTTP tab.

SNMP unencrypted
Activates/deactivates the monitoring of the SNMP server.

Possible values:
 marked (default setting)
Monitoring is active.
If at least one of the following conditions applies, then in the Security status frame, the value
changes to error:
– The SNMPv1 function is enabled.
– The SNMPv2 function is enabled.
– The encryption for SNMPv3 is disabled.
You enable the encryption in the Device Security > User Management dialog, in the SNMP
encryption type column.
 unmarked
Monitoring is inactive.

You specify the settings for the SNMP agent in the Device Security > Management Access > Server
dialog, SNMP tab.

Access to system monitor with serial interface possible


Activates/deactivates the monitoring of the system monitor.

When the system monitor is activated, the user has the possibility to change to the system monitor
via a serial connection.

RM GUI EAGLE 307


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Status Configuration > Security Status ]

Possible values:
 marked
Monitoring is active.
If you activate the system monitor, then in the Security status frame, the value changes to error.
 unmarked (default setting)
Monitoring is inactive.

You activate/deactivate the system monitor in the Diagnostics > System > Selftest dialog.

Saving the configuration profile on the external memory possible


Activates/deactivates the monitoring of the configuration profile in the external memory.

Possible values:
 marked
Monitoring is active.
If you activate the saving of the configuration profile in the external memory, then in the Security
status frame, the value changes to error.
 unmarked (default setting)
Monitoring is inactive.

You activate/deactivate the saving of the configuration profile in the external memory in the Basic
Settings > External Memory dialog.

Load unencrypted config from external memory


Activates/deactivates the monitoring of loading unencrypted configuration profiles from the external
memory.

Possible values:
 marked (default setting)
Monitoring is active.
If the settings allow the device to load an unencrypted configuration profile from the external
memory, then in the Security status frame, the value changes to error.
If the following preconditions are fulfilled, then the Security status frame in the Basic Settings >
System dialog, displays an alarm.
– The configuration profile stored in the external memory is unencrypted.
and
– The Config priority column in the Basic Settings > External Memory dialog has the value first.
 unmarked
Monitoring is inactive.

Link interrupted on enabled device ports


Activates/deactivates the monitoring of the link on the active ports.

Possible values:
 marked
Monitoring is active.
If the link interrupts on an active port, then in the Security status frame, the value changes to
error. In the Port tab, you have the option of selecting the ports to be monitored individually.
 unmarked (default setting)
Monitoring is inactive.

308 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Status Configuration > Security Status ]

Access with HiDiscovery possible


Activates/deactivates the monitoring of the HiDiscovery function.

Possible values:
 marked (default setting)
Monitoring is active.
If you enable the HiDiscovery function, then in the Security status frame, the value changes to
error.
 unmarked
Monitoring is inactive.

You enable/disable the HiDiscovery function in the Basic Settings > Network dialog.

Self-signed HTTPS certificate present


Activates/deactivates the monitoring of the HTTPS certificate.

Possible values:
 marked (default setting)
Monitoring is active.
If the HTTPS server uses a self-created digital certificate, then in the Security status frame, the
value changes to error.
 unmarked
Monitoring is inactive.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

[Port]

Table

Port
Displays the port number.

Link interrupted on enabled device ports


Activates/deactivates the monitoring of the link on the active ports.

RM GUI EAGLE 309


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Status Configuration > Signal Contact ]

Possible values:
 marked
Monitoring is active.
If the port is enabled (Basic Settings > Port dialog, Configuration tab, Port on checkbox is marked)
and the link is down on the port, then in the Security status frame, the value changes to error.
 unmarked (default setting)
Monitoring is inactive.

This setting takes effect when you mark the Link interrupted on enabled device ports checkbox in the
Diagnostics > Status Configuration > Security Status dialog, Global tab.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

[Status]

Table

Timestamp
Displays the date and time of the event in the format, Month Day, Year hh:mm:ss AM/PM.

Cause
Displays the event which caused the SNMP trap.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

8.1.3 Signal Contact


[ Diagnostics > Status Configuration > Signal Contact ]

The signal contact is a potential-free relay contact. The device thus lets you perform remote
diagnosis. The device uses the relay contact to signal the occurrence of events by opening the relay
contact and interrupting the closed circuit.

Note: The device can contain several signal contacts. Each contact contains the same monitoring
functions. Several contacts allow you to group various functions together providing flexibility in
system monitoring.

The menu contains the following dialogs:


 Signal Contact 1 / Signal Contact 2

310 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Status Configuration > Signal Contact > Signal Contact 1 ]

[Link] Signal Contact 1 / Signal Contact 2


[ Diagnostics > Status Configuration > Signal Contact > Signal Contact 1 ]

In this dialog you specify the trigger conditions for the signal contact.

The signal contact gives you the following options:


 Monitoring the correct operation of the device.
 Signaling the device status of the device.
 Signaling the security status of the device.
 Controlling external devices by manually setting the signal contacts.

The device displays detected faults in the Status tab and also in the Basic Settings > System dialog,
Signal contact status frame.

The dialog contains the following tabs:


 [Global]
 [Port]
 [Status]

[Global]

Configuration

Mode
Specifies which events the signal contact indicates.

Possible values:
 Manual setting (default setting for Signal Contact 2, if present)
You use this setting to manually open or close the signal contact, for example to turn on or off
a remote device. See the Contact option list.
 Monitoring correct operation (default setting)
Using this setting the signal contact indicates the status of the parameters specified in the table
below.
 Device status
Using this setting the signal contact indicates the status of the parameters monitored in the
Diagnostics > Status Configuration > Device Status dialog. In addition, you can read the status in the
Signal contact status frame.
 Security status
Using this setting the signal contact indicates the status of the parameters monitored in the
Diagnostics > Status Configuration > Security Status dialog. In addition, you can read the status in
the Signal contact status frame.
 Device/Security status
Using this setting the signal contact indicates the status of the parameters monitored in the
Diagnostics > Status Configuration > Device Status and the Diagnostics > Status Configuration >
Security Status dialog. In addition, you can read the status in the Signal contact status frame.

Contact
Toggles the signal contact manually. The prerequisite is that you select in the Mode drop-down list
the value Manual setting.

RM GUI EAGLE 311


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Status Configuration > Signal Contact > Signal Contact 1 ]

Possible values:
 open
The signal contact is opened.
 close
The signal contact is closed.

Signal contact status

Signal contact status


Displays the current status of the signal contact.

Possible values:
 Opened (error)
The signal contact is opened. The circuit is interrupted.
 Closed (ok)
The signal contact is closed. The circuit is closed.

Trap configuration

Send trap
Activates/deactivates the sending of SNMP traps when the device detects changes in the
monitored functions.

Possible values:
 marked
The sending of SNMP traps is active.
If the device detects a change in the monitored functions, then the device sends an SNMP trap.
 unmarked (default setting)
The sending of SNMP traps is inactive.

The prerequisite for sending SNMP traps is that you enable the function in the Diagnostics > Status
Configuration > Alarms (Traps) dialog and specify at least 1 trap destination.

Monitoring correct operation

In the table you specify the parameters that the device monitors. The device signals the occurrence
of an event by opening the signal contact.

Temperature
Activates/deactivates the monitoring of the temperature in the device.

312 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Status Configuration > Signal Contact > Signal Contact 1 ]

Possible values:
 marked (default setting)
Monitoring is active.
If the temperature exceeds / falls below the threshold values, then the signal contact opens.
 unmarked
Monitoring is inactive.

You specify the temperature thresholds in the Basic Settings > System dialog, Upper temp. limit [°C]
field and Lower temp. limit [°C] field.

Connection errors
Activates/deactivates the monitoring of the link status of the port/interface.

Possible values:
 marked
Monitoring is active.
If the link interrupts on a monitored port/interface, then the signal contact opens.
In the Port tab, you have the option of selecting the ports/interfaces to be monitored individually.
 unmarked (default setting)
Monitoring is inactive.

External memory removed


Activates/deactivates the monitoring of the active external memory.

Possible values:
 marked
Monitoring is active.
If you remove the active external memory from the device, then the signal contact opens.
 unmarked (default setting)
Monitoring is inactive.

External memory not in sync with NVM


Activates/deactivates the monitoring of the configuration profile in the device and in the external
memory.

Possible values:
 marked
Monitoring is active.
The signal contact opens in the following situations:
– The configuration profile only exists in the device.
– The configuration profile in the device differs from the configuration profile in the external
memory.
 unmarked (default setting)
Monitoring is inactive.

Power supply
Activates/deactivates the monitoring of the power supply unit.

RM GUI EAGLE 313


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Status Configuration > Signal Contact > Signal Contact 1 ]

Possible values:
 marked (default setting)
Monitoring is active.
If the device has a detected power supply fault, then the signal contact opens.
 unmarked
Monitoring is inactive.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

[Port]

Table

Port
Displays the port number.

Propagate connection error


Activates/deactivates the monitoring of the link on the port/interface.

Possible values:
 marked
Monitoring is active.
If the link interrupts on the selected port/interface, then the signal contact opens.
 unmarked (default setting)
Monitoring is inactive.

This setting takes effect when you mark the Connection errors checkbox in the Global tab.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

[Status]

Table

Timestamp
Displays the date and time of the event in the format, Month Day, Year hh:mm:ss AM/PM.

314 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Status Configuration > Alarms (Traps) ]

Cause
Displays the event which caused the SNMP trap.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

8.1.4 Alarms (Traps)


[ Diagnostics > Status Configuration > Alarms (Traps) ]

The device lets you send an SNMP trap as a reaction to specific events. In this dialog, you specify
the trap destinations to which the device sends the SNMP traps.

The events for which the device triggers an SNMP trap, you specify, for example, in the following
dialogs:
 in the Diagnostics > Status Configuration > Device Status dialog
 in the Diagnostics > Status Configuration > Security Status dialog

When loopback interfaces are set up, the device uses the IP address of the 1st loopback interface
as the source of the SNMP traps. Otherwise, the device uses the address of the device
management.

Operation

Operation
Enables/disables the sending of SNMP traps to the trap destinations.

Possible values:
 On (default setting)
The sending of SNMP traps is enabled.
 Off
The sending of SNMP traps is disabled.

Table

Name
Specifies the name of the trap destination.

Possible values:
 Alphanumeric ASCII character string with 1..32 characters

RM GUI EAGLE 315


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Status Configuration > Alarms (Traps) ]

Address
Specifies the IP address and the port number of the trap destination.

Possible values:
 <Valid IPv4 address>:<port number>

Active
Activates/deactivates the sending of SNMP traps to this trap destination.

Possible values:
 marked (default setting)
The sending of SNMP traps to this trap destination is active.
 unmarked
The sending of SNMP traps to this trap destination is inactive.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Opens the Create window to add a new entry to the table.


 In the Name field you specify a name for the trap destination.
 In the Address field you specify the IP address and the port number of the trap destination.
If you choose not to enter a port number, then the device automatically adds the port number
162.

316 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > System ]

8.2 System
[ Diagnostics > System ]

The menu contains the following dialogs:


 System Information
 Configuration Check
 ARP
 Selftest

RM GUI EAGLE 317


Release 3.4 03/2020
Diagnostics
[ Diagnostics > System > System Information ]

8.2.1 System Information


[ Diagnostics > System > System Information ]

This dialog displays the current operating condition of individual components in the device. The
displayed values are a snapshot; they represent the operating condition at the time the dialog was
loaded to the page.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Save system information


Opens the HTML page in a new web browser window or tab. You can save the HTML page on your
PC using the appropriate web bowser command.

318 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > System > Configuration Check ]

8.2.2 Configuration Check


[ Diagnostics > System > Configuration Check ]

The device lets you compare the settings in the device with the settings in its neighboring devices.
For this purpose, the device uses the information that it received from its neighboring devices
through topology recognition (LLDP).

The dialog lists the deviations detected, which affect the performance of the communication
between the device and the recognized neighboring devices.

You update the content of the table by clicking the button. When the table remains empty, the
configuration check was successful and the settings in the device are compatible with the settings
in the detected neighboring devices.

If you have set up more than 39 VLANs in the device, then the dialog constantly displays a warning.
The reason is the limited number of possible VLAN data sets in LLDP packets with a maximum
length. The device compares the first 39 VLANs automatically. If you have set up 40 or more
VLANs in the device, then check the congruence of the further VLANs manually, if necessary.

Note: The dialog displays the devices detected as connected to the neighboring device as if they
were directly connected to the device itself.

Summary

You also find this information when you position the mouse pointer over the button in the
Toolbar in the top part of the Navigation area.

Error
Displays the number of errors that the device detected during the configuration check.

Warning
Displays the number of warnings that the device detected during the configuration check.

Information
Displays the amount of information that the device detected during the configuration check.

Table

When you highlight a row in the table, the device displays additional information in the area beneath
it.

ID
Displays the rule ID of the deviations having occurred. The dialog combines several deviations with
the same rule ID under one rule ID.

RM GUI EAGLE 319


Release 3.4 03/2020
Diagnostics
[ Diagnostics > System > Configuration Check ]

Level
Displays the level of deviation between the settings in this device and the settings in the detected
neighboring devices.

The device differentiates between the following access statuses:


 INFORMATION
The performance of the communication between the two devices is not impaired.
 WARNING
The performance of the communication between the two devices is possibly impaired.
 ERROR
The communication between the two devices is impaired.

Message
Displays the information, warnings and errors having occurred more precisely.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

320 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > System > ARP ]

8.2.3 ARP
[ Diagnostics > System > ARP ]

This dialog displays the MAC and IP addresses of the neighboring devices connected to the device
management.

Table

Port
Displays the port number.

IP address
Displays the IP address of a device that responded to an ARP query to this device.

MAC address
Displays the MAC address of a device that responded to an ARP query to this device.

Last updated
Displays the time in seconds since the current settings of the entry were registered in the ARP
table.

Type
Displays the type of the ARP entry.

Possible values:
 static
Static ARP entry. When the ARP table is deleted, the device keeps the ARP entry.
 dynamic
Dynamic ARP entry. When the Aging time [s] has been exceeded and the device does not receive
any data from this device during this time, the device deletes the ARP entry.

Active
Displays that the ARP table contains the IP/MAC address assignment as an active entry.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Reset ARP table


Removes the dynamically set up addresses from the ARP table.

RM GUI EAGLE 321


Release 3.4 03/2020
Diagnostics
[ Diagnostics > System > Selftest ]

8.2.4 Selftest
[ Diagnostics > System > Selftest ]

This dialog lets you do the following:


 Enable/disable the option of entering the system monitor upon the system start.
 Specify how the device behaves in the case of an error.

Configuration

If the device does not detect any readable configuration profile when restarting, then the following
settings block your access to the device permanently.
 SysMon1 is available checkbox is unmarked.
 Load default config on error checkbox is unmarked.

This is the case, for example, if the password of the configuration profile that you are loading differs
from the password set in the device. To have the device unlocked again, contact your sales partner.

SysMon1 is available
Activates/deactivates the access to the system monitor during the restart.

Possible values:
 marked (default setting)
The device lets you open the system monitor during the restart.
 unmarked
The device starts without the option of opening to the system monitor.

Among other things, the system monitor lets you update the device software and to delete saved
configuration profiles.

Load default config on error


Activates/deactivates the loading of the default settings if the device does not detect any readable
configuration profile when restarting.

Possible values:
 marked (default setting)
The device loads the default settings.
 unmarked
The device interrupts the restart and stops. The access to the device management is possible
only using the Command Line Interface through the serial interface.
To regain the access to the device through the network, open the system monitor and reset the
settings. Upon restart, the device loads the default settings.

322 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > System > Selftest ]

Table

In this table you specify how the device behaves in the case of an error.

Cause
Error causes to which the device reacts.

Possible values:
 task
The device detects errors in the applications executed, for example if a task terminates or is not
available.
 resource
The device detects errors in the resources available, for example if the memory is becoming
scarce.
 software
The device detects software errors, for example error in the consistency check.
 hardware
The device detects hardware errors, for example in the chip set.

Action
Specifies how the device behaves if the adjacent event occurs.

Possible values:
 reboot (default setting)
The device triggers a restart.
 logOnly
The device registers the detected error in the log file. See the Diagnostics > Report > System Log
dialog.
 sendTrap
The device sends an SNMP trap.
The prerequisite for sending SNMP traps is that you enable the function in the Diagnostics >
Status Configuration > Alarms (Traps) dialog and specify at least 1 trap destination.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 323


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Syslog ]

8.3 Syslog
[ Diagnostics > Syslog ]

The device lets you report selected events, independent of the severity of the event, to different
syslog servers. In this dialog, you specify the settings for this function and manage up to 8 syslog
servers.

Operation

Operation
Enables/disables the sending of events to the syslog servers.

Possible values:
 On
The sending of events is enabled.
The device sends the events specified in the table to the specified syslog servers.
 Off (default setting)
The sending of events is disabled.

Table

Index
Displays the index number to which the table entry relates.

When you delete a table entry, this leaves a gap in the numbering. When you create a new table
entry, the device fills the first gap.

Possible values:
 1..8

IP address
Specifies the IP address of the syslog server.

Possible values:
 Valid IPv4 address (default setting: [Link])

Destination UDP port


Specifies the UDP port on which the syslog server expects the log entries.

Possible values:
 1..65535 (default setting: 514)

Min. severity
Specifies the minimum severity of the events. The device sends a log entry for events with this
severity and with more urgent severities to the syslog server.

324 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Syslog ]

Possible values:
 emergency
 alert
 critical
 error
 warning (default setting)
 notice
 informational
 debug

Type
Specifies the type of the log entry transmitted by the device.

Possible values:
 systemlog (default setting)
 audittrail

Active
Activates/deactivates the transmission of events to the syslog server:
 marked
The device sends events to the syslog server.
 unmarked (default setting)
The transmission of events to the syslog server is deactivated.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 325


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Ports ]

8.4 Ports
[ Diagnostics > Ports ]

The menu contains the following dialogs:


 SFP

326 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Ports > SFP ]

8.4.1 SFP
[ Diagnostics > Ports > SFP ]

This dialog lets you look at the SFP transceivers currently connected to the device and their
properties.

Table

The table displays valid values if the device is equipped with SFP transceivers.

Port
Displays the port number.

Module type
Type of the SFP transceiver, for example M-SFP-SX/LC.

Serial number
Displays the serial number of the SFP transceiver.

Connector type
Displays the connector type.

Supported
Displays whether the device supports the SFP transceiver.

Temperature [°C]
Operating temperature of the SFP transceiver in °Celsius.

Tx power [mW]
Transmission power of the SFP transceiver in mW.

Rx power [mW]
Receiving power of the SFP transceiver in mW.

Tx power [dBm]
Transmission power of the SFP transceiver in dBm.

Rx power [dBm]
Receiving power of the SFP transceiver in dBm.

RM GUI EAGLE 327


Release 3.4 03/2020
Diagnostics
[ Diagnostics > LLDP ]

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

8.5 LLDP
[ Diagnostics > LLDP ]

The device lets you gather information about neighboring devices. For this, the device uses the Link
Layer Discovery Protocol (LLDP). This information enables a network management station to map
the structure of your network.

This menu lets you configure the topology discovery and to display the information received in table
form.

The menu contains the following dialogs:


 LLDP Configuration
 LLDP Topology Discovery

328 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > LLDP > Configuration ]

8.5.1 LLDP Configuration


[ Diagnostics > LLDP > Configuration ]

This dialog lets you configure the topology discovery for every port.

Operation

Operation
Enables/disables the LLDP function.

Possible values:
 On (default setting)
The LLDP function is enabled.
The topology discovery using LLDP is active in the device.
 Off
The LLDP function is disabled.

Configuration

Transmit interval [s]


Specifies the interval in seconds at which the device transmits LLDP data packets.

Possible values:
 5..32768 (default setting: 30)

Transmit interval multiplier


Specifies the factor for determining the time-to-live value for the LLDP data packets.

Possible values:
 2..10 (default setting: 4)

The time-to-live value coded in the LLDP header results from multiplying this value with the value
in the Transmit interval [s] field.

Reinit delay [s]


Displays the delay in seconds for the reinitialization of a port.

If in the Operation column the value Off is specified, then the device tries to reinitialize the port after
the time specified here has elapsed.

Transmit delay [s]


Displays the delay in seconds for transmitting successive LLDP data packets after configuration
changes in the device occur.

RM GUI EAGLE 329


Release 3.4 03/2020
Diagnostics
[ Diagnostics > LLDP > Configuration ]

Notification interval [s]


Specifies the interval in seconds for transmitting LLDP notifications.

Possible values:
 5..3600 (default setting: 5)

After transmitting a notification trap, the device waits for a minimum of the time specified here
before transmitting the next notification trap.

Table

Port
Displays the port number.

Operation
Specifies whether the port transmits and receives LLDP data packets.

Possible values:
 transmit
The port transmits LLDP data packets but does not save any information about neighboring
devices.
 receive
The port receives LLDP data packets but does not transmit any information to neighboring
devices.
 receive and transmit (default setting)
The port transmits LLDP data packets and saves information about neighboring devices.
 disabled
The port does not transmit LLDP data packets and does not save information about neighboring
devices.

Notification
Activates/deactivates the LLDP notifications on the port.

Possible values:
 marked
LLDP notifications are active on the port.
 unmarked (default setting)
LLDP notifications are inactive on the port.

Transmit port description


Activates/deactivates the transmitting of a TLV (Type Length Value) with the port description.

Possible values:
 marked (default setting)
The transmitting of the TLV is active.
The device transmits the TLV with the port description.
 unmarked
The transmitting of the TLV is inactive.
The device does not transmit a TLV with the port description.

330 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > LLDP > Configuration ]

Transmit system name


Activates/deactivates the transmitting of a TLV (Type Length Value) with the device name.

Possible values:
 marked (default setting)
The transmitting of the TLV is active.
The device transmits the TLV with the device name.
 unmarked
The transmitting of the TLV is inactive.
The device does not transmit a TLV with the device name.

Transmit system description


Activates/deactivates the transmitting of the TLV (Type Length Value) with the system description.

Possible values:
 marked (default setting)
The transmitting of the TLV is active.
The device transmits the TLV with the system description.
 unmarked
The transmitting of the TLV is inactive.
The device does not transmit a TLV with the system description.

Transmit system capabilities


Activates/deactivates the transmitting of the TLV (Type Length Value) with the system capabilities.

Possible values:
 marked (default setting)
The transmitting of the TLV is active.
The device transmits the TLV with the system capabilities.
 unmarked
The transmitting of the TLV is inactive.
The device does not transmit a TLV with the system capabilities.

Neighbors (max.)
Limits the number of neighboring devices to be recorded for this port.

Possible values:
 1..50 (default setting: 10)

FDB mode
Specifies which function the device uses to record neighboring devices on this port.

Possible values:
 lldpOnly
The device uses only LLDP data packets to record neighboring devices on this port.
 macOnly
The device uses learned MAC addresses to record neighboring devices on this port. The device
uses the MAC address only if there is no other entry in the address table (FDB, Forwarding
Database) for this port.

RM GUI EAGLE 331


Release 3.4 03/2020
Diagnostics
[ Diagnostics > LLDP > Configuration ]

 both
The device uses LLDP data packets and learned MAC addresses to record neighboring devices
on this port.
 autoDetect (default setting)
If the device receives LLDP data packets at this port, then the device operates the same as with
the lldpOnly setting. Otherwise, the device operates the same as with the macOnly setting.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

332 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > LLDP > Topology Discovery ]

8.5.2 LLDP Topology Discovery


[ Diagnostics > LLDP > Topology Discovery ]

Devices in networks send notifications in the form of packets which are also known as "LLDPDU"
(LLDP data units). The data that is sent and received via LLDPDU are useful for many reasons.
Thus the device detects which devices in the network are neighbors and via which ports they are
connected.

The dialog lets you display the network and to detect the connected devices along with their specific
features.

This dialog displays the collected LLDP information for the neighboring devices. This information
enables a network management station to map the structure of your network.

When devices both with and without an active topology discovery function are connected to a port,
the topology table hides the devices without active topology discovery.

When only devices without active topology discovery are connected to a port, the table contains
one line for this port to represent every device. This line contains the number of connected devices.

The Forwarding Database (FDB) address table contains MAC addresses of devices that the
topology table hides for the sake of clarity.

When you use 1 port to connect several devices, for example via a hub, the table contains 1 line
for each connected device.

Table

Port
Displays the port number.

Neighbor identifier
Displays the chassis ID of the neighboring device. This can be the basis MAC address of the
neighboring device, for example.

FDB
Displays whether or not the connected device has active LLDP support.

Possible values:
 marked
The connected device does not have active LLDP support.
The device uses information from its address table (FDB, Forwarding Database)
 unmarked (default setting)
The connected device has active LLDP support.

Neighbor IP address
Displays the IP address with which the access to the neighboring device management is possible.

RM GUI EAGLE 333


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Report ]

Neighbor port description


Displays a description for the port of the neighboring device.

Neighbor system name


Displays the device name of the neighboring device.

Neighbor system description


Displays a description for the neighboring device.

Port ID
Displays the ID of the port through which the neighboring device is connected to the device.

Autonegotiation supported
Displays whether the port of the neighboring device supports autonegotiation.

Autonegotiation
Displays whether autonegotiation is enabled on the port of the neighboring device.

PoE supported
Displays whether the port of the neighboring device supports Power over Ethernet (PoE).

PoE enabled
Displays whether Power over Ethernet (PoE) is enabled on the port of the neighboring device.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

8.6 Report
[ Diagnostics > Report ]

The menu contains the following dialogs:


 Report Global
 Persistent Logging
 System Log
 Audit Trail

334 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Report > Global ]

8.6.1 Report Global


[ Diagnostics > Report > Global ]

The device lets you log specific events using the following outputs:
 on the console
 on one or more syslog servers
 on a connection to the Command Line Interface set up using SSH

In this dialog, you specify the required settings. By assigning the severity you specify which events
the device registers.

The dialog lets you save a ZIP archive with system information on your PC.

Console logging

Operation
Enables/disables the Console logging function.

Possible values:
 On
The Console logging function is enabled.
The device logs the events on the console.
 Off (default setting)
The Console logging function is disabled.

Severity
Specifies the minimum severity for the events. The device logs events with this severity and with
more urgent severities.

The device outputs the messages on the serial interface.

Possible values:
 emergency
 alert
 critical
 error
 warning (default setting)
 notice
 informational
 debug

RM GUI EAGLE 335


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Report > Global ]

Buffered logging

The device buffers logged events in 2 separate storage areas so that the log entries for urgent
events are kept.

This dialog lets you specify the minimum severity for events that the device buffers in the storage
area with a higher priority.

Severity
Specifies the minimum severity for the events. The device buffers log entries for events with this
severity and with more urgent severities in the storage area with a higher priority.

Possible values:
 emergency
 alert
 critical
 error
 warning (default setting)
 notice
 informational
 debug

SNMP logging

When you enable the logging of SNMP requests, the device sends these as events with the preset
severity notice to the list of syslog servers. The preset minimum severity for a syslog server entry
is critical.

To send SNMP requests to a syslog server, you have a number of options to change the default
settings. Select the ones that meet your requirements best.
 Set the severity for which the device creates SNMP requests as events to warning or error and
change the minimum severity for a syslog entry for one or more syslog servers to the same
value.
You also have the option of creating a separate syslog server entry for this.
 When you set the severity for SNMP requests to critical or higher. The device then sends
SNMP requests as events with the severity critical or higher to the syslog servers.
 When you set the minimum severity for one or more syslog server entries to notice or lower.
Then it is possible that the device sends many events to the syslog servers.

Log SNMP get request


Enables/disables the logging of SNMP Get requests.

Possible values:
 On
The logging is enabled.
The device registers SNMP Get requests as events in the syslog.
In the Severity get request drop-down list, you select the severity for this event.
 Off (default setting)
The logging is disabled.

336 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Report > Global ]

Log SNMP set request


Enables/disables the logging of SNMP Set requests.

Possible values:
 On
The logging is enabled.
The device registers SNMP Set requests as events in the syslog.
In the Severity set request drop-down list, you select the severity for this event.
 Off (default setting)
The logging is disabled.

Severity get request


Specifies the severity of the event that the device registers for SNMP Get requests.

Possible values:
 emergency
 alert
 critical
 error
 warning
 notice (default setting)
 informational
 debug

Severity set request


Specifies the severity of the event that the device registers for SNMP Set requests.

Possible values:
 emergency
 alert
 critical
 error
 warning
 notice (default setting)
 informational
 debug

CLI logging

Operation
Enables/disables the CLI logging function.

RM GUI EAGLE 337


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Report > Global ]

Possible values:
 On
The CLI logging function is enabled.
The device logs every command received using the Command Line Interface.
 Off (default setting)
The CLI logging function is disabled.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Download support information


Generates a ZIP archive which the web browser lets you download from the device.

The ZIP archive contains system information about the device. You will find an explanation of the
files contained in the ZIP archive in the following section.

Support Information: Files contained in ZIP archive

File name Format Comments


[Link] HTML Contains the chronological recording of the system events and
saved user changes in the Audit Trail.
[Link] XML Contains the configuration profile with the default settings.
script TEXT Contains the output of the command show running-config
script.
[Link] XML Contains the configuration profile with the current operating
settings.
[Link] TEXT Contains device internal service information.
[Link] HTML Contains information about the current settings and operating
parameters.
[Link] HTML Contains the logged events in the Log file. See the Diagnostics >
Report > System Log dialog.

Meaning of the event severities

Severity Meaning
emergency Device not ready for operation
alert Immediate user intervention required
critical Critical status
error Error status
warning Warning
notice Significant, normal status
informational Informal message
debug Debug message

338 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Report > Persistent Logging ]

8.6.2 Persistent Logging


[ Diagnostics > Report > Persistent Logging ]

The device lets you save log entries permanently in a file in the external memory. Therefore, even
after the device is restarted you have access to the log entries.

In this dialog, you limit the size of the log file and specify the minimum severity for the events to be
saved. When the log file reaches the specified size, the device archives this file and saves the
following log entries in a newly created file.

In the table the device displays you the log files held in the external memory. As soon as the
specified maximum number of files has been attained, the device deletes the oldest file and
renames the remaining files. This helps ensure that there is enough memory space in the external
memory.

Note: Verify that an external memory is connected. To verify if an external memory is connected,
see the Status column in the Basic Settings > External Memory dialog. We recommend to monitor the
external memory connection using the Device Status function, see the External memory removal
parameter in the Diagnostics > Status Configuration > Device Status dialog.

Operation

Operation
Enables/disables the Persistent Logging function.

Only activate this function if the external memory is available in the device.

Possible values:
 On (default setting)
The Persistent Logging function is enabled.
The device saves the log entries in a file in the external memory.
 Off
The Persistent Logging function is disabled.

Configuration

Max. file size [kbyte]


Specifies the maximum size of the log file in KBytes. When the log file reaches the specified size,
the device archives this file and saves the following log entries in a newly created file.

Possible values:
 0..4096 (default setting: 1024)

The value 0 deactivates saving of log entries in the log file.

Files (max.)
Specifies the number of log files that the device keeps in the external memory.

RM GUI EAGLE 339


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Report > Persistent Logging ]

As soon as the specified maximum number of files has been attained, the device deletes the oldest
file and renames the remaining files.

Possible values:
 0..25 (default setting: 4)

The value 0 deactivates saving of log entries in the log file.

Severity
Specifies the minimum severity of the events. The device saves the log entry for events with this
severity and with more urgent severities in the log file in the external memory.

Possible values:
 emergency
 alert
 critical
 error
 warning (default setting)
 notice
 informational
 debug

Log file target


Specifies the external memory device for logging.

Possible values:
 usb
External USB memory (ACA21/ACA22)

Table

Index
Displays the index number to which the table entry relates.

Possible values:
 1..25

The device automatically assigns this number.

File name
Displays the file name of the log file in the external memory.

Possible values:
 messages
 messages.X

340 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Report > Persistent Logging ]

File size [byte]


Displays the size of the log file in the external memory in bytes.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Delete persistent log file


Removes the log files from the external memory.

RM GUI EAGLE 341


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Report > System Log ]

8.6.3 System Log


[ Diagnostics > Report > System Log ]

The device logs device-internal events in a log file (System Log).

This dialog displays the log file (System Log). The dialog lets you save the log file in HTML format
on your PC.

In order to search the log file for search terms, use the search function of your web browser.

The log file is kept until a restart is performed in the device. After the restart the device creates the
file again.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Save log file


Opens the HTML page in a new web browser window or tab. You can save the HTML page on your
PC using the appropriate web bowser command.

Delete log file


Removes the logged events from the log file.

342 RM GUI EAGLE


Release 3.4 03/2020
Diagnostics
[ Diagnostics > Report > Audit Trail ]

8.6.4 Audit Trail


[ Diagnostics > Report > Audit Trail ]

This dialog displays the log file (Audit Trail). The dialog lets you save the log file as an HTML file
on your PC.

In order to search the log file for search terms, use the search function of your web browser.

The device logs system events and writing user actions in the device. This lets you keep track of
WHO changes WHAT in the device and WHEN. The prerequisite is that the user role auditor or
administrator is assigned to your user account.

The device logs the following user actions, among others:


 A user logging on via Command Line Interface (local or remote)
 A user logging off manually
 Automatic logging off of a user in the Command Line Interface after a specified period of
inactivity
 Device restart
 Locking of a user account due to too many unsuccessful logon attempts
 Locking of the access to the device management due to unsuccessful logon attempts
 Commands executed in the Command Line Interface, apart from show commands
 Changes to configuration variables
 Changes to the system time
 File transfer operations, including firmware updates
 Configuration changes via HiDiscovery
 Firmware updates and automatic configuration of the device via the external memory
 Opening and closing of SNMP via an HTTPS tunnel

The device does not log passwords. The logged entries are write-protected and remain saved in
the device after a restart.

Note: During the restart, access to the system monitor is possible using the default settings of the
device. If an attacker gains physical access to the device, then he is able to reset the device settings
to its default values using the system monitor. After this, the device and log file are accessible using
the standard password. Take appropriate measures to restrict physical access to the device.
Otherwise, deactivate access to the system monitor. See the Diagnostics > System > Selftest dialog,
SysMon1 is available checkbox.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Save audit trail file


Opens the HTML page in a new web browser window or tab. You can save the HTML page on your
PC using the appropriate web bowser command.

RM GUI EAGLE 343


Release 3.4 03/2020
Advanced
[ Advanced > DNS ]

9 Advanced

The menu contains the following dialogs:


 DNS
 Command Line Interface

9.1 DNS
[ Advanced > DNS ]

The menu contains the following dialogs:


 DNS Client
 DNS Cache

9.1.1 DNS Client


[ Advanced > DNS > Client ]

DNS (Domain Name System) is a service in the network that translates host names into IP
addresses. This name resolution lets you contact other devices using their host names instead of
their IP addresses.

The Client function enables the device to send requests for resolving hostnames in IP addresses to
a DNS server.

The menu contains the following dialogs:


 DNS Client Global
 DNS Client Current
 DNS Client Static
 DNS Client Static Hosts

344 RM GUI EAGLE


Release 3.4 03/2020
Advanced
[ Advanced > DNS > Client > Global ]

[Link] DNS Client Global


[ Advanced > DNS > Client > Global ]

In this dialog, you enable the Client function.

Operation

Operation
Enables/disables the Client function.

Possible values:
 On
The Client function is enabled.
The device sends requests for resolving hostnames in IP addresses to a DNS server.
 Off (default setting)
The Client function is disabled.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 345


Release 3.4 03/2020
Advanced
[ Advanced > DNS > Client > Current ]

[Link] DNS Client Current


[ Advanced > DNS > Client > Current ]

This dialog displays to which DNS servers the device sends requests for resolving hostnames in IP
addresses.

Table

Index
Displays the sequential number of the DNS server.

Address
Displays the IP address of the DNS server. The device forwards requests for resolving host names
in IP addresses to the DNS server with this IP address.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

346 RM GUI EAGLE


Release 3.4 03/2020
Advanced
[ Advanced > DNS > Client > Static ]

[Link] DNS Client Static


[ Advanced > DNS > Client > Static ]

In this dialog, you specify the DNS servers to which the device forwards requests for resolving host
names in IP addresses. The device lets you specify up to 4 IP addresses yourself or to transfer the
IP addresses from a DHCP server.

Configuration

Configuration source
Specifies the source from which the device obtains the IP address of DNS servers to which the
device addresses requests.

Possible values:
 user
The device uses the IP addresses specified in the table.

Table

Index
Displays the sequential number of the DNS server.

The device lets you specify up to 4 DNS servers.

Address
Specifies the IP address of the DNS server.

Possible values:
 Valid IPv4 address (default setting: [Link])

Active
Activates/deactivates the table entry.

The device sends requests to the DNS server configured in the first active table entry. When the
device does not receive a response from this server, it sends requests to the DNS server configured
in the next active table entry.

Possible values:
 marked
The DNS client sends requests to this DNS server.
Prerequisites:
 Enable the DNS-client function in the Advanced > DNS > Global dialog.
 Select in the Configuration frame, Configuration source drop-down-list the value user.
 unmarked (default setting)
The device does not send requests to this DNS server.

RM GUI EAGLE 347


Release 3.4 03/2020
Advanced
[ Advanced > DNS > Client > Static ]

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

348 RM GUI EAGLE


Release 3.4 03/2020
Advanced
[ Advanced > DNS > Client > Static Hosts ]

[Link] DNS Client Static Hosts


[ Advanced > DNS > Client > Static Hosts ]

This dialog lets you specify up to 64 hostnames which you link with one IP address each. Upon a
request for resolving hostnames in IP addresses, the device searches this table for a corresponding
entry. When the device does not find a corresponding entry, it forwards the request.

Table

Index
Displays the index number to which the table entry relates.

Possible values:
 1..64

Name
Specifies the hostname.

Possible values:
 Alphanumeric ASCII character string with 0..255 characters

IP address
Specifies the IP address under which the host is reachable.

Possible values:
 Valid IPv4 address

Active
Activates/deactivates the table entry.

Possible values:
 marked
The device resolves a request for the host name for this entry.
 unmarked
After receiving a request for this host name, the device sends a request to one of the configured
name servers for resolution.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

RM GUI EAGLE 349


Release 3.4 03/2020
Advanced
[ Advanced > DNS > Cache ]

9.1.2 DNS Cache


[ Advanced > DNS > Cache ]

The Cache function enables the device to respond to requests for resolving hostnames in IP
addresses.

The menu contains the following dialogs:


 DNS Cache Global

350 RM GUI EAGLE


Release 3.4 03/2020
Advanced
[ Advanced > DNS > Cache > Global ]

[Link] DNS Cache Global


[ Advanced > DNS > Cache > Global ]

In this dialog, you enable the Cache function. When the Cache function is enabled, the device
operates as a Caching DNS server.

When a downstream device requests the IP address of an unknown hostname and the Caching
DNS server finds a matching entry in its cache, the Caching DNS server returns the IP address.
When the Caching DNS server does not find a matching entry in its cache, the Caching DNS server
request the IP address from a DNS server specified in the Advanced > DNS > Client > Static Hosts
dialog.

The cache provides memory space for up to 128 hostnames with associated IP address.

Operation

Operation
Enables/disables the Cache function.

Possible values:
 On (default setting)
The Cache function is enabled.
 Off
The Cache function is disabled.

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Flush cache
Removes every entry from the DNS cache.

9.2 Command Line Interface


[ Advanced > CLI ]

This dialog lets you access the device using the Command Line Interface.

The prerequisites are:


 In the device, enable the SSH server in the Device Security > Management Access > Server dialog,
tab SSH.
 On your workstation, install a SSH-capable client application which registers a handler for URLs
starting with ssh:// in your operating system.

RM GUI EAGLE 351


Release 3.4 03/2020
Advanced
[ Advanced > CLI ]

Buttons

You find the description of the standard buttons in section “Buttons” on page 13.

Open SSH connection


Opens the SSH-capable client application.

When you click the button, the web application passes the URL of the device starting with ssh://
and the user name of the currently logged on user.

If the web browser finds a SSH-capable client application, then the SSH-capable client establishes
a connection to the device using the SSH protocol.

352 RM GUI EAGLE


Release 3.4 03/2020
Index

A Index

0-9
1to1 NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 272

A
Access restriction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 84
Aging time . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 176, 321
Alarms . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 315
ARP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 186, 192
ARP table . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 192, 321
Audit trail . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 343
Authentication list . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 61

C
Certificate . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17, 35, 65, 81, 82, 146, 309
CLI . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 88
Command line interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 88
Community names . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 91
Configuration check . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 319
Configuration profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12, 26
Context menu . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
Counter reset . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 45

D
Deep packet inspection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 123
Destination NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 275
Device software . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
Device software backup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
Device status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15, 301
DNS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 344
DNS cache . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 350
DNS client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 345
Domain name system . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 344
DoS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 133
Double NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 292
DPI . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 123

E
Egress rate limiter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 178
Encryption . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26
ENVM . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24, 26, 31, 37, 302, 308, 313, 340
Event severity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 338
External memory . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24, 26, 31, 37, 340

F
FAQ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 357
FDB . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 180
Filter MAC addresses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 180
Fingerprint . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 77, 81
Firewall learning mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 106
Flash memory . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24
Flow control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 176
Forwarding database . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 180

RM GUI EAGLE 353


Release 3.4 03/2020
Index

H
HiDiscovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20, 309, 343
HiVRRP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 259
Host key . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 78
HTML . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 318, 342
HTTP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 79
HTTP server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 307
HTTPS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 80

I
ICMP redirect . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 182, 187
Industrial HiVision . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8, 74
Ingress rate limiter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 178
IP access restriction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 84

L
L3 relay . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 247
LDAP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 61
LLDP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 328
Load/save . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26
Log file . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 45, 342
Login banner . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 89, 92
Loopback interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 252

M
MAC address table . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 180
Management access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20, 84
Management VLAN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
Menu . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
Modbus enforcer . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 124

N
NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 270, 272, 292
Network address translation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 270
Network time protocol . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 48
NTP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 48
NVM . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11, 12, 18, 24, 31

O
OPC enforcer . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 131
OSPF . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 197

P
Password . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 57, 306
Password length . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 57, 306
Persistent logging . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 339
Port forwarding . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 275
Power supply . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17, 303, 313
Pre-Login banner . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 92
Proxy ARP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 186

354 RM GUI EAGLE


Release 3.4 03/2020
Index

R
RADIUS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 61, 95
RAM . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 31
RAM test . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 322
Rate limiter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 178
Reboot . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 45
Relay . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 247
Router interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 185
Routing table . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 235

S
Secure shell . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 75
Security status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16, 305
Self-test . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 322
Serial interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 307
Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26
Severity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 338
SFP module . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 327
Signal contact . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16, 310
SNMP server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 74, 307
SNMP traps . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43, 200, 241, 255, 301, 305, 312, 315
SNMPv1/v2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 91
Software backup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
Software update . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
Source routing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 182
SSH server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 75
Stratum . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 48, 50
Switch dump . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 338
Syslog . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 324
System information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 318
System log . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 342
System monitor . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 322

T
Technical questions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 357
Temperature . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18, 302, 312
Threshold values network load . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 178
Time to live . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 184
Topology discovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 333
Tracking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 239, 268
Training courses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 357
Trap destination . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 315
Traps . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43, 200, 241, 255, 301, 305, 312, 315
TTL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 184

U
User administration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56

V
Virtual router redundancy protocol . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 254
VLAN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
VRRP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 254
VRRP statistics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 266
VRRP tracking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 268

W
Watchdog . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26, 30
Web server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 79, 80

RM GUI EAGLE 355


Release 3.4 03/2020
Index

Z
ZIP archive . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 338

356 RM GUI EAGLE


Release 3.4 03/2020
Further support

B Further support

Technical questions

For technical questions, please contact any Hirschmann dealer in your area or Hirschmann directly.

You find the addresses of our partners on the Internet at [Link].

A list of local telephone numbers and email addresses for technical support directly from
Hirschmann is available at [Link].

This site also includes a free of charge knowledge base and a software download section.

Technical Documents

The current manuals and operating instructions for Hirschmann products are available at
[Link].

Hirschmann Competence Center

The Hirschmann Competence Center is ahead of its competitors on three counts with its complete
range of innovative services:
 Consulting incorporates comprehensive technical advice, from system evaluation through
network planning to project planning.
 Training offers you an introduction to the basics, product briefing and user training with
certification.
You find the training courses on technology and products currently available at
[Link].
 Support ranges from the first installation through the standby service to maintenance concepts.

With the Hirschmann Competence Center, you decided against making any compromises. Our
client-customized package leaves you free to choose the service components you want to use.

RM GUI EAGLE 357


Release 3.4 03/2020
Readers’ Comments

C Readers’ Comments

What is your opinion of this manual? We are constantly striving to provide as comprehensive a
description of our product as possible, as well as important information to assist you in the operation
of this product. Your comments and suggestions help us to further improve the quality of our
documentation.

Your assessment of this manual:

Very Good Good Satisfactory Mediocre Poor


Precise description O O O O O
Readability O O O O O
Understandability O O O O O
Examples O O O O O
Structure O O O O O
Comprehensive O O O O O
Graphics O O O O O
Drawings O O O O O
Tables O O O O O

Did you discover any errors in this manual?


If so, on what page?

Suggestions for improvement and additional information:

358 RM GUI EAGLE


Release 3.4 03/2020
Readers’ Comments

General comments:

Sender:

Company / Department:

Name / Telephone number:

Street:

Zip code / City:

E-mail:

Date / Signature:

Dear User,

Please fill out and return this page


 as a fax to the number +49 (0)7127/14-1600 or
 per mail to
Hirschmann Automation and Control GmbH
Department 01RD-NT
Stuttgarter Str. 45-51
72654 Neckartenzlingen
Germany

RM GUI EAGLE 359


Release 3.4 03/2020
Reference Manual
Command Line Interface (CLI)
Industrial Security Router
EAGLE40

RM CLI EAGLE40 Technical Support


Release 3.4 03/2020 [Link]
The naming of copyrighted trademarks in this manual, even when not specially indicated, should not be taken to mean that these names may
be considered as free in the sense of the trademark and tradename protection law and hence that they may be freely used by anyone.

© 2020 Hirschmann Automation and Control GmbH

Manuals and software are protected by copyright. All rights reserved. The copying, reproduction, translation, conversion into any electronic
medium or machine scannable form is not permitted, either in whole or in part. An exception is the preparation of a backup copy of the software
for your own use.

The performance features described here are binding only if they have been expressly agreed when the contract was made. This document
was produced by Hirschmann Automation and Control GmbH according to the best of the company's knowledge. Hirschmann reserves the
right to change the contents of this document without prior notice. Hirschmann can give no guarantee in respect of the correctness or accuracy
of the information in this document.

Hirschmann can accept no responsibility for damages, resulting from the use of the network components or the associated operating software.
In addition, we refer to the conditions of use specified in the license contract.

You can get the latest version of this manual on the Internet at the Hirschmann product site ([Link]).

Hirschmann Automation and Control GmbH


Stuttgarter Str. 45-51
72654 Neckartenzlingen
Germany

Rel. 3.4 - 03/2020 – 23.03.2020


Contents

Cont e nt s

Sa fe t y inst ruc t ions 16

First login (Pa ssw ord c ha nge ) 17

About t his M a nua l 18

1 Applic a t ion List s 19


1.1 appllists 19
1.1.1 appllists set-authlist 19
1.1.2 appllists enable 19
1.1.3 appllists disable 19
1.2 show 19
1.2.1 show appllists 19

2 Aut he nt ic a t ion List s 20


2.1 authlists 20
2.1.1 authlists add 20
2.1.2 authlists delete 20
2.1.3 authlists set-policy 20
2.1.4 authlists enable 20
2.1.5 authlists disable 21
2.2 show 21
2.2.1 show authlists 21

3 Com m a nd Line I nt e rfa c e (CLI ) 22


3.1 cli 22
3.1.1 cli serial-timeout 22
3.1.2 cli prompt 22
3.1.3 cli numlines 22
3.1.4 cli banner operation 22
3.1.5 cli banner text 22
3.2 show 23
3.2.1 show cli global 23
3.2.2 show cli command-tree 23
3.3 logging 23
3.3.1 logging cli-command 23
3.4 show 23
3.4.1 show logging cli-command 23

4 Cloc k 24
4.1 clock 24
4.1.1 clock set 24
4.1.2 clock timezone offset 24
4.2 show 24
4.2.1 show clock 24

5 Configura t ion 25
5.1 save 25
5.1.1 save profile 25
5.2 config 25
5.2.1 config watchdog admin-state 25
5.2.2 config watchdog timeout 25
5.2.3 config encryption password set 25
5.2.4 config encryption password clear 25
5.2.5 config envm auto-update 26
5.2.6 config envm config-save 26

RM CLI EAGLE40 3
Release 3.4 03/2020
Contents

5.2.7 config envm load-priority 26


5.2.8 config profile select 26
5.2.9 config profile delete 26
5.2.10 config fingerprint verify nvm profile 27
5.2.11 config fingerprint verify nvm num 27
5.2.12 config fingerprint verify envm profile 27
5.2.13 config fingerprint verify envm num 27
5.3 copy 27
5.3.1 copy sysinfo system envm 27
5.3.2 copy sysinfoall system envm 27
5.3.3 copy firmware envm 27
5.3.4 copy firmware remote 28
5.3.5 copy config running-config nvm 28
5.3.6 copy config running-config remote 28
5.3.7 copy config nvm 28
5.3.8 copy config envm 28
5.3.9 copy config remote 28
5.4 clear 29
5.4.1 clear config 29
5.4.2 clear factory 29
5.5 show 29
5.5.1 show running-config 29
5.6 show 29
5.6.1 show config envm settings 29
5.6.2 show config envm properties 29
5.6.3 show config watchdog 29
5.6.4 show config encryption 29
5.6.5 show config profiles 30
5.6.6 show config status 30
5.7 swap 30
5.7.1 swap firmware system backup 30

6 De vic e M onit oring 31


6.1 device-status 31
6.1.1 device-status monitor link-failure 31
6.1.2 device-status monitor temperature 31
6.1.3 device-status monitor envm-removal 31
6.1.4 device-status monitor envm-not-in-sync 31
6.1.5 device-status monitor power-supply 31
6.1.6 device-status trap 32
6.2 device-status 32
6.2.1 device-status link-alarm 32
6.3 show 32
6.3.1 show device-status monitor 32
6.3.2 show device-status state 32
6.3.3 show device-status trap 32
6.3.4 show device-status events 33
6.3.5 show device-status link-alarm 33
6.3.6 show device-status all 33

7 De vic e Se c urit y 34
7.1 security-status 34
7.1.1 security-status monitor pwd-change 34
7.1.2 security-status monitor pwd-min-length 34
7.1.3 security-status monitor pwd-policy-config 34
7.1.4 security-status monitor pwd-policy-inactive 34
7.1.5 security-status monitor http-enabled 35
7.1.6 security-status monitor snmp-unsecure 35
7.1.7 security-status monitor sysmon-enabled 35
7.1.8 security-status monitor extnvm-upd-enabled 35
7.1.9 security-status monitor no-link-enabled 35
7.1.10 security-status monitor hidisc-enabled 36
7.1.11 security-status monitor extnvm-load-unsecure 36
7.1.12 security-status monitor https-certificate 36

4 RM CLI EAGLE40
Release 3.4 03/2020
Contents

7.1.13 security-status trap 36


7.2 security-status 36
7.2.1 security-status no-link 36
7.3 show 37
7.3.1 show security-status monitor 37
7.3.2 show security-status state 37
7.3.3 show security-status no-link 37
7.3.4 show security-status trap 37
7.3.5 show security-status events 37
7.3.6 show security-status all 37

8 Dom a in N a m e Syst e m (DN S) 38


8.1 dns 38
8.1.1 dns client servers add 38
8.1.2 dns client servers delete 38
8.1.3 dns client servers modify 38
8.1.4 dns client servers enable 38
8.1.5 dns client servers disable 38
8.2 show 39
8.2.1 show dns client info 39
8.2.2 show dns client servers 39

9 De e p Pa c k e t I nspe c t ion (DPI ) 40


9.1 dpi 40
9.1.1 dpi modbus commit 40
9.1.2 dpi modbus addprofile 40
9.1.3 dpi modbus modifyprofile 41
9.1.4 dpi modbus copyprofile 42
9.1.5 dpi modbus delprofile 42
9.1.6 dpi modbus enableprofile 42
9.1.7 dpi modbus disableprofile 43
9.1.8 dpi opc commit 43
9.1.9 dpi opc addprofile 43
9.1.10 dpi opc modifyprofile 43
9.1.11 dpi opc copyprofile 43
9.1.12 dpi opc delprofile 44
9.1.13 dpi opc enableprofile 44
9.1.14 dpi opc disableprofile 44
9.2 show 44
9.2.1 show dpi modbus profiletable 44
9.2.2 show dpi modbus pending 44
9.2.3 show dpi opc profiletable 44
9.2.4 show dpi opc pending 44

10 Fire w a ll Le a rning M ode (FLM ) 45


10.1 flm 45
10.1.1 flm operation 45
10.1.2 flm action 45
10.1.3 flm interface add 45
10.1.4 flm interface delete 45
10.2 show 45
10.2.1 show flm global 45
10.2.2 show flm interface 46

11 H iDisc ove ry 47
11.1 network 47
11.1.1 network hidiscovery operation 47
11.1.2 network hidiscovery mode 47
11.2 show 47
11.2.1 show network hidiscovery 47

12 H ype rt e x t T ra nsfe r Prot oc ol (H T T P) 48

RM CLI EAGLE40 5
Release 3.4 03/2020
Contents

12.1 http 48
12.1.1 http port 48
12.1.2 http server 48
12.2 show 48
12.2.1 show http 48

13 H T T P Se c ure (H T T PS) 49
13.1 https 49
13.1.1 https server 49
13.1.2 https port 49
13.1.3 https fingerprint-type 49
13.1.4 https certificate 49
13.2 copy 49
13.2.1 copy httpscert remote 49
13.2.2 copy httpscert envm 50
13.3 show 50
13.3.1 show https 50

14 I nt e rfa c e 51
14.1 shutdown 51
14.1.1 shutdown 51
14.2 auto-negotiate 51
14.2.1 auto-negotiate 51
14.3 auto-power-down 51
14.3.1 auto-power-down 51
14.4 cable-crossing 51
14.4.1 cable-crossing 51
14.5 linktraps 52
14.5.1 linktraps 52
14.6 speed 52
14.6.1 speed 52
14.7 name 52
14.7.1 name 52
14.8 power-state 52
14.8.1 power-state 52
14.9 show 53
14.9.1 show port 53

15 I nt e rfa c e St a t ist ic s 54
15.1 clear 54
15.1.1 clear port-statistics 54
15.2 show 54
15.2.1 show interface counters 54
15.2.2 show interface statistics 54
15.2.3 show interface ether-stats 54

16 I nt e rn 55
16.1 help 55
16.2 logout 55
16.3 history 55
16.4 exit 55
16.5 serviceshell 55
16.5.1 serviceshell start 55
16.5.2 serviceshell deactivate 55
16.6 traceroute 55
16.6.1 traceroute source 56

6 RM CLI EAGLE40
Release 3.4 03/2020
Contents

16.7 reboot 56
16.8 ping 56
16.8.1 ping source 56
16.9 show 56
16.9.1 show serviceshell 56

17 Ope n Short e st Pa t h First (OSPF) 57


17.1 ip 57
17.1.1 ip ospf area 57
17.1.2 ip ospf trapflags all 59
17.1.3 ip ospf operation 59
17.1.4 ip ospf 1583compatability 59
17.1.5 ip ospf default-metric 59
17.1.6 ip ospf router-id 60
17.1.7 ip ospf external-lsdb-limit 60
17.1.8 ip ospf exit-overflow 60
17.1.9 ip ospf maximum-path 60
17.1.10ip ospf spf-delay 60
17.1.11ip ospf spf-holdtime 60
17.1.12ip ospf auto-cost 60
17.1.13ip ospf distance intra 61
17.1.14ip ospf distance inter 61
17.1.15ip ospf distance external 61
17.1.16ip ospf re-distribute 61
17.1.17ip ospf distribute-list 61
17.1.18ip ospf default-info originate 62
17.2 ip 62
17.2.1 ip ospf operation 62
17.2.2 ip ospf area-id 62
17.2.3 ip ospf link-type 62
17.2.4 ip ospf priority 63
17.2.5 ip ospf transmit-delay 63
17.2.6 ip ospf retransmit-interval 63
17.2.7 ip ospf hello-interval 63
17.2.8 ip ospf dead-interval 63
17.2.9 ip ospf cost 64
17.2.10ip ospf mtu-ignore 64
17.2.11ip ospf authentication type 64
17.2.12ip ospf authentication key 64
17.2.13ip ospf authentication key-id 64
17.3 show 64
17.3.1 show ip ospf global 64
17.3.2 show ip ospf area 65
17.3.3 show ip ospf stub 65
17.3.4 show ip ospf database internal 65
17.3.5 show ip ospf database external 65
17.3.6 show ip ospf range 65
17.3.7 show ip ospf interface 65
17.3.8 show ip ospf virtual-link 65
17.3.9 show ip ospf virtual-neighbor 65
17.3.10show ip ospf neighbor 65
17.3.11show ip ospf statistics 66
17.3.12show ip ospf re-distribute 66
17.3.13show ip ospf nssa 66
17.3.14show ip ospf route 66

18 V irt ua l Rout e r Re dunda nc y Prot oc ol (V RRP) 67


18.1 ip 67
18.1.1 ip vrrp operation 67
18.1.2 ip vrrp trap auth-failure 67
18.1.3 ip vrrp trap new-master 67
18.2 ip 67
18.2.1 ip vrrp add 67
18.2.2 ip vrrp modify 68
18.2.3 ip vrrp delete 68

RM CLI EAGLE40 7
Release 3.4 03/2020
Contents

18.2.4 ip vrrp enable 68


18.2.5 ip vrrp disable 68
18.2.6 ip vrrp virtual-address add 68
18.2.7 ip vrrp virtual-address delete 68
18.2.8 ip vrrp track add 68
18.2.9 ip vrrp track modify 69
18.2.10ip vrrp track delete 69
18.3 show 69
18.3.1 show ip vrrp interface 69
18.3.2 show ip vrrp global 69

19 Addre ss Re solut ion Prot oc ol (I P ARP) 70


19.1 ip 70
19.1.1 ip arp add 70
19.1.2 ip arp delete 70
19.1.3 ip arp enable 70
19.1.4 ip arp disable 70
19.1.5 ip arp timeout 70
19.1.6 ip arp response-time 70
19.1.7 ip arp retries 70
19.2 show 71
19.2.1 show ip arp info 71
19.2.2 show ip arp table 71
19.2.3 show ip arp static 71
19.2.4 show ip arp entry 71
19.3 clear 71
19.3.1 clear ip arp-cache 71

20 L3 Re la y 72
20.1 ip 72
20.1.1 ip udp-helper operation 72
20.1.2 ip udp-helper server add 72
20.1.3 ip udp-helper server delete 72
20.1.4 ip udp-helper server enable 72
20.1.5 ip udp-helper server disable 72
20.1.6 ip udp-helper maxhopcount 73
20.1.7 ip udp-helper minwaittime 73
20.1.8 ip udp-helper cidoptmode 73
20.2 ip 73
20.2.1 ip udp-helper server add 73
20.2.2 ip udp-helper server delete 73
20.2.3 ip udp-helper server enable 73
20.2.4 ip udp-helper server disable 74
20.3 show 74
20.3.1 show ip udp-helper status 74
20.3.2 show ip udp-helper global 74
20.3.3 show ip udp-helper interface 74
20.3.4 show ip udp-helper statistics 74
20.4 clear 74
20.4.1 clear ip udp-helper 74

21 I nt e rne t Prot oc ol V e rsion 4 (I Pv4 ) 75


21.1 network 75
21.1.1 network protocol 75
21.1.2 network parms 75
21.2 clear 75
21.2.1 clear arp-table-switch 75
21.3 show 75
21.3.1 show network parms 75
21.4 show 75
21.4.1 show arp 76

8 RM CLI EAGLE40
Release 3.4 03/2020
Contents

22 Link La ye r Disc ove ry Prot oc ol (LLDP) 77


22.1 lldp 77
22.1.1 lldp operation 77
22.1.2 lldp config chassis admin-state 77
22.1.3 lldp config chassis notification-interval 77
22.1.4 lldp config chassis tx-hold-multiplier 77
22.1.5 lldp config chassis tx-interval 77
22.2 show 77
22.2.1 show lldp global 78
22.2.2 show lldp port 78
22.2.3 show lldp remote-data 78
22.3 lldp 78
22.3.1 lldp admin-state 78
22.3.2 lldp fdb-mode 78
22.3.3 lldp max-neighbors 78
22.3.4 lldp notification 79
22.3.5 lldp tlv port-desc 79
22.3.6 lldp tlv sys-cap 79
22.3.7 lldp tlv sys-desc 79
22.3.8 lldp tlv sys-name 79

23 Logging 81
23.1 logging 81
23.1.1 logging audit-trail 81
23.1.2 logging buffered severity 81
23.1.3 logging host add 81
23.1.4 logging host delete 81
23.1.5 logging host enable 81
23.1.6 logging host disable 82
23.1.7 logging host modify 82
23.1.8 logging syslog operation 82
23.1.9 logging current-console operation 82
23.1.10logging current-console severity 82
23.1.11logging console operation 83
23.1.12logging console severity 83
23.2 show 83
23.2.1 show logging buffered 84
23.2.2 show logging traplogs 84
23.2.3 show logging console 84
23.2.4 show logging persistent 84
23.2.5 show logging syslog 84
23.2.6 show logging host 84
23.3 copy 84
23.3.1 copy eventlog buffered envm 84
23.3.2 copy eventlog buffered remote 84
23.3.3 copy eventlog persistent 85
23.3.4 copy traplog system envm 85
23.3.5 copy traplog system remote 85
23.3.6 copy audittrail system envm 85
23.3.7 copy audittrail system remote 85
23.4 clear 85
23.4.1 clear logging buffered 85
23.4.2 clear logging persistent 85
23.4.3 clear eventlog 86

24 M a na ge m e nt Ac c e ss 87
24.1 network 87
24.1.1 network management access web timeout 87
24.1.2 network management access add 87
24.1.3 network management access delete 87
24.1.4 network management access modify 87
24.1.5 network management access operation 88
24.1.6 network management access status 88

RM CLI EAGLE40 9
Release 3.4 03/2020
Contents

24.2 show 88
24.2.1 show network management access global 88
24.2.2 show network management access rules 88

25 N e t w ork Addre ss T ra nsla t ion (N AT ) 89


25.1 nat 89
25.1.1 nat dnat commit 89
25.1.2 nat dnat add 89
25.1.3 nat dnat modify 89
25.1.4 nat dnat delete 90
25.1.5 nat dnat logtrap 90
25.1.6 nat dnat state 90
25.1.7 nat dnat if add 91
25.1.8 nat dnat if delete 91
25.1.9 nat 1to1nat commit 91
25.1.10nat 1to1nat add 91
25.1.11nat 1to1nat modify 91
25.1.12nat 1to1nat delete 92
25.1.13nat 1to1nat logtrap 92
25.1.14nat 1to1nat state 92
25.1.15nat masq commit 92
25.1.16nat masq add 92
25.1.17nat masq modify 92
25.1.18nat masq delete 93
25.1.19nat masq logtrap 93
25.1.20nat masq ipsec-exempt 93
25.1.21nat masq state 93
25.1.22nat masq if add 93
25.1.23nat masq if delete 94
25.1.24nat doublenat commit 94
25.1.25nat doublenat add 94
25.1.26nat doublenat modify 94
25.1.27nat doublenat delete 94
25.1.28nat doublenat logtrap 94
25.1.29nat doublenat state 95
25.1.30nat doublenat if add 95
25.1.31nat doublenat if delete 95
25.2 show 95
25.2.1 show nat dnat rules 95
25.2.2 show nat dnat if 95
25.2.3 show nat dnat logtrap 96
25.2.4 show nat masq rules 96
25.2.5 show nat masq logtrap 96
25.2.6 show nat masq if 96
25.2.7 show nat 1to1nat rules 96
25.2.8 show nat 1to1nat logtrap 96
25.2.9 show nat doublenat rules 96
25.2.10show nat doublenat logtrap 96
25.2.11show nat doublenat if 97

26 N e t w ork T im e Prot oc ol (N T P) 98
26.1 ntp 98
26.1.1 ntp client operation 98
26.1.2 ntp client operating-mode 98
26.1.3 ntp server operation 98
26.1.4 ntp server operating-mode 98
26.1.5 ntp server localclock-stratum 98
26.1.6 ntp peers add 98
26.1.7 ntp peers delete 99
26.2 show 99
26.2.1 show ntp client-status 99
26.2.2 show ntp server-status 99

27 Pa c k e t Filt e r 100
27.1 packet-filter 100

10 RM CLI EAGLE40
Release 3.4 03/2020
Contents

27.1.1 packet-filter l3 commit 100


27.1.2 packet-filter l3 defaultpolicy 100
27.1.3 packet-filter l3 checksum-validation 100
27.1.4 packet-filter l3 addrule 100
27.1.5 packet-filter l3 modifyrule 101
27.1.6 packet-filter l3 delrule 101
27.1.7 packet-filter l3 enablerule 101
27.1.8 packet-filter l3 disablerule 101
27.1.9 packet-filter l3 logmode 102
27.1.10packet-filter l3 addif 102
27.1.11packet-filter l3 delif 102
27.1.12packet-filter l3 enableif 102
27.1.13packet-filter l3 disableif 102
27.2 clear 102
27.2.1 clear fw-state-table 103
27.3 show 103
27.3.1 show packet-filter l3 global 103
27.3.2 show packet-filter l3 ruletable 103
27.3.3 show packet-filter l3 iftable 103

28 Pa ssw ord M a na ge m e nt 104


28.1 passwords 104
28.1.1 passwords min-length 104
28.1.2 passwords max-login-attempts 104
28.1.3 passwords min-uppercase-chars 104
28.1.4 passwords min-lowercase-chars 104
28.1.5 passwords min-numeric-chars 104
28.1.6 passwords min-special-chars 104
28.1.7 passwords login-attempt-period 104
28.2 show 105
28.2.1 show passwords 105

29 Ra dius 106
29.1 radius 106
29.1.1 radius server attribute 4 106
29.1.2 radius server auth add 106
29.1.3 radius server auth delete 106
29.1.4 radius server auth modify 106
29.1.5 radius server retransmit 107
29.1.6 radius server timeout 107
29.2 show 107
29.2.1 show radius global 107
29.2.2 show radius auth servers 107
29.2.3 show radius auth statistics 107
29.3 clear 107
29.3.1 clear radius 107

30 Re m ot e Aut he nt ic a t ion 109


30.1 ldap 109
30.1.1 ldap operation 109
30.1.2 ldap cache-timeout 109
30.1.3 ldap flush-user-cache 109
30.1.4 ldap role-policy 109
30.1.5 ldap basedn 109
30.1.6 ldap search-attr 109
30.1.7 ldap bind-user 110
30.1.8 ldap bind-passwd 110
30.1.9 ldap default-domain 110
30.1.10ldap client server add 110
30.1.11ldap client server delete 110
30.1.12ldap client server enable 110
30.1.13ldap client server disable 110
30.1.14ldap client server modify 111
30.1.15ldap mapping add 111

RM CLI EAGLE40 11
Release 3.4 03/2020
Contents

30.1.16ldap mapping delete 111


30.1.17ldap mapping enable 111
30.1.18ldap mapping disable 111
30.2 show 112
30.2.1 show ldap global 112
30.2.2 show ldap client server 112
30.2.3 show ldap mapping 112
30.3 copy 112
30.3.1 copy ldapcacert remote 112
30.3.2 copy ldapcacert envm 112

31 Re m ot e M onit oring (RM ON ) 113


31.1 show 113
31.1.1 show rmon statistics 113

32 Sc ript File 114


32.1 script 114
32.1.1 script apply 114
32.1.2 script validate 114
32.1.3 script list system 114
32.1.4 script list envm 114
32.1.5 script delete 114
32.2 copy 114
32.2.1 copy script envm 114
32.2.2 copy script remote 115
32.2.3 copy script nvm 115
32.3 show 115
32.3.1 show script envm 115
32.3.2 show script system 115

33 Se lft e st 116
33.1 selftest 116
33.1.1 selftest action 116
33.1.2 selftest ramtest 116
33.1.3 selftest system-monitor 116
33.1.4 selftest boot-default-on-error 116
33.2 show 117
33.2.1 show selftest action 117
33.2.2 show selftest settings 117

34 Sm a ll Form -fa c t or Plugga ble (SFP) 118


34.1 show 118
34.1.1 show sfp 118

35 Signa l Cont a c t 119


35.1 signal-contact 119
35.1.1 signal-contact mode 119
35.1.2 signal-contact monitor link-failure 119
35.1.3 signal-contact monitor envm-not-in-sync 119
35.1.4 signal-contact monitor envm-removal 119
35.1.5 signal-contact monitor temperature 120
35.1.6 signal-contact monitor power-supply 120
35.1.7 signal-contact state 120
35.1.8 signal-contact trap 120
35.2 signal-contact 121
35.2.1 signal-contact link-alarm 121
35.3 show 121
35.3.1 show signal-contact 121

36 Sim ple N e t w ork M a na ge m e nt Prot oc ol (SN M P) 122

12 RM CLI EAGLE40
Release 3.4 03/2020
Contents

36.1 snmp 122


36.1.1 snmp access version v1 122
36.1.2 snmp access version v2 122
36.1.3 snmp access version v3 122
36.1.4 snmp access port 122
36.2 show 122
36.2.1 show snmp access 123

37 SN M P Com m unit y 124


37.1 snmp 124
37.1.1 snmp community ro 124
37.1.2 snmp community rw 124
37.2 show 124
37.2.1 show snmp community 124

38 SN M P Logging 125
38.1 logging 125
38.1.1 logging snmp-request get operation 125
38.1.2 logging snmp-request get severity 125
38.1.3 logging snmp-request set operation 125
38.1.4 logging snmp-request set severity 126
38.2 show 126
38.2.1 show logging snmp 126

39 Se c ure She ll (SSH ) 127


39.1 ssh 127
39.1.1 ssh server 127
39.1.2 ssh timeout 127
39.1.3 ssh port 127
39.1.4 ssh max-sessions 127
39.1.5 ssh key rsa 127
39.1.6 ssh key fingerprint-type 127
39.2 copy 128
39.2.1 copy sshkey remote 128
39.2.2 copy sshkey envm 128
39.3 show 128
39.3.1 show ssh 128

40 Syst e m 129
40.1 system 129
40.1.1 system name 129
40.1.2 system location 129
40.1.3 system contact 129
40.1.4 system pre-login-banner operation 129
40.1.5 system pre-login-banner text 129
40.1.6 system resources operation 130
40.2 temperature 130
40.2.1 temperature upper-limit 130
40.2.2 temperature lower-limit 130
40.3 show 130
40.3.1 show eventlog 130
40.3.2 show system info 130
40.3.3 show system pre-login-banner 130
40.3.4 show system flash-status 131
40.3.5 show system resources 131

41 T ra ps 132
41.1 snmp 132
41.1.1 snmp trap operation 132
41.1.2 snmp trap mode 132

RM CLI EAGLE40 13
Release 3.4 03/2020
Contents

41.1.3 snmp trap delete 132


41.1.4 snmp trap add 132
41.2 show 132
41.2.1 show snmp traps 133

42 U nic a st Rout ing 134


42.1 routing 134
42.1.1 routing add 134
42.1.2 routing delete 134
42.2 ip 134
42.2.1 ip routing 134
42.2.2 ip proxy-arp max-delay 134
42.3 show 134
42.3.1 show ip global 135
42.4 show 135
42.4.1 show ip interface 135
42.4.2 show ip statistics 135
42.5 ip 135
42.5.1 ip proxy-arp operation 135
42.5.2 ip address secondary 135
42.5.3 ip address primary 136
42.5.4 ip mtu 136
42.5.5 ip icmp redirects 136
42.6 ip 136
42.6.1 ip route add 136
42.6.2 ip route modify 136
42.6.3 ip route delete 137
42.6.4 ip route distance 137
42.6.5 ip route track add 137
42.6.6 ip route track delete 137
42.6.7 ip default-route add 137
42.6.8 ip default-route modify 137
42.6.9 ip default-route delete 138
42.6.10ip loopback add 138
42.6.11ip loopback delete 138
42.6.12ip icmp redirects 138
42.6.13ip icmp echo-reply 138
42.6.14ip icmp rate-limit interval 138
42.6.15ip icmp rate-limit burst-size 138
42.7 show 139
42.7.1 show ip route all 139
42.7.2 show ip route local 139
42.7.3 show ip route static 139
42.7.4 show ip route entry 139
42.7.5 show ip route tracking 139

43 T ra c k ing 140
43.1 track 140
43.1.1 track add 140
43.1.2 track delete 140
43.1.3 track enable 140
43.1.4 track disable 140
43.1.5 track trap 140
43.1.6 track description 141
43.1.7 track modify interface 141
43.1.8 track modify ping 141
43.1.9 track modify logical 141
43.2 show 142
43.2.1 show track overview 142
43.2.2 show track interface 142
43.2.3 show track ping 142
43.2.4 show track logical 142
43.2.5 show track application 142

14 RM CLI EAGLE40
Release 3.4 03/2020
Contents

44 V irt ua l Priva t e N e t w ork (V PN ) 143


44.1 ipsec 143
44.1.1 ipsec certificate delete 143
44.1.2 ipsec certificate upload passphrase 143
44.1.3 ipsec connection add 143
44.1.4 ipsec connection modify 144
44.1.5 ipsec connection status 146
44.1.6 ipsec connection delete 146
44.1.7 ipsec traffic-selector 147
44.2 show 147
44.2.1 show ipsec general 147
44.2.2 show ipsec connections summary 147
44.2.3 show ipsec connections access 148
44.2.4 show ipsec connections certificates 148
44.2.5 show ipsec connections key-exchange 148
44.2.6 show ipsec connections data-exchange 148
44.2.7 show ipsec connections status 148
44.2.8 show ipsec traffic-selectors 148
44.2.9 show ipsec certificate summary 148
44.2.10show ipsec certificate details 148

45 U se rs 149
45.1 users 149
45.1.1 users add 149
45.1.2 users delete 149
45.1.3 users enable 149
45.1.4 users disable 149
45.1.5 users password 149
45.1.6 users snmpv3 authentication 149
45.1.7 users snmpv3 encryption 150
45.1.8 users access-role 150
45.1.9 users lock-status 150
45.1.10users password-policy-check 150
45.2 show 150
45.2.1 show users 150

A Furt he r support 151

B Re a de rs’ Com m e nt s 152

RM CLI EAGLE40 15
Release 3.4 03/2020
Safety instructions

Sa fe t y inst ruc t ions

WARN I N G
UNCONTROLLED MACHINE ACTIONS
To avoid uncontrolled machine actions caused by data loss, configure all the data transmission devices
individually.
Before you start any machine which is controlled via data transmission, be sure to complete the configuration of
all data transmission devices.

Failure to follow these instructions can result in death, serious injury, or equipment damage.

WARN I N G
UNWANTED APPLICATION BEHAVIOR
Configuration of the Ethernet devices shall be done by an Ethernet expert.
Before you start any application based on an AFS and/or AFF network, be sure to complete the configuration of
all Ethernet devices correctly.

Failure to follow these instructions can result in equipment damage, serious injury or even death.

16 RM CLI EAGLE40
Release 3.4 03/2020
First login (Pa ssw ord cha nge )
To help prevent undesired access to the device, it is imperative that you change the default password during initial
setup.
Perform the following steps:
 Open the Graphical User Interface, the Command Line Interface, or HiView the first time you log on to the
device.
 Log on to the device with the default password.
The device prompts you to type in a new password.
 Type in your new password.
To help increase security, choose a password that contains at least 8 characters which includes upper-case
characters, lower-case characters, numerical digits, and special characters.
 The device prompts you to confirm your new password.
 Log on to the device again with your new password.

Note: If you lost your password, then use the System Monitor to reset the password.

For further information see: [Link].

RM CLI EAGLE40 17
Release 3.4 03/2020
About t his M a nua l

The “Installation” user manual contains a device description, safety instructions, a description of the display, and
the other information that you need to install the device.

The “Configuration” user manual contains the information you need to start operating the device. It takes you step
by step from the first startup operation through to the basic settings for operation in your environment.

The “Graphical User Interface” reference manual contains detailed information on using the graphical user
interface to operate the individual functions of the device.

The “Command Line Interface” reference manual contains detailed information on using the Command Line
Interface to operate the individual functions of the device.

The Industrial HiVision Network Management software provides you with additional options for smooth
configuration and monitoring:
 Auto-topology discovery
 Browser interface
 Client/server structure
 Event handling
 Event log
 Simultaneous configuration of multiple devices
 Graphical user interface with network layout
 SNMP/OPC gateway

18 RM CLI EAGLE40
Release 3.4 03/2020
1 Applic at ion List s

1 .1 a ppllist s
Configure an application list.

1 .1 .1 a ppllist s se t -a ut hlist
Set an authentication list reference that shall be used by given application.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: appllists set-authlist <P-1> <P-2>
Parameter Value Meaning
P-1 string <application> Name of an application list.
P-2 string <authlist_name> Name of referenced authentication list.

1 .1 .2 a ppllist s e na ble
Activate a login application list.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: appllists enable <P-1>
Parameter Value Meaning
P-1 string <application> Name of an application list.

1 .1 .3 a ppllist s disa ble


Deactivate a login application list.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: appllists disable <P-1>
Parameter Value Meaning
P-1 string <application> Name of an application list.

1 .2 show
Display device options and settings.

1 .2 .1 show a ppllist s
Display the ordered methods for application lists.
 Mode: Command is in all modes available.
 Privilege Level: Administrator
 Format: show appllists

RM CLI EAGLE40 19
Release 3.4 03/2020
2 Aut he nt ic at ion List s

2 .1 a ut hlist s
Configure an authentication list.

2 .1 .1 a ut hlist s a dd
Create a new login authentication list.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: authlists add <P-1>
Parameter Value Meaning
P-1 string <authlist_name> Name of an authentication list.

2 .1 .2 a ut hlist s de le t e
Delete an existing login authentication list.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: authlists delete <P-1>
Parameter Value Meaning
P-1 string <authlist_name> Name of an authentication list.

2 .1 .3 a ut hlist s se t -polic y
Set the policies of a login authentication list.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: authlists set-policy <P-1> <P-2> [<P-3> [<P-4> [<P-5> [<P-6>]]]]
Parameter Value Meaning
P-1 string <authlist_name> Name of an authentication list.
P-2 reject Authentication is rejected / not allowed
local Authentication by local user DB
radius Authentication by RADIUS server
Idap Authentication by remote server
P-3 reject Authentication is rejected / not allowed
local Authentication by local user DB
radius Authentication by RADIUS server
Idap Authentication by remote server
P-4 reject Authentication is rejected / not allowed
local Authentication by local user DB
radius Authentication by RADIUS server
Idap Authentication by remote server
P-5 reject Authentication is rejected / not allowed
local Authentication by local user DB
radius Authentication by RADIUS server
Idap Authentication by remote server
P-6 reject Authentication is rejected / not allowed
local Authentication by local user DB
radius Authentication by RADIUS server
Idap Authentication by remote server

2 .1 .4 a ut hlist s e na ble
Activate a login authentication list.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: authlists enable <P-1>
Parameter Value Meaning
P-1 string <authlist_name> Name of an authentication list.

20 RM CLI EAGLE40
Release 3.4 03/2020
2 .1 .5 a ut hlist s disa ble
Deactivate a login authentication list.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: authlists disable <P-1>
Parameter Value Meaning
P-1 string <authlist_name> Name of an authentication list.

2 .2 show
Display device options and settings.

2 .2 .1 show a ut hlist s
Display the ordered methods for authentication lists.
 Mode: Command is in all modes available.
 Privilege Level: Administrator
 Format: show authlists

RM CLI EAGLE40 21
Release 3.4 03/2020
3 Com m a nd Line I nt e rfa c e (CLI )

3 .1 cli
Set the CLI preferences.

3 .1 .1 c li se ria l-t im e out


Set login timeout for serial line connection to CLI. Setting to 0 will disable the timeout. The value is active after next
login.
 Mode: Privileged Exec Mode
 Privilege Level: Operator
 Format: cli serial-timeout <P-1>
Parameter Value Meaning
P-1 0..160 Enter a number in the given range. Setting to 0 will disable the timeout.

3 .1 .2 c li prom pt
Change the system prompt. Following wildcards are allowed: %d date, %t time, %i IP address, %m MAC address
,%p product name
 Mode: Privileged Exec Mode
 Privilege Level: Operator
 Format: cli prompt <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 128 characters. Following wildcards are
allowed: %d date, %t time, %i IP address, %m MAC address ,%p product name

3 .1 .3 c li num line s
Screen size for 'more' (23 = default). Enter a 0 will disable the feature. The value is only valid for the current
session.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: cli numlines <P-1>
Parameter Value Meaning
P-1 0..250 Screen size for 'more' (23 = default). Enter a 0 will disable the feature. The
value is only valid for the current session.

3 .1 .4 c li ba nne r ope ra t ion


Enable or disable the CLI login banner.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: cli banner operation

 no c li ba nne r ope ra t ion


Disable the option
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: no cli banner operation

3 .1 .5 c li ba nne r t e x t
Set the text for the CLI login banner (C printf format syntax allowed: ).
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: cli banner text <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 1024 characters (allowed characters are from
ASCII 32 to 127).

22 RM CLI EAGLE40
Release 3.4 03/2020
3 .2 show
Display device options and settings.

3 .2 .1 show c li globa l
Display the CLI preferences.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show cli global

3 .2 .2 show c li c om m a nd-t re e
Display a list of every command.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show cli command-tree

3 .3 logging
Logging configuration.

3 .3 .1 logging c li-c om m a nd
Enable or disable the CLI command logging.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: logging cli-command

 no logging c li-c om m a nd
Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no logging cli-command

3 .4 show
Display device options and settings.

3 .4 .1 show logging c li-c om m a nd


Display the CLI command logging preferences.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show logging cli-command

RM CLI EAGLE40 23
Release 3.4 03/2020
4 Clock

4 .1 clock
Configure local and DST clock settings.

4 .1 .1 c loc k se t
Edit current local time.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: clock set <P-1> <P-2>
Parameter Value Meaning
P-1 YYYY-MM-DD Local date (range: 2004-01-01 - 2037-12-31).
P-2 HH:MM:SS Local time.

4 .1 .2 c loc k t im e zone offse t


Local time offset (in minutes) with respect to UTC (positive values for locations east of Greenwich).
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: clock timezone offset <P-1>
Parameter Value Meaning
P-1 -780..840 Edit the timezone offset (in minutes).

4 .2 show
Display device options and settings.

4 .2 .1 show c loc k
Display the current time information.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show clock

24 RM CLI EAGLE40
Release 3.4 03/2020
5 Configurat ion

5 .1 save
Save the configuration to the specified destination.

5 .1 .1 sa ve profile
Save the configuration to the specific profile.
 Mode: All Privileged Modes
 Privilege Level: Operator
 Format: save profile <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 32 characters.

5 .2 c onfig
Configure the configuration saving settings.

5 .2 .1 c onfig w a t c hdog a dm in-st a t e


Enable or disable the configuration undo feature.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: config watchdog admin-state

 no c onfig w a t c hdog a dm in-st a t e


Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no config watchdog admin-state

5 .2 .2 c onfig w a t c hdog t im e out


Configure the configuration undo timeout (unit: seconds).
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: config watchdog timeout <P-1>
Parameter Value Meaning
P-1 30..600 Enter a number in the given range.

5 .2 .3 c onfig e nc rypt ion pa ssw ord se t


Set the configuration file password.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: config encryption password set [<P-1>] [<P-2>]
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 64 characters.
P-2 string Enter a user-defined text, max. 64 characters.

5 .2 .4 c onfig e nc rypt ion pa ssw ord c le a r


Clear the configuration file password.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: config encryption password clear [<P-1>]
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 64 characters.

RM CLI EAGLE40 25
Release 3.4 03/2020
5 .2 .5 c onfig e nvm a ut o-upda t e
Allow automatic firmware updates with this memory device.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: config envm auto-update <P-1>
Parameter Value Meaning
P-1 usb USB Storage Device

 no c onfig e nvm a ut o-upda t e


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no config envm auto-update <P-1>
Parameter Value Meaning
P-1 usb USB Storage Device

5 .2 .6 c onfig e nvm c onfig-sa ve


Allow the configuration to be saved to this memory device.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: config envm config-save <P-1>
Parameter Value Meaning
P-1 usb USB Storage Device

 no c onfig e nvm c onfig-sa ve


Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no config envm config-save <P-1>

5 .2 .7 c onfig e nvm loa d-priorit y


Configure the order of configuration load attempts from memory devices at boot time. If one load is successful,
then the device discards further attempts.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: config envm load-priority <P-1> <P-2>
Parameter Value Meaning
P-1 usb USB Storage Device
P-2 disable Config will not be loaded at all
first Config will be loaded first. If successful, no other config will be tried.

5 .2 .8 c onfig profile se le c t
Select a configuration profile to be the active configuration.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: config profile select <P-1> <P-2>
Parameter Value Meaning
P-1 nvm You can only select nvm for this command.
P-2 1..20 Index of the profile entry.

5 .2 .9 c onfig profile de le t e
Delete a specific configuration profile.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: config profile delete <P-1> num <P-2> profile <P-3>
num: Select the index of a profile to delete.
profile: Select the name of a profile to delete.
Parameter Value Meaning
P-1 nvm non-volatile memory
envm external non-volatile memory device
P-2 1..20 Index of the profile entry.
P-3 string Enter a user-defined text, max. 32 characters.

26 RM CLI EAGLE40
Release 3.4 03/2020
5 .2 .1 0 c onfig finge rprint ve rify nvm profile
Select the name of a profile to be verified.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: config fingerprint verify nvm profile <P-1> <P-2>
Parameter Value Meaning
P-1 string Filename.
P-2 string Enter hash as 40 hexa-decimal characters.

5 .2 .1 1 c onfig finge rprint ve rify nvm num


Select the index number of a profile to be verified.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: config fingerprint verify nvm num <P-1> <P-2>
Parameter Value Meaning
P-1 1..20 Index of the profile entry.
P-2 string Enter hash as 40 hexa-decimal characters.

5 .2 .1 2 c onfig finge rprint ve rify e nvm profile


Select the name of a profile to be verified.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: config fingerprint verify envm profile <P-1> <P-2>
Parameter Value Meaning
P-1 string Filename.
P-2 string Enter hash as 40 hexa-decimal characters.

5 .2 .1 3 c onfig finge rprint ve rify e nvm num


Select the index number of a profile to be verified.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: config fingerprint verify envm num <P-1> <P-2>
Parameter Value Meaning
P-1 1..20 Index of the profile entry.
P-2 string Enter hash as 40 hexa-decimal characters.

5 .3 c opy
Copy different kinds of items.

5 .3 .1 c opy sysinfo syst e m e nvm


Copy the system information to external non-volatile memory.
 Mode: Privileged Exec Mode
 Privilege Level: Operator
 Format: copy sysinfo system envm [filename <P-1>]
[filename]: Enter the filename (format [Link]) to be saved in external non-volatile memory.
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 32 characters.

5 .3 .2 c opy sysinfoa ll syst e m e nvm


Copy the system information and the event log from the device to external non-volatile memory.
 Mode: Privileged Exec Mode
 Privilege Level: Operator
 Format: copy sysinfoall system envm

5 .3 .3 c opy firm w a re e nvm


Copy a firmware image to the device from external non-volatile memory.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: copy firmware envm <P-1> system

RM CLI EAGLE40 27
Release 3.4 03/2020
system: Copy a firmware image to the device from external non-volatile memory.
Parameter Value Meaning
P-1 string Filename.

5 .3 .4 c opy firm w a re re m ot e
Copy a firmware image to the device from a server.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: copy firmware remote <P-1> system
system: Copy a firmware image to the device from a file server.
Parameter Value Meaning
P-1 string Enter a valid server URL.

5 .3 .5 c opy c onfig running-c onfig nvm


Copy the running-config to non-volatile memory.
 Mode: Privileged Exec Mode
 Privilege Level: Operator
 Format: copy config running-config nvm [profile <P-1>]
[profile]: Save the configuration as a specific profile name.
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 32 characters.

5 .3 .6 c opy c onfig running-c onfig re m ot e


Copy the running-config to a file server.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: copy config running-config remote <P-1>
Parameter Value Meaning
P-1 string Enter a valid server URL.

5 .3 .7 c opy c onfig nvm


Load a configuration from non-volatile memory to the running-config.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: copy config nvm [profile <P-1>] running-config remote <P-2>
[profile]: Load a configuration from a specific profile name.
running-config: (Re)-load a configuration from non-volatile memory to the running-config.
remote: Copy a configuration from non-volatile memory to a server.
Parameter Value Meaning
P-1 string Filename.
P-2 string Enter a valid server URL.

5 .3 .8 c opy c onfig e nvm


Copy a configuration from external non-volatile memory to non-volatile memory.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: copy config envm [profile <P-1>] nvm
[profile]: Copy a specific configuration profile from external non-volatile memory to non-volatile memory.
nvm: Copy a specific profile from external non-volatile memory to non-volatile memory.
Parameter Value Meaning
P-1 string Filename.

5 .3 .9 c opy c onfig re m ot e
Copy a configuration file to the device from a server.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: copy config remote <P-1> nvm [profile <P-2>] running-config
nvm: Copy a configuration file from a server to non-volatile memory.
[profile]: Copy a configuration from a server to a specific profile in non-volatile memory.
running-config: Copy a configuration file from a server to the running-config.
Parameter Value Meaning
P-1 string Enter a valid server URL.
P-2 string Enter a user-defined text, max. 32 characters.

28 RM CLI EAGLE40
Release 3.4 03/2020
5 .4 cle a r
Clear several items.

5 .4 .1 c le a r c onfig
Clear the running configuration.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: clear config

5 .4 .2 c le a r fa c t ory
Set the device back to the factory settings (use with care).
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: clear factory

5 .5 show
Display device options and settings.

5 .5 .1 show running-c onfig


Display the currently running configuration.
 Mode: Command is in all modes available.
 Privilege Level: Administrator
 Format: show running-config

5 .6 show
Display device options and settings.

5 .6 .1 show c onfig e nvm se t t ings


Display the settings of the external non-volatile memory.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show config envm settings

5 .6 .2 show c onfig e nvm prope rt ie s


Display the properties of the external non-volatile memory.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show config envm properties

5 .6 .3 show c onfig w a t c hdog


Display the Auto Configuration Undo settings.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show config watchdog

5 .6 .4 show c onfig e nc rypt ion


Display the settings for configuration encryption.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show config encryption

RM CLI EAGLE40 29
Release 3.4 03/2020
5 .6 .5 show c onfig profile s
Display the configuration profiles.
 Mode: Command is in all modes available.
 Privilege Level: Administrator
 Format: show config profiles <P-1> [<P-2>]
Parameter Value Meaning
P-1 nvm non-volatile memory
envm external non-volatile memory device
P-2 1..20 Index of the profile entry.

5 .6 .6 show c onfig st a t us
Display the synchronization status of the running configuration with the non-volatile memory and the ACA.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show config status

5 .7 sw a p
Swap software images.

5 .7 .1 sw a p firm w a re syst e m ba c k up
Swap the main and backup images.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: swap firmware system backup

30 RM CLI EAGLE40
Release 3.4 03/2020
6 Devic e M onit oring

6 .1 devic e -st at us
Configure various device conditions to be monitored.

6 .1 .1 de vic e -st a t us m onit or link -fa ilure


Enable or disable monitor state of network connection(s).
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: device-status monitor link-failure

 no de vic e -st a t us m onit or link -fa ilure


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no device-status monitor link-failure

6 .1 .2 de vic e -st a t us m onit or t e m pe ra t ure


Enable or disable monitoring of the device temperature.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: device-status monitor temperature

6 .1 .3 de vic e -st a t us m onit or e nvm -re m ova l


Enable or disable monitoring the presence of the external non-volatile memory.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: device-status monitor envm-removal

 no de vic e -st a t us m onit or e nvm -re m ova l


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no device-status monitor envm-removal

6 .1 .4 de vic e -st a t us m onit or e nvm -not -in-sync


Enable or disable monitoring synchronization between the external non-volatile memory and the running
configuration.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: device-status monitor envm-not-in-sync

 no de vic e -st a t us m onit or e nvm -not -in-sync


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no device-status monitor envm-not-in-sync

6 .1 .5 de vic e -st a t us m onit or pow e r-supply


Enable or disable monitoring the condition of the power supply(s).
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: device-status monitor power-supply <P-1>
Parameter Value Meaning
P-1 1..2 Number of power supply.

RM CLI EAGLE40 31
Release 3.4 03/2020
 no de vic e -st a t us m onit or pow e r-supply
Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no device-status monitor power-supply <P-1>

6 .1 .6 de vic e -st a t us t ra p
Configure the device to send a trap when the device status changes.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: device-status trap

 no de vic e -st a t us t ra p
Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no device-status trap

6 .2 devic e -st at us
Configure various device conditions to be monitored.

6 .2 .1 de vic e -st a t us link -a la rm


Configure the monitor settings of the port link.
 Mode: Interface Range Mode
 Privilege Level: Administrator
 Format: device-status link-alarm

 no de vic e -st a t us link -a la rm


Disable the option
 Mode: Interface Range Mode
 Privilege Level: Administrator
 Format: no device-status link-alarm

6 .3 show
Display device options and settings.

6 .3 .1 show de vic e -st a t us m onit or


Display the device monitoring configurations.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show device-status monitor

6 .3 .2 show de vic e -st a t us st a t e


Display the current state of the device.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show device-status state

6 .3 .3 show de vic e -st a t us t ra p


Display the device trap information and configurations.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show device-status trap

32 RM CLI EAGLE40
Release 3.4 03/2020
6 .3 .4 show de vic e -st a t us e ve nt s
Display occurred device status events.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show device-status events

6 .3 .5 show de vic e -st a t us link -a la rm


Display the monitor configurations of the network ports.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show device-status link-alarm

6 .3 .6 show de vic e -st a t us a ll


Display the configurable device status settings.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show device-status all

RM CLI EAGLE40 33
Release 3.4 03/2020
7 Devic e Se c urit y

7 .1 se c urit y-st at us
Configure the security status settings.

7 .1 .1 se c urit y-st a t us m onit or pw d-c ha nge


Sets the monitoring of default password change for 'user' and 'admin'.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: security-status monitor pwd-change

 no se c urit y-st a t us m onit or pw d-c ha nge


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no security-status monitor pwd-change

7 .1 .2 se c urit y-st a t us m onit or pw d-m in-le ngt h


Sets the monitoring of minimum length of the password (smaller 8).
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: security-status monitor pwd-min-length

 no se c urit y-st a t us m onit or pw d-m in-le ngt h


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no security-status monitor pwd-min-length

7 .1 .3 se c urit y-st a t us m onit or pw d-polic y-c onfig


Sets the monitoring whether the minimum password policy is configured. The device changes the security status
to the value "error" if the value for at least one of the following password rules is 0: "minimum upper
cases","minimum lower cases","minimum numbers","minimum special characters".
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: security-status monitor pwd-policy-config

 no se c urit y-st a t us m onit or pw d-polic y-c onfig


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no security-status monitor pwd-policy-config

7 .1 .4 se c urit y-st a t us m onit or pw d-polic y-ina c t ive


Sets the monitoring whether at least one user is configured with inactive policy [Link] device changes the
security status to the value "error" if the function "policy check" is inactive for at least 1 user account.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: security-status monitor pwd-policy-inactive

 no se c urit y-st a t us m onit or pw d-polic y-ina c t ive


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no security-status monitor pwd-policy-inactive

34 RM CLI EAGLE40
Release 3.4 03/2020
7 .1 .5 se c urit y-st a t us m onit or ht t p-e na ble d
Sets the monitoring of the activation of http on the switch.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: security-status monitor http-enabled

 no se c urit y-st a t us m onit or ht t p-e na ble d


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no security-status monitor http-enabled

7 .1 .6 se c urit y-st a t us m onit or snm p-unse c ure


Sets the monitoring of SNMP security (SNMP v1/v2 is enabled or v3 encryption is disabled).
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: security-status monitor snmp-unsecure

 no se c urit y-st a t us m onit or snm p-unse c ure


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no security-status monitor snmp-unsecure

7 .1 .7 se c urit y-st a t us m onit or sysm on-e na ble d


Sets the monitoring of the activation of System Monitor 1 on the switch.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: security-status monitor sysmon-enabled

 no se c urit y-st a t us m onit or sysm on-e na ble d


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no security-status monitor sysmon-enabled

7 .1 .8 se c urit y-st a t us m onit or e x t nvm -upd-e na ble d


Sets the monitoring of activation of the configuration saving to external non volatile memory.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: security-status monitor extnvm-upd-enabled

 no se c urit y-st a t us m onit or e x t nvm -upd-e na ble d


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no security-status monitor extnvm-upd-enabled

7 .1 .9 se c urit y-st a t us m onit or no-link -e na ble d


Sets the monitoring of no link detection.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: security-status monitor no-link-enabled

 no se c urit y-st a t us m onit or no-link -e na ble d


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no security-status monitor no-link-enabled

RM CLI EAGLE40 35
Release 3.4 03/2020
7 .1 .1 0 se c urit y-st a t us m onit or hidisc -e na ble d
Sets the monitoring of HiDiscovery.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: security-status monitor hidisc-enabled

 no se c urit y-st a t us m onit or hidisc -e na ble d


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no security-status monitor hidisc-enabled

7 .1 .1 1 se c urit y-st a t us m onit or e x t nvm -loa d-unse c ure


Sets the monitoring of security of the configuration loading from extnvm.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: security-status monitor extnvm-load-unsecure

 no se c urit y-st a t us m onit or e x t nvm -loa d-unse c ure


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no security-status monitor extnvm-load-unsecure

7 .1 .1 2 se c urit y-st a t us m onit or ht t ps-c e rt ific a t e


Sets the monitoring whether auto generated self-signed HTTPS certificate is in use.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: security-status monitor https-certificate

 no se c urit y-st a t us m onit or ht t ps-c e rt ific a t e


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no security-status monitor https-certificate

7 .1 .1 3 se c urit y-st a t us t ra p
Configure if a trap is sent when the security status changes.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: security-status trap

 no se c urit y-st a t us t ra p
Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no security-status trap

7 .2 se c urit y-st at us
Configure the security status interface settings.

7 .2 .1 se c urit y-st a t us no-link


Configure the monitoring of the specific ports.
 Mode: Interface Range Mode
 Privilege Level: Administrator
 Format: security-status no-link

36 RM CLI EAGLE40
Release 3.4 03/2020
 no se c urit y-st a t us no-link
Disable the option
 Mode: Interface Range Mode
 Privilege Level: Administrator
 Format: no security-status no-link

7 .3 show
Display device options and settings.

7 .3 .1 show se c urit y-st a t us m onit or


Display the security status monitoring settings.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show security-status monitor

7 .3 .2 show se c urit y-st a t us st a t e


Display the current security status.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show security-status state

7 .3 .3 show se c urit y-st a t us no-link


Display the settings of the monitoring of the specific network ports.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show security-status no-link

7 .3 .4 show se c urit y-st a t us t ra p


Display the security status trap information and settings.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show security-status trap

7 .3 .5 show se c urit y-st a t us e ve nt s


Display the occurred security status events.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show security-status events

7 .3 .6 show se c urit y-st a t us a ll


Display the security status settings.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show security-status all

RM CLI EAGLE40 37
Release 3.4 03/2020
8 Dom a in N a m e Syst e m (DN S)

8 .1 dns
Set DNS parameters.

8 .1 .1 dns c lie nt se rve rs a dd


Add a new DNS server.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: dns client servers add <P-1> ip <P-2>
ip: Enter the DNS server address.
Parameter Value Meaning
P-1 1..4 DNS Client servers index.
P-2 a.b.c.d IP address.

8 .1 .2 dns c lie nt se rve rs de le t e


Delete a DNS server.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: dns client servers delete <P-1>
Parameter Value Meaning
P-1 1..4 DNS Client servers index.

8 .1 .3 dns c lie nt se rve rs m odify


Modify a DNS server entry.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: dns client servers modify <P-1> ip <P-2> status <P-3> operation <P-4>
ip: Change the DNS server address.
status: Change the status of this DNS server.
operation: Change the status of this DNS server.
Parameter Value Meaning
P-1 1..4 DNS Client servers index.
P-2 a.b.c.d IP address.
P-3 enable Enable the option.
disable Disable the option.
P-4 enable Enable the option.
disable Disable the option.

8 .1 .4 dns c lie nt se rve rs e na ble


Activate a DNS server entry.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: dns client servers enable <P-1>
Parameter Value Meaning
P-1 1..4 DNS Client servers index.

8 .1 .5 dns c lie nt se rve rs disa ble


Deactivate a DNS server entry.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: dns client servers disable <P-1>
Parameter Value Meaning
P-1 1..4 DNS Client servers index.

38 RM CLI EAGLE40
Release 3.4 03/2020
8 .2 show
Display device options and settings.

8 .2 .1 show dns c lie nt info


Display the DNS Client related information.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show dns client info

8 .2 .2 show dns c lie nt se rve rs


Display the DNS Client servers.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show dns client servers

RM CLI EAGLE40 39
Release 3.4 03/2020
9 De e p Pa cke t I nspe c t ion (DPI )

9 .1 dpi
Creation and configuration of DPI profiles.

9 .1 .1 dpi m odbus c om m it
Writes all changes made in the DPI MODBUS profiles to the enforcer.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: dpi modbus commit

9 .1 .2 dpi m odbus a ddprofile


Adds a profile to the DPI MODBUS profile table.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: dpi modbus addprofile <P-1> [description <P-2> [function-type <P-3>]
[function-code-list <P-4>] [unit-identifier-list <P-5>] [sanity-check <P-6>]
[exception <P-7>] [reset <P-8>]
[description]: Profile description name for the DPI MODBUS profile.
[function-type]: Function type of corresponding function codes.
[function-code-list]: Function code list. A function code has the syntax 'val'. Function codes are
separated by a comma. When more than one value for an function code is specified the values are separated
by the pipe symbol ('|').
[unit-identifier-list]: Unit identifier list. A unit identifier has the syntax 'val'. To specify no options,
the value 'none' must be given. Unit identifiers are separated by a comma.
[sanity-check]: Sanity check including format and specification.
[exception]: Device exception message.
[reset]: Reset connection message.
Parameter Value Meaning
P-1 1..32 Profile index 1 - 32
P-2 string Profile description name
P-3 readonly Read only function codes for function code list
readwrite Read write function codes for function code list
programming Programming function codes for function code list
all All possible function codes for function code list (allow any function code)
advanced Keeps the function code list from the previous selection and makes it editable by the user
P-4 1..255 Function codes 1 - 255
1|0-65535 Function code read coils, coil address range 0 - 65535
2|0-65535 Function code read discrete inputs, input address range 0 - 65535
3|0-65535 Function code read holding registers, register address range 0 - 65535
4|0-65535 Function code read input registers, register address range 0 - 65535
5|0-65535 Function code write single coil, coil address range 0 - 65535
6|0-65535 Function code write single register, register address range 0 - 65535
7 Function code read exception status
8 Function code diagnostic
11 Function code get com event counter
12 Function code get comm event log
13 Function code program (584/984)
14 Function code poll (584/984)
15|0-65535 Function code write multiple coils, coil address range 0 - 65535
16|0-65535 Function code write multiple registers, register address range 0 - 65535
17 Function code report slave id
20 Function code read file record
21 Function code write file record
22|0-65535 Function code mask write register, register address range 0 - 65535
23|0-65535|0-65535 Function code read/write multiple registers, read address range 0 - 65535, write address range 0 - 65535
24|0-65535 Function code read fifo queue, pointer address range 0 - 65535
40 Function code program (concept)
42 Function code concept symbol table

40 RM CLI EAGLE40
Release 3.4 03/2020
Parameter Value Meaning
43 Function code encapsulated interface transport
48 Function code advantech co. ltd. - management functions
66 Function code scan data inc. - expanded read holding registers
67 Function code scan data inc. - expanded write holding registers
90 Function code unity programming/ofs
100 Function code scattered register read
125 Function code schneider electric - firmware replacement
P-5 0..255 Unit identifier 0 - 255
none No unit identifier 'none'
P-6 yes True
no False
P-7 yes True
no False
P-8 yes True
no False

9 .1 .3 dpi m odbus m odifyprofile


Modifies a profile in the DPI MODBUS profile table.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: dpi modbus modifyprofile <P-1> [description <P- 2>] [function-type <P-3>]
[function-code-list <P-4>] [unit-identifier-list <P-5>] [sanity-check <P-6>]
[exception <P-7>] [reset <P-8>]
[description]: Profile description name for the DPI MODBUS profile.
[function-type]: Function type of corresponding function codes.
[function-code-list]: Function code list. A function code has the syntax 'val'. Function codes are
separated by a comma. When more than one value for an function code is specified the values are separated by
the pipe symbol ('|').
[unit-identifier-list]: Unit identifier list. A unit identifier has the syntax 'val'. To specify no options, the
value 'none' must be given. Unit identifiers are separated by a comma.
[sanity-check]: Sanity check including format and specification.
[exception]: Device exception message.
[reset]: Reset connection message.
Parameter Value Meaning
P-1 1..32 Profile index 1 - 32
P-2 string Profile description name
P-3 readonly Read only function codes for function code list
readwrite Read write function codes for function code list
programming Programming function codes for function code list
all All possible function codes for function code list (allow any function code)
advanced Keeps the function code list from the previous selection and makes it editable by the user

RM CLI EAGLE40 41
Release 3.4 03/2020
Parameter Value Meaning
P-4 1..255 Function codes 1 - 255
1|0-65535 Function code read coils, coil address range 0 - 65535
2|0-65535 Function code read discrete inputs, input address range 0 - 65535
3|0-65535 Function code read holding registers, register address range 0 - 65535
4|0-65535 Function code read input registers, register address range 0 - 65535
5|0-65535 Function code write single coil, coil address range 0 - 65535
6|0-65535 Function code write single register, register address range 0 - 65535
7 Function code read exception status
8 Function code diagnostic
11 Function code get com event counter
12 Function code get comm event log
13 Function code program (584/984)
14 Function code poll (584/984)
15|0-65535 Function code write multiple coils, coil address range 0 - 65535
16|0-65535 Function code write multiple registers, register address range 0 - 65535
17 Function code report slave id
20 Function code read file record
21 Function code write file record
22|0-65535 Function code mask write register, register address range 0 - 65535
23|0-65535|0-65535 Function code read/write multiple registers, read address range 0 - 65535, write address range 0 - 65535
24|0-65535 Function code read fifo queue, pointer address range 0 - 65535
40 Function code program (concept)
42 Function code concept symbol table
43 Function code encapsulated interface transport
48 Function code advantech co. ltd. - management functions
66 Function code scan data inc. - expanded read holding registers
67 Function code scan data inc. - expanded write holding registers
90 Function code unity programming/ofs
100 Function code scattered register read
125 Function code schneider electric - firmware replacement
P-5 0..255 Unit identifier 0 - 255
none No unit identifier 'none'
P-6 yes True
no False
P-7 yes True
no False
P-8 yes True
no False

9 .1 .4 dpi m odbus c opyprofile


Copies a profile to another DPI MODBUS profile.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: dpi modbus copyprofile <P-1> <P-2>
Parameter Value Meaning
P-1 1..32 Profile source index 1 - 32
P-2 1..32 Profile destination index 1 - 32

9 .1 .5 dpi m odbus de lprofile


Deletes a profile from the DPI MODBUS profile table. You cannot delete an active profile or if an enforcer
mappings to it.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: dpi modbus delprofile <P-1>
Parameter Value Meaning
P-1 1..32 Profile source index 1 - 32

9 .1 .6 dpi m odbus e na ble profile


Disables a profile in the DPI MODBUS profile table. You cannot inactivate a profile if an active enforcer mappings
to it.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: dpi modbus enableprofile <P-1>

42 RM CLI EAGLE40
Release 3.4 03/2020
Parameter Value Meaning
P-1 1..32 Profile source index 1 - 32

9 .1 .7 dpi m odbus disa ble profile


Enables a profile in the DPI MODBUS profile table. A profile can only be activated when all required parameters
are set. After activation modifications no longer possible.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: dpi modbus disableprofile <P-1>
Parameter Value Meaning
P-1 1..32 Profile source index 1 - 32

9 .1 .8 dpi opc c om m it
Writes all changes made in the DPI OPC profiles to the enforcer.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: dpi opc commit

9 .1 .9 dpi opc a ddprofile


Adds a profile to the DPI OPC profile table.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: dpi opc addprofile <P-1> [description <P-2>] [sanity-check <P-3>] [fragment-
check <P-4>] [timeoutconnect <P-5>]
[description]: Profile description/name for the DPI OPC profile.
[sanity-check]: Sanity check including format and specification.
[fragment-check]: Fragment check.
[timeout-connect]: Timeout at connect.
Parameter Value Meaning
P-1 1..32 Profile source index 1 - 32
P-2 string Profile description/name
P-3 yes True
no False
P-4 yes True
no False
P-5 0..60 Timeout in seconds 0 - 60

9 .1 .1 0 dpi opc m odifyprofile


Modifies a profile in the DPI OPC profile table.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: dpi opc modifyprofile <P-1> [description <P-2>] [sanity-check <P-3>]
[fragment-check <P-4>] [timeoutconnect <P-5>]
[description]: Profile description/name for the DPI OPC profile.
[sanity-check]: Sanity check including format and specification.
[fragment-check]: Fragment check.
[timeout-connect]: Timeout at connect.
Parameter Value Meaning
P-1 1..32 Profile source index 1 - 32
P-2 string Profile description/name
P-3 yes True
no False
P-4 yes True
no False
P-5 0..60 Timeout in seconds 0 - 60

9 .1 .1 1 dpi opc c opyprofile


Copies a profile to another DPI OPC profile.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: dpi opc copyprofile <P-1> <P-2>
Parameter Value Meaning
P-1 1..32 Profile source index 1 - 32

RM CLI EAGLE40 43
Release 3.4 03/2020
Parameter Value Meaning
P-2 1..32 Profile destination index 1 - 32

9 .1 .1 2 dpi opc de lprofile


Deletes a profile from the DPI OPC profile table. You cannot delete an active profile or if an enforcer mappings to it.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: dpi opc delprofile <P-1>
Parameter Value Meaning
P-1 1..32 Profile source index 1 - 32

9 .1 .1 3 dpi opc e na ble profile


Disables a profile in the DPI OPC profile table. You cannot inactivate a profile if an active enforcer mappings to it.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: dpi opc enableprofile <P-1>
Parameter Value Meaning
P-1 1..32 Profile source index 1 - 32

9 .1 .1 4 dpi opc disa ble profile


Enables a profile in the DPI OPC profile table. A profile can only be activated when all required parameters are
set. After activation modifications no longer possible.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: dpi opc disableprofile <P-1>
Parameter Value Meaning
P-1 1..32 Profile source index 1 - 32

9 .2 show
9 .2 .1 show dpi m odbus profile t a ble
Show the DPI MODBUS profile table.
 Mode: Command is in all modes available
 Privilege Level: Guest
 Format: show dpi modbus profiletable

9 .2 .2 show dpi m odbus pe nding


Show whether uncommitted changes for DPI MODBUS enforcer exist.
 Mode: Command is in all modes available
 Privilege Level: Guest
 Format: show dpi modbus pending

9 .2 .3 show dpi opc profile t a ble


Show the DPI OPC profile table.
 Mode: Command is in all modes available
 Privilege Level: Guest
 Format: show dpi opc profiletable

9 .2 .4 show dpi opc pe nding


Show whether uncommitted changes for DPI OPC enforcer exist.
 Mode: Command is in all modes available
 Privilege Level: Guest
 Format: show dpi opc pending

44 RM CLI EAGLE40
Release 3.4 03/2020
1 0 Fire w a ll Le a r ning M ode (FLM )

1 0 .1 flm
Configure the firewall learning mode.

1 0 .1 .1 flm ope ra t ion


Enable/disable the firewall learning mode.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: flm operation <P-1>
Parameter Value Meaning
P-1 enable Enable the firewall learning mode.
disable Disable the firewall learning mode.

 no flm ope ra t ion


Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no flm operation <P-1>

1 0 .1 .2 flm a c t ion
Set the action for the firewall learning mode.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: flm action <P-1>
Parameter Value Meaning
P-1 start Start a learning phase.
stop Stop a learning phase.
continue Continue the previous learning phase.
clear Clear the learned data.

1 0 .1 .3 flm int e rfa c e a dd


Add an interface to the firewall learning mode.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: flm interface add <P-1>
Parameter Value Meaning
P-1 slot no./port no.

1 0 .1 .4 flm int e rfa c e de le t e


Delete an interface from the firewall learning mode.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: flm interface delete <P-1>
Parameter Value Meaning
P-1 slot no./port no.

1 0 .2 show
Display device options and settings.

1 0 .2 .1 show flm globa l


Display the information and settings for the firewall learning mode.
 Mode: Command is in all modes available
 Privilege Level: Guest
 Format: show flm global

RM CLI EAGLE40 45
Release 3.4 03/2020
1 0 .2 .2 show flm int e rfa c e
Display the interfaces selected for the firewall learning mode
 Mode: Command is in all modes available
 Privilege Level: Guest
 Format: show flm interface

46 RM CLI EAGLE40
Release 3.4 03/2020
1 1 H iDisc ove r y

1 1 .1 ne t w ork
Configure the inband and outband connectivity.

1 1 .1 .1 ne t w ork hidisc ove ry ope ra t ion


Enable/disable the HiDiscovery protocol on this device.
 Mode: Privileged Exec Mode
 Privilege Level: Operator
 Format: network hidiscovery operation <P-1>
Parameter Value Meaning
P-1 enable Enable the HiDiscovery protocol.
disable Disable the HiDiscovery protocol.

 no ne t w ork hidisc ove ry ope ra t ion


Disable the option
 Mode: Privileged Exec Mode
 Privilege Level: Operator
 Format: no network hidiscovery operation <P-1>
Parameter Value Meaning
P-1 enable Enable the HiDiscovery protocol.
disable Disable the HiDiscovery protocol.

1 1 .1 .2 ne t w ork hidisc ove ry m ode


Set the access level for HiDiscovery.
 Mode: Privileged Exec Mode
 Privilege Level: Operator
 Format: network hidiscovery mode <P-1>
Parameter Value Meaning
P-1 read-write Allow detection and configuration.
read-only Allow only detection, no configuration.

1 1 .2 show
Display device options and settings.

1 1 .2 .1 show ne t w ork hidisc ove ry


Display the HiDiscovery settings.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show network hidiscovery

RM CLI EAGLE40 47
Release 3.4 03/2020
1 2 H ype r t ex t Tra nsfe r Prot oc ol (H T T P)

1 2 .1 ht t p
Set HTTP parameters.

1 2 .1 .1 ht t p port
Set the HTTP port number.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: http port <P-1>
Parameter Value Meaning
P-1 1..65535 Port number of the HTTP server (default: 80).

1 2 .1 .2 ht t p se rve r
Enable or disable the HTTP server.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: http server

 no ht t p se rve r
Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no http server

1 2 .2 show
Display device options and settings.

1 2 .2 .1 show ht t p
Display the HTTP server information.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show http

48 RM CLI EAGLE40
Release 3.4 03/2020
1 3 H T T P Se c ure (H T T PS)

1 3 .1 ht t ps
Set HTTPS parameters.

1 3 .1 .1 ht t ps se rve r
Enable or disable the HTTPS server.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: https server

 no ht t ps se rve r
Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no https server

1 3 .1 .2 ht t ps port
Set the HTTPS port number.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: https port <P-1>
Parameter Value Meaning
P-1 1..65535 Port number of the web server (default: 443).

1 3 .1 .3 ht t ps finge rprint -t ype


Configure fingerprint type.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: https fingerprint-type <P-1>
Parameter Value Meaning
P-1 sha1 Configure sha1 fingerprint
sha256 Configure sha256 fingerprint

1 3 .1 .4 ht t ps c e rt ific a t e
Generate/Delete HTTPS X509/PEM certificate.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: https certificate <P-1>
Parameter Value Meaning
P-1 generate Generates the item
delete Deletes the item

1 3 .2 c opy
Copy different kinds of items.

1 3 .2 .1 c opy ht t psc e rt re m ot e
Copy X509/PEM certificate from a server to the specified destination.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: copy httpscert remote <P-1> nvm
nvm: Copy HTTPS certificate (PEM) from a server to the device.
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 128 characters.

RM CLI EAGLE40 49
Release 3.4 03/2020
1 3 .2 .2 c opy ht t psc e rt e nvm
Copy X509/PEM certificate from external non-volatile memory to the specified destination.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: copy httpscert envm <P-1> nvm
nvm: Copy X509/PEM certificate from external non-volatile memory to the device.
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 128 characters.

1 3 .3 show
Display device options and settings.

1 3 .3 .1 show ht t ps
Display the HTTPS server information.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show https

50 RM CLI EAGLE40
Release 3.4 03/2020
1 4 I nt e rfa c e

1 4 .1 shut dow n
1 4 .1 .1 shut dow n
Enable or disable the interface.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: shutdown

 no shut dow n
Disable the option
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: no shutdown

1 4 .2 a ut o-ne got iat e


1 4 .2 .1 a ut o-ne got ia t e
Enable or disable automatic negotiation on the interface. The cable crossing settings have no effect if auto-
negotiation is enabled. In this case cable crossing is always set to auto. Cable crossing is set to the value chosen
by the user if auto-negotiation is disabled.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: auto-negotiate

 no a ut o-ne got ia t e
Disable the option
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: no auto-negotiate

1 4 .3 a ut o-pow e r-dow n
1 4 .3 .1 a ut o-pow e r-dow n
Set the auto-power-down mode on the interface.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: auto-power-down <P-1>
Parameter Value Meaning
P-1 auto-power-save The port goes in a low power mode.
no-power-save The port does not use the automatic power save mode.

1 4 .4 c a ble -c rossing
1 4 .4 .1 c a ble -c rossing
Cable crossing settings on the interface. The cable crossing settings have no effect if auto-negotiation is enabled.
In this case cable crossing is always set to auto. Cable crossing is set to the value chosen by the user if auto-
negotiation is disabled.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: cable-crossing <P-1>

RM CLI EAGLE40 51
Release 3.4 03/2020
Parameter Value Meaning
P-1 mdi The port does not use the crossover mode.
mdix The port uses the crossover mode.
auto-mdix The port uses the auto crossover mode.

1 4 .5 link t ra ps
1 4 .5 .1 link t ra ps
Enable/disable link up/down traps on the interface.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: linktraps

 no link t ra ps
Disable the option
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: no linktraps

1 4 .6 spe e d
1 4 .6 .1 spe e d
Sets the speed and duplex setting for the interface.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: speed <P-1> [<P-2>]
Parameter Value Meaning
P-1 10 10 MBit/s.
100 100 MBit/s.
1000 1000 MBit/s.
P-2 full full duplex.
half half duplex.

1 4 .7 na m e
1 4 .7 .1 na m e
Set or remove a descriptive name for the interface.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: name <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 64 characters.

1 4 .8 pow e r-st at e
1 4 .8 .1 pow e r-st a t e
Enable or disable the power state on the interface. The interface power state settings have no effect if the interface
admin state is enabled.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: power-state

52 RM CLI EAGLE40
Release 3.4 03/2020
 no pow e r-st a t e
Disable the option
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: no power-state

1 4 .9 show
Display device options and settings.

1 4 .9 .1 show port
Display the interface parameters.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show port [<P-1>]
Parameter Value Meaning
P-1 slot no./port no.

RM CLI EAGLE40 53
Release 3.4 03/2020
1 5 I nt e rfa c e St at ist ic s

1 5 .1 cle a r
Clear several items.

1 5 .1 .1 c le a r port -st a t ist ic s


Clear all statistics counter.
 Mode: Privileged Exec Mode
 Privilege Level: Operator
 Format: clear port-statistics

1 5 .2 show
Display device options and settings.

1 5 .2 .1 show int e rfa c e c ount e rs


Display the interface counters.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show interface counters

1 5 .2 .2 show int e rfa c e st a t ist ic s


Display the summary interface statistics.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show interface statistics [<P-1>]
Parameter Value Meaning
P-1 slot no./port no.

1 5 .2 .3 show int e rfa c e e t he r-st a t s


Display the detailed interface statistics.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show interface ether-stats [<P-1>]
Parameter Value Meaning
P-1 slot no./port no.

54 RM CLI EAGLE40
Release 3.4 03/2020
1 6 I nt e r n

1 6 .1 he lp
Display the help text for various special keys.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: help

1 6 .2 logout
Exit this session.
 Mode: Command is in all modes available.
 Privilege Level: any
 Format: logout

1 6 .3 hist or y
Display a list of previously run commands.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: history

1 6 .4 ex it
Exit from vlan mode.
 Mode: VLAN Mode
 Privilege Level: Operator
 Format: exit

1 6 .5 se r vic e she ll
Enter system mode.

1 6 .5 .1 se rvic e she ll st a rt
Start serviceshell prompt
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: serviceshell start

1 6 .5 .2 se rvic e she ll de a c t iva t e


Disable the service shell access permanently (Cannot be undone).
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: serviceshell deactivate

1 6 .6 t ra c e rout e
Trace route to a specified host.

RM CLI EAGLE40 55
Release 3.4 03/2020
1 6 .6 .1 t ra c e rout e sourc e
Source address for traceroute command.
 Mode: Privileged Exec Mode.
 Privilege Level: Operator
 Format: traceroute <P-1> source <P-2>
Parameter Value Meaning
P-1 string Hostname or IP address.
P-2 A.B.C.D IP address.

1 6 .7 reboot
Reset the device (cold start).
 Mode: All Privileged Modes
 Privilege Level: any
 Format: reboot

1 6 .8 ping
Send ICMP echo packets to a specified host or IP address.

1 6 .8 .1 ping sourc e
Source address for ping command.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: ping <P-1> source <P-2>
Parameter Value Meaning
P-1 string Hostname or IP address.
P-2 A.B.C.D IP address.

1 6 .9 show
Display device options and settings.

1 6 .9 .1 show se rvic e she ll


Display the service shell access.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show serviceshell

56 RM CLI EAGLE40
Release 3.4 03/2020
1 7 Ope n Shor t e st Pat h First (OSPF)

1 7 .1 ip
Set IP parameters.

1 7 .1 .1 ip ospf a re a
Administer the OSPF areas. An area is a sub-division of an OSPF autonomous system. You identify an area by
an area-id. OSPF networks, routers, and links that have the same area-id form a logical set.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip ospf area <P-1> range add <P-2> <P-3> <P-4> modify <P-5> <P-6> <P-7> <P-
8> delete <P-9> <P-10> <P-11> add delete stub add <P-12> modify <P-13> summarylsa
<P-14> default-cost <P-15> delete <P-16> virtual-link add <P-17> delete <P-18>
modify <P-19> authentication type <P-20> key <P-21> key-id <P-22> hello-interval
<P-23> dead-interval <P-24> transmit-delay <P-25> retransmit-interval <P-26> nssa
add <P-27> delete <P-28> modify translator role <P-29> stability-interval <P-30>
summary no-redistribute default-info originate [metric <P-31>] [metric-type <P-
32>]
range: Configure the range for the area. You summarize the networks within this range into a single routing
domain.
add: Create an area.
modify: Modify the parameters of an existing area.
delete: Delete a specific area.
add: Create a new area.
delete: Delete an existing area.
stub: Configure the preferences for a stub area. You shield stub areas from external route advertisements, but
the area receives advertisements from networks that belong to other areas of the same autonomous system.
add: Create a stub area. The command also allows you to convert an existing area to a stub area.
modify: Modify the stub area parameters.
summarylsa: Configure the summary LSA mode for a stub area. When enabled, the router both summarizes and
propagates summary LSAs.
default-cost: Set the default cost for the stub area.
delete: Remove a stub area. After removal, the area receives external route advertisements.
virtual-link: Configure a virtual link. You use the virtual link to connect the router to the backbone area
([Link]) through a non-backbone area or to connect two parts of a partitioned backbone area ([Link]) through a
non-backbone area.
add: Add a virtual neighbor.
delete: Delete a virtual neighbor.
modify: Modify the parameters of a virtual neighbor.
authentication: Configure the authentication type. The device authenticates the OSPF protocol exchanges in
the OSPF packet header which includes an authentication type field.
type: Configure the authentication type. Authentication types are 0 for null authentication, 1 for simple password
authentication, and 2 for cryptographic authentication.
key: Configure the authentication key.
key-id: Configure the authentication key-id for md5 authentication. This field identifies the algorithm and secret
key used to create the message digest appended to the OSPF packet.
hello-interval: Configure the OSPF hello-interval for the virtual link, in seconds. The hello timer controls the
time interval between sending two consecutive hello packets. Set this value to the same hello-interval value of the
virtual neighbors.
dead-interval: Configure the OSPF dead-interval for the virtual link, in seconds. If the timer expires without
the router receiving hello packets from a virtual neighbor, the router declares the neighbor router as down. Set the
timer to at least four times the value of the hello-interval.
transmit-delay: Configure the OSPF transmit-delay for the virtual link, in seconds. Transmit delay is the time
that you estimate it takes to transmit a link-state update packet over the virtual link.
retransmit-interval: Configure the OSPF retransmit-interval for the virtual link, in seconds. The retransmit
interval is the time between two consecutive link-state advertisement transmissions. Link-state advertisements
contain such information as database descriptions and link-state request packets for adjacencies belonging to
virtual link.
nssa: Configure a NSSA(Not-So-Stubby-Area).
add: Add a NSSA.

RM CLI EAGLE40 57
Release 3.4 03/2020
delete: Delete a NSSA.
modify: Modify the parameters of a NSSA.
translator: Configure the NSSA translator related parameters.
role: Configure the NSSA translator role.
stability-interval: Configure the translator stability interval for the NSSA, in seconds.
summary: Configure the import summary for the specified NSSA.
no-redistribute: Configure route redistribution for the specified NSSA.
default-info: Configure the nssa default information origination parameters.
originate: Configuration whether a Type-7 LSA should be originated into the NSSA.
[metric]: Configure the metric for the NSSA.
[metric-type]: Configure the metric type for default information.
Parameter Value Meaning
P-1 A.B.C.D IP address.
P-2 summary-link Configure summary links LSDB type optional mode.
nssa-external-link Configure nssa external link LSDB type optional mode.
P-3 A.B.C.D IP address.
P-4 a.b.c.d IP subnet mask.
P-5 summary-link Configure summary links LSDB type optional mode.
nssa-external-link Configure nssa external link LSDB type optional mode.
P-6 A.B.C.D IP address.
P-7 a.b.c.d IP subnet mask.
P-8 advertise Set as advertise.
do-not-advertise Set as do-not-advertise.
P-9 summary-link Configure summary links LSDB type optional mode.
nssa-external-link Configure nssa external link LSDB type optional mode.
P-10 A.B.C.D IP address.
P-11 a.b.c.d IP subnet mask.
P-12 0 Configure the TOS (0 is for Normal Service).
P-13 0 Configure the TOS (0 is for Normal Service).
P-14 no-area-summary Disable the router from sending area link state advertisement summaries.
send-area-summary Enable the router to send area link state advertisement summaries. The router
floods LSAs within the area using multicast. Every topology change starts a
new flood of LSAs.
P-15 0..16777215 Configure the default cost.
P-16 0 Configure the TOS (0 is for Normal Service).
P-17 A.B.C.D IP address.
P-18 A.B.C.D IP address.
P-19 A.B.C.D IP address.
P-20 none Configure the authentication type as none (Key and key ID is not required).
simple Configure the authentication type as simple (Key ID is not required).
md5 Configure the authentication type as md5 for the interface.
P-21 string <key> Configure the authentication key.
P-22 0..255 Enter a number in the given range.
P-23 1..65535 Enter a number between 1 and 65535
P-24 1..65535 Enter a number between 1 and 65535
P-25 0..3600 Enter a number in the given range.
P-26 0..3600 Enter a number in the given range.
P-27 import-nssa Configure the area as NSSA only.
P-28 import-external Change the area to support external LSAs also.
P-29 always Configure the NSSA translator role as always. When used as a border router,
the router translates LSAs regardless of the translator states of the other
NSSA border routers.
candidate Configure the NSSA translator role as a candidate. When used as a border router,
the router participates in the translator election process. The router
maintains a list of reachable NSSA border routers.
P-30 0..65535 Enter a number between 0 and 65535
P-31 1..16777214 Configure the metric value.
P-32 ospf-metric Set the metric type as ospf Metric.
comparable-cost Set the metric type as comparable cost.
non-comparable Set the metric type as non-comparable.

58 RM CLI EAGLE40
Release 3.4 03/2020
 no ip ospf a re a
Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no ip ospf area <P-1> range add modify delete add delete stub add modify
summarylsa default-cost delete virtual-link add delete modify authentication
type key key-id hello-interval dead-interval transmit-delay retransmit-interval
nssa add delete modify translator role stability-interval summary no-
redistribute default-info originate [metric] [metric-type]

1 7 .1 .2 ip ospf t ra pfla gs a ll
Set all trapflags at once.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip ospf trapflags all <P-1>
Parameter Value Meaning
P-1 [cr] Enable the Bit.

 no ip ospf t ra pfla gs a ll
Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no ip ospf trapflags all <P-1>

1 7 .1 .3 ip ospf ope ra t ion


Enable or disable the OSPF admin mode. When enabled, the device initiates the OSPF process if the OSPF
function is active on at least one interface.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip ospf operation

 no ip ospf ope ra t ion


Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no ip ospf operation

1 7 .1 .4 ip ospf 1 5 8 3 c om pa t a bilit y
Enable or disable the 1583compatibility for calculating routes external to the autonomous system. When enabled,
the router is compatible with the preference rules defined in RFC1583, section 16.4.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip ospf 1583compatability

 no ip ospf 1 5 8 3 c om pa t a bilit y
Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no ip ospf 1583compatability

1 7 .1 .5 ip ospf de fa ult -m e t ric


Configure the default metric for re-distributed routes, when OSPF redistributes routes from other protocols.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip ospf default-metric <P-1>
Parameter Value Meaning
P-1 1..16777214 Configure the default metric for redistributed routes.

 no ip ospf de fa ult -m e t ric


Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no ip ospf default-metric <P-1>

RM CLI EAGLE40 59
Release 3.4 03/2020
Parameter Value Meaning
P-1 1..16777214 Configure the default metric for redistributed routes.

1 7 .1 .6 ip ospf rout e r-id


Configure the router ID to uniquely identify this OSPF router in the autonomous system. If a tie occurs during the
designated router election, the router with the higher router ID is the designated router.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip ospf router-id <P-1>
Parameter Value Meaning
P-1 A.B.C.D IP address.

1 7 .1 .7 ip ospf e x t e rna l-lsdb-lim it


Configure the OSPF external lsdb limitation, which is the maximum number of non-default AS-external-LSA
entries that the router stores in the link-state database. When the value -1 is configured, you disable the limitation.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip ospf external-lsdb-limit <P-1>
Parameter Value Meaning
P-1 -1..2147483647 Configure the external lsdb limit.

1 7 .1 .8 ip ospf e x it -ove rflow


Configure the OSPF exit overflow interval, in seconds. After the timer expires the router will attempt to leave the
overflow-state. To disable the exit overflow interval function set the value to 0.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip ospf exit-overflow <P-1>
Parameter Value Meaning
P-1 0..2147483647 Configure the exit overflow interval.

1 7 .1 .9 ip ospf m a x im um -pa t h
Configure the maximum number of paths that OSPF reports.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip ospf maximum-path <P-1>
Parameter Value Meaning
P-1 1..4 Set the maximum path.

1 7 .1 .1 0 ip ospf spf-de la y
Configure the SPF delay, in seconds. The Shortest Path First (SPF) delay is the time that the device waits for the
network to stabilize before calculating the shortest path tree, after a topology change.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip ospf spf-delay <P-1>
Parameter Value Meaning
P-1 0..65535 Enter a number between 0 and 65535

1 7 .1 .1 1 ip ospf spf-holdt im e
Configure the minimum time between two consecutive SPF calculations, in seconds.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip ospf spf-holdtime <P-1>
Parameter Value Meaning
P-1 0..65535 Enter a number between 0 and 65535

1 7 .1 .1 2 ip ospf a ut o-c ost


Set the auto cost reference bandwidth of the router interfaces for ospf metric calculations. The default reference
bandwidth is 100 Mbps.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip ospf auto-cost <P-1>

60 RM CLI EAGLE40
Release 3.4 03/2020
Parameter Value Meaning
P-1 1..4294967 Configure the auto cost for OSPF calculation.

1 7 .1 .1 3 ip ospf dist a nc e int ra


Enter the preference type as intra. Use intra-area routing when the device routes packets solely within an area,
such as an internal router.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip ospf distance intra <P-1>
Parameter Value Meaning
P-1 1..255 Enter the value.

1 7 .1 .1 4 ip ospf dist a nc e int e r


Enter the preference type as inter. Use inter-area routing when the device routes packets into or out of an area,
such as an area border router.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip ospf distance inter <P-1>
Parameter Value Meaning
P-1 1..255 Enter the value.

1 7 .1 .1 5 ip ospf dist a nc e e x t e rna l


Enter the preference type as external. Use external-area routing when the device routes packets into or out of an
autonomous system, such as an autonomous system boundary router (ASBR).
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip ospf distance external <P-1>
Parameter Value Meaning
P-1 1..255 Enter the value.

1 7 .1 .1 6 ip ospf re -dist ribut e


Configure the OSPF route re-distribution. An ASBR is able to translate information from other OSPF processes in
separate areas and routes from other sources, such as static routes or other dynamic routing protocols, into the
OSPF protocol.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip ospf re-distribute <P-1> [metric <P-2>] [metric-type <P-3>] [tag <P-4>]
[subnets <P-5>]
[metric]: Configure the OSPF route re-distribution metric parameters.
[metric-type]: Configure the OSPF route redistribution metric-type.
[tag]: Configure the OSPF route redistribution tag parameters.
[subnets]: Allow the router to redistribute subnets into OSPF.
Parameter Value Meaning
P-1 connected Select the source protocol as connected.
static Select the source protocol as static.
P-2 0..16777214 Configure the metric.
P-3 1..2 Configure the metric type.
P-4 0..4294967295 Configure the tag.
P-5 enable Enable the option.
disable Disable the option.

 no ip ospf re -dist ribut e


Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no ip ospf re-distribute <P-1>

1 7 .1 .1 7 ip ospf dist ribut e -list


Configure the distribute list for the routes from other source protocols.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip ospf distribute-list <P-1> <P-2>

RM CLI EAGLE40 61
Release 3.4 03/2020
Parameter Value Meaning
P-1 out Configure as out to re-distribute routes with ACL rules
P-2 connected Select the source protocol as connected.
static Select the source protocol as static.

 no ip ospf dist ribut e -list


Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no ip ospf distribute-list <P-1> <P-2>

1 7 .1 .1 8 ip ospf de fa ult -info origina t e


Originate the OSPF default information.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip ospf default-info originate [always] [metric <P-1>] [metric-type <P-2>]
[always]: Always advertise the [Link]/[Link] route information.
[metric]: Configure the metric for default information.
[metric-type]: Configure the metric type for default information.
Parameter Value Meaning
P-1 1..16777214 Configure the metric value.
P-2 external-type1 Set the metric type for default information as external type-1. The type 1
value sets the metric to the sum of the internal and external OSPF metrics.
external-type2 Set the metric type for default information as external type-2. The type 2
value sets the metric to the sum of external OSPF metrics from the source AS
to the destination AS.

 no ip ospf de fa ult -info origina t e


Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no ip ospf default-info originate [always] [metric <P-1>]

1 7 .2 ip
IP interface commands.

1 7 .2 .1 ip ospf ope ra t ion


Enable or disable OSPF on port.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip ospf operation

 no ip ospf ope ra t ion


Disable the option
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: no ip ospf operation

1 7 .2 .2 ip ospf a re a -id
Configure the area ID that uniquely identifies the area to which the interface is connected.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip ospf area-id <P-1>
Parameter Value Meaning
P-1 A.B.C.D IP address.

1 7 .2 .3 ip ospf link -t ype


Configure the OSPF link type.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip ospf link-type <P-1>

62 RM CLI EAGLE40
Release 3.4 03/2020
Parameter Value Meaning
P-1 broadcast Configure the link-type as broadcast for the interface. In broadcast networks,
routers discover their neighbors dynamically using the OSPF hello protocol.
nbma Configure the link-type as Non-Broadcast Multi-Access for the interface. The
nbma mode, emulates OSPF operation over a broadcast network. The nbma mode is
the most efficient way to run OSPF over non-broadcast networks, both in terms
of the LSDB size and the amount of routing protocol traffic. However, this mode
requires direct communication between every router in the nbma network.
point-to-point Configure the link-type as point-to-point for the interface. Use the point-to-
point link-type in a network that joins a single pair of routers.
point-to-multipoint Configure the link-type as point-to-multipoint for the interface. In the point-
to-multipoint mode, OSPF treats each router-to-router link over non-broadcast
networks as if they were point-to-point links.

1 7 .2 .4 ip ospf priorit y
Configure the OSPF router priority which the router uses in multi-access networks for the designated router
election algorithm. The router with the higher router priority is the designated router. A value of 0 declares the
router as ineligible for designated router elections.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip ospf priority <P-1>
Parameter Value Meaning
P-1 0..255 Configure the priority.

1 7 .2 .5 ip ospf t ra nsm it -de la y


Configure the OSPF transmit-delay for the interface, in seconds. The transmit-delay is the time that you estimate
it takes to transmit a link-state update packet over the interface.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip ospf transmit-delay <P-1>
Parameter Value Meaning
P-1 0..3600 Enter a number in the given range.

1 7 .2 .6 ip ospf re t ra nsm it -int e rva l


Configure the OSPF retransmit-interval for the interface, in seconds. The retransmit-interval is the interval after
which link-state advertisements containing database description and link-state request packets, are re-transmitted
for adjacencies belonging to this interface.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip ospf retransmit-interval <P-1>
Parameter Value Meaning
P-1 0..3600 Enter a number in the given range.

1 7 .2 .7 ip ospf he llo-int e rva l


Configure the OSPF hello-interval for the interface, in seconds. The hello timer controls the time interval between
two consecutive hello packets. Set this value to the same hello-interval value of the neighbor.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip ospf hello-interval <P-1>
Parameter Value Meaning
P-1 1..65535 Enter a number between 1 and 65535

1 7 .2 .8 ip ospf de a d-int e rva l


Configure the OSPF dead-interval for the interface, in seconds. If the timer expires without the router receiving
hello packets from the neighbor, the router declares the neighbor router as down. Set the timer to at least four
times the value of the hello-interval.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip ospf dead-interval <P-1>
Parameter Value Meaning
P-1 1..65535 Enter a number between 1 and 65535

RM CLI EAGLE40 63
Release 3.4 03/2020
1 7 .2 .9 ip ospf c ost
Configure the OSPF cost for the interface. The cost of a specific interface indicates the overhead required to send
packets across the link. If set to 0, OSPF calculates the cost from the reference bandwidth and the interface speed.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip ospf cost <P-1>
Parameter Value Meaning
P-1 1- Auto cost for OSPF calculation
4294967_hmcliListO
SPFcost

1 7 .2 .1 0 ip ospf m t u-ignore
Enable/Disable OSPF MTU mismatch on interface.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip ospf mtu-ignore

 no ip ospf m t u-ignore
Disable the option
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: no ip ospf mtu-ignore

1 7 .2 .1 1 ip ospf a ut he nt ic a t ion t ype


Configure authentication type.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip ospf authentication type <P-1>
Parameter Value Meaning
P-1 none Configure the authentication type as none (Key and key ID is not required).
simple Configure the authentication type as simple (Key ID is not required).
md5 Configure the authentication type as md5 for the interface.

1 7 .2 .1 2 ip ospf a ut he nt ic a t ion k e y
Configure authentication key.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip ospf authentication key <P-1>
Parameter Value Meaning
P-1 string <key> Configure the authentication key.

1 7 .2 .1 3 ip ospf a ut he nt ic a t ion k e y-id


Configure authentication key-id for md5 authentication.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip ospf authentication key-id <P-1>
Parameter Value Meaning
P-1 0..255 Enter a number in the given range.

1 7 .3 show
Display device options and settings.

1 7 .3 .1 show ip ospf globa l


Display the OSPF global configurations.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip ospf global

64 RM CLI EAGLE40
Release 3.4 03/2020
1 7 .3 .2 show ip ospf a re a
Display the OSPF area related information.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip ospf area [<P-1>]
Parameter Value Meaning
P-1 A.B.C.D IP address.

1 7 .3 .3 show ip ospf st ub
Display the OSPF stub area related information.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip ospf stub

1 7 .3 .4 show ip ospf da t a ba se int e rna l


Display the internal LSA database information.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip ospf database internal

1 7 .3 .5 show ip ospf da t a ba se e x t e rna l


Display the external LSA database information.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip ospf database external

1 7 .3 .6 show ip ospf ra nge


Display the OSPF area range information.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip ospf range

1 7 .3 .7 show ip ospf int e rfa c e


Display the OSPF interface related information.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip ospf interface [<P-1>]
Parameter Value Meaning
P-1 slot no./port no.

1 7 .3 .8 show ip ospf virt ua l-link


Display the OSPF virtual-link related information.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip ospf virtual-link <P-1> <P-2>
Parameter Value Meaning
P-1 A.B.C.D IP address.
P-2 A.B.C.D IP address.

1 7 .3 .9 show ip ospf virt ua l-ne ighbor


Display the OSPF Virtual-link neighbor information
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip ospf virtual-neighbor

1 7 .3 .1 0 show ip ospf ne ighbor


Display the OSPF neighbor related information.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip ospf neighbor [<P-1>]

RM CLI EAGLE40 65
Release 3.4 03/2020
Parameter Value Meaning
P-1 slot no./port no.

1 7 .3 .1 1 show ip ospf st a t ist ic s


Display the OSPF statistics.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip ospf statistics

1 7 .3 .1 2 show ip ospf re -dist ribut e


Display the OSPF re-distribute related information
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip ospf re-distribute <P-1>
Parameter Value Meaning
P-1 connected Select the source protocol as connected.
static Select the source protocol as static.

1 7 .3 .1 3 show ip ospf nssa


Display the OSPF NSSA related information.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip ospf nssa <P-1>
Parameter Value Meaning
P-1 A.B.C.D IP address.

1 7 .3 .1 4 show ip ospf rout e


Display the OSPF routes.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip ospf route

66 RM CLI EAGLE40
Release 3.4 03/2020
1 8 V ir t ua l Rout e r Re dunda ncy Prot oc ol (V RRP)

1 8 .1 ip
Set IP parameters.

1 8 .1 .1 ip vrrp ope ra t ion


Enables or disables VRRP globally on the device.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip vrrp operation

 no ip vrrp ope ra t ion


Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no ip vrrp operation

1 8 .1 .2 ip vrrp t ra p a ut h-fa ilure


Enable or disable the sending of a trap if this router detects an authentication failure on any of its VRRP interfaces.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip vrrp trap auth-failure

 no ip vrrp t ra p a ut h-fa ilure


Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no ip vrrp trap auth-failure

1 8 .1 .3 ip vrrp t ra p ne w -m a st e r
Enable or disable the sending of a trap if this router becomes new master for any of its VRRP interfaces.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip vrrp trap new-master

 no ip vrrp ope ra t ion


Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no ip vrrp trap new-master

1 8 .2 ip
IP interface commands.

1 8 .2 .1 ip vrrp a dd
Create a new VRRP instance.
 Mode: Interface Range Mode.
 Privilege Level: Operator
 Format: ip vrrp add <P-1> [priority <P-2>] [interval <P-3>]
[priority]: Priority of the virtual router ..... default 100
[interval]: Advertisement Interval in seconds .. default 1
Parameter Value Meaning
P-1 1..255 Enter a virtual router ID.
P-2 1..254 Enter a priority value.
P-3 1..255 Enter a number in the given range.

RM CLI EAGLE40 67
Release 3.4 03/2020
1 8 .2 .2 ip vrrp m odify
Modify parameters of a VRRP instance.
 Mode: Interface Range Mode.
 Privilege Level: Operator
 Format: ip vrrp modify <P-1> [priority <P-2>] [interval <P-3>]
[priority]: Priority of the virtual router
[interval]: Advertisement Interval in seconds
Parameter Value Meaning
P-1 1..255 Enter a virtual router ID.
P-2 1..254 Enter a priority value.
P-3 1..255 Enter a number in the given range.

1 8 .2 .3 ip vrrp de le t e
Delete a VRRP instance.
 Mode: Interface Range Mode.
 Privilege Level: Operator
 Format: ip vrrp delete
Parameter Value Meaning
P-1 1..255 Enter a virtual router ID.

1 8 .2 .4 ip vrrp e na ble
Enable a VRRP instance.
 Mode: Interface Range Mode.
 Privilege Level: Operator
 Format: ip vrrp enable <P-1>
Parameter Value Meaning
P-1 1..255 Enter a virtual router ID.

1 8 .2 .5 ip vrrp disa ble


Enable a VRRP instance.
 Mode: Interface Range Mode.
 Privilege Level: Operator
 Format: ip vrrp disable <P-1>
Parameter Value Meaning
P-1 1..255 Enter a virtual router ID.

1 8 .2 .6 ip vrrp virt ua l-a ddre ss a dd


Add a virtual address.
 Mode: Interface Range Mode.
 Privilege Level: Operator
 Format: ip vrrp virtual-address add <P-1> <P-2>
Parameter Value Meaning
P-1 1..255 Enter a virtual router ID.
P-2 A.B.C.D IP address.

1 8 .2 .7 ip vrrp virt ua l-a ddre ss de le t e


Delete a virtual address.
 Mode: Interface Range Mode.
 Privilege Level: Operator
 Format: ip vrrp virtual-address add <P-1> <P-2>
Parameter Value Meaning
P-1 1..255 Enter a virtual router ID.
P-2 A.B.C.D IP address.

1 8 .2 .8 ip vrrp t ra c k a dd
Add a tracking object to the vrrp instance.
 Mode: Interface Range Mode.
 Privilege Level: Operator
 Format: ip vrrp track add <P-1> <P-2> [decrement <P-3>]
[decrement]: Configure the decrement value. Default is 20
Parameter Value Meaning
P-1 1..255 Enter a virtual router ID.

68 RM CLI EAGLE40
Release 3.4 03/2020
Parameter Value Meaning
P-2 string Track instance.
P-3 1..253 Enter the decrement value. The priority will be decremented by the configured
value.

1 8 .2 .9 ip vrrp t ra c k m odify
Modify a tracking object to the vrrp instance.
 Mode: Interface Range Mode.
 Privilege Level: Operator
 Format: ip vrrp track modify <P-1> <P-2> [decrement <P-3>]
[decrement]: Configure the decrement value. Default is 20
Parameter Value Meaning
P-1 1..255 Enter a virtual router ID.
P-2 string Track instance.
P-3 1..253 Enter the decrement value. The priority will be decremented by the configured
value.

1 8 .2 .1 0 ip vrrp t ra c k de le t e
Delete a tracking object to the vrrp instance.
 Mode: Interface Range Mode.
 Privilege Level: Operator
 Format: ip vrrp track delete <P-1> <P-2>
Parameter Value Meaning
P-1 1..255 Enter a virtual router ID.
P-2 string Track instance.

1 8 .3 show
Display device options and settings.

1 8 .3 .1 show ip vrrp int e rfa c e


Show parameters of one VRRP instances.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip vrrp interface [<P-1> [<P-2>]]
Parameter Value Meaning
P-1 slot no./port no.
P-2 1..255 Enter a virtual router ID.

1 8 .3 .2 show ip vrrp globa l


Show global VRRP parameters.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip vrrp global

RM CLI EAGLE40 69
Release 3.4 03/2020
1 9 Addre ss Re solut ion Prot oc ol (I P ARP)

1 9 .1 ip
Set IP parameters.

1 9 .1 .1 ip a rp a dd
Add a static arp entry.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip arp add <P-1> <P-2>
Parameter Value Meaning
P-1 A.B.C.D IP address.
P-2 aa:bb:cc:dd:ee:ff MAC address.

1 9 .1 .2 ip a rp de le t e
Delete a static arp entry.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip arp delete <P-1>
Parameter Value Meaning
P-1 A.B.C.D IP address.

1 9 .1 .3 ip a rp e na ble
Enable a static arp entry.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip arp enable <P-1>
Parameter Value Meaning
P-1 a.b.c.d IP address.

1 9 .1 .4 ip a rp disa ble
Disable a static arp entry.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip arp disable <P-1>
Parameter Value Meaning
P-1 a.b.c.d IP address.

1 9 .1 .5 ip a rp t im e out
Configure ARP entry age-out time (in seconds).
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip arp timeout <P-1>
Parameter Value Meaning
P-1 15..21600 Enter the arp response time.

1 9 .1 .6 ip a rp re sponse -t im e
Configure ARP request response timeout (in seconds).
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip arp response-time <P-1>
Parameter Value Meaning
P-1 1..10 Enter the arp response time.

1 9 .1 .7 ip a rp re t rie s
Configure ARP count of maximum requests for retries.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip arp retries <P-1>

70 RM CLI EAGLE40
Release 3.4 03/2020
Parameter Value Meaning
P-1 1..10 Enter the arp max retries.

1 9 .2 show
Display device options and settings.

1 9 .2 .1 show ip a rp info
Displays ARP summary information.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip arp info

1 9 .2 .2 show ip a rp t a ble
Displays ARP cache entries.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip arp table

1 9 .2 .3 show ip a rp st a t ic
Displays static ARP entries.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip arp static

1 9 .2 .4 show ip a rp e nt ry
Displays ARP cache entry.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip arp entry <P-1>
Parameter Value Meaning
P-1 A.B.C.D IP address.

1 9 .3 cle a r
Clear several items.

1 9 .3 .1 c le a r ip a rp-c a c he
Clear IP data of several items.
 Mode: Privileged Exec Mode
 Privilege Level: Operator
 Format: clear ip arp-cache [gateway]
[gateway]: Also clear gateway ARP entries.

RM CLI EAGLE40 71
Release 3.4 03/2020
2 0 L3 Re la y

2 0 .1 ip
Set IP parameters.

2 0 .1 .1 ip udp-he lpe r ope ra t ion


Enable or disable the IP helper and DHCP relay.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip udp-helper operation

 no ip udp-he lpe r ope ra t ion


Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no ip udp-helper operation

2 0 .1 .2 ip udp-he lpe r se rve r a dd


Add a global relay agent to process DHCP client requests and UDP broadcast packets received on any interface.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip udp-helper server add <P-1> <P-2>
Parameter Value Meaning
P-1 67_hmcliList_IpHelpe DHCP server port number.
rUdpPorts
P-2 A.B.C.D IP address.

2 0 .1 .3 ip udp-he lpe r se rve r de le t e


Delete a global relay agent.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip udp-helper server delete <P-1> <P-2>
Parameter Value Meaning
P-1 67_hmcliList_IpHelpe DHCP server port number.
rUdpPorts
P-2 A.B.C.D IP address.

2 0 .1 .4 ip udp-he lpe r se rve r e na ble


Enable a global relay agent to process DHCP client requests and UDP broadcast packets received on any
interface.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip udp-helper server enable <P-1> <P-2>
Parameter Value Meaning
P-1 67_hmcliList_IpHelpe DHCP server port number.
rUdpPorts
P-2 A.B.C.D IP address.

2 0 .1 .5 ip udp-he lpe r se rve r disa ble


Disable a global relay agent from processing DHCP client requests and UDP broadcast packets received on any
interface.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip udp-helper server disable <P-1> <P-2>
Parameter Value Meaning
P-1 67_hmcliList_IpHelpe DHCP server port number.
rUdpPorts
P-2 A.B.C.D IP address.

72 RM CLI EAGLE40
Release 3.4 03/2020
2 0 .1 .6 ip udp-he lpe r m a x hopc ount
Configure the DHCP relay maximum hop count.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip udp-helper maxhopcount <P-1>
Parameter Value Meaning
P-1 1..16 Enter a number in the given range.

2 0 .1 .7 ip udp-he lpe r m inw a it t im e


Configure DHCP relay minimum wait time in seconds.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip udp-helper minwaittime <P-1>
Parameter Value Meaning
P-1 0..100 Enter a number in the given range.

2 0 .1 .8 ip udp-he lpe r c idopt m ode


Enable or disable DHCP relay circuit id option mode.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip udp-helper cidoptmode

 no ip udp-he lpe r c idopt m ode


Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no ip udp-helper cidoptmode

2 0 .2 ip
IP interface commands.

2 0 .2 .1 ip udp-he lpe r se rve r a dd


Add a relay agent to process DHCP client requests and UDP broadcast packets received on a specific interface.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip udp-helper server add <P-1> <P-2>
Parameter Value Meaning
P-1 67_hmcliList_IpHelpe DHCP server port number.
rUdpPorts
P-2 A.B.C.D IP address.

2 0 .2 .2 ip udp-he lpe r se rve r de le t e


Delete a relay agent from a specific interface.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip udp-helper server delete <P-1> <P-2>
Parameter Value Meaning
P-1 67_hmcliList_IpHelpe DHCP server port number.
rUdpPorts
P-2 A.B.C.D IP address.

2 0 .2 .3 ip udp-he lpe r se rve r e na ble


Enable a relay agent to process DHCP client requests and UDP broadcast packets received on a specific
interface.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip udp-helper server enable <P-1> <P-2>
Parameter Value Meaning
P-1 67_hmcliList_IpHelpe DHCP server port number.
rUdpPorts

RM CLI EAGLE40 73
Release 3.4 03/2020
Parameter Value Meaning
P-2 A.B.C.D IP address.

2 0 .2 .4 ip udp-he lpe r se rve r disa ble


Disable a relay agent from processing DHCP client requests and UDP broadcast packets received on a specific
interface.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip udp-helper server disable <P-1> <P-2>
Parameter Value Meaning
P-1 67_hmcliList_IpHelpe DHCP server port number.
rUdpPorts
P-2 A.B.C.D IP address.

2 0 .3 show
Display device options and settings.

2 0 .3 .1 show ip udp-he lpe r st a t us


Display the IP helper and DHCP relay status information.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip udp-helper status

2 0 .3 .2 show ip udp-he lpe r globa l


Display the DHCP and UDP relays defined globally.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip udp-helper global

2 0 .3 .3 show ip udp-he lpe r int e rfa c e


Display the DHCP and UDP relays defined for specific interfaces.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip udp-helper interface [<P-1>]
Parameter Value Meaning
P-1 slot no./port no.

2 0 .3 .4 show ip udp-he lpe r st a t ist ic s


Display the IP helper and DHCP relay statistics.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip udp-helper statistics

2 0 .4 cle a r
Clear several items.

2 0 .4 .1 c le a r ip udp-he lpe r
Reset IP helper and DHCP relay statistics.
 Mode: Privileged Exec Mode
 Privilege Level: Operator
 Format: clear ip udp-helper

74 RM CLI EAGLE40
Release 3.4 03/2020
2 1 I nt e r ne t Prot oc ol Ve rsion 4 (I Pv4 )

2 1 .1 ne t w ork
Configure the inband and outband connectivity.

2 1 .1 .1 ne t w ork prot oc ol
Select DHCP, BOOTP or none as the network configuration protocol.
 Mode: Privileged Exec Mode
 Privilege Level: Operator
 Format: network protocol <P-1>
Parameter Value Meaning
P-1 none No network config protocol
bootp BOOTP
dhcp DHCP

2 1 .1 .2 ne t w ork pa rm s
Set network address, netmask and gateway
 Mode: Privileged Exec Mode
 Privilege Level: Operator
 Format: network parms <P-1> <P-2> [<P-3>]
Parameter Value Meaning
P-1 A.B.C.D IP address.
P-2 A.B.C.D IP address.
P-3 A.B.C.D IP address.

2 1 .2 cle a r
Clear several items.

2 1 .2 .1 c le a r a rp-t a ble -sw it c h


Clear the agent's ARP table (cache).
 Mode: Privileged Exec Mode
 Privilege Level: Operator
 Format: clear arp-table-switch

2 1 .3 show
Display device options and settings.

2 1 .3 .1 show ne t w ork pa rm s
Display the network settings.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show network parms

2 1 .4 show
Display device options and settings.

RM CLI EAGLE40 75
Release 3.4 03/2020
2 1 .4 .1 show a rp
Display the ARP table.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show arp

76 RM CLI EAGLE40
Release 3.4 03/2020
2 2 Link La ye r Disc ove r y Prot oc ol (LLDP)

2 2 .1 lldp
Configure of Link Layer Discovery Protocol.

2 2 .1 .1 lldp ope ra t ion


Enable or disable the LLDP operational state.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: lldp operation

 no lldp ope ra t ion


Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no lldp operation

2 2 .1 .2 lldp c onfig c ha ssis a dm in-st a t e


Enable or disable the LLDP operational state.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: lldp config chassis admin-state <P-1>
Parameter Value Meaning
P-1 enable Enable the option.
disable Disable the option.

2 2 .1 .3 lldp c onfig c ha ssis not ific a t ion-int e rva l


Enter the LLDP notification interval in seconds.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: lldp config chassis notification-interval <P-1>
Parameter Value Meaning
P-1 5..3600 Enter a number in the given range.

2 2 .1 .4 lldp c onfig c ha ssis t x -hold-m ult iplie r


Enter the LLDP transmit hold multiplier.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: lldp config chassis tx-hold-multiplier <P-1>
Parameter Value Meaning
P-1 2..10 Enter a number in the given range.

2 2 .1 .5 lldp c onfig c ha ssis t x -int e rva l


Enter the LLDP transmit interval in seconds.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: lldp config chassis tx-interval <P-1>
Parameter Value Meaning
P-1 5..32768 Enter a number in the given range.

2 2 .2 show
Display device options and settings.

RM CLI EAGLE40 77
Release 3.4 03/2020
2 2 .2 .1 show lldp globa l
Display the LLDP global configurations.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show lldp global

2 2 .2 .2 show lldp port


Display the port specific LLDP configurations.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show lldp port [<P-1>]
Parameter Value Meaning
P-1 slot no./port no.

2 2 .2 .3 show lldp re m ot e -da t a


Remote information collected with LLDP.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show lldp remote-data [<P-1>]
Parameter Value Meaning
P-1 slot no./port no.

2 2 .3 lldp
Configure of Link Layer Discovery Protocol on a port.

2 2 .3 .1 lldp a dm in-st a t e
Configure how the interface processes LLDP frames.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: lldp admin-state <P-1>
Parameter Value Meaning
P-1 tx-only Interface will only transmit LLDP frames. Received frames are not processed.
rx-only Interface will only receive LLDP frames. Frames are not transmitted.
tx-and-rx Interface will transmit and receive LLDP frames. This is the default setting.
disable Interface will neither transmit nor process received LLDP frames.

2 2 .3 .2 lldp fdb-m ode


Configure the LLDP FDB mode for this interface.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: lldp fdb-mode <P-1>
Parameter Value Meaning
P-1 lldp-only Collected remote data will be based on received LLDP frames only.
mac-only Collected remote data will be based on the switch's FDB entries only.
both Collected remote data will be based on received LLDP frames as well as on the
switch's FDB entries.
auto-detect As long as no LLDP frames are received, the collected remote data will be based
on the switch's FDB entries only. After the first LLDP frame is received, the
remote data will be based on received LLDP frames only. This is the default
setting.

2 2 .3 .3 lldp m a x -ne ighbors


Enter the LLDP max neighbors for interface.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: lldp max-neighbors <P-1>
Parameter Value Meaning
P-1 1..50 Enter a number in the given range.

78 RM CLI EAGLE40
Release 3.4 03/2020
2 2 .3 .4 lldp not ific a t ion
Enable or disable the LLDP notification operation for interface.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: lldp notification

 no lldp not ific a t ion


Disable the option
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: no lldp notification

2 2 .3 .5 lldp t lv port -de sc


Enable or disable port description TLV transmission.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: lldp tlv port-desc <P-1>
Parameter Value Meaning
P-1 [cr] Enable the Bit.

 no lldp t lv port -de sc


Disable the option
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: no lldp tlv port-desc <P-1>

2 2 .3 .6 lldp t lv sys-c a p
Enable or disable system capabilities TLV transmission.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: lldp tlv sys-cap <P-1>
Parameter Value Meaning
P-1 [cr] Enable the Bit.

 no lldp t lv sys-c a p
Disable the option
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: no lldp tlv sys-cap <P-1>

2 2 .3 .7 lldp t lv sys-de sc
Enable or disable system description TLV transmission.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: lldp tlv sys-desc <P-1>
Parameter Value Meaning
P-1 [cr] Enable the Bit.

 no lldp t lv sys-de sc
Disable the option
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: no lldp tlv sys-desc <P-1>

2 2 .3 .8 lldp t lv sys-na m e
Enable or disable system name TLV transmission.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: lldp tlv sys-name <P-1>
Parameter Value Meaning
P-1 [cr] Enable the Bit.

RM CLI EAGLE40 79
Release 3.4 03/2020
 no lldp t lv sys-na m e
Disable the option
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: no lldp tlv sys-name <P-1>

80 RM CLI EAGLE40
Release 3.4 03/2020
2 3 Logging

2 3 .1 logging
Logging configuration.

2 3 .1 .1 logging a udit -t ra il
Add a comment for the audit trail.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: logging audit-trail <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 80 characters.

2 3 .1 .2 logging buffe re d se ve rit y


Configure the minimum severity level to be logged to the high priority buffer.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: logging buffered severity <P-1>
Parameter Value Meaning
P-1 emergency System is unusable. System failure has occurred.
alert Action must be taken immediately. Unrecoverable failure of a component. System
failure likely.
critical Recoverable failure of a component that may lead to system failure.
error Error conditions. Recoverable failure of a component.
warning Minor failure, e.g. misconfiguration of a component.
notice Normal but significant conditions.
informational Informational messages.
debug Debug-level messages.
0 Same as emergency
1 Same as alert
2 Same as critical
3 Same as error
4 Same as warning
5 Same as notice
6 Same as informational
7 Same as debug

2 3 .1 .3 logging host a dd
Add a new logging host.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: logging host add <P-1> addr <P-2>
addr: Enter the IP address of the server.
Parameter Value Meaning
P-1 1..8 Syslog server entry index
P-2 a.b.c.d IP address.

2 3 .1 .4 logging host de le t e
Delete a logging host.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: logging host delete <P-1>
Parameter Value Meaning
P-1 1..8 Syslog server entry index

2 3 .1 .5 logging host e na ble


Enable a logging host.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: logging host enable <P-1>

RM CLI EAGLE40 81
Release 3.4 03/2020
Parameter Value Meaning
P-1 1..8 Syslog server entry index

2 3 .1 .6 logging host disa ble


Disable a logging host.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: logging host disable <P-1>
Parameter Value Meaning
P-1 1..8 Syslog server entry index

2 3 .1 .7 logging host m odify


Modify an existing logging host.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: logging host modify <P-1> [addr <P-2>]
[addr]: Enter the IP address of the server.
Parameter Value Meaning
P-1 1..8 Syslog server entry index
P-2 a.b.c.d IP address.

2 3 .1 .8 logging syslog ope ra t ion


Enable or disable the syslog client.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: logging syslog operation

 no logging syslog ope ra t ion


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no logging syslog operation

2 3 .1 .9 logging c urre nt -c onsole ope ra t ion


Enable or disable logging messages to the current remote console.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: logging current-console operation

 no logging c urre nt -c onsole ope ra t ion


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no logging current-console operation

2 3 .1 .1 0 logging c urre nt -c onsole se ve rit y


Configure the minimum severity level to be sent to the current remote console.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: logging current-console severity <P-1>

82 RM CLI EAGLE40
Release 3.4 03/2020
Parameter Value Meaning
P-1 emergency System is unusable. System failure has occurred.
alert Action must be taken immediately. Unrecoverable failure of a component. System
failure likely.
critical Recoverable failure of a component that may lead to system failure.
error Error conditions. Recoverable failure of a component.
warning Minor failure, e.g. misconfiguration of a component.
notice Normal but significant conditions.
informational Informational messages.
debug Debug-level messages.
0 Same as emergency
1 Same as alert
2 Same as critical
3 Same as error
4 Same as warning
5 Same as notice
6 Same as informational
7 Same as debug

2 3 .1 .1 1 logging c onsole ope ra t ion


Enable or disable logging to the local V.24 console.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: logging console operation

 no logging c onsole ope ra t ion


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no logging console operation

2 3 .1 .1 2 logging c onsole se ve rit y


Configure the minimum severity level to be logged to the V.24 console.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: logging console severity <P-1>
Parameter Value Meaning
P-1 emergency System is unusable. System failure has occurred.
alert Action must be taken immediately. Unrecoverable failure of a component. System
failure likely.
critical Recoverable failure of a component that may lead to system failure.
error Error conditions. Recoverable failure of a component.
warning Minor failure, e.g. misconfiguration of a component.
notice Normal but significant conditions.
informational Informational messages.
debug Debug-level messages.
0 Same as emergency
1 Same as alert
2 Same as critical
3 Same as error
4 Same as warning
5 Same as notice
6 Same as informational
7 Same as debug

2 3 .2 show
Display device options and settings.

RM CLI EAGLE40 83
Release 3.4 03/2020
2 3 .2 .1 show logging buffe re d
Display the buffered (in-memory) log entries.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show logging buffered [<P-1>]
Parameter Value Meaning
P-1 string <filter> Enter a comma separated list of severity ranges, numbers or enum
strings are allowed. Example: 0-1,informational-debug

2 3 .2 .2 show logging t ra plogs


Display the trap log entries.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show logging traplogs

2 3 .2 .3 show logging c onsole


Display the console logging configurations.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show logging console

2 3 .2 .4 show logging pe rsist e nt


Display the persistent logging configurations.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show logging persistent [logfiles]
[logfiles]: List the persistent log files.

2 3 .2 .5 show logging syslog


Display the current syslog operational setting.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show logging syslog

2 3 .2 .6 show logging host


Display a list of logging hosts currently configured.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show logging host

2 3 .3 c opy
Copy different kinds of items.

2 3 .3 .1 c opy e ve nt log buffe re d e nvm


Copy a buffered log from the device to external non-volatile memory.
 Mode: Privileged Exec Mode
 Privilege Level: Operator
 Format: copy eventlog buffered envm <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 32 characters.

2 3 .3 .2 c opy e ve nt log buffe re d re m ot e


Copy a buffered log from the device to a file server.
 Mode: Privileged Exec Mode
 Privilege Level: Operator
 Format: copy eventlog buffered remote <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 128 characters.

84 RM CLI EAGLE40
Release 3.4 03/2020
2 3 .3 .3 c opy e ve nt log pe rsist e nt
Copy the persistent logs from the device to an envm or a file server.
 Mode: Privileged Exec Mode
 Privilege Level: Operator
 Format: copy eventlog persistent <P-1> envm <P-2> remote <P-3>
envm: Copy the persistent log from the device to external non-volatile memory.
remote: Copy the persistent logs from the device to a file server.
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 32 characters.
P-2 string Enter a user-defined text, max. 32 characters.
P-3 string Enter a user-defined text, max. 128 characters.

2 3 .3 .4 c opy t ra plog syst e m e nvm


Copy the traplog from the device to external non-volatile memory.
 Mode: Privileged Exec Mode
 Privilege Level: Operator
 Format: copy traplog system envm <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 32 characters.

2 3 .3 .5 c opy t ra plog syst e m re m ot e


Copy the traplog from the device to a file server
 Mode: Privileged Exec Mode
 Privilege Level: Operator
 Format: copy traplog system remote <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 128 characters.

2 3 .3 .6 c opy a udit t ra il syst e m e nvm


Copy the audit trail from the device to external non-volatile memory.
 Mode: Privileged Exec Mode
 Privilege Level: Operator, Auditor
 Format: copy audittrail system envm <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 32 characters.

2 3 .3 .7 c opy a udit t ra il syst e m re m ot e


Copy the audit trail from the device to a file server.
 Mode: Privileged Exec Mode
 Privilege Level: Operator, Auditor
 Format: copy audittrail system remote <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 128 characters.

2 3 .4 cle a r
Clear several items.

2 3 .4 .1 c le a r logging buffe re d
Clear buffered log from memory.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: clear logging buffered

2 3 .4 .2 c le a r logging pe rsist e nt
Clear persistent log from memory.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: clear logging persistent

RM CLI EAGLE40 85
Release 3.4 03/2020
2 3 .4 .3 c le a r e ve nt log
Clear the event log entries from memory.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: clear eventlog

86 RM CLI EAGLE40
Release 3.4 03/2020
2 4 M a na ge m e nt Ac c e ss

2 4 .1 ne t w ork
Configure the inband and outband connectivity.

2 4 .1 .1 ne t w ork m a na ge m e nt a c c e ss w e b t im e out
Set the web interface idle timeout.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: network management access web timeout <P-1>
Parameter Value Meaning
P-1 0..160 Idle timeout of a session in minutes (default: 5).

2 4 .1 .2 ne t w ork m a na ge m e nt a c c e ss a dd
Add a new entry with index.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: network management access add <P-1> [ip <P-2>] [mask <P-3>] [http <P-4>]
[https <P-5>] [snmp <P-6>]
[ip]: Configure IP address which should have access to management.
[mask]: Configure network mask to allow a subnet for management access.
[http]: Configure if HTTP is allowed to have management access.
[https]: Configure if HTTPS is allowed to have management access.
[snmp]: Configure if SNMP is allowed to have management access.
Parameter Value Meaning
P-1 1..16 Pool entry index.
P-2 a.b.c.d IP address.
P-3 0..32 Prefix length netmask.
P-4 enable Enable the option.
disable Disable the option.
P-5 enable Enable the option.
disable Disable the option.
P-6 enable Enable the option.
disable Disable the option.

2 4 .1 .3 ne t w ork m a na ge m e nt a c c e ss de le t e
Delete an entry with index.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: network management access delete <P-1>
Parameter Value Meaning
P-1 1..16 Pool entry index.

2 4 .1 .4 ne t w ork m a na ge m e nt a c c e ss m odify
Modify an entry with index.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: network management access modify <P-1> ip <P-2> mask <P-3> http <P-4> https
<P-5> snmp <P-6> ssh <P-7>
ip: Configure ip-address which should have access to management.
mask: Configure network mask to allow a subnet for management access.
http: Configure if HTTP is allowed to have management access.
https: Configure if HTTPS is allowed to have management access.
snmp: Configure if SNMP is allowed to have management access.
ssh: Configure if SSH is allowed to have management access.
Parameter Value Meaning
P-1 1..16 Pool entry index.
P-2 a.b.c.d IP address.
P-3 0..32 Prefix length netmask.

RM CLI EAGLE40 87
Release 3.4 03/2020
Parameter Value Meaning
P-4 enable Enable the option.
disable Disable the option.
P-5 enable Enable the option.
disable Disable the option.
P-6 enable Enable the option.
disable Disable the option.
P-7 enable Enable the option.
disable Disable the option.

2 4 .1 .5 ne t w ork m a na ge m e nt a c c e ss ope ra t ion


Enable/Disable operation for RMA.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: network management access operation

 no ne t w ork m a na ge m e nt a c c e ss ope ra t ion


Disable the option
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: no network management access operation

2 4 .1 .6 ne t w ork m a na ge m e nt a c c e ss st a t us
Activate/Deactivate an entry.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: network management access status <P-1>
Parameter Value Meaning
P-1 1..16 Pool entry index.

 no ne t w ork m a na ge m e nt a c c e ss st a t us
Disable the option
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: no network management access status <P-1>

2 4 .2 show
Display device options and settings.

2 4 .2 .1 show ne t w ork m a na ge m e nt a c c e ss globa l


Display the global restricted management access preferences.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show network management access global

2 4 .2 .2 show ne t w ork m a na ge m e nt a c c e ss rule s


Display the restricted management access rules.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show network management access rules [<P-1>]
Parameter Value Meaning
P-1 1..16 Pool entry index.

88 RM CLI EAGLE40
Release 3.4 03/2020
2 5 N e t w ork Addre ss Tra nslat ion (N AT )

2 5 .1 nat
Manage NAT rules

2 5 .1 .1 na t dna t c om m it
Commit pending changes for DNAT (commits all NAT changes).
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat dnat commit

2 5 .1 .2 na t dna t a dd
Add rule to DNAT
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat dnat add <P-1> [cfg <P-2> <P-3> <P-4> <P-5> <P-6> <P-7> <P-8> [<P-9>]]
[cfg]: Configure the rule immediately
Parameter Value Meaning
P-1 1..255 DNAT rule number
P-2 a.b.c.d Source IP address
a.b.c.d/n CIDR mask
!a.b.c.d !<a.b.c.d> Everything BUT this address
!a.b.c.d/n !<a.b.c.d/n> Everything BUT this CIDR mask
any any Any
P-3 number number UDP/TCP Source Port
nu-nu nu-nu Port Range
nu,nu-nu nu,nu-nu List of ports (or port ranges)
any any Any port (or protocol without a port)
P-4 a.b.c.d Destination IP address
a.b.c.d/n CIDR mask
!a.b.c.d !<a.b.c.d> Everything BUT this address
!a.b.c.d/n !<a.b.c.d/n> Everything BUT this CIDR mask
any any Any
P-5 number number of the UDP/TCP Destination Port
nu-nu nu-nu Port Range
number,number nu,nu-nu List of ports (or port ranges)
any any Any port (or protocol without a port)
P-6 a.b.c.d New destination IP address
P-7 number number of the UDP/TCP New Destination Port
any any Any port (or protocol without a port)
P-8 icmp Internet Control Message Protocol
igmp Internet Group Management Protocol
ipip IP-within-IP Encapsulation Protocol
tcp Transmission Control Protocol
udp User Datagram Protocol
esp Encapsulating Security Protocol
ah Authentication Header
any Any of the above
P-9 string Rule description/name

2 5 .1 .3 na t dna t m odify
Configure single DNAT rule
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat dnat modify <P-1> <P-2> <P-3> <P-4> <P-5> <P-6> <P-7> <P-8> [<P-9>]
Parameter Value Meaning
P-1 1..255 DNAT rule number

RM CLI EAGLE40 89
Release 3.4 03/2020
Parameter Value Meaning
P-2 a.b.c.d Source IP address
a.b.c.d/n CIDR mask
!a.b.c.d !<a.b.c.d> Everything BUT this address
!a.b.c.d/n !<a.b.c.d/n> Everything BUT this CIDR mask
any any Any
P-3 number number UDP/TCP Source Port
nu-nu nu-nu Port Range
nu,nu-nu nu,nu-nu List of ports (or port ranges)
any any Any port (or protocol without a port)
P-4 a.b.c.d Destination IP address
a.b.c.d/n CIDR mask
!a.b.c.d !<a.b.c.d> Everything BUT this address
!a.b.c.d/n !<a.b.c.d/n> Everything BUT this CIDR mask
any any Any
P-5 number number of the UDP/TCP Destination Port
nu-nu nu-nu Port Range
number,number nu,nu-nu List of ports (or port ranges)
any any Any port (or protocol without a port)
P-6 a.b.c.d New destination IP address
P-7 number number of the UDP/TCP New Destination Port
any any Any port (or protocol without a port)
P-8 icmp Internet Control Message Protocol
igmp Internet Group Management Protocol
ipip IP-within-IP Encapsulation Protocol
tcp Transmission Control Protocol
udp User Datagram Protocol
esp Encapsulating Security Protocol
ah Authentication Header
any Any of the above
P-9 string Rule description/name

2 5 .1 .4 na t dna t de le t e
Delete rule from DNAT
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat dnat delete <P-1>
Parameter Value Meaning
P-1 1..255 DNAT rule number

2 5 .1 .5 na t dna t logt ra p
Set log/trap for DNAT rule
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat dnat logtrap <P-1> <P-2> <P-3>
Parameter Value Meaning
P-1 1..255 DNAT rule number
P-2 no Disable Logging
yes Enable Logging
P-3 no Disable SNMP Trap
yes Enable SNMP Trap

2 5 .1 .6 na t dna t st a t e
Enable/Disable specific DNAT rule
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat dnat state <P-1> <P-2>
Parameter Value Meaning
P-1 1..255 DNAT rule number
P-2 enable Enable the option.
disable Disable the option.

90 RM CLI EAGLE40
Release 3.4 03/2020
2 5 .1 .7 na t dna t if a dd
Add Interface
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat dnat if add <P-1> <P-2> <P-3>
Parameter Value Meaning
P-1 slot no./port no.
P-2 1..255 DNAT rule number
P-3 0..4294967295 Priority

2 5 .1 .8 na t dna t if de le t e
Delete interface
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat dnat if delete <P-1> <P-2>
Parameter Value Meaning
P-1 slot no./port no.
P-2 1..255 DNAT rule number

2 5 .1 .9 na t 1 t o1 na t c om m it
Commit pending changes for 1:1 NAT (commits every NAT change).
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat 1to1nat commit

2 5 .1 .1 0 na t 1 t o1 na t a dd
Add rule to 1:1 NAT
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat 1to1nat add <P-1> [cfg <P-2> <P-3> <P-4>] [ingress <P-5>] [egress <P-6>
[<P-7>]]
[cfg]: Configure the rule immediately
[ingress]: Configure ingress interface
[egress]: Configure egress interface
Parameter Value Meaning
P-1 1..256 1:1 NAT rule number
P-2 a.b.c.d Virtual destination IP address
a.b.c.d/n CIDR mask
P-3 a.b.c.d Actual destination IP address
a.b.c.d/n CIDR mask
P-4 0..4294967295 Priority
P-5 slot no./port no.
P-6 slot no./port no.
P-7 string Rule description/name

2 5 .1 .1 1 na t 1 t o1 na t m odify
Configure single 1:1 NAT rule
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat 1to1nat modify <P-1> <P-2> <P-3> <P-4> [ingress <P-5>] [egress <P-6>
[<P-7>]]
[ingress]: Configure ingress interface
[egress]: Configure egress interface
Parameter Value Meaning
P-1 1..256 1:1 NAT rule number
P-2 a.b.c.d Virtual destination IP address
a.b.c.d/n CIDR mask
P-3 a.b.c.d Actual destination IP address
a.b.c.d/n CIDR mask
P-4 0..4294967295 Priority
P-5 slot no./port no.
P-6 slot no./port no.
P-7 string Rule description/name

RM CLI EAGLE40 91
Release 3.4 03/2020
2 5 .1 .1 2 na t 1 t o1 na t de le t e
Delete the rule from 1:1 NAT
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat 1to1nat delete <P-1>
Parameter Value Meaning
P-1 1..256 1:1 NAT rule number

2 5 .1 .1 3 na t 1 t o1 na t logt ra p
Set log/trap for 1:1 NAT rule
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat 1to1nat logtrap <P-1> <P-2> <P-3>
Parameter Value Meaning
P-1 1..256 1:1 NAT rule number
P-2 no Disable Logging
yes Enable Logging
P-3 no Disable SNMP Trap
yes Enable SNMP Trap

2 5 .1 .1 4 na t 1 t o1 na t st a t e
Enable/Disable specific 1:1 NAT rule
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat 1to1nat state <P-1> <P-2>
Parameter Value Meaning
P-1 1..256 1:1 NAT rule number
P-2 enable Enable the option.
disable Disable the option.

2 5 .1 .1 5 na t m a sq c om m it
Commit pending changes for Masquerading (commits every NAT change).
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat masq commit

2 5 .1 .1 6 na t m a sq a dd
Add rule to Masquerading
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat masq add <P-1> [cfg <P-2> <P-3> <P-4> [<P-5>]]
[cfg]: Configure the rule immediately
Parameter Value Meaning
P-1 1..128 Masquerading rule number
P-2 a.b.c.d Source IP address
a.b.c.d/n CIDR mask
!a.b.c.d !<a.b.c.d> Everything BUT this address
!a.b.c.d/n !<a.b.c.d/n> Everything BUT this CIDR mask
any any Any
P-3 number number UDP/TCP Source Port
nu-nu nu-nu Port Range
nu,nu-nu nu,nu-nu List of ports (or port ranges)
any any Any port (or protocol without a port)
P-4 tcp Transmission Control Protocol
udp User Datagram Protocol
any Any protocol at all
P-5 string Rule description/name

2 5 .1 .1 7 na t m a sq m odify
Configure single Masquerading rule
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat masq modify <P-1> <P-2> <P-3> <P-4> [<P-5>]

92 RM CLI EAGLE40
Release 3.4 03/2020
Parameter Value Meaning
P-1 1..128 Masquerading rule number
P-2 a.b.c.d Source IP address
a.b.c.d/n CIDR mask
!a.b.c.d !<a.b.c.d> Everything BUT this address
!a.b.c.d/n !<a.b.c.d/n> Everything BUT this CIDR mask
any any Any
P-3 number number UDP/TCP Source Port
nu-nu nu-nu Port Range
nu,nu-nu nu,nu-nu List of ports (or port ranges)
any any Any port (or protocol without a port)
P-4 tcp Transmission Control Protocol
udp User Datagram Protocol
any Any protocol at all
P-5 string Rule description/name

2 5 .1 .1 8 na t m a sq de le t e
Delete rule from Masquerading
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat masq delete <P-1>
Parameter Value Meaning
P-1 1..128 Masquerading rule number

2 5 .1 .1 9 na t m a sq logt ra p
Set log/trap for Masquerading rule
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat masq logtrap <P-1> <P-2> <P-3>
Parameter Value Meaning
P-1 1..128 Masquerading rule number
P-2 no Disable Logging
yes Enable Logging
P-3 no Disable SNMP Trap
yes Enable SNMP Trap

2 5 .1 .2 0 na t m a sq ipse c -e x e m pt
Exclude IPsec traffic from Masquerading rule
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat masq ipsec-exempt <P-1> <P-2>
Parameter Value Meaning
P-1 1..128 Masquerading rule number
P-2 disabled Apply rule to IPsec traffic
enabled Do not apply rule to IPsec traffic

2 5 .1 .2 1 na t m a sq st a t e
Enable/Disable specific Masquerading rule
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat masq state <P-1> <P-2>
Parameter Value Meaning
P-1 1..128 Masquerading rule number
P-2 enable Enable the option.
disable Disable the option.

2 5 .1 .2 2 na t m a sq if a dd
Add interface
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat masq if add <P-1> <P-2> <P-3>
Parameter Value Meaning
P-1 slot no./port no.
P-2 1..128 Masquerading rule number

RM CLI EAGLE40 93
Release 3.4 03/2020
Parameter Value Meaning
P-3 0..4294967295 Priority

2 5 .1 .2 3 na t m a sq if de le t e
Delete interface
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat masq if delete <P-1> <P-2>
Parameter Value Meaning
P-1 slot no./port no.
P-2 1..128 Masquerading rule number

2 5 .1 .2 4 na t double na t c om m it
Commit pending changes for Double NAT (commits all NAT changes).
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat doublenat commit

2 5 .1 .2 5 na t double na t a dd
Add rule to Double NAT
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat doublenat add <P-1> [cfg <P-2> <P-3> <P-4> <P-5> [<P-6>]]
[cfg]: Configure the rule immediately
Parameter Value Meaning
P-1 1..255 Double NAT rule number
P-2 a.b.c.d Local internal IP address
P-3 a.b.c.d Local external IP address
P-4 a.b.c.d Remote Internal IP Address
P-5 a.b.c.d Remote External IP Address
P-6 string Rule description/name

2 5 .1 .2 6 na t double na t m odify
Configure single Double NAT rule
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat doublenat modify <P-1> <P-2> <P-3> <P-4> <P-5> [<P-6>]
Parameter Value Meaning
P-1 1..255 Double NAT rule number
P-2 a.b.c.d Local internal IP address
P-3 a.b.c.d Local external IP address
P-4 a.b.c.d Remote Internal IP Address
P-5 a.b.c.d Remote External IP Address
P-6 string Rule description/name

2 5 .1 .2 7 na t double na t de le t e
Delete rule from Double NAT
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat doublenat delete <P-1>
Parameter Value Meaning
P-1 1..255 Double NAT rule number

2 5 .1 .2 8 na t double na t logt ra p
Set log/trap for Double NAT rule
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat doublenat logtrap <P-1> <P-2> <P-3>
Parameter Value Meaning
P-1 1..255 Double NAT rule number
P-2 no Disable Logging
yes Enable Logging

94 RM CLI EAGLE40
Release 3.4 03/2020
Parameter Value Meaning
P-3 no Disable SNMP Trap
yes Enable SNMP Trap

2 5 .1 .2 9 na t double na t st a t e
Enable/Disable specific Double NAT rule
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat doublenat state <P-1> <P-2>
Parameter Value Meaning
P-1 1..255 Double NAT rule number
P-2 enable Enable the option.
disable Disable the option.

2 5 .1 .3 0 na t double na t if a dd
Add Interface
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat doublenat if add <P-1> <P-2> <P-3> <P-4>
Parameter Value Meaning
P-1 slot no./port no.
P-2 ingress Ingress
egress Egress
both Both
P-3 1..255 Double NAT rule number
P-4 0..4294967295 Priority

2 5 .1 .3 1 na t double na t if de le t e
Delete interface
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: nat doublenat if delete <P-1> <P-2> <P-3>
Parameter Value Meaning
P-1 slot no./port no.
P-2 ingress Ingress
egress Egress
both Both
P-3 1..255 Double NAT rule number

2 5 .2 show
Display device options and settings.

2 5 .2 .1 show na t dna t rule s


Show DNAT rules.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show nat dnat rules [<P-1>]
Parameter Value Meaning
P-1 1..255 DNAT rule number

2 5 .2 .2 show na t dna t if
Show DNAT interface configuration.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show nat dnat if

RM CLI EAGLE40 95
Release 3.4 03/2020
2 5 .2 .3 show na t dna t logt ra p
Show Log/Trap settings for DNAT rules
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show nat dnat logtrap [<P-1>]
Parameter Value Meaning
P-1 1..255 DNAT rule number

2 5 .2 .4 show na t m a sq rule s
Show Masquerading rules.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show nat masq rules [<P-1>]
Parameter Value Meaning
P-1 1..128 Masquerading rule number

2 5 .2 .5 show na t m a sq logt ra p
Show Log/Trap settings for Masquerading rules.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show nat masq rules [<P-1>]
Parameter Value Meaning
P-1 1..128 Masquerading rule number

2 5 .2 .6 show na t m a sq if
Show Masquerading interface configuration.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show nat masq if

2 5 .2 .7 show na t 1 t o1 na t rule s
Show 1:1 NAT rules.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show nat 1to1nat rules [<P-1>]
Parameter Value Meaning
P-1 1..255 1:1 NAT rule number

2 5 .2 .8 show na t 1 t o1 na t logt ra p
Show 1:1 NAT rules.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show nat 1to1nat rules [<P-1>]
Parameter Value Meaning
P-1 1..255 1:1 NAT rule number

2 5 .2 .9 show na t double na t rule s


Show Double NAT rules.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show nat doublenat rules [<P-1>]
Parameter Value Meaning
P-1 1..255 Double NAT rule number

2 5 .2 .1 0 show na t double na t logt ra p


Display the Log/Trap settings for Double NAT rules.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show nat doublenat logtrap [<P-1>]
Parameter Value Meaning
P-1 1..255 Double NAT rule number

96 RM CLI EAGLE40
Release 3.4 03/2020
2 5 .2 .1 1 show na t double na t if
Show Double NAT interface configuration.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show nat doublenat if

RM CLI EAGLE40 97
Release 3.4 03/2020
2 6 N e t w ork T im e Prot oc ol (N T P)

2 6 .1 nt p
Configure NTP settings.

2 6 .1 .1 nt p c lie nt ope ra t ion


Enable or disable the NTP client.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ntp client operation <P-1>
Parameter Value Meaning
P-1 enable Enable the option.
disable Disable the option.

2 6 .1 .2 nt p c lie nt ope ra t ing-m ode


Set the NTP client operating mode.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ntp client operating-mode <P-1>
Parameter Value Meaning
P-1 unicast Enable NTP client in unicast operating mode.
broadcast Enable NTP client in broadcast operating mode.

2 6 .1 .3 nt p se rve r ope ra t ion


Enable or disable the NTP server.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ntp server operation <P-1>
Parameter Value Meaning
P-1 enable Enable the option.
disable Disable the option.

2 6 .1 .4 nt p se rve r ope ra t ing-m ode


Set the NTP server operating mode.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ntp server operating-mode <P-1>
Parameter Value Meaning
P-1 symmetric Enable NTP server in symmetric operating mode.
client-server Enable NTP server in client-server operating mode.

2 6 .1 .5 nt p se rve r loc a lc loc k -st ra t um


Set the stratum of the localclock.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ntp server localclock-stratum <P-1>
Parameter Value Meaning
P-1 1..16 Localclock stratum.

2 6 .1 .6 nt p pe e rs a dd
Add a new peer.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ntp peers add <P-1> ip <P-2> [iburst <P-3>] [burst <P-4>] [prefer <P-5>]
ip: Set the peer address.
[iburst]: Speed up the initial synchronization (default: disabled). Used only when operating in client-unicast
mode.
[burst]: Increase the precision on links with high jitter (default: disabled). Used only in client-unicast mode.
[prefer]: If correctly operating, choose this peer as synchronization source (default: disabled).

98 RM CLI EAGLE40
Release 3.4 03/2020
Parameter Value Meaning
P-1 1..4 NTP servers index.
P-2 a.b.c.d IP address.
P-3 enable Enable the option.
disable Disable the option.
P-4 enable Enable the option.
disable Disable the option.
P-5 enable Enable the option.
disable Disable the option.

2 6 .1 .7 nt p pe e rs de le t e
Delete a peer.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ntp peers delete <P-1>
Parameter Value Meaning
P-1 1..4 NTP servers index.

2 6 .2 show
Display device options and settings.

2 6 .2 .1 show nt p c lie nt -st a t us


Status of the NTP client connection.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ntp client-status

2 6 .2 .2 show nt p se rve r-st a t us


Overall operational status of the NTP server.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ntp server-status

RM CLI EAGLE40 99
Release 3.4 03/2020
2 7 Pa cke t Filt e r

2 7 .1 pa cke t -filt e r
Creation and configuration of Firewall rules.

2 7 .1 .1 pa c k e t -filt e r l3 c om m it
Writes all changes made in the L3 firewall configuration to the device
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: packet-filter l3 commit

2 7 .1 .2 pa c k e t -filt e r l3 de fa ult polic y


Sets the default policy of the L3 and DynFw rule tables
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: packet-filter l3 defaultpolicy <P-1>
Parameter Value Meaning
P-1 accept Accept packets
drop Drop packets without notification
reject Drop packets and notify source

2 7 .1 .3 pa c k e t -filt e r l3 c he c k sum -va lida t ion


Configures the connection tracking checksum validation in Netfilter
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: packet-filter l3 checksum-validation

 no pa c k e t -filt e r l3 c he c k sum -va lida t ion


Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no packet-filter l3 checksum-validation

2 7 .1 .4 pa c k e t -filt e r l3 a ddrule
Adds a rule to the L3 firewall table
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: packet-filter l3 addrule <P-1> <P-2> <P-3> <P-4> <P-5> <P-6> <P-7> <P-8>
[description <P-9>]
[description]: Rule description/name for the L3 firewall rule
Parameter Value Meaning
P-1 1..2048 Rule index
P-2 string Source IP address/CIDR mask/'any'
P-3 string Source port/port list with comma/port range with hyphen/'any'
P-4 string Target IP address/CIDR mask/'any'
P-5 string Target port/port list with comma/port range with hyphen/'any'
P-6 icmp Internet Control Message Protocol
igmp Internet Group Management Protocol
ipip IP-within-IP Encapsulation Protocol
tcp Transmission Control Protocol
udp User Datagram Protocol
esp Encapsulating Security Protocol
ah Authentication Header
any Any of the above
P-7 string Parameters for rule (or 'none')

100 RM CLI EAGLE40


Release 3.4 03/2020
Parameter Value Meaning
P-8 accept Accept packets
drop Drop packets without notification
reject Drop packets and notify source
enforce-modbus Accept or drop packets by Modbus TCP/IP enforcer, protocol should be tcp or udp
enforce-opc Accept or drop packets by opc enforcer, protocol should be tcp
enforce-iec104 Accept or drop packets by IEC104 enforcer, protocol should be tcp
P-9 string Rule description/name

2 7 .1 .5 pa c k e t -filt e r l3 m odifyrule
Modifies a rule to the L3 firewall table
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: packet-filter l3 modifyrule <P-1> <P-2> <P-3> <P-4> <P-5> <P-6> <P-7> <P-8>
[description <P-9>]
[description]: Rule description/name for the L3 firewall rule
Parameter Value Meaning
P-1 1..2048 Rule index
P-2 string Source IP address/CIDR mask/'any'
P-3 string Source port/port list with comma/port range with hyphen/'any'
P-4 string Target IP address/CIDR mask/'any'
P-5 string Target port/port list with comma/port range with hyphen/'any'
P-6 icmp Internet Control Message Protocol
igmp Internet Group Management Protocol
ipip IP-within-IP Encapsulation Protocol
tcp Transmission Control Protocol
udp User Datagram Protocol
esp Encapsulating Security Protocol
ah Authentication Header
any Any of the above
P-7 string Parameters for rule (or 'none')
P-8 accept Accept packets
drop Drop packets without notification
reject Drop packets and notify source
enforce-modbus Accept or drop packets by Modbus TCP/IP enforcer, protocol should be tcp or udp
enforce-opc Accept or drop packets by opc enforcer, protocol should be tcp
enforce-iec104 Accept or drop packets by IEC104 enforcer, protocol should be tcp
P-9 string Rule description/name

2 7 .1 .6 pa c k e t -filt e r l3 de lrule
Deletes a rule from L3 rule table
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: packet-filter l3 delrule <P-1>
Parameter Value Meaning
P-1 1..2048 Rule index

2 7 .1 .7 pa c k e t -filt e r l3 e na ble rule


Enables a rule from L3 rule table. A rule can only be activated when all required parameters are set and at least
one interface is mapped to the rule. You cannot activate a rule if an enforcer mappings to an inactive profile.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: packet-filter l3 enablerule <P-1>
Parameter Value Meaning
P-1 1..2048 Rule index

2 7 .1 .8 pa c k e t -filt e r l3 disa ble rule


Disables a rule from L3 rule table
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: packet-filter l3 disablerule <P-1>
Parameter Value Meaning
P-1 1..2048 Rule index

RM CLI EAGLE40 101


Release 3.4 03/2020
2 7 .1 .9 pa c k e t -filt e r l3 logm ode
Set logmode for a rule from L3 rule table
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: packet-filter l3 logmode <P-1> <P-2>
Parameter Value Meaning
P-1 1..2048 Rule index
P-2 log Log when rule is applied
trap Send trap when rule is applied
logtrap Log and send trap when rule is applied
none Disable log and trap

2 7 .1 .1 0 pa c k e t -filt e r l3 a ddif
Adds an interface to a L3 firewall rule
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: packet-filter l3 addif <P-1> <P-2> <P-3> <P-4>
Parameter Value Meaning
P-1 slot no./port no.
P-2 ingress Ingress
egress Egress
P-3 1..2048 Rule index
P-4 0..4294967295 Priority

2 7 .1 .1 1 pa c k e t -filt e r l3 de lif
Deletes an interface of a L3 firewall rule
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: packet-filter l3 delif <P-1> <P-2> <P-3>
Parameter Value Meaning
P-1 slot no./port no.
P-2 ingress Ingress
egress Egress
P-3 1..2048 Rule index

2 7 .1 .1 2 pa c k e t -filt e r l3 e na ble if
Enables an interface of a L3 firewall rule
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: packet-filter l3 enableif <P-1> <P-2> <P-3>
Parameter Value Meaning
P-1 slot no./port no.
P-2 ingress Ingress
egress Egress
P-3 1..2048 Rule index

2 7 .1 .1 3 pa c k e t -filt e r l3 disa ble if


Disables an interface of a L3 firewall rule
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: packet-filter l3 disableif <P-1> <P-2> <P-3>
Parameter Value Meaning
P-1 slot no./port no.
P-2 ingress Ingress
egress Egress
P-3 1..2048 Rule index

2 7 .2 cle a r
Clear several items.

102 RM CLI EAGLE40


Release 3.4 03/2020
2 7 .2 .1 c le a r fw -st a t e -t a ble
Clear Firewall connection tracking table.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: clear fw-state-table

2 7 .3 show
Display device options and settings.

2 7 .3 .1 show pa c k e t -filt e r l3 globa l


Display the packet-filter global information and settings.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show packet-filter l3 global

2 7 .3 .2 show pa c k e t -filt e r l3 rule t a ble


Display the L3 rule table.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show packet-filter l3 ruletable

2 7 .3 .3 show pa c k e t -filt e r l3 ift a ble


Display the L3 interface mapping table.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show packet-filter l3 iftable

RM CLI EAGLE40 103


Release 3.4 03/2020
2 8 Pa ssw ord M a na ge m e nt

2 8 .1 pa ssw ords
Manage password policies and options.

2 8 .1 .1 pa ssw ords m in-le ngt h


Set minimum password length for user passwords.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: passwords min-length <P-1>
Parameter Value Meaning
P-1 1..64 Enter a number in the given range.

2 8 .1 .2 pa ssw ords m a x -login-a t t e m pt s


Set maximum login attempts for the users.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: passwords max-login-attempts <P-1>
Parameter Value Meaning
P-1 0..5 Enter a number in the given range.

2 8 .1 .3 pa ssw ords m in-uppe rc a se -c ha rs


Set minimum upper case characters for user passwords.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: passwords min-uppercase-chars <P-1>
Parameter Value Meaning
P-1 0..16 Enter a number in the given range.

2 8 .1 .4 pa ssw ords m in-low e rc a se -c ha rs


Set minimum lower case characters for user passwords.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: passwords min-lowercase-chars <P-1>
Parameter Value Meaning
P-1 0..16 Enter a number in the given range.

2 8 .1 .5 pa ssw ords m in-num e ric -c ha rs


Set minimum numeric characters for user passwords.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: passwords min-numeric-chars <P-1>
Parameter Value Meaning
P-1 0..16 Enter a number in the given range.

2 8 .1 .6 pa ssw ords m in-spe c ia l-c ha rs


Set minimum special characters for user passwords.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: passwords min-special-chars <P-1>
Parameter Value Meaning
P-1 0..16 Enter a number in the given range.

2 8 .1 .7 pa ssw ords login-a t t e m pt -pe riod


The time period [minutes] in which the number of failed authentication attempts is counted. Value 0 disables this
functionality.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: passwords login-attempt-period <P-1>

104 RM CLI EAGLE40


Release 3.4 03/2020
Parameter Value Meaning
P-1 0 Disables the counting.
1..60 Enter a number in the given range.

2 8 .2 show
Display device options and settings.

2 8 .2 .1 show pa ssw ords


Display the password policies and options.
 Mode: Command is in all modes available.
 Privilege Level: Administrator
 Format: show passwords

RM CLI EAGLE40 105


Release 3.4 03/2020
2 9 Ra dius

2 9 .1 ra dius
Configure RADIUS parameters.

2 9 .1 .1 ra dius se rve r a t t ribut e 4


Specifies the RADIUS client to use the NAS-IP Address attribute in the RADIUS requests.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: radius server attribute 4 <P-1>
Parameter Value Meaning
P-1 A.B.C.D IP address.

2 9 .1 .2 ra dius se rve r a ut h a dd
Add a RADIUS authentication server.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: radius server auth add <P-1> ip <P-2> [name <P-3>] [port <P-4>]
ip: RADIUS authentication server IP address.
[name]: RADIUS authentication server name.
[port]: RADIUS authentication server port (default: 1812).
Parameter Value Meaning
P-1 1..8 Next RADIUS server valid index (it can be seen with '#show radius global'
command).
P-2 string Hostname or IP address.
P-3 string Enter a user-defined text, max. 32 characters.
P-4 1..65535 Enter port number between 1 and 65535

2 9 .1 .3 ra dius se rve r a ut h de le t e
Delete a RADIUS authentication server.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: radius server auth delete <P-1>
Parameter Value Meaning
P-1 1..8 RADIUS server index.

2 9 .1 .4 ra dius se rve r a ut h m odify


Change a RADIUS authentication server parameters.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: radius server auth modify <P-1> [name <P-2>] [port <P-3>] [msgauth <P-4>]
[primary <P-5>] [status <P-6>] [secret [<P-7>]] [encrypted <P-8>]
[name]: RADIUS authentication server name.
[port]: RADIUS authentication server port (default: 1812).
[msgauth]: Enable or disable the message authenticator attribute for this server.
[primary]: Configure the primary RADIUS server.
[status]: Enable or disable a RADIUS authentication server entry.
[secret]: Configure the shared secret for the RADIUS authentication server.
[encrypted]: Configure the encrypted shared secret.
Parameter Value Meaning
P-1 1..8 RADIUS server index.
P-2 string Enter a user-defined text, max. 32 characters.
P-3 1..65535 Enter port number between 1 and 65535
P-4 enable Enable the option.
disable Disable the option.
P-5 enable Enable the option.
disable Disable the option.
P-6 enable Enable the option.
disable Disable the option.
P-7 string Enter a user-defined text, max. 128 characters.

106 RM CLI EAGLE40


Release 3.4 03/2020
Parameter Value Meaning
P-8 string Enter a user-defined text, max. 128 characters.

2 9 .1 .5 ra dius se rve r re t ra nsm it


Configure the retransmit value for the RADIUS server.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: radius server retransmit <P-1>
Parameter Value Meaning
P-1 1..15 Maximum number of retransmissions (default: 4).

2 9 .1 .6 ra dius se rve r t im e out


Configure the RADIUS server timeout value.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: radius server timeout <P-1>
Parameter Value Meaning
P-1 1..30 Timeout in seconds (default: 5).

2 9 .2 show
Display device options and settings.

2 9 .2 .1 show ra dius globa l


Display the global RADIUS configuration.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show radius global

2 9 .2 .2 show ra dius a ut h se rve rs


Display the configured RADIUS authentication servers.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show radius auth servers [<P-1>]
Parameter Value Meaning
P-1 1..8 RADIUS server index.

2 9 .2 .3 show ra dius a ut h st a t ist ic s


Display the RADIUS authentication server statistics.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show radius auth statistics <P-1>
Parameter Value Meaning
P-1 1..8 RADIUS server index.

2 9 .3 cle a r
Clear several items.

2 9 .3 .1 c le a r ra dius
Clear the RADIUS statistics.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: clear radius <P-1>
Parameter Value Meaning
P-1 statistics Clear the RADIUS statistics.

RM CLI EAGLE40 107


Release 3.4 03/2020
108 RM CLI EAGLE40
Release 3.4 03/2020
3 0 Re m ot e Aut he nt ic at ion

3 0 .1 lda p
Configure LDAP settings.

3 0 .1 .1 lda p ope ra t ion


Enable or disable the remote authentication operation.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ldap operation

 no lda p ope ra t ion


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no ldap operation

3 0 .1 .2 lda p c a c he -t im e out
Configure LDAP user cache entry timeout.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ldap cache-timeout <P-1>
Parameter Value Meaning
P-1 1..1440 Enter a number in the given range.

3 0 .1 .3 lda p flush-use r-c a c he


Flush LDAP user cache.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ldap flush-user-cache <P-1>
Parameter Value Meaning
P-1 action Flush the LDAP user cache.

3 0 .1 .4 lda p role -polic y


Configure LDAP user role selection policy.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ldap role-policy <P-1>
Parameter Value Meaning
P-1 highest Use the role mapping with the highest user role.
first Use the first matching role mapping table entry.

3 0 .1 .5 lda p ba se dn
Base distinguished name for LDAP query at the external AD server.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ldap basedn <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 255 characters.

3 0 .1 .6 lda p se a rc h-a t t r
Search attribute for LDAP query at the external AD server.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ldap search-attr <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 64 characters.

RM CLI EAGLE40 109


Release 3.4 03/2020
3 0 .1 .7 lda p bind-use r
Bind-account user name for LDAP query at the external AD server.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ldap bind-user <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 255 characters.

3 0 .1 .8 lda p bind-pa ssw d


Bind-account user password for LDAP query at the external AD server.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ldap bind-passwd <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 64 characters.

3 0 .1 .9 lda p de fa ult -dom a in


Default domain used for users without a domain name.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ldap default-domain <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 64 characters.

3 0 .1 .1 0 lda p c lie nt se rve r a dd


Add a LDAP client server connection.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ldap client server add <P-1> <P-2> [port <P-3>] [security <P-4>]
[description <P-5>]
[port]: Set the port number of the external LDAP server.
[security]: Set the security settings for the connection to external LDAP server.
[description]: Description of the external LDAP server.
Parameter Value Meaning
P-1 1..4 Enter a number in the given range.
P-2 a.b.c.d IP address.
P-3 1..65535 Port number of LDAP Server.
P-4 none
ssl
startTLS
P-5 string Enter a user-defined text, max. 100 characters.

3 0 .1 .1 1 lda p c lie nt se rve r de le t e


Delete a LDAP client server connection.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ldap client server delete <P-1>
Parameter Value Meaning
P-1 1..4 Enter a number in the given range.

3 0 .1 .1 2 lda p c lie nt se rve r e na ble


Enable a LDAP client server connection.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ldap client server enable <P-1>
Parameter Value Meaning
P-1 1..4 Enter a number in the given range.

3 0 .1 .1 3 lda p c lie nt se rve r disa ble


Disable a LDAP client server connection.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ldap client server disable <P-1>

110 RM CLI EAGLE40


Release 3.4 03/2020
Parameter Value Meaning
P-1 1..4 Enter a number in the given range.

3 0 .1 .1 4 lda p c lie nt se rve r m odify


Modify a LDAP client server connection.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ldap client server modify <P-1> [addr <P-2>] [port <P-3>] [security <P-4>]
[description <P-5>]
[addr]: Modify the host address of the external LDAP server.
[port]: Modify the port number of the external LDAP server.
[security]: Modify the security settings for the connection to external LDAP server.
[description]: Modify the description of the external LDAP server.
Parameter Value Meaning
P-1 1..4 Enter a number in the given range.
P-2 a.b.c.d IP address.
P-3 1..65535 Port number of LDAP Server.
P-4 none
ssl
startTLS
P-5 string Enter a user-defined text, max. 100 characters.

3 0 .1 .1 5 lda p m a pping a dd
Add a LDAP mapping entry.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ldap mapping add <P-1> access-role <P-2> mapping-type <P-3> mapping-
parameter <P-4>
access-role: Access role type.
mapping-type: Role mapping type.
mapping-parameter: Role mapping parameter.
Parameter Value Meaning
P-1 1..64 Enter a number in the given range.
P-2 slot no./port no.
P-3 attribute
group
P-4 string Enter a user-defined text, max. 255 characters.

3 0 .1 .1 6 lda p m a pping de le t e
Delete a LDAP role mapping entry.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ldap mapping delete <P-1>
Parameter Value Meaning
P-1 1..64 Enter a number in the given range.

3 0 .1 .1 7 lda p m a pping e na ble


Activate a LDAP role mapping entry.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ldap mapping enable <P-1>
Parameter Value Meaning
P-1 1..64 Enter a number in the given range.

3 0 .1 .1 8 lda p m a pping disa ble


Deactivate a LDAP role mapping entry.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ldap mapping disable <P-1>
Parameter Value Meaning
P-1 1..64 Enter a number in the given range.

RM CLI EAGLE40 111


Release 3.4 03/2020
3 0 .2 show
Display device options and settings.

3 0 .2 .1 show lda p globa l


Display the LDAP configuration parameters and information.
 Mode: Command is in all modes available.
 Privilege Level: Administrator
 Format: show ldap global

3 0 .2 .2 show lda p c lie nt se rve r


Display the LDAP client server connections.
 Mode: Command is in all modes available.
 Privilege Level: Administrator
 Format: show ldap client server [<P-1>]
Parameter Value Meaning
P-1 1..4 Enter a number in the given range.

3 0 .2 .3 show lda p m a pping


Display the LDAP role mapping entries.
 Mode: Command is in all modes available.
 Privilege Level: Administrator
 Format: show ldap mapping [<P-1>]
Parameter Value Meaning
P-1 1..64 Enter a number in the given range.

3 0 .3 c opy
Copy different kinds of items.

3 0 .3 .1 c opy lda pc a c e rt re m ot e
Copy CA certificate file (*.pem) from the remote AD server to the specified destination.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: copy ldapcacert remote <P-1> nvm [<P-2>]
nvm: Copy CA certificate file (*.pem) from the remote AD server to the device.
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 128 characters.
P-2 string Enter a user-defined text, max. 100 characters.

3 0 .3 .2 c opy lda pc a c e rt e nvm


Copy CA certificate file (*.pem) from external non-volatile memory to the specified destination.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: copy ldapcacert envm <P-1> nvm [<P-2>]
nvm: Copy CA certificate file (*.pem) from external non-volatile memory to the device.
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 128 characters.
P-2 string Enter a user-defined text, max. 100 characters.

112 RM CLI EAGLE40


Release 3.4 03/2020
3 1 Re m ot e M onit oring (RM ON )

3 1 .1 show
Display device options and settings.

3 1 .1 .1 show rm on st a t ist ic s
Show RMON statistics configuration.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show rmon statistics [<P-1>]
Parameter Value Meaning
P-1 slot no./port
no.

RM CLI EAGLE40 113


Release 3.4 03/2020
3 2 Sc ript File

3 2 .1 sc ript
CLI Script File.

3 2 .1 .1 sc ript a pply
Executes the CLI script file available in the device.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: script apply <P-1>
Parameter Value Meaning
P-1 string Filename.

3 2 .1 .2 sc ript va lida t e
Only validates the CLI script file available in the device.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: script validate <P-1>
Parameter Value Meaning
P-1 string Filename.

3 2 .1 .3 sc ript list syst e m


List all the script files available in the device memory.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: script list system

3 2 .1 .4 sc ript list e nvm


List all the script files available in external non-volatile memory.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: script list envm

3 2 .1 .5 sc ript de le t e
Delete the CLI script files.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: script delete [<P-1>]
Parameter Value Meaning
P-1 string Filename.

3 2 .2 c opy
Copy different kinds of items.

3 2 .2 .1 c opy sc ript e nvm


Copy script file from external non-volatile memory to specified destination.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: copy script envm <P-1> running-config nvm <P-2>
running-config: Copy script file from external non-volatile memory to the running-config.
nvm: Copy script file from external non-volatile memory to the non-volatile memory.
Parameter Value Meaning
P-1 string Filename.
P-2 string Enter a user-defined text, max. 32 characters.

114 RM CLI EAGLE40


Release 3.4 03/2020
3 2 .2 .2 c opy sc ript re m ot e
Copy script file from server to specified destination.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: copy script remote <P-1> running-config nvm <P-2>
running-config: Copy script file from file server to running-config.
nvm: Copy script file to non-volatile memory.
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 128 characters.
P-2 string Enter a user-defined text, max. 32 characters.

3 2 .2 .3 c opy sc ript nvm


Copy Script file from non-volatile memory to the specified destination.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: copy script nvm <P-1> running-config envm <P-2> remote <P-3>
running-config: Copy Script file from non-volatile system memory to running-config.
envm: Copy Script file to external non-volatile memory device.
remote: Copy Script file to file server.
Parameter Value Meaning
P-1 string Filename.
P-2 string Enter a user-defined text, max. 32 characters.
P-3 string Enter a user-defined text, max. 128 characters.

3 2 .3 show
Display device options and settings.

3 2 .3 .1 show sc ript e nvm


Display the content of the CLI script file present in the envm.
 Mode: Command is in all modes available.
 Privilege Level: Administrator
 Format: show script envm <P-1>
Parameter Value Meaning
P-1 string Filename.

3 2 .3 .2 show sc ript syst e m


Display the content of the CLI script file present in the device.
 Mode: Command is in all modes available.
 Privilege Level: Administrator
 Format: show script system <P-1>
Parameter Value Meaning
P-1 string Filename.

RM CLI EAGLE40 115


Release 3.4 03/2020
3 3 Se lft e st

3 3 .1 se lft e st
Configure the selftest settings.

3 3 .1 .1 se lft e st a c t ion
Configure the action that a selftest component should take.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: selftest action <P-1> <P-2>
Parameter Value Meaning
P-1 task Configure the action for task errors.
resource Configure the action for lack of resources.
software Configure the action for broken software integrity.
hardware Configure the action for detected hardware errors.
P-2 log-only Write a message to the logging file.
send-trap Send a trap to the management station.
reboot Reboot the device.

3 3 .1 .2 se lft e st ra m t e st
Enable or disable the RAM selftest on cold start of the device. When disabled the device booting time is reduced.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: selftest ramtest

 no se lft e st ra m t e st
Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no selftest ramtest

3 3 .1 .3 se lft e st syst e m -m onit or


Enable or disable the System Monitor 1 access during the boot phase. Please note: If the System Monitor is
disabled it is possible to loose access to the device permanently in case of loosing administrator password or mis-
configuration.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: selftest system-monitor

 no se lft e st syst e m -m onit or


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no selftest system-monitor

3 3 .1 .4 se lft e st boot -de fa ult -on-e rror


Enable or disable loading of the default configuration in case there is any error loading the configuration during
boot phase. If disabled the system will be halted.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: selftest boot-default-on-error

 no se lft e st boot -de fa ult -on-e rror


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no selftest boot-default-on-error

116 RM CLI EAGLE40


Release 3.4 03/2020
3 3 .2 show
Display device options and settings.

3 3 .2 .1 show se lft e st a c t ion


Display the actions the device takes if an error occurs.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show selftest action

3 3 .2 .2 show se lft e st se t t ings


Display the selftest settings.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show selftest settings

RM CLI EAGLE40 117


Release 3.4 03/2020
3 4 Sm a ll For m -fa c t or Plugga ble (SFP)

3 4 .1 show
Display device options and settings.

3 4 .1 .1 show sfp
Show info about plugged in SFP modules.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show sfp [<P-1>]
Parameter Value Meaning
P-1 slot no./port no.

118 RM CLI EAGLE40


Release 3.4 03/2020
3 5 Signa l Cont a c t

3 5 .1 signa l-c ont a c t


Configure the signal contact settings.

3 5 .1 .1 signa l-c ont a c t m ode


Configure the Signal Contact mode setting.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: signal-contact <P-1> mode <P-2>
Parameter Value Meaning
P-1 signal contact no.
P-2 manual The signal contact's status is determined by the associated manual setting
(subcommand 'state').
monitor The signal contact's status is determined by the associated monitor settings.
device-status The signal contact's status is determined by the device status.
security-status The signal contact's status is determined by the security status.
dev-sec-status The signal contact's status is determined by the device status and security
status.

3 5 .1 .2 signa l-c ont a c t m onit or link -fa ilure


Sets the monitoring of the network connection(s).
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: signal-contact <P-1> monitor link-failure
Parameter Value Meaning
P-1 signal contact no.

 no signa l-c ont a c t m onit or link -fa ilure


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no signal-contact <P-1> monitor link-failure

3 5 .1 .3 signa l-c ont a c t m onit or e nvm -not -in-sync


Sets the monitoring whether the external non-volatile memory device is in sync with the running configuration.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: signal-contact <P-1> monitor envm-not-in-sync
Parameter Value Meaning
P-1 signal contact no.

 no signa l-c ont a c t m onit or e nvm -not -in-sync


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no signal-contact <P-1> monitor envm-not-in-sync

3 5 .1 .4 signa l-c ont a c t m onit or e nvm -re m ova l


Sets the monitoring of the external non-volatile memory device removal.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: signal-contact <P-1> monitor envm-removal
Parameter Value Meaning
P-1 signal contact no.

RM CLI EAGLE40 119


Release 3.4 03/2020
 no signa l-c ont a c t m onit or e nvm -re m ova l
Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no signal-contact <P-1> monitor envm-removal

3 5 .1 .5 signa l-c ont a c t m onit or t e m pe ra t ure


Sets the monitoring of the device temperature.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: signal-contact <P-1> monitor temperature
Parameter Value Meaning
P-1 signal contact no.

 no signa l-c ont a c t m onit or t e m pe ra t ure


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no signal-contact <P-1> monitor temperature

3 5 .1 .6 signa l-c ont a c t m onit or pow e r-supply


Sets the monitoring of the power supply(s).
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: signal-contact <P-1> monitor power-supply <P-2>
Parameter Value Meaning
P-1 signal contact no.
P-2 1..2 Number of power supply.

 no signa l-c ont a c t m onit or pow e r-supply


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no signal-contact <P-1> monitor power-supply <P-2>

3 5 .1 .7 signa l-c ont a c t st a t e


Configure the Signal Contact manual state (only takes immediate effect in manual mode).
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: signal-contact <P-1> state <P-2>
Parameter Value Meaning
P-1 signal contact no.
P-2 open Open the signal contact (only takes effect in the manual mode).
close Close the signal contact (only takes effect in the manual mode).

3 5 .1 .8 signa l-c ont a c t t ra p


Configure if a trap is sent when the Signal Contact changes state (in monitor mode).
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: signal-contact <P-1> trap
Parameter Value Meaning
P-1 signal contact no.

 no signa l-c ont a c t t ra p


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no signal-contact <P-1> trap

120 RM CLI EAGLE40


Release 3.4 03/2020
3 5 .2 signa l-c ont a c t
Configure the signal contact interface settings.

3 5 .2 .1 signa l-c ont a c t link -a la rm


Configure the monitoring of the specific network ports.
 Mode: Interface Range Mode
 Privilege Level: Administrator
 Format: signal-contact <P-1> link-alarm
Parameter Value Meaning
P-1 signal contact no.

 no signa l-c ont a c t link -a la rm


Disable the option
 Mode: Interface Range Mode
 Privilege Level: Administrator
 Format: no signal-contact <P-1> link-alarm

3 5 .3 show
Display device options and settings.

3 5 .3 .1 show signa l-c ont a c t


Display the signal contact settings.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show signal-contact <P-1> mode monitor state trap link-alarm events all
mode: Display the signal contact mode.
monitor: Display the signal contact monitor settings.
state: Display the signal contact state (open/close).
Note: This covers the signal contact`s administrative setting as well as its actual state.
trap: Display the signal contact trap information and settings.
link-alarm: Display the settings of the monitoring of the specific network ports.
events: Display the occurred device status events.
all: Display the signal contact settings for the specified signal contact.
Parameter Value Meaning
P-1 signal contact no.

RM CLI EAGLE40 121


Release 3.4 03/2020
3 6 Sim ple N e t w ork M a na ge m e nt Prot oc ol (SN M P)

3 6 .1 snm p
Configure of SNMP versions and traps.

3 6 .1 .1 snm p a c c e ss ve rsion v1
Enable or disable SNMP version V1.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: snmp access version v1

 no snm p a c c e ss ve rsion v1
Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no snmp access version v1

3 6 .1 .2 snm p a c c e ss ve rsion v2
Enable or disable SNMP version V2.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: snmp access version v2

 no snm p a c c e ss ve rsion v2
Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no snmp access version v2

3 6 .1 .3 snm p a c c e ss ve rsion v3
Enable or disable SNMP version V3.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: snmp access version v3

 no snm p a c c e ss ve rsion v3
Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no snmp access version v3

3 6 .1 .4 snm p a c c e ss port
Configure the SNMP access port.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: snmp access port <P-1>
Parameter Value Meaning
P-1 1..65535 Port number of the SNMP server (default: 161).

3 6 .2 show
Display device options and settings.

122 RM CLI EAGLE40


Release 3.4 03/2020
3 6 .2 .1 show snm p a c c e ss
Display the SNMP access configuration settings.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show snmp access

RM CLI EAGLE40 123


Release 3.4 03/2020
3 7 SN M P Com m unit y

3 7 .1 snm p
Configure of SNMP versions and traps.

3 7 .1 .1 snm p c om m unit y ro
SNMP v1/v2 read-only community.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: snmp community ro

3 7 .1 .2 snm p c om m unit y rw
SNMP v1/v2 read-write community.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: snmp community rw

3 7 .2 show
Display device options and settings.

3 7 .2 .1 show snm p c om m unit y


Display the SNMP v1/2 community.
 Mode: Command is in all modes available.
 Privilege Level: Administrator
 Format: show snmp community

124 RM CLI EAGLE40


Release 3.4 03/2020
3 8 SN M P Logging

3 8 .1 logging
Logging configuration.

3 8 .1 .1 logging snm p-re que st ge t ope ra t ion


Enable or disable logging of SNMP GET or SET requests.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: logging snmp-request get operation <P-1>
Parameter Value Meaning
P-1 enable Enable logging of SNMP GET or SET requests.
disable Disable logging of SNMP GET or SET requests.

 no logging snm p-re que st ge t ope ra t ion


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no logging snmp-request get operation <P-1>

3 8 .1 .2 logging snm p-re que st ge t se ve rit y


Define severity level.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: logging snmp-request get severity <P-1>
Parameter Value Meaning
P-1 emergency System is unusable. System failure has occurred.
alert Action must be taken immediately. Unrecoverable failure of a component. System
failure likely.
critical Recoverable failure of a component that may lead to system failure.
error Error conditions. Recoverable failure of a component.
warning Minor failure, e.g. misconfiguration of a component.
notice Normal but significant conditions.
informational Informational messages.
debug Debug-level messages.
0 Same as emergency
1 Same as alert
2 Same as critical
3 Same as error
4 Same as warning
5 Same as notice
6 Same as informational
7 Same as debug

3 8 .1 .3 logging snm p-re que st se t ope ra t ion


Enable or disable logging of SNMP GET or SET requests.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: logging snmp-request set operation <P-1>
Parameter Value Meaning
P-1 enable Enable logging of SNMP GET or SET requests.
disable Disable logging of SNMP GET or SET requests.

 no logging snm p-re que st se t ope ra t ion


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no logging snmp-request set operation <P-1>

RM CLI EAGLE40 125


Release 3.4 03/2020
3 8 .1 .4 logging snm p-re que st se t se ve rit y
Define severity level.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: logging snmp-request set severity <P-1>
Parameter Value Meaning
P-1 emergency System is unusable. System failure has occurred.
alert Action must be taken immediately. Unrecoverable failure of a component. System
failure likely.
critical Recoverable failure of a component that may lead to system failure.
error Error conditions. Recoverable failure of a component.
warning Minor failure, e.g. misconfiguration of a component.
notice Normal but significant conditions.
informational Informational messages.
debug Debug-level messages.
0 Same as emergency
1 Same as alert
2 Same as critical
3 Same as error
4 Same as warning
5 Same as notice
6 Same as informational
7 Same as debug

3 8 .2 show
Display device options and settings.

3 8 .2 .1 show logging snm p


Display the SNMP logging settings.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show logging snmp

126 RM CLI EAGLE40


Release 3.4 03/2020
3 9 Se c ure She ll (SSH )

3 9 .1 ssh
Set SSH parameters.

3 9 .1 .1 ssh se rve r
Enable or disable the SSH server.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ssh server

 no ssh se rve r
Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no ssh server

3 9 .1 .2 ssh t im e out
Set the SSH connection idle timeout in minutes (default: 5).
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ssh timeout <P-1>
Parameter Value Meaning
P-1 0..160 Idle timeout of a session in minutes (default: 5).

3 9 .1 .3 ssh port
Set the SSH server port number (default: 22).
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ssh port <P-1>
Parameter Value Meaning
P-1 1..65535 Port number of the SSH server (default: 22).

3 9 .1 .4 ssh m a x -se ssions


Set the maximum number of concurrent SSH sessions (default: 5).
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ssh max-sessions <P-1>
Parameter Value Meaning
P-1 1..5 Maximum number of concurrent SSH sessions.

3 9 .1 .5 ssh k e y rsa
Generate or delete RSA key
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ssh key rsa <P-1>
Parameter Value Meaning
P-1 generate Generates the item
delete Deletes the item

3 9 .1 .6 ssh k e y finge rprint -t ype


Configure fingerprint type
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ssh key fingerprint-type <P-1>
Parameter Value Meaning
P-1 md5 Configure md5 fingerprint of the existing SSH host key
sha256 Configure sha256 fingerprint of the existing SSH host key.

RM CLI EAGLE40 127


Release 3.4 03/2020
3 9 .2 c opy
Copy different kinds of items.

3 9 .2 .1 c opy sshk e y re m ot e
Copy the SSH key from a server to the specified destination.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: copy sshkey remote <P-1> nvm
nvm: Copy the SSH key from a server to non-volatile memory.
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 128 characters.

3 9 .2 .2 c opy sshk e y e nvm


Copy the SSH key from external non-volatile memory to the specified destination.
 Mode: Privileged Exec Mode
 Privilege Level: Administrator
 Format: copy sshkey envm <P-1> nvm
nvm: Copy the SSH key from external non-volatile memory to non-volatile memory.
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 128 characters.

3 9 .3 show
Display device options and settings.

3 9 .3 .1 show ssh
Display the SSH server and client information.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ssh

128 RM CLI EAGLE40


Release 3.4 03/2020
4 0 Syst e m

4 0 .1 syst e m
Set system related values e.g. name of the device, location of the device, contact data for the person responsible
for the device, and pre-login banner text.

4 0 .1 .1 syst e m na m e
Edit the name of the device. The system name consists of an alphanumeric ASCII character string with 0..255
characters.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: system name <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 255 characters.

4 0 .1 .2 syst e m loc a t ion


Edit the location of the device. The system location consists of an alphanumeric ASCII character string with 0..255
characters.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: system location <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 255 characters.

4 0 .1 .3 syst e m c ont a c t
Edit the contact information for the person responsible for the device. The contact data consists of an
alphanumeric ASCII character string with 0..255 characters.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: system contact <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 255 characters.

4 0 .1 .4 syst e m pre -login-ba nne r ope ra t ion


Enable or disable the pre-login banner. You use the pre-login banner to display a greeting or information to users
before they login to the device.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: system pre-login-banner operation

 no syst e m pre -login-ba nne r ope ra t ion


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no system pre-login-banner operation

4 0 .1 .5 syst e m pre -login-ba nne r t e x t


Edit the text for the pre-login banner (C printf format syntax allowed: ) The device allows you to edit an
alphanumeric ASCII character string with up to 512 characters.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: system pre-login-banner text <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 512 characters (allowed characters are from
ASCII 32 to 127).

RM CLI EAGLE40 129


Release 3.4 03/2020
4 0 .1 .6 syst e m re sourc e s ope ra t ion
Enable or disable the measurement operation.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: system resources operation

 no syst e m re sourc e s ope ra t ion


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no system resources operation

4 0 .2 t e m pe rat ure
Configure the upper and lower temperature limits of the device. The device allows you to set the threshold as an
integer from -99 through 99. You configure the temperatures in degrees Celsius.

4 0 .2 .1 t e m pe ra t ure uppe r-lim it


Configure the upper temperature limit.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: temperature upper-limit <P-1>
Parameter Value Meaning
P-1 -99..99 Upper temperature threshold ([C], default 70).

4 0 .2 .2 t e m pe ra t ure low e r-lim it


Configure the lower temperature limit.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: system location <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 255 characters.

4 0 .3 show
Display device options and settings.

4 0 .3 .1 show e ve nt log
Display the event log notice and warning entries with time stamp.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show eventlog

4 0 .3 .2 show syst e m info


Display the system related information.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show system info

4 0 .3 .3 show syst e m pre -login-ba nne r


Display the pre-login banner status and text.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show system pre-login-banner

130 RM CLI EAGLE40


Release 3.4 03/2020
4 0 .3 .4 show syst e m fla sh-st a t us
Display the flash memory statistics of the device.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show system flash-status

4 0 .3 .5 show syst e m re sourc e s


Display the system resources information (CPU utilization, memory and network CPU utilization).
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show system resources

RM CLI EAGLE40 131


Release 3.4 03/2020
4 1 Tra ps

4 1 .1 snm p
Configure of SNMP versions and traps.

4 1 .1 .1 snm p t ra p ope ra t ion


Global enable/disable SNMP trap.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: snmp trap operation

 no snm p t ra p ope ra t ion


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no snmp trap operation

4 1 .1 .2 snm p t ra p m ode
Enable/disable SNMP trap entry.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: snmp trap mode <P-1>
Parameter Value Meaning
P-1 string <name> Trap name (1 to 32 characters)

 no snm p t ra p m ode
Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no snmp trap mode <P-1>

4 1 .1 .3 snm p t ra p de le t e
Delete SNMP trap entry.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: snmp trap delete <P-1>
Parameter Value Meaning
P-1 string <name> Trap name (1 to 32 characters)

4 1 .1 .4 snm p t ra p a dd
Add SNMP trap entry.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: snmp trap add <P-1> <P-2>
Parameter Value Meaning
P-1 string <name> Trap name (1 to 32 characters)
P-2 a.b.c.d a.b.c.d Single IP address.
a.b.c.d:n a.b.c.d:n Address with port.

4 1 .2 show
Display device options and settings.

132 RM CLI EAGLE40


Release 3.4 03/2020
4 1 .2 .1 show snm p t ra ps
Display the SNMP traps.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show snmp traps

RM CLI EAGLE40 133


Release 3.4 03/2020
4 2 U nic a st Rout ing

4 2 .1 rout ing
Create routing on VLAN.

4 2 .1 .1 rout ing a dd
Enable routing on VLAN.
 Mode: VLAN Database Mode
 Privilege Level: Operator
 Format: routing add <P-1>
Parameter Value Meaning
P-1 1.4042 Enter the VLAN ID.

4 2 .1 .2 rout ing de le t e
Disable routing on VLAN.
 Mode: VLAN Database Mode
 Privilege Level: Operator
 Format: routing delete <P-1>
Parameter Value Meaning
P-1 1.4042 Enter the VLAN ID.

4 2 .2 ip
Set IP parameters.

4 2 .2 .1 ip rout ing
Enables or disables Routing globally on the device.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip routing

 no ip rout ing
Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no ip routing

4 2 .2 .2 ip prox y-a rp m a x -de la y


Configure the maximum time a Proxy ARP response can be delayed.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip proxy-arp max-delay <P-1>
Parameter Value Meaning
P-1 0..1000 Enter Proxy ARP max response delay ms

4 2 .3 show
Display device options and settings.

134 RM CLI EAGLE40


Release 3.4 03/2020
4 2 .3 .1 show ip globa l
Displays all the summary information of the IP, including the ICMP rate limit configuration and the global ICMP
Redirect configuration.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip global

4 2 .4 show
Display device options and settings.

4 2 .4 .1 show ip int e rfa c e


Show interface parameters.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip interface <P-1>
Parameter Value Meaning
P-1 slot no./port no.

4 2 .4 .2 show ip st a t ist ic s
Show global IP statistics.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip statistics

4 2 .5 ip
IP interface commands.

4 2 .5 .1 ip prox y-a rp ope ra t ion


Enables or disables Proxy ARP on the interface.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip proxy-arp operation

 no ip prox y-a rp ope ra t ion


Disable the option
 Mode: Interface Config Mode
 Privilege Level: Operator
 Format: no ip proxy-arp operation

4 2 .5 .2 ip a ddre ss se c onda ry
Designates whether an IP Address is a secondary address on this interface.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip address secondary <P-1> <P-2>
Parameter Value Meaning
P-1 A.B.C.D IP address.
P-2 a.b.c.d IP subnet mask.

 no ip a ddre ss se c onda ry
Disable the option
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: no ip address secondary <P-1>

RM CLI EAGLE40 135


Release 3.4 03/2020
4 2 .5 .3 ip a ddre ss prim a ry
Designates whether an IP Address is a primary address on this interface.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip proxy-arp operation
Parameter Value Meaning
P-1 A.B.C.D IP address.
P-2 a.b.c.d IP subnet mask.

 no ip a ddre ss prim a ry
Disable the option
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: no ip address primary

4 2 .5 .4 ip m t u
Set MTU size for IP protocol.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip mtu <P-1>
Parameter Value Meaning
P-1 68..12266 value for MTU that could be between 68 and 12266.

4 2 .5 .5 ip ic m p re dire c t s
Enables or disables the generation of ICMP Redirect messages.
 Mode: Interface Range Mode
 Privilege Level: Operator
 Format: ip icmp interface

4 2 .6 ip
Set IP parameters.

4 2 .6 .1 ip rout e a dd
Add a static route entry.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip route add <P-1> <P-2> <P-3> [preference <P-4>]
[preference]: Change the preference value of a [Link] ip entry <P-1>
Parameter Value Meaning
P-1 A.B.C.D IP address.
P-2 A.B.C.D IP address.
P-3 A.B.C.D IP address.
P-4 1..255 Enter a number in the given range.

4 2 .6 .2 ip rout e m odify
Modify a static route entry.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip route modify <P-1> <P-2> <P-3> [preference <P-4>] [preference]: Change the
preference value of a route.
Parameter Value Meaning
P-1 A.B.C.D IP address.
P-2 A.B.C.D IP address.
P-3 A.B.C.D IP address.
P-4 1..255 Enter a number in the given range.

136 RM CLI EAGLE40


Release 3.4 03/2020
4 2 .6 .3 ip rout e de le t e
Delete a static route entry.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip route delete <P-1> <P-2> <P-3>
Parameter Value Meaning
P-1 A.B.C.D IP address.
P-2 A.B.C.D IP address.
P-3 A.B.C.D IP address.

4 2 .6 .4 ip rout e dist a nc e
Default preference for static routes.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip route delete <P-1>
Parameter Value Meaning
P-1 1..255 Enter a number in the given range.

4 2 .6 .5 ip rout e t ra c k a dd
Default preference for static routes.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip route track add <P-1> <P-2> <P-3> <P-4>
Parameter Value Meaning
P-1 A.B.C.D IP address.
P-2 A.B.C.D IP address.
P-3 A.B.C.D IP address.
P-4 string Track instance.

4 2 .6 .6 ip rout e t ra c k de le t e
Remove a track-id for a static route entry.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip route track delete <P-1> <P-2> <P-3> <P-4>
Parameter Value Meaning
P-1 A.B.C.D IP address.
P-2 A.B.C.D IP address.
P-3 A.B.C.D IP address.

4 2 .6 .7 ip de fa ult -rout e a dd
Add a static default route entry.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip default-route add <P-1> [preference <P-2>]
[preference]: Change the preference value of a route.
Parameter Value Meaning
P-1 A.B.C.D IP address.
P-2 1..255 Enter a number in the given range.

4 2 .6 .8 ip de fa ult -rout e m odify


Modify a static default route entry.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip default-route modify <P-1> [preference <P-2>]
[preference]: Change the preference value of a route.
Parameter Value Meaning
P-1 A.B.C.D IP address.
P-2 1..255 Enter a number in the given range.

RM CLI EAGLE40 137


Release 3.4 03/2020
4 2 .6 .9 ip de fa ult -rout e de le t e
Delete a static default route entry.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip default-route delete <P-1>
Parameter Value Meaning
P-1 A.B.C.D IP address.

4 2 .6 .1 0 ip loopba c k a dd
Enable a loopback interface.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip loopback add <P-1>
Parameter Value Meaning
P-1 1..8 Enter the loopback id in the given range.

4 2 .6 .1 1 ip loopba c k de le t e
Disable a loopback interface.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip loopback delete <P-1>
Parameter Value Meaning
P-1 1..8 Enter the loopback id in the given range.

4 2 .6 .1 2 ip ic m p re dire c t s
Enables or disables the generation of ICMP Redirect messages.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip icmp redirects

 no ip ic m p re dire c t s
Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no ip icmp redirects

4 2 .6 .1 3 ip ic m p e c ho-re ply
Enables or disables the generation of ICMP Echo Reply messages.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip icmp echo-reply

 no ip ic m p e c ho-re ply
Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no ip icmp echo-reply

4 2 .6 .1 4 ip ic m p ra t e -lim it int e rva l


Configure ICMP rate limit interval in milliseconds.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip icmp rate-limit interval <P-1>
Parameter Value Meaning
P-1 0..2147483647 Configure the interval.

4 2 .6 .1 5 ip ic m p ra t e -lim it burst -size


Configure ICMP rate limit burst size.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: ip icmp rate-limit burst-size <P-1>

138 RM CLI EAGLE40


Release 3.4 03/2020
Parameter Value Meaning
P-1 1..200 Configure the burst-size.

4 2 .7 show
Display device options and settings.

4 2 .7 .1 show ip rout e a ll
Display static, dynamic and local routes.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip route all

4 2 .7 .2 show ip rout e loc a l


Display the local routes.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip route local

4 2 .7 .3 show ip rout e st a t ic
Display the static routes.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ip route static

4 2 .7 .4 show ip rout e e nt ry
Display router route entry information.
 Mode: Global Config Mode
 Privilege Level: Guest
 Format: show ip route entry <P-1> <P-2>
Parameter Value Meaning
P-1 A.B.C.D IP address.
P-2 A.B.C.D IP address.

4 2 .7 .5 show ip rout e t ra c k ing


Display tracking information for static routes.
 Mode: Global Config Mode
 Privilege Level: Guest
 Format: show ip route tracking

RM CLI EAGLE40 139


Release 3.4 03/2020
4 3 Tra ck ing

4 3 .1 t ra ck
Configure tracking instances on the device.

4 3 .1 .1 t ra c k a dd
Create a tracking instance.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: track add <P-1> <P-2>
Parameter Value Meaning
P-1 interface interface tracking
ping ping tracking
logical logical tracking
P-2 1..256 Enter a number in the given range.

4 3 .1 .2 t ra c k de le t e
Delete a tracking instance.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: track delete <P-1> <P-2>
Parameter Value Meaning
P-1 interface interface tracking
ping ping tracking
logical logical tracking
P-2 1..256 Enter a number in the given range.

4 3 .1 .3 t ra c k e na ble
Activate a tracking instance.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: track enable <P-1> <P-2>
Parameter Value Meaning
P-1 interface interface tracking
ping ping tracking
logical logical tracking
P-2 1..256 Enter a number in the given range.

4 3 .1 .4 t ra c k disa ble
Deactivate a tracking instance.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: track disable <P-1> <P-2>
Parameter Value Meaning
P-1 interface interface tracking
ping ping tracking
logical logical tracking
P-2 1..256 Enter a number in the given range.

4 3 .1 .5 t ra c k t ra p
Enable/Disable the StateChange trap for the corresponding tracking instance.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: users password <P-1> [<P-2>]
Parameter Value Meaning
P-1 interface interface tracking
ping ping tracking
logical logical tracking
P-2 1..256 Enter a number in the given range.

140 RM CLI EAGLE40


Release 3.4 03/2020
 no t ra c k t ra p
Disable the option
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: no track trap <P-1> <P-2>

4 3 .1 .6 t ra c k de sc ript ion
Set the description for the corresponding tracking instance.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: track description <P-1> <P-2> <P-3>
Parameter Value Meaning
P-1 interface interface tracking
ping ping tracking
logical logical tracking
P-2 1..256 Enter a number in the given range.
p-3 string Enter a user-defined text, max. 255 characters.

4 3 .1 .7 t ra c k m odify int e rfa c e


Modify the configuration of an interface tracking instance.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: track modify interface <P-1> [interface <P-2>][linkup-delay <P-3>]
[linkdown-delay <P-4>]
[interface <P-2>]: Set the interface number of the interface tracking instance.
[linkup-delay <P-3>]: Set the linkup-delay of the interface tracking instance
[linkdown-delay <P-4>]: Set the linkdown-delay of the interface tracking
instance
Parameter Value Meaning
P-1 slot no./port
no.
P-2 slot no./port
no.
p-3 0..255 Enter a number in the given range.
P-4 0..255 Enter a number in the given range.

4 3 .1 .8 t ra c k m odify ping
Modify the configuration of a ping tracking instance.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: track modify ping <P-1> <P-2> [interface <P-2>][address <P-3>]
[interval <P-4>] [miss <P-5>] [success <P-6>] [timeout <P-7>] [ttl <P-8>]
[interface]: Set the source interface number of the ping tracking instance.
[address]: Set the address of the router to be monitored.
[interval]: Set the number of milliseconds between the pings to the target router address.
[miss]: Set the number of consecutive ping misses until the tracked object is considered to be down.
[success]: Set the of consecutive ping successes until the tracked object is considered to be up.
[timeout]: Set the timeout in milliseconds for a ping reply.
[ttl]: Set the time to live for a ping request packet.
Parameter Value Meaning
P-1 slot no./port no.
P-2 slot no./port no.
P-3 a.b.c.d IP address.
P-4 100..20000 value for ping tracking interval range between 100 and 20000.
P-5 1..10 value for ping tracking interval range between 1 and 10.
P-6 1..10 value for ping tracking range between 1 and 10.
P-7 10..10000 value for ping tracking time range between 10 and 10000.
P-8 1..255 Enter a number in the given range.

4 3 .1 .9 t ra c k m odify logic a l
Modify the configuration of a logical tracking instance.
 Mode: Global Config Mode
 Privilege Level: Operator
 Format: track modify logical <P-1> <P-2> <P-3> <P-4>

RM CLI EAGLE40 141


Release 3.4 03/2020
Parameter Value Meaning
P-1 slot no./port no.
P-2 string Track instance.
P-3 and AND operator.
ir OR operator.
P-4 string Track instance.

4 3 .2 show
Display device options and settings.

4 3 .2 .1 show t ra c k ove rvie w


Display information and settings for tracking instances.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show track overview

4 3 .2 .2 show t ra c k int e rfa c e


Display information and settings for interface tracking instances.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show track interface [<P-1>]
Parameter Value Meaning
P-1 slot no./port no.

4 3 .2 .3 show t ra c k ping
Display information and settings for ping tracking instances.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show track ping [<P-1>]
Parameter Value Meaning
P-1 slot no./port no.

4 3 .2 .4 show t ra c k logic a l
Display information and settings for logical tracking instances.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show track logical [<P-1>]
Parameter Value Meaning
P-1 slot no./port no.

4 3 .2 .5 show t ra c k a pplic a t ion


Display information and settings for interface application registrations.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show track application

142 RM CLI EAGLE40


Release 3.4 03/2020
4 4 V ir t ua l Privat e N e t w ork (V PN )

4 4 .1 ipse c
Configure IPsec VPN settings.

4 4 .1 .1 ipse c c e rt ific a t e de le t e
Delete a certificate uploaded to the device.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ipsec certificate delete <P-1>
Parameter Value Meaning
P-1 1..100 Certificate Table Index.

4 4 .1 .2 ipse c c e rt ific a t e uploa d pa ssphra se


Passphrase that will be used to decrypt the next uploaded file, before storing on the device (note: will not be stored
after the next upload, no matter if it is used or not!)
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ipsec certificate upload passphrase <P-1>
Parameter Value Meaning
P-1 string Enter a user-defined text, max. 128 characters.

4 4 .1 .3 ipse c c onne c t ion a dd


Add a IPsec VPN connection (use next free index if none submitted).
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ipsec connection add <P-1> [name <P-2>]
[name]: IPsec VPN connection name.
Parameter Value Meaning
P-1 1..256 VPN connection index.
P-2 string Enter a user-defined text, max. 128 characters.

RM CLI EAGLE40 143


Release 3.4 03/2020
4 4 .1 .4 ipse c c onne c t ion m odify
Modify a IPsec VPN connection (index in connection is mandatory).
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: users ipsec connection modify <P-1> name <P-2> certificate ca add <P-3> clear
local <P-4> [remote <P-5>][privkey <P-6>] [passphrase <P-7>] debug informational
<P-8> not-handled <P-9> access [method <P-10>] [preshared-key <P-11>] [local-type
<P-12>] [local-id <P-13>] [remote-type <P-14>] [remote-id <P-15>] keyexchange mode
[protocol <P-16>] [startup <P-17>] [dpdtimeout <P-18>] [lifetime <P-19>]
[exchange-mode <P-20>] [margintime <P-21>] [re-authenticate <P-22>]algorithms
[key-agreement <P-23>] [integrity <P-24>][encryption <P-25>] endpoints [local-
address <P-26>][remote-address <P-27>] data-exchange mode [lifetime <P-28>]
algorithms [key-agreement <P-29>] [integrity <P-30>] [encryption <P-31>]
name: IPsec VPN connection name.
certificate: Manage certificates for this connection.
ca: Set the CA certificate file name(s). Also supports comma-separated chains.
add: Add a CA file name to the current connection.
clear: Remove all the CA file names added to the current connection.
local: Set the file name of the certificate that will identify the current device.
[remote]: Set the file name of the certificate that will identify the remote device.
[privkey]: Set the file name of the private key (if it is encrypted and cannot be automatically matched to the
certificate).
[passphrase]: Set the passphrase to be used with an encrypted private
key or PKCS12 encrypted container (warning: will be stored in the config!).
debug: IPsec VPN connection additonal debugging information to event log.
informational: Enable or disable debug of informational messages.
not-handled: Enable or disable debug of not handled messages.
access: IPsec VPN access.
[method]: Authentication method to be used.
[pre-shared-key]: Preshared key (passphrase).
[local-type]: Type of local peer identifier.
[local-id]: Local peer identifier.
[remote-type]: Type of remote peer identifier.
[remote-id]: Remote peer identifier.
key-exchange: Key exchange parameters.
mode: Key exchange mode.
[protocol]: Version of the key exchange protocol.
[startup]: Key exchange at startup.
[dpd-timeout]: Dead peer detection timeout.
[lifetime]: IKE security association lifetime.
[exchange-mode]: IKE exchange mode.
[margintime]: IKE and IPsec margintime for re-keying before timeout.
[re-authenticate]: Re-authenticate at end of IKE lifetime (IKEv2 only).
algorithms: Key exchange algorithms.
[key-agreement]: Key agreement algorithm to be used.
[integrity]: Integrity (MAC) algorithm to be used in IKEv2.
[encryption]: Encryption algorithm to be used.
endpoints: IPsec VPN tunnel endpoints.
[local-address]: Address of local security gateway.
[remote-address]: Address of remote security gateway.
data-exchange: Data exchange parameters.
mode: Data exchange mode.
[lifetime]: Lifetime of IPsec SA.
algorithms: Data exchange algorithms.
[key-agreement]: Key agreement algorithm to be used.
[integrity]: Integrity (MAC) algorithm to be used in IPsec.
[encryption]: Algorithm to be used for IPsec payload encryption.
Parameter Value Meaning
P-1 1..256 VPN connection index.
P-2 string Enter a user-defined text, max. 128 characters.
P-3 string Filename.
P-4 string Filename.
P-4 string Filename.
P-5 string Filename.

144 RM CLI EAGLE40


Release 3.4 03/2020
Parameter Value Meaning
P-6 string Filename.
P-7 string Enter a user-defined text, max. 128 characters.
P-8 debug_inform debug informational
P-9 debug_unhandled debug unhandled
P-10 psk Pre-shared key.
x509rsa Individual X.509 RSA certificates.
pkcs12 Single PKCS12 file with all certificates (including CA).
P-11 string Enter a user-defined text, max. 128 characters.
P-12 default Local IPv4 address.
address IPv4 address or host name (use from address field).
id Use identifier.
P-13 string Enter a user-defined text, max. 255 characters.
P-14 any Not checked.
address IPv4 address or host name (use from address field).
id Use identifier.
P-15 string Enter a user-defined text, max. 255 characters.
P-16 auto Accept IKEv1/v2 as responder, start with IKEv2 as initiator.
v1 IKE version 1 (ISAKMP).
v2 IKE version 2.
P-17 initiator Initiates the IKE at startup.
responder Peer starts the IKE initiation.
P-18 0..86400 Interval between liveness messages in seconds, 0 to disable.
P-19 300..86400 Lifetime of IKE SA in seconds (max. 24h).
P-20 main Initiates or accepts main mode only.
aggressive Initiates or accepts aggressive only.
P-21 1..1800 Margintime for re-keying before timeout.
P-22 true True
false False
P-23 any Accept all algorithms as responder, use default as initiator.
modp1024 RSA with 1024 bits modulus.
modp1536 RSA with 1536 bits modulus.
modp2048 RSA with 2048 bits modulus.
modp3072 RSA with 3072 bits modulus.
modp4096 RSA with 4096 bits modulus.
P-24 any Accept all algorithms as responder, use default as initiator.
hmacmd5 HMAC-MD5
hmacsha1 HMAC-SHA1
hmacsha256 HMAC-SHA256
hmacsha384 HMAC-SHA384
hmacsha512 HMAC-SHA512
P-25 any Accept all algorithms as responder, use default as initiator.
des DES
des3 Triple-DES
aes128 AES with 128 key bits.
aes192 AES with 192 key bits.
aes256 AES with 256 key bits.
P-2 any Use the primary IP address of external interface.
a.b.c.d a.b.c.d IP address.
nu,nu-nu [Link] FQDN
P-27 any Use the primary IP address of external interface.
a.b.c.d a.b.c.d IP address.
nu,nu-nu [Link] FQDN
P-28 300..28800 Lifetime of IPsec SA in seconds (Max. 8h).
P-29 any Accept all algorithms as responder, use default as initiator.
modp1024 RSA with 1024 bits modulus.
modp1536 RSA with 1536 bits modulus.
modp2048 RSA with 2048 bits modulus.
modp3072 RSA with 3072 bits modulus.
modp4096 RSA with 4096 bits modulus.
none No perfect forward secrecy.
P-29 any Accept all algorithms as responder, use default as initiator.
hmacmd5 HMAC-MD5
hmacsha1 HMAC-SHA1
hmacsha256 HMAC-SHA256
hmacsha384 HMAC-SHA384
hmacsha512 HMAC-SHA512

RM CLI EAGLE40 145


Release 3.4 03/2020
Parameter Value Meaning
P-31 any Accept all algorithms as responder, use default as initiator.
des DES
des3 Triple-DES
aes128 AES with 128 key bits.
aes192 AES with 192 key bits.
aes256 AES with 256 key bits.
aes128ctr AES-COUNTER with 128 key bits.
aes192ctr AES-COUNTER with 192 key bits.
aes256ctr AES-COUNTER with 256 key bits.
aes128gcm64 AES-GCM with 64 bit ICV with 128 key bits.
aes128gcm96 AES-GCM with 96 bit ICV with 128 key bits.
aes128gcm128 AES-GCM with 128 bit ICV with 128 key bits.
aes192gcm64 AES-GCM with 64 bit ICV with 192 key bits.
aes192gcm96 AES-GCM with 96 bit ICV with 192 key bits.
aes192gcm128 AES-GCM with 128 bit ICV with 192 key bits.
aes256gcm64 AES-GCM with 64 bit ICV with 256 key bits.
aes256gcm96 AES-GCM with 96 bit ICV with 256 key bits.
aes256gcm128 AES-GCM with 128 bit ICV with 256 key bits.

 no ipse c c onne c t ion m odify


Disable the option
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: no ipsec connection modify name certificate ca add clear local [remote]
[privkey] [passphrase]debug informational <P-8> not-handled <P-9> access
[method] [pre-shared-key] [local-type] [local-id] [remote-type] [remote-id]
key-exchange mode [protocol] [startup] [dpd-timeout] [lifetime] [exchangemode]
[margintime] [re-authenticate] algorithms [key-agreement] [integrity]
[encryption] endpoints [local-address] [remote-address] data-exchange mode
[lifetime] algorithms [key-agreement] [integrity] [encryption]

4 4 .1 .5 ipse c c onne c t ion st a t us


Enable or disable a IPsec VPN connection (index in connection is mandatory).
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ipsec connection status <P-1> <P-2>
Parameter Value Meaning
P-1 1..256 VPN connection index.
P-2 enable Enable the option.
disable Disable the option.

4 4 .1 .6 ipse c c onne c t ion de le t e


Delete a IPsec VPN connection (index in connection is mandatory).
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ipsec connection delete <P-1>
Parameter Value Meaning
P-1 1..256 VPN connection index.

146 RM CLI EAGLE40


Release 3.4 03/2020
4 4 .1 .7 ipse c t ra ffic -se le c t or
IPsec VPN traffic selectors.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: ipsec traffic-selector <P-1> add <P-2> [name <P-3>] delete <P-4> modify <P5>
[name <P-6>] [source-net <P-7>] [source-restriction <P-8>] [dest-net <P-9>][dest-
restriction <P-10>] status <P-11> <P-12>
add: Add new traffic selector.
[name]: Traffic selector ID.
delete: Delete an existing traffic selector.
modify: Modify an existing traffic selector.
[name]: Traffic selector ID.
[source-net]: Source address for the traffic selector.
[source-restriction]: Source restriction for the traffic selector.
[dest-net]: Destination address for the traffic selector.
[dest-restriction]: Destination restriction for the traffic selector.
status: Enable or disable an existing traffic selector.
Parameter Value Meaning
P-1 1..256 VPN connection index.
P-2 1..256 Index of the traffic selector (unique inside of a IPsec VPN connection).
P-3 string Enter a user-defined text, max. 128 characters.
P-4 1..256 Index of the traffic selector (unique inside of a IPsec VPN connection).
P-5 1..256 Index of the traffic selector (unique inside of a IPsec VPN connection).
P-6 string Enter a user-defined text, max. 128 characters.
P-7 a.b.c.d a.b.c.d Single IP address.
a.b.c.d a.b.c.d Address range in CIDR notation.
any Any IP address.
P-8 string 'protocol/port' Traffic selector restriction can be given as string, e.g. tcp/http or can be given as numbers,
e.g. 6/80 (=tcp/http)'protocol/port' Traffic selector restriction can be given as string, e.g. http (= any/http)
or can be given as numbers,e.g. /53 (= any/53) 'protocol/port 'Traffic selector restriction can be given as
string, e.g. udp (= udp/any) or can be given as numbers, e.g. 17 (= 17(udp)/any) an empty restriction ''
means to have no restriction (any/any)
P-9 a.b.c.d a.b.c.d Single IP address.
a.b.c.d a.b.c.d Address range in CIDR notation.
any Any IP address.
P-10 string 'protocol/port' Traffic selector restriction can be given as string, e.g. tcp/http or can be given as numbers,
e.g. 6/80 (=tcp/http)'protocol/port' Traffic selector restriction can be given as string, e.g. http (= any/http)
or can be given as numbers, e.g. /53 (= any/53)'protocol/port' Traffic selector restriction can be given as
string, e.g. udp (= udp/any) or can be given as numbers, e.g. 17 (= 17(udp)/any) an empty restriction
'' means to have no restriction (any/any)
P-11 1..256 Index of the traffic selector (unique inside of a IPsec VPN connection).
P-12 enable Enable the option.
disable Disable the option.

4 4 .2 show
Display device options and settings.

4 4 .2 .1 show ipse c ge ne ra l
General IPsec VPN settings.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ipsec general

4 4 .2 .2 show ipse c c onne c t ions sum m a ry


Overview of all configured connections.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ipsec connections summary

RM CLI EAGLE40 147


Release 3.4 03/2020
4 4 .2 .3 show ipse c c onne c t ions a c c e ss
IPsec connection access settings.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ipsec connections access <P-1>
Parameter Value Meaning
P-1 1..256 VPN connection index.

4 4 .2 .4 show ipse c c onne c t ions c e rt ific a t e s


IPsec connection certificates.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ipsec connections certificates <P-1>
Parameter Value Meaning
P-1 1..256 VPN connection index.

4 4 .2 .5 show ipse c c onne c t ions k e y-e x c ha nge


IPsec connection key exchange settings (IKE).
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ipsec connections key-exchange <P-1>
Parameter Value Meaning
P-1 1..256 VPN connection index.

4 4 .2 .6 show ipse c c onne c t ions da t a -e x c ha nge


IPsec connection data exchange settings.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ipsec connections data-exchange <P-1>
Parameter Value Meaning
P-1 1..256 VPN connection index.

4 4 .2 .7 show ipse c c onne c t ions st a t us


IPsec connection status.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ipsec connections data-exchange <P-1>
Parameter Value Meaning
P-1 1..256 VPN connection index.

4 4 .2 .8 show ipse c t ra ffic -se le c t ors


Traffic selectors for a IPsec VPN connection.
 Mode: Command is in all modes available.
 Privilege Level: Guest
 Format: show ipsec traffic-selectors <P-1> [<P-2>]
Parameter Value Meaning
P-1 1..256 VPN connection index.
P-2 1..256 Index of the traffic selector (unique inside of a IPsec VPN connection).

4 4 .2 .9 show ipse c c e rt ific a t e sum m a ry


Show a summary of all uploaded certificates and private keys.
 Mode: Command is in all modes available.
 Privilege Level: Administrator
 Format: show ipsec certificate summary

4 4 .2 .1 0 show ipse c c e rt ific a t e de t a ils


Show details about a specific certificate or private key.
 Mode: Command is in all modes available.
 Privilege Level: Administrator
 Format: show ipsec certificate details <P-1>
Parameter Value Meaning
P-1 1..100 Certificate Table Index.

148 RM CLI EAGLE40


Release 3.4 03/2020
4 5 U se rs

4 5 .1 use rs
Manage Users and User Accounts.

4 5 .1 .1 use rs a dd
Add a new user.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: users add <P-1>
Parameter Value Meaning
P-1 string <user> User name (up to 32 characters).

4 5 .1 .2 use rs de le t e
Delete an existing user.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: users delete <P-1>
Parameter Value Meaning
P-1 string <user> User name (up to 32 characters).

4 5 .1 .3 use rs e na ble
Enable user.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: users enable <P-1>
Parameter Value Meaning
P-1 string <user> User name (up to 32 characters).

4 5 .1 .4 use rs disa ble


Disable user.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: users disable <P-1>
Parameter Value Meaning
P-1 string <user> User name (up to 32 characters).

4 5 .1 .5 use rs pa ssw ord


Change user password.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: users password <P-1> [<P-2>]
Parameter Value Meaning
P-1 string <user> User name (up to 32 characters).
P-2 string Enter a user-defined text, max. 64 characters.

4 5 .1 .6 use rs snm pv3 a ut he nt ic a t ion


Specify authentication setting for a user.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: users snmpv3 authentication <P-1> <P-2>
Parameter Value Meaning
P-1 string <user> User name (up to 32 characters).
P-2 md5 MD5 as SNMPv3 user authentication mode.
sha1 SHA1 as SNMPv3 user authentication mode.

RM CLI EAGLE40 149


Release 3.4 03/2020
4 5 .1 .7 use rs snm pv3 e nc rypt ion
Specify encryption settings for a user.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: users snmpv3 encryption <P-1> <P-2>
Parameter Value Meaning
P-1 string <user> User name (up to 32 characters).
P-2 none SNMPv3 encryption method is none.
des DES as SNMPv3 encryption method.
aescfb128 AES-128 as SNMPv3 encryption method.

4 5 .1 .8 use rs a c c e ss-role
Specify snmpv3 access role for a user.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: users access-role <P-1> <P-2>
Parameter Value Meaning
P-1 string <user> User name (up to 32 characters).
P-2 slot no./port no.

4 5 .1 .9 use rs loc k -st a t us


Set the lockout status of a specified user.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: users lock-status <P-1> <P-2>
Parameter Value Meaning
P-1 string <user> User name (up to 32 characters).
P-2 unlock Unlock specific user. User can login again.

4 5 .1 .1 0 use rs pa ssw ord-polic y-c he c k


Set password policy check option. The device checks the "minimum password length", regardless of the setting
for this option.
 Mode: Global Config Mode
 Privilege Level: Administrator
 Format: users password-policy-check <P-1> <P-2>
Parameter Value Meaning
P-1 string <user> User name (up to 32 characters).
P-2 enable Enable the option.
disable Disable the option.

4 5 .2 show
Display device options and settings.

4 5 .2 .1 show use rs
Display the users and user accounts information.
 Mode: Command is in all modes available.
 Privilege Level: Administrator
 Format: show users

150 RM CLI EAGLE40


Release 3.4 03/2020
A Fur t he r suppor t

Technical questions
For technical questions, please contact any Hirschmann dealer in your area or Hirschmann directly.
You find the addresses of our partners on the Internet at [Link].
A list of local telephone numbers and email addresses for technical support directly from Hirschmann is available
at [Link].
This site also includes a free of charge knowledge base and a software download section.

Technical Documents
The current manuals and operating instructions for Hirschmann products are available at [Link].

Hirschmann Competence Center


The Hirschmann Competence Center is ahead of its competitors on three counts with its complete range of
innovative services:
 Consulting incorporates comprehensive technical advice, from system evaluation through network planning to
project planning.
 Training offers you an introduction to the basics, product briefing and user training with certification.
You find the training courses on technology and products currently available at [Link].
 Support ranges from the first installation through the standby service to maintenance concepts.
With the Hirschmann Competence Center, you decided against making any compromises. Our client-customized
package leaves you free to choose the service components you want to use.

RM CLI EAGLE40 151


Release 3.4 03/2020
B Re a de rs’ Com m e nt s
What is your opinion of this manual? We are constantly striving to provide as comprehensive a description of our
product as possible, as well as important information to assist you in the operation of this product. Your comments
and suggestions help us to further improve the quality of our documentation.

Your assessment of this manual:

Very Good Good Satisfactory Mediocre Poor


Precise description O O O O O
Readability O O O O O
Understandability O O O O O
Examples O O O O O
Structure O O O O O
Comprehensive O O O O O
Graphics O O O O O
Drawings O O O O O
Tables O O O O O

Did you discover any errors in this manual?


If so, on what page?

Suggestions for improvement and additional information:

General comments:

Sender:

Company / Department:

Name / Telephone number:

Street:

Zip code / City:

152 RM CLI EAGLE40


Release 3.4 03/2020
E-mail:

Date / Signature:

Dear User,
Please fill out and return this page
 as a fax to the number +49 (0)7127/14-1600 or
 per mail to
Hirschmann Automation and Control GmbH
Department 01RD-NT
Stuttgarter Str. 45-51
72654 Neckartenzlingen

RM CLI EAGLE40 153


Release 3.4 03/2020
User Manual
Configuration
Industrial Security Router
EAGLE40

UM Config EAGLE Technical support


Release 3.4 03/2020 [Link]
The naming of copyrighted trademarks in this manual, even when not specially indicated, should not be taken to mean that
these names may be considered as free in the sense of the trademark and tradename protection law and hence that they may
be freely used by anyone.

© 2020 Hirschmann Automation and Control GmbH

Manuals and software are protected by copyright. All rights reserved. The copying, reproduction, translation, conversion into
any electronic medium or machine scannable form is not permitted, either in whole or in part. An exception is the preparation
of a backup copy of the software for your own use.

The performance features described here are binding only if they have been expressly agreed when the contract was made.
This document was produced by Hirschmann Automation and Control GmbH according to the best of the company's
knowledge. Hirschmann reserves the right to change the contents of this document without prior notice. Hirschmann can give
no guarantee in respect of the correctness or accuracy of the information in this document.

Hirschmann can accept no responsibility for damages, resulting from the use of the network components or the associated
operating software. In addition, we refer to the conditions of use specified in the license contract.

You can get the latest version of this manual on the Internet at the Hirschmann product site ([Link]).

Hirschmann Automation and Control GmbH


Stuttgarter Str. 45-51
72654 Neckartenzlingen
Germany

2020-03-25 UM Config EAGLE


Release 3.4 03/2020
Contents

Contents

Safety instructions. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8

About this Manual . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9

Key. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10

Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11

1 User interfaces . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
1.1 Graphical User Interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
1.2 Command Line Interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
1.2.1 Preparing the data connection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
1.2.2 Access to the Command Line Interface using SSH (Secure Shell) . . . . . . . . . . . . . . . . . . . . . . 14
1.2.3 Access to the Command Line Interface using the serial interface . . . . . . . . . . . . . . . . . . . . . . . . 16
1.2.4 User rights . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18
1.2.5 Mode-based command hierarchy. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19
1.2.6 Executing the commands. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
1.2.7 Structure of a command. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
1.2.8 Examples of commands. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25
1.2.9 Input prompt . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26
1.2.10 Key combinations. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28
1.2.11 Data entry elements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29
1.2.12 Use cases . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 30
1.2.13 Service Shell . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32
1.3 System monitor . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35
1.3.1 Functional scope . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35
1.3.2 Starting the System Monitor. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35

2 Specifying the IP parameters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37


2.1 IP parameter basics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37
2.1.1 IP address (version 4) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37
2.1.2 Netmask . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38
2.1.3 Classless Inter-Domain Routing. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40
2.2 Specifying the IP parameters using the Command Line Interface . . . . . . . . . . . . . . . . . . . . . . . . 41
2.3 Specifying the IP parameters using HiDiscovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43
2.4 Specifying the IP parameters using the Graphical User Interface . . . . . . . . . . . . . . . . . . . . . . . . 45

3 Access to the device . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 46


3.1 First login (Password change) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 46
3.2 Authentication lists . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47
3.2.1 Applications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47
3.2.2 Policies. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47
3.2.3 Managing authentication lists. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 48
3.2.4 Adjust the settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49

UM Config EAGLE 3
Release 3.4 03/2020
Contents

3.3 User management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51


3.3.1 Access roles. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51
3.3.2 Managing user accounts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 53
3.3.3 Default setting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 53
3.3.4 Changing default passwords . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54
3.3.5 Setting up a new user account. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55
3.3.6 Deactivating the user account . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56
3.3.7 Adjusting policies for passwords . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 57
3.4 LDAP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 58
3.4.1 Coordination with the server administrator. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 58
3.4.2 Example configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59
3.5 SNMP access. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 62
3.5.1 SNMPv1/v2 access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 62
3.5.2 SNMPv3 access. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 63

4 VPN – Virtual Private Network . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64


4.1 IPsec – Internet Protocol Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64
4.2 IKE – Internet Key Exchange . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66
4.2.1 Authentication . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66
4.2.2 Encryption . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66
4.2.3 Creating a certificate using OpenSSL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66
4.3 Application examples . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 69
4.3.1 Connecting 2 subnetworks. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 69

5 Managing configuration profiles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 73


5.1 Detecting changed settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 73
5.2 Saving the settings. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 74
5.2.1 Saving the configuration profile in the device. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 74
5.2.2 Saving the configuration profile in the external memory . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 76
5.2.3 Exporting a configuration profile. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 76
5.3 Loading settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 78
5.3.1 Activating a configuration profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 78
5.3.2 Loading the configuration profile from the external memory . . . . . . . . . . . . . . . . . . . . . . . . . . . . 79
5.3.3 Importing a configuration profile. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 80
5.4 Reset the device to the factory defaults . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 82
5.4.1 Using the Graphical User Interface or Command Line Interface . . . . . . . . . . . . . . . . . . . . . . . . . 82
5.4.2 Using the System Monitor . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 82

6 Loading software updates. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 84


6.1 Software update from the PC. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 84
6.2 Software update from a server. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 86
6.3 Software update from the external memory . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 87
6.3.1 Manually—initiated by the administrator . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 87
6.3.2 Automatically—initiated by the device . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 87
6.4 Loading a previous software version . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 89

7 Configuring the ports . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 90


7.1 Enabling/disabling the port. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 90
7.2 Selecting the operating mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 91

8 Assistance in the protection from unauthorized access . . . . . . . . . . . . . . . . . . . . . . . . . . . . 92


8.1 Changing the SNMPv1/v2 community . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 92

4 UM Config EAGLE
Release 3.4 03/2020
Contents

8.2 Disabling SNMPv1/v2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 93


8.3 Disabling HTTP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 94
8.4 Disabling the HiDiscovery access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 95
8.5 Activating the IP access restriction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 96
8.6 Adjusting the session timeouts. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99

9 Controlling the data traffic . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 101


9.1 Packet filter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 103
9.1.1 Description of the Packet Filter function. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 103
9.1.2 Application example for Packet Filter. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 104
9.2 Helping protect against unauthorized access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 108
9.3 Deep Packet Inspection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 109
9.3.1 Description of the Deep Packet Inspection - Modbus Enforcer function . . . . . . . . . . . . . . . . . . 109
9.3.2 Application example for Modbus Enforcer . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 110
9.3.3 Create and edit Modbus Enforcer rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 111

10 Synchronizing the system time in the network. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 113


10.1 Basic settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 114
10.1.1 Setting the time . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 114
10.1.2 Automatic daylight saving time changeover. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 115
10.2 NTP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 116
10.2.1 Preparing the NTP configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 117
10.2.2 NTP configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 117
10.2.3 Multicast-Groups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 119

11 Network load control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 121


11.1 Direct packet distribution . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 121
11.1.1 Learning MAC addresses. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 121
11.1.2 Aging of learned MAC addresses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 121
11.1.3 Static address entries. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 122
11.2 Rate limiter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 124

12 Routing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 125
12.1 Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 125
12.2 Routing - Basics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 126
12.2.1 ARP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 127
12.2.2 CIDR . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 129
12.2.3 Multinetting. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 129
12.3 Static Routing. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 131
12.3.1 Port-based Router Interface. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 131
12.3.2 VLAN-based Router-Interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 133
12.3.3 Configuration of a Static Route . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 136
12.3.4 Static route tracking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 139
12.4 NAT – Network Address Translation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 145
12.4.1 Applying the NAT Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 145
12.4.2 1:1 NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 146
12.4.3 Destination NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 148
12.4.4 Masquerading NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 150
12.4.5 Double NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 151

UM Config EAGLE 5
Release 3.4 03/2020
Contents

12.5 Tracking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 155


12.5.1 Interface tracking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 155
12.5.2 Ping tracking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 156
12.5.3 Logical tracking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 157
12.5.4 Configuring the tracking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 157
12.6 VRRP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 165
12.6.1 VRRP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 165
12.6.2 VRRP with load sharing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 168
12.6.3 VRRP with Multinetting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 168
12.7 OSPF . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 170
12.7.1 OSPF-Topology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 171
12.7.2 General Operation of OSPF. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 176
12.7.3 Setting up the Adjacency . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 176
12.7.4 Synchronization of the LSDB . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 178
12.7.5 Route Calculation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 179
12.7.6 Configuring OSPF . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 180
12.7.7 Limiting the distribution of the routes using an ACL. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 183
12.8 Entering the IP Parameters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 194

13 Operation diagnosis . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 197


13.1 Sending SNMP traps . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 197
13.1.1 List of SNMP traps . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 198
13.1.2 SNMP traps for configuration activity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 199
13.1.3 SNMP trap setting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 199
13.1.4 ICMP messaging . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 200
13.2 Monitoring the Device Status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 201
13.2.1 Events which can be monitored . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 201
13.2.2 Configuring the Device Status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 202
13.2.3 Displaying the Device Status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 203
13.3 Security Status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 204
13.3.1 Events which can be monitored . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 204
13.3.2 Configuring the Security Status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 205
13.3.3 Displaying the Security Status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 206
13.4 Out-of-Band signaling . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 207
13.4.1 Controlling the Signal contact . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 207
13.4.2 Monitoring the Device and Security Statuses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 208
13.5 Port status indication . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 211
13.6 Port event counter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 212
13.6.1 Detecting non-matching duplex modes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 212
13.7 Displaying the SFP status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 214
13.8 Topology discovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 215
13.8.1 Displaying the Topology discovery results . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 215
13.9 Reports. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 217
13.9.1 Global settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 217
13.9.2 Syslog . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 219
13.9.3 System Log . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 220
13.9.4 Audit Trail . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 220

14 Advanced functions of the device . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 222


14.1 Using the device as a DNS client. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 222
14.1.1 Configuring a DNS server example . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 223

6 UM Config EAGLE
Release 3.4 03/2020
Contents

A Setting up the configuration environment. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 224


A.1 Preparing access via SSH . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 224
A.1.1 Generating a key in the device. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 224
A.1.2 Loading your own key onto the device. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 225
A.1.3 Preparing the SSH client program . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 225
A.2 HTTPS certificate . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 227
A.2.1 HTTPS certificate management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 228
A.2.2 Access through HTTPS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 229

B Appendix. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 230
B.1 Literature references . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 230
B.2 Maintenance. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 231
B.3 Management Information Base (MIB) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 232
B.4 List of RFCs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 235
B.5 Underlying IEEE Standards . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 237
B.6 Underlying ANSI Norms . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 238
B.7 Technical Data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 239
B.8 Copyright of integrated Software . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 240
B.9 Abbreviations used. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 241

C Index . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 242

D Further support . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 248

E Readers’ Comments . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 249

UM Config EAGLE 7
Release 3.4 03/2020
Safety instructions

Safety instructions

WARNING
UNCONTROLLED MACHINE ACTIONS

To avoid uncontrolled machine actions caused by data loss, configure all the data transmission
devices individually.

Before you start any machine which is controlled via data transmission, be sure to complete the
configuration of all data transmission devices.

Failure to follow these instructions can result in death, serious injury, or equipment
damage.

8 UM Config EAGLE
Release 3.4 03/2020
About this Manual

About this Manual

The “Configuration” user manual contains the information you need to start operating the device. It
takes you step by step from the first startup operation through to the basic settings for operation in
your environment.

The “Installation” user manual contains a device description, safety instructions, a description of the
display, and the other information that you need to install the device.

The “Graphical User Interface” reference manual contains detailed information on using the
graphical user interface to operate the individual functions of the device.

The “Command Line Interface” reference manual contains detailed information on using the
Command Line Interface to operate the individual functions of the device.

The Industrial HiVision Network Management software provides you with additional options for
smooth configuration and monitoring:
 Auto-topology discovery
 Browser interface
 Client/server structure
 Event handling
 Event log
 Simultaneous configuration of multiple devices
 Graphical user interface with network layout
 SNMP/OPC gateway

UM Config EAGLE 9
Release 3.4 03/2020
Key

Key

The designations used in this manual have the following meanings:

 List
 Work step
Link Cross-reference with link
Note: A note emphasizes a significant fact or draws your attention to a dependency.
Courier Representation of a CLI command or field contents in the graphical user interface

Execution in the Graphical User Interface

Execution in the Command Line Interface

10 UM Config EAGLE
Release 3.4 03/2020
Introduction

Introduction

The device has been developed for use in a harsh industrial environment. Accordingly, the
installation process has been kept simple. Thanks to the selected default settings, you only have
to enter a few settings before starting to operate the device.

UM Config EAGLE 11
Release 3.4 03/2020
User interfaces
1.1 Graphical User Interface

1 User interfaces

The device lets you specify the settings of the device using the following user interfaces.

Table 1: User interfaces for accessing the device management

User interface Can be reached through … Prerequisite


Graphical User Interface Ethernet (In-Band) Web browser
Command Line Interface Ethernet (In-Band) Terminal emulation software
Serial interface (Out-of-Band)
System monitor Serial interface (Out-of-Band) Terminal emulation software

1.1 Graphical User Interface

System requirements

To open the Graphical User Interface, you need the desktop version of a web browser with HTML5
support.

Note: Third-party software such as web browsers validate certificates based on criteria such as
their expiration date and current cryptographic parameter recommendations. Old certificates can
cause errors for example, when they expire or cryptographic recommendations change. To solve
validation conflicts with third-party software, transfer your own up-to-date certificate onto the device
or regenerate the certificate with the latest firmware.

Starting the Graphical User Interface

The prerequisite for starting the Graphical User Interface is that the IP parameters are configured
in the device. See “Specifying the IP parameters” on page 37.
 Start your web browser.
 Type the IP address of the device in the address field of the web browser.
Use the following form: [Link]
The web browser sets up the connection to the device and displays the Login page.
 When you want to change the language of the Graphical User Interface, click the appropriate
link in the top right corner of the Login page.
 Enter the user name.
 Enter the password.
 Click the Login button.
The web browser displays the Graphical User Interface.

12 UM Config EAGLE
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

1.2 Command Line Interface

The Command Line Interface enables you to use the functions of the device through a local or
remote connection.

The Command Line Interface provides IT specialists with a familiar environment for configuring IT
devices. As an experienced user or administrator, you have knowledge about the basics and about
using Hirschmann devices.

1.2.1 Preparing the data connection

Information for assembling and starting up your device can be found in the “Installation” user
manual.
 Connect the device with the network. The prerequisite for a successful data connection is the
correct setting of the network parameters.

You can access the user interface of the Command Line Interface for example, with the freeware
program PuTTY.

This program is provided on the product CD.


 Install the PuTTY program on your computer.

UM Config EAGLE 13
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

1.2.2 Access to the Command Line Interface using SSH (Secure Shell)

In the following example we use the PuTTY program. Another option to access your device using
SSH is the OpenSSH Suite.

Proceed as follows:
 Start the PuTTY program on your computer.

Figure 1: PuTTY input screen

 In the Host Name (or IP address) field you enter the IP address of your device.
The IP address consists of 4 decimal numbers with values from 0 to 255. The 4 decimal numbers
are separated by points.
 To specify the connection type, select the SSH radio button in the Connection type option list.
After selecting and setting the required parameters, the device enables you to set up the data
connection using SSH.

14 UM Config EAGLE
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

 Click the Open button to set up the data connection to your device.
Depending on the device and the time at which SSH was configured, setting up the connection
takes up to a minute.
When you first login to your device, towards the end of the connection setup, the PuTTY program
displays a security alert message and lets you check the fingerprint of the key.

Figure 2: Security alert prompt for the fingerprint

 Check the fingerprint.


This helps protect yourself from unwelcome guests.
 When the fingerprint matches the fingerprint of the device key, click the Yes button.
The device lets you display the finger prints of the device keys with the command show ssh or in
the Device Security > Management Access > Server dialog, SSH tab.
The Command Line Interface appears on the screen with a window for entering the user name.
The device enables up to 5 users to have access to the Command Line Interface at the same
time.
 Enter the user name.
The default user name is admin.
 Press the <Enter> key.
 Enter the password.
The default password is private.
 Press the <Enter> key.

Note: This device is a security-relevant product. Change the password during the first startup
procedure.

UM Config EAGLE 15
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

login as: admin


admin@[Link]’s password:

Copyright (c) 2011-2020 Hirschmann Automation and Control GmbH

All rights reserved

EAGLE Release 3.4

(Build date 2019-02-05 19:17)

System Name : EAGLE-FD122E


Management IP : [Link]
Subnet Mask : [Link]
Base MAC : EC:E5:55:01:02:03
System Time : 2020-01-01 17:39:01

NOTE: Enter '?' for Command Help. Command help displays all options
that are valid for the particular mode.
For the syntax of a particular command form, please
consult the documentation.

EAGLE>

Figure 3: Start screen of the Command Line Interface

1.2.3 Access to the Command Line Interface using the serial interface

The serial interface is used to locally connect an external network management station (VT100
terminal or PC with terminal emulation). The interface lets you set up a data connection to the
Command Line Interface and to the system monitor.

VT 100 terminal settings


Speed 115200 bit/s
Data 8 bit
Stopbit 1 bit
Handshake off
Parity none

16 UM Config EAGLE
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

Proceed as follows:
 Connect the device to a terminal using the serial interface. Alternatively connect the device to a
COM port of your PC using terminal emulation based on VT100 and press any key.
 Alternatively you set up the serial data connection to the device with the serial interface using
the PuTTY program. Press the <Enter> key.

Figure 4: Serial data connection with the serial interface using the PuTTY program

 Press any key on your terminal keyboard a number of times until the login screen indicates the
CLI mode.
 Enter the user name.
The default user name is admin.
 Press the <Enter> key.
 Enter the password.
The default password is private.
 Press the <Enter> key.

Note: This device is a security-relevant product. Change the password during the first startup
procedure.

UM Config EAGLE 17
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

Copyright (c) 2011-2020 Hirschmann Automation and Control GmbH

All rights reserved

EAGLE Release 3.4

(Build date 2019-02-05 19:17)

System Name : EAGLE-FD122E


Management IP : [Link]
Subnet Mask : [Link]
Base MAC : EC:E5:55:01:02:03
System Time : 2020-01-01 17:39:01

NOTE: Enter '?' for Command Help. Command help displays all options
that are valid for the particular mode.
For the syntax of a particular command form, please
consult the documentation.

EAGLE>

Figure 5: Start screen of the Command Line Interface

1.2.4 User rights

The device functions available to you as a user depend on your access role. When you are logged
on to the user interface with a specific access role, the functions of the access role are available to
you.

The commands available to you as a user, also depend on the Command Line Interface mode in
which you are currently working. See “Mode-based command hierarchy” on page 19.

18 UM Config EAGLE
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

Access roles

The user interface offers the following access roles:

Administrator

Auditor
Operator User

Table 2: Access roles and scope of user authorizations

Access role User authorizations


User Users logged on with the access role User are authorized to monitor the device.
Auditor Users logged on with the access role Auditor are authorized to monitor the device
and to save the log file in the Diagnostics > Report > Audit Trail dialog.
Operator Users logged on with the access role Operator are authorized to monitor the
device and to change the settings – with the exception of security settings for
device access.
Administrator Users logged on with the access role Administrator are authorized to monitor the
device and to change the settings.
Unauthorized Unauthorized users are blocked, and the device rejects the user login. Assign this
value to temporarily lock the user account. If a detected error occurs during an
access role change, then the device assigns this access role to the user account.

1.2.5 Mode-based command hierarchy

In the Command Line Interface, the commands are grouped in the related modes, according to the
type of the command. Every command mode supports specific Hirschmann software commands.

The commands available to you as a user depend on your privilege level (administrator, operator,
guest, auditor). They also depend on the mode in which you are currently working. When you switch
to a specific mode, the commands of the mode are available to you.

The User Exec mode commands are an exception. The Command Line Interface enables you to
execute these commands in the Privileged Exec mode, too.

UM Config EAGLE 19
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

The following figure displays the modes of the Command Line Interface.

ROOT

Login Logout

Limited The User Exec


functionality User Exec Mode commands
are available in
Privileged Exec
Mode, too.
Enable Exit

Basic functions,
basic settings Privileged Exec Mode

Configure Exit Vlan Exit


database

Advanced VLAN
configurations Global Configuration Mode VLAN Database Mode configu-
rations

Interface Exit
<slot/port>

Configurations
on one or Interface Range Mode
several ports
Figure 6: Structure of the Command Line Interface

The Command Line Interface supports, depending on the user level, the following modes:
 User Exec mode
When you login to the Command Line Interface, you enter the User Exec mode. The User Exec
mode contains a limited range of commands.
Command prompt: (EAGLE) >
 Privileged Exec mode
To access the entire range of commands, you enter the Privileged Exec mode. If you login as a
privileged user, then you are able to enter the Privileged Exec mode. In the Privileged Exec
mode, you are able to execute the User Exec mode commands, too.
Command prompt:(EAGLE) #
 VLAN mode
The VLAN mode contains VLAN-related commands.
Command prompt: (EAGLE) (VLAN)#

20 UM Config EAGLE
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

 Global Config mode


The Global Config mode lets you perform modifications to the current configuration. This mode
groups general setup commands.
Command prompt: (EAGLE) (config)#
 Interface Range mode
The commands in the Interface Range mode affect a specific port, a selected group of multiple
ports or all port of the device. The commands modify a value or switch a function on/off on one
or more specific ports.
– All physical ports in the device
Command prompt: (EAGLE) ((interface) all)#
Example: When you switch from the Global Config mode to the Interface Range mode, the
command prompt changes as follows:
(EAGLE) (config)#interface all
(EAGLE) ((Interface)all)#
– A single port on one interface
Command prompt: (EAGLE) (interface <slot/port>)#
Example: When you switch from the Global Config mode to the Interface Range mode, the
command prompt changes as follows:
(EAGLE) (config)#interface 2/1
(EAGLE) (interface 2/1)#
– A range of ports on one interface
Command prompt: (EAGLE) (interface <interface range> )#
Example: When you switch from the Global Config mode to the Interface Range mode, the
command prompt changes as follows:
(EAGLE) (config)#interface 1/2-1/4
(EAGLE) ((Interface)1/2-1/4)#
– A list of single ports
Command prompt: (EAGLE) (interface <interface list>)#
Example: When you switch from the Global Config mode to the Interface Range mode, the
command prompt changes as follows:
(EAGLE) (config)#interface 1/2,1/4,1/5
(EAGLE) ((Interface)1/2,1/4,1/5)#
– A list of port ranges and single ports
Command prompt: (EAGLE) (interface <complex range>)#
Example: When you switch from the Global Config mode to the Interface Range mode, the
command prompt changes as follows:
(EAGLE) (config)#interface 1/2-1/4,1/6-1/9
(EAGLE) ((Interface)1/2-1/4,1/6-1/9)

The following table displays the command modes, the command prompts (input request
characters) visible in the corresponding mode, and the option with which you quit this mode.

Table 3: Command modes

Command mode Access method Quit or start next mode


User Exec mode First access level. Perform basic To quit you enter logout:
tasks and list system information. (EAGLE) >logout
Are you sure (Y/N) ?y

Privileged Exec From the User Exec mode, you enter To quit the Privileged Exec mode and
mode the command enable: return to the User Exec mode, you enter
(EAGLE) >enable exit:
(EAGLE) # (EAGLE) #exit
(EAGLE) >

UM Config EAGLE 21
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

Table 3: Command modes

Command mode Access method Quit or start next mode


VLAN mode From the Privileged Exec mode, you To end the VLAN mode and return to the
enter the command vlan database: Privileged Exec mode, you enter exit or
(EAGLE) #vlan database press Ctrl Z.
(EAGLE) (Vlan)# (EAGLE) (Vlan)#exit
(EAGLE) #
Global Config From the Privileged Exec mode, you To quit the Global Config mode and
mode enter the command configure: return to the Privileged Exec mode, you
(EAGLE) #configure enter exit:
(EAGLE) (config)# (EAGLE) (config)#exit
From the User Exec mode, you enter (EAGLE) #
the command enable, and then in To then quit the Privileged Exec mode
Privileged Exec mode, enter the and return to the User Exec mode, you
command Configure: enter exit again:
(EAGLE) >enable (EAGLE) #exit
(EAGLE) #configure (EAGLE) >
(EAGLE) (config)#
Interface Range From the Global Config mode you To quit the Interface Range mode and
mode enter the command interface return to the Global Config mode, you
{all|<slot/port>|<interface range> enter exit. To return to the Privileged
|<interface list>|<complex range>}. Exec mode, you press Ctrl Z.
(EAGLE) (config)#interface <slot/ (EAGLE) (interface slot/port)#exit
port> (EAGLE) #
(EAGLE) (interface slot/port)#

When you enter a question mark (?) after the prompt, the Command Line Interface displays a list
of the available commands and a short description of the commands.

(EAGLE)>
cli Set the CLI preferences.
enable Turn on privileged commands.
help Display help for various special keys.
history Show a list of previously run commands.
logout Exit this session.
ping Send ICMP echo packets to a specified IP address.
show Display device options and settings.

(EAGLE)>

Figure 7: Commands in the User Exec mode

1.2.6 Executing the commands

Syntax analysis

When you login to the Command Line Interface, you enter the User Exec mode. The Command
Line Interface displays the prompt (EAGLE)> on the screen.

22 UM Config EAGLE
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

When you enter a command and press the <Enter> key, the Command Line Interface starts the
syntax analysis. The Command Line Interface searches the command tree for the desired
command.

When the command is outside the Command Line Interface command range, a message informs
you of the detected error.

Example:

The user wants to execute the show system info command, but enters info without f and presses
the <Enter> key.

The Command Line Interface then displays a message:

(EAGLE)>show system ino

Error: Invalid command 'ino'

Command tree

The commands in the Command Line Interface are organized in a tree structure. The commands,
and where applicable the related parameters, branch down until the command is completely
defined and therefore executable. The Command Line Interface checks the input. When you
entered the command and the parameters correctly and completely, you execute the command
with the <Enter> key.

After you entered the command and the required parameters, the other parameters entered are
treated as optional parameters. When one of the parameters is unknown, the Command Line
Interface displays a syntax message.

The command tree branches for the required parameters until the required parameters have
reached the last branch in the structure.

With optional parameters, the command tree branches until the required parameters and the
optional parameters have reached the last branch in the structure.

1.2.7 Structure of a command

This section describes the syntax, conventions and terminology, and uses examples to represent
them.

Format of commands

Most of the commands include parameters.

When the command parameter is missing, the Command Line Interface informs you about the
detection of an incorrect command syntax.

This manual displays the commands and parameters in the Courier font.

UM Config EAGLE 23
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

Parameters

The sequence of the parameters is relevant for the correct syntax of a command.

Parameters are required values, optional values, selections, or a combination of these things. The
representation indicates the type of the parameter.

Table 4: Parameter and command syntax

<command> Commands in pointed brackets (<>) are obligatory.


[command] Commands in square brackets ([]) are optional.
<parameter> Parameters in pointed brackets (<>) are obligatory.
[parameter] Parameters in square brackets ([]) are optional.
... An ellipsis (3 points in sequence without spaces) after an element
indicates that you can repeat the element.
[Choice1 | Choice2] A vertical line enclosed in brackets indicates a selection option.
Select one value.
Elements separated by a vertical line and enclosed in square
brackets indicate an optional selection (Option1 or Option2 or no
selection).
{list} Curved brackets ({}) indicate that a parameter is to be selected from
a list of options.
{Choice1 | Choice2} Elements separated by a vertical line and enclosed in curved
brackets ({}) indicate an obligatory selection option (option1 or
option2).
[param1 {Choice1 | Displays an optional parameter that contains an obligatory selection.
Choice2}]
<a.b.c.d> Small letters are wild cards. You enter parameters with the notation
a.b.c.d with decimal points (for example IP addresses)
<cr> You press the <Enter> key to create a line break (carriage return).

The following list displays the possible parameter values within the Command Line Interface:

Table 5: Parameter values in the Command Line Interface

Value Description
IP address This parameter represents a valid IPv4 address. The address
consists of 4 decimal numbers with values from 0 to 255. The 4
decimal numbers are separated by a decimal point. The IP address
[Link] is a valid entry.
MAC address This parameter represents a valid MAC address. The address
consists of 6 hexadecimal numbers with values from 00 to FF. The
numbers are separated by a colon, for example, 00:F6:29:B2:81:40.
string User-defined text with a length in the specified range, for example a
maximum of 32 characters.
character string Use double quotation marks to indicate a character string, for
example “System name with space character”.
number Whole integer in the specified range, for example 0..999999.
date Date in format YYYY-MM-DD.
time Time in format HH:MM:SS.

24 UM Config EAGLE
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

Network addresses

Network addresses are a requirement for establishing a data connection to a remote work station,
a server, or another network. You distinguish between IP addresses and MAC addresses.

The IP address is an address allocated by the network administrator. The IP address is unique in
one network area.

The MAC addresses are assigned by the hardware manufacturer. MAC addresses are unique
worldwide.

The following table displays the representation and the range of the address types:

Table 6: Format and range of network addresses

Address Format Range Example


Type
IP Address [Link] nnn: 0 to 255 (decimal) [Link]
MAC mm:mm:mm:mm:m mm: 00 to ff (hexadecimal A7:C9:89:DD:A9:B3
Address m:mm number pairs)

Strings

A string is indicated by quotation marks. For example, “System name with space character”. Space
characters are not valid user-defined strings. You enter a space character in a parameter between
quotation marks.

Example:
*(EAGLE)#cli prompt Device name
Error: Invalid command 'name'

*(EAGLE)#cli prompt 'Device name'

*(Device name)#

1.2.8 Examples of commands

Example 1: clear arp-table-switch

Command for clearing the ARP table of the management agent (cache).

clear arp-table-switchis the command name. The command is executable without any other
parameters by pressing the <Enter> key.

Example 2: radius server timeout

Command to configure the RADIUS server timeout value.


(EAGLE) (config)#radius server timeout
<1..30> Timeout in seconds (default: 5).

UM Config EAGLE 25
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

radius server timeout is the command name.

The parameter is required. The value range is 1..30.

Example 3: radius server auth modify <1..8>

Command to set the parameters for RADIUS authentication server 1.


(EAGLE) (config)#radius server auth modify 1
[name] RADIUS authentication server name.
[port] RADIUS authentication server port.
(default: 1812).
[msgauth] Enable or disable the message authenticator
attribute for this server.
[primary] Configure the primary RADIUS server.
[status] Enable or disable a RADIUS authentication
server entry.
[secret] Configure the shared secret for the RADIUS
authentication server.
[encrypted] Configure the encrypted shared secret.
<cr> Press Enter to execute the command.

radius server auth modify is the command name.

The parameter <1..8> (RADIUS server index) is required. The value range is 1..8 (integer).

The parameters [name], [port], [msgauth], [primary], [status], [secret] and [encrypted] are
optional.

1.2.9 Input prompt

Command mode

With the input prompt, the Command Line Interface displays which of the three modes you are in:
 (EAGLE) >
User Exec mode
 (EAGLE) #
Privileged Exec mode
 (EAGLE) (config)#
Global Config mode
 (EAGLE) (Vlan)#
VLAN Database mode
 (EAGLE) ((Interface)all)#
Interface Range mode / All ports of the device
 (EAGLE) ((Interface)2/1)#
Interface Range mode / A single port on one interface
 (EAGLE) ((Interface)1/2-1/4)#
Interface Range mode / A range of ports on one interface
 (EAGLE) ((Interface)1/2,1/4,1/5)#
Interface Range mode / A list of single ports
 (EAGLE) ((Interface)1/1-1/2,1/4-1/6)#
Interface Range mode / A list of port ranges and single ports

26 UM Config EAGLE
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

Asterisk, pound sign and exclamation point


 Asterisk *
An asterisk * in the first or second position of the input prompt displays you that the settings in
the volatile memory and the settings in the non-volatile memory are different. In your
configuration, the device has detected modifications which have not been saved.
*(EAGLE)>
 Pound sign #
A pound sign # at the beginning of the input prompt displays you that the boot parameters and
the parameters during the boot phase are different.
*#(EAGLE)>
 Exclamation point !
An exclamation point ! at the beginning of the input prompt displays: the password for the user
or admin user account corresponds with the default setting.
!(EAGLE)>

Wildcards

The device lets you change the command line prompt.

The Command Line Interface supports the following wildcards:

Table 7: Using wildcards within the Command Line Interface input prompt

Wildcard Description
%d System date
%t System time
%i IP address of the device
%m MAC address of the device
%p Product name of the device

!(EAGLE)>enable

!(EAGLE)#cli prompt %i

![Link]#cli prompt (EAGLE)%d

!*(EAGLE)2020-01-27#cli prompt (EAGLE)%d%t

!*(EAGLE)2020-01-2715:45:41#cli prompt %m

!*AA:BB:CC:DD:EE:FF#

UM Config EAGLE 27
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

1.2.10 Key combinations

The following key combinations make it easier for you to work with the Command Line Interface:

Table 8: Key combinations in the Command Line Interface

Key combination Description


CTRL + H, Backspace Delete previous character
CTRL + A Go to beginning of line
CTRL + E Go to end of line
CTRL + F Go forward one character
CTRL + B Go backward one character
CTRL + D Delete current character
CTRL + U, X Delete to beginning of line
CTRL + K Delete to end of line
CTRL + W Delete previous word
CTRL + P Go to previous line in history buffer
CTRL + R Rewrite or paste the line
CTRL + N Go to next line in history buffer
CTRL + Z Return to root command prompt
CTRL + G Aborts running tcpdump session
Tab, <SPACE> Command line completion
Exit Go to next lower command prompt
? List choices

The Help command displays the possible key combinations in Command Line Interface on the
screen:

28 UM Config EAGLE
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

(EAGLE) #help

HELP:
Special keys:

Ctrl-H, BkSp delete previous character


Ctrl-A .... go to beginning of line
Ctrl-E .... go to end of line
Ctrl-F .... go forward one character
Ctrl-B .... go backward one character
Ctrl-D .... delete current character
Ctrl-U, X .. delete to beginning of line
Ctrl-K .... delete to end of line
Ctrl-W .... delete previous word
Ctrl-P .... go to previous line in history buffer
Ctrl-R .... rewrites or pastes the line
Ctrl-N .... go to next line in history buffer
Ctrl-Z .... return to root command prompt
Ctrl-G .... aborts running tcpdump session
Tab, <SPACE> command-line completion
Exit .... go to next lower command prompt
? .... list choices

(EAGLE) #

Figure 8: Listing the key combinations with the Help command

1.2.11 Data entry elements

Command completion

To simplify typing commands, the Command Line Interface lets you use command completion (Tab
Completion). Thus you are able to abbreviate key words.
 Type in the beginning of a keyword. When the characters entered identify a keyword, the
Command Line Interface completes the keyword after you press the tab key or the space key.
When there is more than one option for completion, enter the letter or the letters necessary for
uniquely identifying the keyword. Press the tab key or the space key again. After that, the system
completes the command or parameter.
 When you make a non-unique entry and press <Tab> or <Space> twice, the Command Line
Interface provides you with a list of options.
 On a non-unique entry and pressing <Tab> or <Space>, the Command Line Interface completes
the command up to the end of the uniqueness. When several commands exist and you press
<Tab> or <Space> again, the Command Line Interface provides you with a list of options.
Example:
(EAGLE) (Config)#lo
(EAGLE) (Config)#log
logging logout
When you enter lo and <Tab> or <Space>, the Command Line Interface completes the
command up to the end of the uniqueness to log.
When you press <Tab> or <Space> again, the Command Line Interface provides you with a list
of options (logging logout).

UM Config EAGLE 29
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

Possible commands/parameters

You can obtain a list of the commands or the possible parameters by entering help or ?, for example
by entering (EAGLE) >show ?

When you enter the command displayed, you get a list of the parameters available for the command
show.

When you enter the command without space character in front of the question mark, the device
displays the help text for the command itself:

!*#(EAGLE)(Config)#show?

show Display device options and settings.

1.2.12 Use cases

Saving the Configuration

To help ensure that your password settings and your other configuration changes are kept after the
device is reset or after an interruption of the voltage supply, you save the configuration. To save
your current configuration, you proceed as follows:
 Enter enable to switch to the Privileged Exec mode.
 Enter the following command:
save [profile]
 Execute the command by pressing the <Enter> key.

30 UM Config EAGLE
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

Syntax of the „radius server auth add“ command

Use this command to add a RADIUS authentication server.


 Mode: Global Config mode
 Privilege Level: Administrator
 Format: radius server auth add <1..8> ip <a.b.c.d>
[name <string>] [port <1..65535>]
– [name]: RADIUS authentication server name.
– [port]: RADIUS authentication server port (default: 1813).

Parameter Meaning Possible values


<1..8> RADIUS server index. 1..8

<a.b.c.d> RADIUS accounting server IP address. IP address


<string> Enter a user-defined text, max. 32
characters.
<1..65535> Enter port number between 1 and 1..65535
65535.

Mode and Privilege Level:


 The prerequisite for executing the command: You are in the Global Config mode. See “Mode-
based command hierarchy” on page 19.
 The prerequisite for executing the command: You have the Administrator access role.

Syntax of commands and parameters: See “Structure of a command” on page 23.

Examples for executable commands:


 radius server auth add 1 ip [Link]
 radius server auth add 2 ip [Link] name radiusserver2
 radius server auth add 3 ip [Link] port 1813
 radius server auth add 4 ip [Link] name radiusserver4 port 1814

UM Config EAGLE 31
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

1.2.13 Service Shell

The Service Shell is for service purposes only.

The Service Shell lets users have access to internal functions of the device. When you need
assistance with your device, the service personnel use the Service Shell to monitor internal
conditions for example, the switch or CPU registers.

Do not execute internal functions without service technician instructions. Executing internal
functions such as deleting the content of the non-volatile memory (NVM) possibly leads to
inoperability of your device.

Start the Service Shell

The prerequisite is that you are in User Exec mode: (EAGLE) >

Perform the following steps:


 Enter enable and press the <Enter> key.
To reduce the effort when typing:
– Enter e and press the <Tab> key.
 Enter serviceshell start and press the <Enter> key.
To reduce the effort when typing:
– Enter ser and press the <Tab> key.
– Enter s and press the <Tab> key.

!EAGLE >enable

!*EAGLE #serviceshell start


WARNING! The service shell offers advanced diagnostics and functions.
Proceed only when instructed by a service technician.

You can return to the previous mode using the 'exit' command.

BusyBox v1.31.0 (2019-09-05 12:17:22 UTC) built-in shell (ash)


Enter 'help' for a list of built-in commands.

!/mnt/fastpath #

Working with the Service Shell

When the Service Shell is active, the timeout of the Command Line Interface is inactive. To help
prevent configuration inconsistencies, end the Service Shell before any other user starts
transferring a new configuration to the device.

32 UM Config EAGLE
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

Display the Service Shell commands

The prerequisite is that you already started the Service Shell.

Perform the following steps:


 Enter help and press the <Enter> key.

/mnt/fastpath # help
Built-in commands:
------------------
. : [ [[ alias bg break cd chdir command continue echo eval exec
exit export false fg getopts hash help history jobs kill let
local pwd read readonly return set shift source test times trap
true type ulimit umask unalias unset wait
/mnt/fastpath #

End the Service Shell

Perform the following steps:


 Enter exit and press the <Enter> key.

Deactivate the Service Shell permanently in the device

When you deactivate the Service Shell, you are still able to configure the device, but you limit the
service personnel to system diagnostics. The service technician has no possibility to access
internal functions of your device.

The deactivation is irreversible, the Service Shell remains permanently deactivated. In order to
reactivate the Service Shell, the device requires disassembly by the manufacturer.

The prerequisites are:


• The Service Shell is not started.
• You are in User Exec mode: (EAGLE) >

Perform the following steps:


 Enter enable and press the <Enter> key.
To reduce the effort when typing:
– Enter e and press the <Tab> key.

UM Config EAGLE 33
Release 3.4 03/2020
User interfaces
1.2 Command Line Interface

 Enter serviceshell deactivate and press the <Enter> key.


To reduce the effort when typing:
– Enter ser and press the <Tab> key.
– Enter dea and press the <Tab> key.
 This step is irreversible!
Press the <Y> key.

!EAGLE >enable

!*EAGLE #serviceshell deactivate


Notice: If you continue, then the Service Shell is permanently deactivated.
This step is irreversible!
For details, refer to the Configuration Manual.
Are you sure (Y/N) ?

34 UM Config EAGLE
Release 3.4 03/2020
User interfaces
1.3 System monitor

1.3 System monitor

The System Monitor lets you set basic operating parameters before starting the operating system.

1.3.1 Functional scope

In the System Monitor, you carry out the following tasks, for example:
 Managing the operating system and verifying the software image
 Updating the operating system
 Starting the operating system
 Deleting configuration profiles, resetting the device to the factory defaults
 Checking boot code information

1.3.2 Starting the System Monitor

Prerequisite:
 Terminal cable for connecting the device to your PC (available as an optional accessory).
 PC with VT100 terminal emulation (such as the PuTTY program) or serial terminal

Perform the following steps:


 Use the terminal cable to connect the serial interface of the device with the COM port of the PC.
 Start the VT100 terminal emulation on the PC.
 Specify the following transmission parameters:

VT 100 terminal settings


Speed 115200 bit/s
Data 8 bit
Stopbit 1 bit
Handshake off
Parity none

 Set up a connection to the device.


 Turn on the device. When the device is already on, reboot it.
The screen displays the following message after rebooting:
Press <1> to enter System Monitor 1.
 Press the <1> key within 3 seconds.
The device starts the System Monitor. The screen displays the following view:

UM Config EAGLE 35
Release 3.4 03/2020
User interfaces
1.3 System monitor

System Monitor 1
(Selected OS: ...-3.4 (2019-02-05 19:17))

1 Manage operating system


2 Update operating system
3 Start selected operating system
4 Manage configurations
5 Show boot code information
q End (reset and reboot)

sysMon1>

Figure 9: System Monitor 1 screen display

 Select a menu item by entering the number.


 To leave a submenu and return to the main menu of System Monitor 1, press the <ESC> key.

36 UM Config EAGLE
Release 3.4 03/2020
Specifying the IP parameters
2.1 IP parameter basics

2 Specifying the IP parameters

When you install the device for the first time, enter the IP parameters.

The device provides the following options for entering the IP parameters during the first installation:
 Entry using the Command Line Interface.
When you preconfigure your device outside its operating environment, or restore the network
access (“In-Band”) to the device, choose this “Out-of-Band” method.
 Entry using the HiDiscovery protocol.
When you have a previously installed network device or you have another Ethernet connection
between your PC and the device, you choose this “In-Band” method.
 Configuration using the external memory.
When you are replacing a device with a device of the same type and have already saved the
configuration in the external memory, you choose this method.
 Configuration using the Graphical User Interface.
When the device already has an IP address and is reachable using the network, the Graphical
User Interface provides you with another option for configuring the IP parameters.

2.1 IP parameter basics

2.1.1 IP address (version 4)

The IP addresses consist of 4 bytes. Write these 4 bytes in decimal notation, separated by a
decimal point.

RFC 1340 written in 1992, defines 5 IP Address classes.

Table 9: IP address classes

Class Network address Host address Address range


A 1 Byte 3 Bytes [Link] to [Link]
B 2 Bytes 2 Bytes [Link] to [Link]
C 3 Bytes 1 Byte [Link] to [Link]
D [Link] to [Link]
E [Link] to [Link]

The first byte of an IP address is the network address. The worldwide leading regulatory board for
assigning network addresses is the IANA ("Internet Assigned Numbers Authority"). When you
require an IP address block, contact your Internet Service Provider (ISP). Your ISP contacts their
local higher-level organization to reserve an IP address block:
 APNIC (Asia Pacific Network Information Center)
Asia/Pacific Region
 ARIN (American Registry for Internet Numbers)
Americas and Sub-Sahara Africa

UM Config EAGLE 37
Release 3.4 03/2020
Specifying the IP parameters
2.1 IP parameter basics

 LACNIC (Regional Latin-American and Caribbean IP Address Registry)


Latin America and some Caribbean Islands
 RIPE NCC (Réseaux IP Européens)
Europe and Surrounding Regions

0 Net ID - 7 bits Host ID - 24 bits Class A

I 0 Net ID - 14 bits Host ID - 16 bits Class B

I I 0 Net ID - 21 bits Host ID - 8 bit s Class C

I I I 0 Multicast Group ID - 28 bits Class D

I I I I reserved for future use - 28 b its Class E

Figure 10: Bit representation of the IP address

When the first bit of an IP address is a zero, it belong to class A for example, the first octet is less
than 128.

When the first bit of an IP address is a one and the second bit is a zero, it belongs to class B for
example, the first octet is between 128 and 191.

When the first 2 bits of an IP address are a one, it belongs to class C for example, the first octet is
higher than 191.

Assigning the host address (host ID) is the responsibility of the network operator. The network
operator alone is responsible for the uniqueness of the assigned IP addresses.

2.1.2 Netmask

Routers and Gateways subdivide large networks into subnetworks. The netmask asssigns the IP
addresses of the individual devices to a particular subnetwork.

You perform subnetwork division using the netmask in much the same way as the division of the
network addresses (net id) into classes A to C.

Set the bits of the host address (host id) that represent the mask to one. Set the remaining host
address bits to zero (see the following examples).

Example of a subnet mask:

Decimal notation
[Link]

Binary notation
11111111.11111111.11000000.00000000
Subnetwork mask bits
Class B

38 UM Config EAGLE
Release 3.4 03/2020
Specifying the IP parameters
2.1 IP parameter basics

Example of applying the subnet mask to IP addresses for subnetwork assignment:

Decimal notation
[Link]
128 < 129 191 › Class B
Binary notation
10000001.11011010.01000001.00010001
Subnetwork 1
Network address

Decimal notation
[Link]
128 < 129 191 › Class B
Binary notation
10000001.11011010.10000001.00010001
Subnetwork 2
Network address

Example of how the netmask is used

In a large network it is possible that Gateways and routers separate the management agent from
its network management station. How does addressing work in such a case?

Romeo

Juliet
Lorenzo

LAN 1
LAN 2

Figure 11: The management agent is separated from its network management station by a router

The network management station “Romeo” wants to send data to the management agent “Juliet”.
Romeo knows Juliet's IP address and also knows that the router “Lorenzo” knows the way to Juliet.

Romeo therefore puts his message in an envelope and writes Juliet's IP address as the destination
address; for the source address he writes his own IP address on the envelope.

Romeo then places this envelope in a second one with Lorenzo's MAC address as the destination
and his own MAC address as the source. This process is comparable to going from Layer 3 to
Layer 2 of the ISO/OSI base reference model.

Finally, Romeo puts the entire data packet into the mailbox which is comparable to going from
Layer 2 to Layer 1, that means to sending the data packet over the Ethernet.

UM Config EAGLE 39
Release 3.4 03/2020
Specifying the IP parameters
2.1 IP parameter basics

Lorenzo receives the letter, removes the outer envelope and recognizes from the inner envelope
that the letter is meant for Juliet. He places the inner envelope in a new outer envelope and
searches his address list (the ARP table) for Juliet's MAC address; he writes her MAC address on
the outer envelope as the destination address and his own MAC address as the source address.
He then places the entire data packet in the mail box.

Juliet receives the letter and removes the outer envelope. She finds the inner envelope with
Romeo's IP address. Opening the inner envelope and reading its contents corresponds to
transferring the message to the higher protocol layers of the ISO/OSI layer model.

Juliet would now like to send a reply to Romeo. She places her reply in an envelope with Romeo's
IP address as destination and her own IP address as source. But where is she to send the answer?
For she did not receive Romeo's MAC address. It was lost, because Lorenzo replaced the outer
envelope.

In the MIB, Juliet finds Lorenzo listed under the variable hm NetGatewayIPAddr as a means of
communicating with Romeo. She therefore puts the envelope with the IP addresses in a further
envelope with Lorenzo's MAC destination address.

The letter now travels back to Romeo via Lorenzo, the same way the first letter traveled from
Romeo to Juliet.

2.1.3 Classless Inter-Domain Routing

Class C with a maximum of 254 addresses was too small, and class B with a maximum of
65534 addresses was too large for most users. Resulting in an ineffective usage of the available
class B addresses.

Class D contains reserved Multicast addresses. Class E is for experimental purposes. A non-
participating Gateway ignores experimental datagrams with these destination addresses.

Since 1993, RFC 1519 has been using Classless Inter-Domain Routing (CIDR) to provide a
solution. CIDR overcomes these class boundaries and supports classless address ranges.

With CIDR, you enter the number of bits that designate the IP address range. You represent the IP
address range in binary form and count the mask bits that designate the netmask. The mask bits
equal the number of bits used for the subnet in a given IP address range.

Example:

IP address, Network mask, IP address,


decimal decimal binary
[Link] [Link] 11000000 10101000 01110000 00000001
[Link] 11000000 10101000 01110000 01111111
25 mask bits
CIDR notation: [Link]/25
Mask bits

The term “supernetting” refers to combing a number of class C address ranges. Supernetting
enables you to subdivide class B address ranges to a fine degree.

40 UM Config EAGLE
Release 3.4 03/2020
Specifying the IP parameters
2.2 Specifying the IP parameters using the Command Line Interface

2.2 Specifying the IP parameters using the Command Line


Interface

There are several methods you enter the system configuration, either using BOOTP/DHCP, the
HiDiscovery protocol, the external memory. You have the option of performing the configuration
over the serial interface using the Command Line Interface.

The device lets you specify the IP parameters using the HiDiscovery protocol or using the
Command Line Interface over the serial interface.

Entering IP addresses

Connect the PC with terminal


program started to the RJ11 socket

Command Line Interface


starts after key press

Log in and change to the


Privileged EXEC Mode

Enter and save IP parameters

End of entering IP addresses

Figure 12: Flow chart for entering IP addresses

UM Config EAGLE 41
Release 3.4 03/2020
Specifying the IP parameters
2.2 Specifying the IP parameters using the Command Line Interface

Note: If a terminal or PC with terminal emulation is unavailable in the vicinity of the installation
location, you can configure the device at your own workstation, then take it to its final installation
location.

 Set up a connection to the device.


The start screen appears.

 Enter the IP parameters.


 Local IP address
In the default setting, the local IP address is [Link].
 Netmask
When you divided your network into subnetworks, and these are identified with a netmask,
enter the netmask here. In the default setting, the local netmask is [Link].
 IP address of the Gateway.
This entry is only required, in cases where the device and the network management station
are located in different subnetworks (see on page 39 “Example of how the netmask is used”).
Specify the IP address of the Gateway between the subnetwork with the device and the path
to the network management station.
In the default setting, the IP address is [Link].
 Save the configuration specified using copy config running-config nvm.

enable Change to the Privileged EXEC mode.


network parms [Link] [Link] Assign the device the IP address [Link] and the
netmask [Link]. You have the option of also
assigning a Gateway address.
copy config running-config nvm Save the current settings in the non-volatile
memory (nvm) in the “selected” configuration profile.

After entering the IP parameters, you easily configure the device using the Graphical User
Interface.

42 UM Config EAGLE
Release 3.4 03/2020
Specifying the IP parameters
2.3 Specifying the IP parameters using HiDiscovery

2.3 Specifying the IP parameters using HiDiscovery

The HiDiscovery protocol enables you to assign IP parameters to the device using the Ethernet.

You easily configure other parameters using the Graphical User Interface.

Install the HiDiscovery software on your PC. The software is on the product DVD supplied with the
device.
 To install it, you start the installation program on the DVD.
 Start the HiDiscovery program.

Figure 13: HiDiscovery

When HiDiscovery is started, HiDiscovery automatically searches the network for those devices
which support the HiDiscovery protocol.

HiDiscovery uses the first network interface found for the PC. When your computer has several
network cards, you can select the one you desire in the HiDiscovery toolbar.

HiDiscovery displays a line for every device that responds to a HiDiscovery protocol inquiry.

HiDiscovery enables you to identify the devices displayed.


 Select a device line.
 To set the LEDs to flashing for the selected device, click the Signal button on the tool bar. To
stop the flashing, click the Signal button again.
 By double-clicking a line, you open a window in which you specify the device name and the IP
parameter.

Figure 14: HiDiscovery – assigning IP parameters

UM Config EAGLE 43
Release 3.4 03/2020
Specifying the IP parameters
2.3 Specifying the IP parameters using HiDiscovery

Note: Disable the HiDiscovery function in the device, after you have assigned the IP parameters to
the device.

Note: Save the settings so that you will still have the entries after a restart.

44 UM Config EAGLE
Release 3.4 03/2020
Specifying the IP parameters
2.4 Specifying the IP parameters using the Graphical User Interface

2.4 Specifying the IP parameters using the Graphical User


Interface

Perform the following steps:

 Open the Basic Settings > Network dialog.


In this dialog you first specify the source from which the device gets its IP parameters after
starting. You also define the VLAN in which the device management can be accessed,
configure the HiDiscovery access and allocate manual IP parameters.
 In the Management interface frame you first specify where the device gets its IP parameters
from:
 In the Local mode, the device uses the network parameters from the internal device
memory.
Note: When you change the allocation mode of the IP address, the device activates the new
mode immediately after you click the button.
 In the VLAN ID column you specify the VLAN in which the device management can be
accessed over the network.
 Note here that you can only access the device management using ports that are members
of the relevant VLAN.
The MAC address field displays the MAC address of the device with which you access the
device over the network.
 In the HiDiscovery protocol v1/v2 frame you specify the settings for accessing the device
using the HiDiscovery software.
 The HiDiscovery protocol lets you allocate an IP address to the device on the basis of its
MAC address. Activate the HiDiscovery protocol if you want to allocate an IP address to
the device from your PC with the HiDiscovery software.
 If required, you enter the IP address, the netmask and the Gateway in the IP parameter
frame.
 To save the changes temporarily, click the button.

UM Config EAGLE 45
Release 3.4 03/2020
Access to the device
3.1 First login (Password change)

3 Access to the device

3.1 First login (Password change)

To help prevent undesired access to the device, it is imperative that you change the default
password during initial setup.

Perform the following steps:


 Open the Graphical User Interface, the HiView application, or the Command Line Interface the
first time you log on to the device.
 Log on to the device with the default password.
The device prompts you to type in a new password.
 Type in your new password.
To help increase security, choose a password that contains at least 8 characters which includes
upper-case characters, lower-case characters, numerical digits, and special characters.
 When you log on to the device with the Command Line Interface, then the device prompts you
to confirm your new password.
 Log on to the device again with your new password.

Note: If you lost your password, then use the System Monitor to reset the password.

For further information see [Link].

46 UM Config EAGLE
Release 3.4 03/2020
Access to the device
3.2 Authentication lists

3.2 Authentication lists

When a user accesses the device using a specific connection, the device verifies the credentials of
the user in an authentication list which contains the policies that the device applies for
authentication.

The prerequisite for a user's access to the device management is that at least one policy is
assigned to the authentication list of the application through which access is performed.

3.2.1 Applications

The device provides an application for each type of connection through which someone accesses
the device:
 Access to the Command Line Interface using a serial connection: Console(V.24)
 Access to the Command Line Interface using SSH: SSH
 Access to the Graphical User Interface: WebInterface

3.2.2 Policies

When a user logs in with valid login data, the device lets the user have access to its device
management. The device authenticates the users using the following policies:
 User management of the device
 LDAP
 RADIUS

The device gives you the option of a fall-back solution. For this, you specify more than one policy
in the authentication list. When authentication is unsuccessful using the current policy, the device
applies the next specified policy.

UM Config EAGLE 47
Release 3.4 03/2020
Access to the device
3.2 Authentication lists

3.2.3 Managing authentication lists

You manage the authentication lists in the Graphical User Interface or in the Command Line
Interface.

Perform the following steps:

 Open the Device Security > Authentication List dialog.


The dialog displays the authentication lists that are set up.

show authlists Displays the authentication lists that are set up.

 Deactivate the authentication list for those applications by means of which no access to the
device is performed.

 In the Active column of the desired authentication list, unmark the checkbox.
 To save the changes temporarily, click the button.

authlists disable <AuthList> Deactivates the authentication list <AuthList>.

48 UM Config EAGLE
Release 3.4 03/2020
Access to the device
3.2 Authentication lists

3.2.4 Adjust the settings

Example:

Set up a separate authentication list for the application WebInterface which is by default included
in the authentication list defaultLoginAuthList. The device forwards authentication requests to
a RADIUS server in the network. As a fall-back solution, the device authenticates users using the
local user management.

Perform the following steps:


 Create an authentication list loginGUI.

 Open the Device Security > Authentication List dialog.


 Click the button.
The dialog displays the Create window.
 Enter a meaningful name in the Name field.
In this example, enter the name loginGUI.
 Click the Ok button.
The device adds a new table entry.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
authlists add loginGUI Creates the authentication list loginGUI.

 Select the policies for the authentication list loginGUI.

 In the Policy 1 column, select the value radius.


 In the Policy 2 column, select the value local.
 In the Policy 3 to Policy 5 columns, select the value reject to help prevent further fall-back.
 In the Active column, mark the checkbox.
 To save the changes temporarily, click the button.

authlists set-policy loginGUI radius Assigns the policies radius, local and reject to the
local reject reject reject authentication list loginGUI.
show authlists Displays the authentication lists that are set up.
authlists enable loginGUI Activates the authentication list loginGUI.

 Assign an application to the authentication list loginGUI.

 In the Device Security > Authentication List dialog, highlight the authentication list loginGUI.
 Click the button and then the Allocate applications item.
The dialog displays the Allocate applications window.
 In the left column, highlight the application WebInterface.

UM Config EAGLE 49
Release 3.4 03/2020
Access to the device
3.2 Authentication lists

 Click the button.


The right column now displays the application WebInterface.
 Click the Ok button.
The dialog displays the updated settings:
– The Dedicated applications column of authentication list loginGUI displays the
application WebInterface.
– The Dedicated applications column of authentication list defaultLoginAuthList does
not display the application WebInterface anymore.
 To save the changes temporarily, click the button.

show appllists Displays the applications and the allocated lists.


appllists set-authlist WebInterface Assigns the loginGUI application to the
loginGUI authentication list WebInterface.

50 UM Config EAGLE
Release 3.4 03/2020
Access to the device
3.3 User management

3.3 User management

When a user logs in with valid login data, the device lets the user have access to its device
management. The device authenticates the users either using the local user management or with
a RADIUS server in the network. To get the device to use the user management, assign the local
policy to an authentication list, see the Device Security > Authentication List dialog.

In the local user management, you manage the user accounts. One user account is usually
allocated to each user.

3.3.1 Access roles

The device lets you use a role-based authorization model to specifically control the access to the
device management. Users to whom a specific authorization profile is allocated are allowed to use
commands and functions from the same authorization profile or a lower one.

The device uses the authorization profiles on every application with which the device management
can be accessed.

UM Config EAGLE 51
Release 3.4 03/2020
Access to the device
3.3 User management

Every user account is linked to an access role that regulates the access to the individual functions
of the device. Depending on the planned activity for the respective user, you assign a pre-defined
access role to the user. The device differentiates between the following access roles.

Table 10: Access roles for user accounts

Role Description Authorized for the following activities


Administrator The user is authorized to All activities with read/write access, including the
monitor and administer the following activities reserved for an administrator:
device.  Add, modify or delete user accounts
 Activate, deactivate or unlock user accounts
 Change every password
 Configure password management
 Set or change system time
 Load files to the device, for example device
configurations, certificates or software images
 Reset settings and security-related settings to
the state on delivery
 Configure RADIUS server and authentication
lists
 Apply scripts using the Command Line
Interface
 Enable/disable CLI logging and SNMP logging
 External memory activation and deactivation
 System monitor activation and deactivation
 Enable/disable the services for the access to
the device management (for example SNMP).
 Configure access restrictions to the Graphical
User Interface or the Command Line Interface
based on the IP addresses
Operator The user is authorized to All activities with read/write access, with the
monitor and configure the exception of the above-named activities, which are
device - with the exception of reserved for an administrator:
security-related settings.
Auditor The user is authorized to Monitoring activities with read access.
monitor the device and to
save the log file in the
Diagnostics > Report > Audit
Trail dialog.
Guest The user is authorized to Monitoring activities with read access.
monitor the device - with the
exception of security-related
settings.
Unauthorized No access to the device No activities allowed.
possible.
 As an administrator you
assign this access role to
temporarily lock a user
account.
 If an administrator assigns
a different access role to
the user account and an
error occurs, then the
device assigns this
access role to the user
account.

52 UM Config EAGLE
Release 3.4 03/2020
Access to the device
3.3 User management

3.3.2 Managing user accounts

You manage the user accounts in the Graphical User Interface or in the Command Line Interface.

Perform the following steps:

 Open the Device Security > User Management dialog.


The dialog displays the user accounts that are set up.

show users Displays the user accounts that are set up.

3.3.3 Default setting

In the state on delivery, the user accounts admin and user are set up in the device.

Table 11: Default settings for the factory setting user accounts

Parameter Default setting


User name admin user
Password private public
Role administrator guest
User locked unmarked unmarked
Policy check unmarked unmarked
SNMP auth type hmacmd5 hmacmd5
SNMP encryption type des des

Change the password for the admin user account before making the device available in the
network.

UM Config EAGLE 53
Release 3.4 03/2020
Access to the device
3.3 User management

3.3.4 Changing default passwords

To help prevent undesired access, change the password of the default user accounts.

Perform the following steps:


 Change the passwords for the admin and user user accounts.

 Open the Device Security > User Management dialog.


The dialog displays the user accounts that are set up.
 To obtain a higher level of complexity for the password, mark the checkbox in the Policy
check column.
Before saving it, the device checks the password according to the policy specified in the
Password policy frame.
Note: The password check can lead to a message in the Security status frame in the Basic
Settings > System dialog. You specify the settings that cause this message in the Basic
Settings > System dialog.
 Click the row of the relevant user account in the Password field. Enter a password of at least
6 characters.
Up to 64 alphanumeric characters are allowed.
 The device differentiates between upper and lower case.
 The minimum length of the password is specified in the Configuration frame. The device
constantly checks the minimum length of the password.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
users password-policy-check <user> Activates the checking of the password for the
enable <user> user account based on the specified policy.
In this way, you obtain a higher level of complexity
for the password.
Note: When you display the security status, the password check can lead to a message (show
security-status all). You specify the settings that cause this message with the command
security-status monitor pwd-policy-inactive.
users password <user> SECRET Specifies the password <user> for the SECRET user
account. Enter at least 6 characters.
save Save the settings in the non-volatile memory (nvm)
in the “selected” configuration profile.

54 UM Config EAGLE
Release 3.4 03/2020
Access to the device
3.3 User management

3.3.5 Setting up a new user account

Allocate a separate user account to each user that accesses the device management. In this way
you can specifically control the authorizations for the access.

In the following example, we will set up the user account for a USER user with the role operator.
Users with the operator role are authorized to monitor and configure the device - with the
exception of security-related settings.

Perform the following steps:


 Create a new user account.

 Open the Device Security > User Management dialog.


 Click the button.
The dialog displays the Create window.
 Enter the name in the User name field.
In this example, we give the user account the name USER.
 Click the Ok button.
 To obtain a higher level of complexity for the password, mark the checkbox in the Policy
check column.
Before saving it, the device checks the password according to the policy specified in the
Password policy frame.
 In the Password field, enter a password of at least 6 characters.
Up to 64 alphanumeric characters are allowed.
 The device differentiates between upper and lower case.
 The minimum length of the password is specified in the Configuration frame. The device
constantly checks the minimum length of the password.
 In the Role column, select the user role.
In this example, we select the value operator.
 To activate the user account, mark the checkbox in the Active column.
 To save the changes temporarily, click the button.
The dialog displays the user accounts that are set up.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
users add USER Creates the USER user account.
users password-policy-check USER Activates the checking of the password for the USER
enable user account based on the specified policy. In this
way, you obtain a higher level of complexity for the
password.
users password USER SECRET Specifies the password USER for the SECRET user
account. Enter at least 6 characters.
users access-role USER operator Assign the user role operator to the user account
USER.
users enable USER Activates the USER user account.
show users Displays the user accounts that are set up.
save Save the settings in the non-volatile memory (nvm)
in the “selected” configuration profile.

Note: When you are setting up a new user account in the Command Line Interface, remember to

UM Config EAGLE 55
Release 3.4 03/2020
Access to the device
3.3 User management

allocate the password.

3.3.6 Deactivating the user account

After a user account is deactivated, the device denies the related user access to the device
management. In contrast to completely deleting it, deactivating a user account lets you keep the
settings and reuse them in the future.

Perform the following steps:


 To keep the user account settings and reuse them in the future, you temporarily deactivate the
user account.

 Open the Device Security > User Management dialog.


The dialog displays the user accounts that are set up.
 In the row for the relevant user account, unmark the checkbox in the Active column.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
users disable <user> To disable user account.
show users Displays the user accounts that are set up.
save Save the settings in the non-volatile memory (nvm)
in the “selected” configuration profile.

 To permanently deactivate the user account settings, you delete the user account.

 Highlight the row for the relevant user account.


 Click the button.

users delete <user> Deletes the <user> user account.


show users Displays the user accounts that are set up.
save Save the settings in the non-volatile memory (nvm)
in the “selected” configuration profile.

56 UM Config EAGLE
Release 3.4 03/2020
Access to the device
3.3 User management

3.3.7 Adjusting policies for passwords

The device lets you check whether the passwords for the user accounts adhere to the specified
policy. When the passwords adhere to the policy, you obtain a higher level of complexity for the
passwords.

The user management of the device lets you activate or deactivate the check separately in each
user account. When you mark the checkbox and the new password fulfills the requirements of the
policy, the device accepts the password change.

In the default settings, practical values for the policy are set up in the device. You have the option
of adjusting the policy to meet your requirements.

Perform the following steps:


 Adjust the policy for passwords to meet your requirements.

 Open the Device Security > User Management dialog.


In the Configuration frame you specify the number user login attempts before the device locks
out the user. You also specify the minimum number of characters that defines a password.
 Specify the values to meet your requirements.
 You specify the number of times that a user attempts to log on to the device in the Login
attempts field. The field lets you define this value in the range 0..5.
In the above example, the value 0 deactivates the function.
 The Min. password length field lets you enter values in the range 1..64.
The dialog displays the policy set up in the Password policy frame.
 Adjust the values to meet your requirements.
 Values in the range 1 through 16 are allowed.
The value 0 deactivates the relevant policy.
To apply the entries specified in the Configuration and Password policy frames, mark the
checkbox in the Policy check column for a particular user.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
passwords min-length 6 Specifies the policy for the minimum length of the
password.
passwords min-lowercase-chars 1 Specifies the policy for the minimum number of
lower-case letters in the password.
passwords min-numeric-chars 1 Specifies the policy for the minimum number of
digits in the password.
passwords min-special-chars 1 Specifies the policy for the minimum number of
special characters in the password.
passwords min-uppercase-chars 1 Specifies the policy for the minimum number of
upper-case letters in the password.
show passwords Displays the policies that are set up.
save Save the settings in the non-volatile memory (nvm)
in the “selected” configuration profile.

UM Config EAGLE 57
Release 3.4 03/2020
Access to the device
3.4 LDAP

3.4 LDAP

Server administrators manage Active Directorys which contain user login credentials for
applications used in the office environment. The Active Directory is hierarchical in nature,
containing user names, passwords, and the authorized read/write permission levels for each user.

This device uses the Lightweight Directory Access Protocol (LDAP) to retrieve user login
information and permission levels from a Active Directory. This provides a “single sign on“ for
network devices. Retrieving the credentials from an Active Directory lets the user login to the device
with the same credentials used in the office environment.

An LDAP session starts with the device contacting the Directory System Agent (DSA) to search the
Active Directory of an LDAP server. If the server finds multiple entries in the Active Directory for a
user, then the server sends the higher permission level found. The DSA listens for information
requests and sends responses on TCP port 389 for LDAP, or on TCP port 636 for LDAP over SSL
(LDAPS). Clients and servers encode LDAPS requests and responses using the Basic Encoding
Rules (BER). The device opens a new connection for every request and closes the connection after
receiving a response from the server.

The device lets you upload a CA certificate to validate the server for Secure Socket Level (SSL)
and Transport Layer Security (TLS) sessions. Whereby, the certificate is optional for TLS sessions.

The device is able to cache credentials for up to 1024 users in memory. If the active directory
servers are unreachable, then the users are still able to login using their office credentials.

3.4.1 Coordination with the server administrator

Configuring the LDAP function requires that the network administrator request the following
information from the server administrator:
 The server name or IP address
 The location of the Active Directory on the server
 The type of connection used
 The TCP listening port
 When required, the location of the CA certificate
 The name of the attribute containing the user login name
 The names of the attribute containing the user permission levels

The server administrator can assign permission levels individually using an attribute such as
description, or to a group using the memberOf attribute. In the Device Security > LDAP > Role
Mapping dialog you specify which attributes receive the various permission levels.

You also have the option to retrieve the name of the attributes containing the user login name and
permission levels using a LDAP browser such as JXplorer or Softerra.

58 UM Config EAGLE
Release 3.4 03/2020
Access to the device
3.4 LDAP

3.4.2 Example configuration

The device is able to establish an encrypted link to a local server using only the server name or to
a server on a different network using an IP address. The server administrator uses attributes to
identify credentials of a user and assign individual and group permission levels.

Using information received from the server administrator, specify which attributes in the Active
Directory contain the user credentials and permission level. The device then compares the user
credentials with the permission levels specified in the device and lets the user login at the assigned
permission level.

Primary Backup
Server Server

[Link] [Link]

Figure 15: LDAP Example Configuration

For this example, the server administrator sent the following information:

Information Primary Server Backup Server


The server name or IP address [Link] [Link]
The location of the Active Country/City/User Country/Company/User
Directory on the server
The type of connection used TLS (with certificate) SSL
The server administrator sent CA certificate for primary server CA certificate for backup server
the CA certificate in an email. saved locally saved locally
The TCP listening port 389 (tls) 636 (ssl)
Name of the attribute containing userPrincipalName userPrincipalName
the user name
The names of the attribute OPERATOR OPERATOR
containing the user permission ADMINISTRATOR ADMINISTRATOR
levels

UM Config EAGLE 59
Release 3.4 03/2020
Access to the device
3.4 LDAP

 Open the Device Security > Authentication List dialog.


 To configure the device to retrieve the user credentials, during log in using the Graphical
User Interface, from the Active Directory first, specify for the defaultLoginAuthList list
the value ldap in thePolicy 1 column.
 Open the Device Security > LDAP > Configuration dialog.
 The device lets you specify the length of time that it saves the login credentials in the
cache. To cache user credentials for a day, in the Configuration frame, Client cache timeout
[min] field, enter the value 1440.
 The Bind user entry is optional. When specified, users enter only their user name to log on
to the device. The service user can be anyone with credentials listed in the Active Directory
under the attribute specified in the User name attribute column. In the Bind user column, enter
the user name and the domain.
 The Base DN is a combination of the domain component (dc) and the organizational unit
(ou). The Base DN lets the device locate a server in a domain (dc) and find the Active
Directory (ou). Specify the location of the Active Directory. In the Base DN column, specify
the value ou=Users,ou=City,ou=Country,dc=server,dc=local.
 In the User name attribute column, enter the value userPrincipalName to specify the
attribute under which the server administrator lists the users.
The device uses a CA certificate to verify the server.
 When the certificate is located on your PC or on a network drive, drag and drop the
certificate in the area. Alternatively click in the area to select the certificate.
 To transfer the CA certificate onto the device, click the Start button.
 To add a table entry, click the button.
 To specify a description, enter the value Primary AD Server in the Description column.
 To specify the server name and domain of the primary server, in the Address column, enter
the value [Link].
 The primary server uses the TCP port 389 for communication which is the Destination TCP
port default value.
 The primary server uses TLS for encrypting communication and a CA certificate for server
validation. In the Connection security column, specify the value startTLS.
 To activate the entry, mark the checkbox in the Active column.
 Using the information received from the server administrator for the Backup server, add,
configure and activate another row.

 Open the Device Security > LDAP > Role Mapping dialog.
 To add a table entry, click the button.
When a user logs on to the device, with LDAP configured and enabled, the device searches
the Active Directory for the credentials of the user. If the device finds the user name and the
password is correct, then the device searches for the value specified in the Type column. If the
device finds the attribute and the text in the Parameter column matches the text in the Active
Directory, then the device lets the user login with the assigned permission level. When the
value attribute is specified in the Type column, specify the value in the Parameter column in
the following form: attributeName=attributeValue.
 In the Role column, enter the value operator to specify the user role.
 To activate the entry, mark the checkbox in the Active column.

60 UM Config EAGLE
Release 3.4 03/2020
Access to the device
3.4 LDAP

 Click the button.


The dialog displays the Create window.
Enter the values received from the server administrator for the administrator role.
To activate the entry, mark the checkbox in the Active column.
 Open the Device Security > LDAP > Configuration dialog.
 To enable the function, select the On radio button in the Operation frame.

The following table describes how to configure the LDAP function in the device using the Command
Line Interface. The table displays the commands for Index 1. To configure Index 2, use the same
commands and substitute the appropriate information.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
ldap cache-timeout 1440 Specify the device to flush the non-volatile memory
after a day.
ldap client server add 1 [Link] Add a connection to the remote authentication
port 389 client server with the host name [Link] and the
UDP port 389.
ldap client server modify 1 security Specify the type of security used for the
startTLS connection.
ldap client server modify 1 description Specify the configuration name of the entry.
Primary_AD_Server
ldap basedn Specify the Base Domain Name used to find the
ou=Users,ou=City,ou=Country,dc=server, Active Directory on the server.
dc=local
ldap search-attr userPrincipalName Specify the attribute to search for in the Active
Directory which contains the credential of the
users.
ldap bind-user user@[Link] Specify the name and domain of the service user.
ldap bind-passwd Ur-123456 Specify the password of the service user.
ldap client server enable 1 Enable the remote authentication client server
connection.
ldap mapping add 1 access-role operator Add a remote authentication role mapping entry for
mapping-type attribute mapping- the Operator role. Map the operator role to the
parameter OPERATOR
attribute containing the word OPERATOR.
ldap mapping enable 1 Enable the remote authentication role mapping
entry.
ldap operation Enable the remote authentication function.

UM Config EAGLE 61
Release 3.4 03/2020
Access to the device
3.5 SNMP access

3.5 SNMP access

The SNMP protocol lets you work with a network management system to monitor the device over
the network and change its settings.

3.5.1 SNMPv1/v2 access

Using SNMPv1 or SNMPv2 the network management system and the device communicate
unencrypted. Every SNMP packet contains the community name in plain text and the IP address
of the sender.

The community names public for read accesses and private for write accesses are preset in the
device. If SNMPv1/v2 is enabled, then the device lets anyone who knows the community name
have access to the device.

Make the following basic provisions to make undesired access to the device more difficult:
 Change the default community names in the device.
Treat the community names with discretion.
Anyone who knows the community name for write access, has the ability to change the settings
of the device.
 Specify a different community name for read/write access than for read access.
 Use SNMPv1 or SNMPv2 only in environments protected from eavesdropping. The protocols
do not use encryption.
 We recommend using SNMPv3 and disabling the access using SNMPv1 and SNMPv2 in the
device.

62 UM Config EAGLE
Release 3.4 03/2020
Access to the device
3.5 SNMP access

3.5.2 SNMPv3 access

Using SNMPv3 the network management system and the device communicate encrypted. The
network management system authenticates itself with the device using the credentials of a user.
The prerequisite for the SNMPv3 access is that in the network management system uses the same
settings that are defined in the device.

The device lets you specify the SNMP auth type and SNMP encryption type parameters individually in
each user account.

When you set up a new user account in the device, the parameters are preset so that the network
management system Industrial HiVision reaches the device immediately.

The user accounts set up in the device use the same passwords in the Graphical User Interface, in
the Command Line Interface, and for SNMPv3.

To adapt the SNMPv3 parameters of the user account settings to the settings in your network
management system, perform the following steps:

 Open the Device Security > User Management dialog.


The dialog displays the user accounts that are set up.
 Click the row of the relevant user account in the SNMP auth type field. Select the desired
setting.
 Click the row of the relevant user account in the SNMP encryption type field. Select the
desired setting.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
users snmpv3 authentication <user> Assigning the HMAC-MD5 or HMACSHA protocol
md5 | sha1 for authentication requests to the <user> user
account.
users snmpv3 encryption <user> des | Assigns the DES or AES-128 algorithm to the
aescfb128 | none <user> user account.
With this algorithm, the device encrypts
authentication requests. The value none removes
the encryption.
show users Display the user accounts that have been
configured.
save Save the settings in the non-volatile memory (nvm)
in the “selected” configuration profile.

UM Config EAGLE 63
Release 3.4 03/2020
VPN – Virtual Private Network
4.1 IPsec – Internet Protocol Security

4 VPN – Virtual Private Network

A virtual private network (VPN) refers to the part of a public network that someone uses for their
private purposes.

The special feature of a VPN, as the name “private” suggests, is that the VPN tunnels the private
data through a public network. Different measures help protect the data of the virtual private
network from spying, data falsification and other attacks from external subscribers.

In the industrial environment, for example, a VPN serves to connect 2 plant sections with each other
using the public Internet.

[Link]/8
[Link]/8

Figure 16: VPN for connecting 2 plant sections

4.1 IPsec – Internet Protocol Security

IPsec is a protocol suite that authenticates and encrypts data packets sent over public networks.

Data transmission in a VPN involves:


 Integrity protection
Integrity protection helps verify that the data transmitted is genuine, for example, that the data
source is a trustworthy sender (is authentic) and that the recipient receives the data in its true
form.
 Encryption
Encryption helps protect the data prohibiting unauthorized persons from viewing the data.
Encryption procedures code the data being transmitted using a code (key) that is only available
to the authorized communication subscribers.
 Traffic flow confidentiality
The traffic flow confidentiality helps protect the identification of the recipient and sender of the
data packet from unauthorized person.
IPsec performs this in the tunnel mode by encrypting the complete IP packet.

64 UM Config EAGLE
Release 3.4 03/2020
VPN – Virtual Private Network
4.1 IPsec – Internet Protocol Security

The 2 endpoints negotiation which security parameters to use on the VPN connection. IPsec
provides 2 modes for the negotiations
 Transport mode
In the transport mode, the 2 endpoints authenticate themselves to each other, then they set up
the parameters required for signatures and encryption. As the communication is taking place
between the 2 specific endpoints, the recipient and sender addresses remain visible.
 Tunnel mode
In the tunnel mode, the 2 Routers/Gateways authenticate themselves to each other, then they
set up the parameters required for signatures and encryption.
With the 2 Routers/Gateways specific, the VPN connection has 2 addressable endpoints. But
the communication takes place between the subscribers of the network connected to the
Routers/Gateways. This enables the transmission of encryption communication data, including
the recipient and sender addresses. The endpoints of the VPN connection use the addresses
of the Routers/Gateways to send data.
The device also lets you use the tunnel mode for the VPN connection between an endpoint and
a Router/Gateway. Thus, the address data within the network connected to the Router/Gateway
remains hidden.

UM Config EAGLE 65
Release 3.4 03/2020
VPN – Virtual Private Network
4.2 IKE – Internet Key Exchange

4.2 IKE – Internet Key Exchange

IPsec uses the IKE protocol (Internet Key Exchange) for authentication, for exchanging keys and
for agreeing on further parameters for the security arrangement of a VPN connection.

4.2.1 Authentication

Use authentication as part of the security arrangement. During authentication, the connection peers
display each other their ID cards, so to speak.

This ID card consists of the following:


 a pre-shared key, which is a character string previously exchanged using a different
communication channel.
 a digital certificate, which was issued by a certification authority (CA).
Certificates based on the X.509 standard contain the following:
– information about the certification authority
– validity period of the certificate
– information about the permitted usage
– the designated name (X.500 DN), which is the identity of the person that the certification
authority assigned the certificate too
– the public key belonging to this identity
– the digital signature for verifying the connection between this identity and its related public
key
Larger companies and authorities usually have their own certification authority.
A commonly used file extension for a certificate based on the PKCS#12 standard is .p12.
You can also find the information contained in a PKCS#12 file separately in individual files with
the file extension .pem.

4.2.2 Encryption

To help protect the data, IKE uses various cryptographic algorithms for data encryption. The
endpoints of the VPN connection require the key to code and decode the data.

The following list contains the initial steps in setting up the IKE security arrangement between the
VPN connection endpoints:
 the endpoints agree on a cryptographic algorithm which subsequently uses the key for coding
and decoding the IKE protocol messages
 the endpoints specify the time periods during which the key exchange takes place
 the endpoints identify the devices on which the coding and decoding takes place. The
administrator specifies the endpoints beforehand in the settings of each endpoint.

After the endpoints complete the steps listed above, the devices agree on the key to code and
decode the data.

4.2.3 Creating a certificate using OpenSSL

Using OpenSSL lets you create and sign a server certificate to use for VPN authentication.

66 UM Config EAGLE
Release 3.4 03/2020
VPN – Virtual Private Network
4.2 IKE – Internet Key Exchange

To create a certificate, perform the following steps. You need a text editor that correctly handles
Unix line breaks, for example the Notepad++ program.
 Download OpenSSL from [Link] and install the application.
 Specify the install directory c:\openssl and accept the other installation defaults.
 Start the Command Prompt program on your computer.
 To create the appropriate directories and files, enter the following commands in the
Administrator window in the Command Prompt window:
C:\Users\username> cd \
C:\> cd openssl
C:\OpenSSL> md certs
C:\OpenSSL> cd certs
C:\OpenSSL\certs> md nameCA
C:\OpenSSL\certs> md nameCA\newcerts
C:\OpenSSL\certs> notepad++ nameCA\[Link]
 Save the [Link] file and exit the Notepad++
program.
 In the Command Prompt window, create a file named [Link], with the following command:
C:\OpenSSL\certs> notepad++ nameCA\[Link]
 Open the [Link] file using the Notepad++ program.
 In the Notepad++ window, enter the value 01 on the first line.
 Save the [Link] file and exit the Notepad++ program.
 To set the path to the OpenSSL application, enter the following command in the Command
Prompt window:
C:\> set path=c:\openssl\bin;%path%
 To set the path to the OpenSSL configuration file, enter the following command in the Command
Prompt window:
C:\OpenSSL\certs> set OPENSSL_CONF=c:\openssl\bin\[Link]
 Using a text editor, edit the configuration file [Link] located in the c:\openssl\bin directory.
The countryName and stateOrProvinceName values are optional. Therefore change the value match
to optional. Save the settings. The resulting configuration is as follows:
# For the CA policy
[ policy_match ]
countryName = optional
stateOrProvinceName = optional
organizationName = match
organizationalUnitName = optional
commonName = supplied
emailAddress = optional
 To create an RSA certificate named [Link], enter the following commands in the Command
Prompt window:
C:\OpenSSL\certs> openssl genrsa -out [Link] 1024

The window displays the following text during certificate generation:


Loading 'screen' into random state - done
Generating RSA private key, 1024 bit long modulus
.................++++++
...........................................................++++++
e is 65537 (0x10001)

The OpenSSL application also lets you generate other certificate types. To display the various
certificate types, open the [Link] application located in the c:\OpenSSL\bin directory, and enter
the ? character in the Command Prompt window.
 To create and sign a Certificate Signing Request (CSR), enter the following commands in the
Command Prompt window:
C:\OpenSSL\certs> openssl req -new -x509 -days 365 -key [Link] -out nameCA/[Link]
 When requested, enter the appropriate distinguished name (DN) information for the CA
certificate. When you press the <Enter> key, you can leave the optional fields blank.
 For example, enter the following values:
Country Name: ch

UM Config EAGLE 67
Release 3.4 03/2020
VPN – Virtual Private Network
4.2 IKE – Internet Key Exchange

State or Province Name: SWISS


Locality Name: Baden
Organization Name: ABB Switzerland Ltd
Org. Unit Name: POWER SYSTEMS
Common Name: EAGLE-FD122E

68 UM Config EAGLE
Release 3.4 03/2020
VPN – Virtual Private Network
4.3 Application examples

4.3 Application examples

The following examples describe the special features occurring in frequently used applications.

4.3.1 Connecting 2 subnetworks

In a large company network, a transfer network connects the subnetworks to each other. A VPN
connects 2 of these subnetworks for example, the production control and the production hall. To
hide the internal IP addresses, configure the VPN to function in the tunnel mode.

The following information about the VPN is available:

Parameter Router 1 Router 2


IP address of internal port [Link] [Link]
IP address of external port [Link] [Link]
Pre-shared key 123456abcdef 123456abcdef
Start IKE mode as Initiator Responder
IP parameters of the connecting [Link]/24 [Link]/24
networks

Prerequisite for further configuration:


 Both device 1 and 2 are in the router mode.
 Specify the IP parameters on the router interfaces.
 The devices in the [Link]/24 subnet have the IP address of the internal interface on Router 1,
as their Gateway.

UM Config EAGLE 69
Release 3.4 03/2020
VPN – Virtual Private Network
4.3 Application examples

1 transfer network 2
[Link]/24
[Link]/24
[Link]/24

internal external external internal


Figure 17: Connecting 2 subnetworks using a transfer network

Perform the following steps:


 Create a VPN connection.

 Open the Virtual Private Network > Connections dialog.


 Click the button.
The Create or select entry table displays the VPN connections already available in the device.
 In the VPN index field, enter an available index number.
 In the VPN description column, specify a connection name for example, Production
Control - Production Hall 1.
 Click the Next button.

 Specify the authentication parameters.

The device uses the values specified in the Authentication dialog to validate its identity. In this
example, the device authenticates itself using a pre-shared key.
 Select in the Authentication type frame, Authentication type field the value Pre-shared key (PSK).
 In the Pre-shared key (PSK) frame, specify the following settings:
 The value 123456abcdef in the Pre-shared key column
 The value 123456abcdef in the Confirm column
The default setting of the Change checkbox lets you enter and confirm the pre-shared key for
new VPN connections. For existing VPN connections the Pre-shared key and the Confirm fields
are inactive. To activate the fields, mark the checkbox in the Change column.
 Click the Next button.

 Specify the Endpoint and Traffic Selector parameters.

The device uses the values specified in the Endpoint and traffic selectors dialog to identify the
data source and destination. The table displays the type of data to send through the VPN
tunnel.
 In the Endpoints frame, specify the following settings:
 The value [Link] in the Local endpoint column
 The value [Link] in the Remote endpoint column

In the current example, the external ports of the 2 device are the endpoints for of the VPN
connection.
 To identify data that the device sends through the VPN tunnel, click the Add traffic selector
button in the Add traffic selector frame.

70 UM Config EAGLE
Release 3.4 03/2020
VPN – Virtual Private Network
4.3 Application examples

 In the Add traffic selector dialog, specify the following settings:


 The value 1 in the Traffic selector index column
The device enters the index number, but also lets you change it.
 The value Any Traffic in the Traffic selector description column
 The value [Link]/24 in the Source address (CIDR) column
 The value in the Source restrictions column is optional.
The default setting is any/any. The device sends only the type of data specified through
the VPN tunnel.
 The value [Link]/24 in the Destination address (CIDR) column
 The value in the Destination restrictions column is optional.
The default setting is any/any. The device excepts only the specified type of data from
the VPN tunnel.
 Click the Ok button.
 Click the Next button.

UM Config EAGLE 71
Release 3.4 03/2020
VPN – Virtual Private Network
4.3 Application examples

 Enter the IKE key exchange IPSec parameters.

The device uses the values specified in the Advanced configuration dialog . In this example, the
device .
 In the General frame, Margin time [s] field, the default setting is 540 s. This is equal to 9
minutes.
 In the IKE/Key-exchange frame, specify the following settings:
 The value auto in the Version column
With this, the device selects the protocol version automatically, depending on the VPN
remote terminal.
 The value initiator in the Startup column
The device initiates the VPN connection to the remote terminal.
 The value email in the IKE local identifier type column
 For example, the value user1@[Link] in the IKE local ID column
 The value email in the Remote identifier type column
 For example, the value user2@[Link] in the Remote ID column
 The value main in the IKE exchange mode column
 The value modp1024 in the IKE key agreement column
 The value hmacsha1 in the IKE integrity (MAC) column
 The value aes128 in the IKE encryption column
 The value 120 in the DPD timeout [s] column
If the device does not receive a sign of life from the remote terminal within 120 seconds,
then it terminates the VPN connection.
 The value 28800 in the IKE lifetime [s] column
After the lifetime elapses, the 2 participating devices agree on new keys for the IKE
security arrangement (IKE SA). The lifetime provides a periodic key change for the IKE
SA.
 In the IPSec/Data-exchange frame, specify the following settings:
 The value modp1024 in the IPsec key agreement column
 The value hmacsha1 in the IPsec integrity (MAC) column
 The value aes128 in the IPsec encryption column
 The value 3600 in the IPsec lifetime [s] column
 To apply the changes, click the Finish button.

 Activate the connection.

 To activate the connection, mark the checkbox in the VPN active column.

 Save the settings.

 To save the changes temporarily, click the button.

 Make exactly the same settings on both devices.


On the second device, replace the IP address and specify the value responder in the Startup
column.

72 UM Config EAGLE
Release 3.4 03/2020
Managing configuration profiles
5.1 Detecting changed settings

5 Managing configuration profiles

If you change the settings of the device during operation, then the device stores the changes in its
memory (RAM). After a reboot the settings are lost.

In order to keep the changes after a reboot, the device lets you save additional settings in a
configuration profile in the non-volatile memory (NVM). In order to make it possible to quickly switch
to other settings, the non-volatile memory offers storage space for multiple configuration profiles.

If an external memory is connected, then the device saves a copy of the configuration profile in the
external memory automatically. This function can be deactivated.

5.1 Detecting changed settings

The device stores changes made to settings during operation in its volatile memory (RAM). The
configuration profile in the non-volatile memory (NVM) remains unchanged until you save it. Until
then, the configuration profiles in memory and non-volatile memory are different.

This device helps you recognize changed settings. When the configuration profile in the memory
(RAM) is different from the "selected" configuration profile in the non-volatile memory (NVM), you can
recognize the difference based on the following criteria:

The status bar at the top of the menu displays the blinking icon. When the configuration
profiles match, the icon is hidden.
In the Basic Settings > Load/Save dialog, the checkbox in the Information frame is unmarked.
When the configuration profiles match, the checkbox is marked.

show config status

Configuration Storage sync State


--------------------------------
running-config to NV........................out of sync
...

When the copy in the external memory is different from the configuration profile in the non-volatile
memory, you see the difference based on the following criteria:

In the Basic Settings > Load/Save dialog, the checkbox in the Information frame is unmarked. If
the configuration profiles match, the checkbox is marked.

show config status

Configuration Storage sync State


--------------------------------
...
NV to ACA...................................out of sync
...

UM Config EAGLE 73
Release 3.4 03/2020
Managing configuration profiles
5.2 Saving the settings

5.2 Saving the settings

5.2.1 Saving the configuration profile in the device

If you change the settings of the device during operation, then the device stores the changes in its
memory (RAM). In order to keep the changes after a reboot, save the configuration profile in the non-
volatile memory (NVM).

Saving a configuration profile

The device stores the settings in the "selected" configuration profile in the non-volatile memory
(NVM).

Perform the following steps:

 Open the Basic Settings > Load/Save dialog.


 Verify that the required configuration profile is "Selected".
You can recognize the “selected” configuration profile because the checkbox in the
Selected column is marked.
 Click the button.

show config profiles nvm Displays the configuration profiles contained in the
non-volatile memory (nvm).
enable Change to the Privileged EXEC mode.
save Save the settings in the non-volatile memory (nvm)
in the “selected” configuration profile.

74 UM Config EAGLE
Release 3.4 03/2020
Managing configuration profiles
5.2 Saving the settings

Copying settings to a configuration profile

The device lets you store the settings saved in the memory (RAM) in a configuration profile other
than the "selected" configuration profile. In this way you create a new configuration profile in the
non-volatile memory (NVM) or overwrite an existing one.

Perform the following steps:

 Open the Basic Settings > Load/Save dialog.


 Click the button and then the Save As.. item.
The dialog displays the Save As.. window.
 In the Name field, change the name of the configuration profile. If you keep the proposed
name, the device will overwrite an existing configuration profile of the same name.
 Click the Ok button.
The new configuration profile is designated as “Selected”.

show config profiles nvm Displays the configuration profiles contained in the
non-volatile memory (nvm).
enable Change to the Privileged EXEC mode.
copy config running-config nvm profile Save the current settings in the configuration
<string> profile named <string> in the non-volatile memory
(nvm). If present, the device overwrites a
configuration profile of the same name. The new
configuration profile is designated as “Selected”.

Selecting a configuration profile

When the non-volatile memory (NVM) contains multiple configuration profiles, you have the option
to select any configuration profile there. The device stores the settings in the “selected”
configuration profile. Upon reboot, the device loads the settings of the “selected” configuration
profile into the memory (RAM).

Perform the following steps:

 Open the Basic Settings > Load/Save dialog.


The table displays the configuration profiles present in the device. You can recognize the
“selected” configuration profile because the checkbox in the Selected column is marked.
 In the table, select the entry of the required configuration profile stored in the non-volatile
memory (NVM).
 Click the button and then the Select item.
In the Selected column, the checkbox of the configuration profile is now marked.

enable Change to the Privileged EXEC mode.


show config profiles nvm Displays the configuration profiles contained in the
non-volatile memory (nvm).

UM Config EAGLE 75
Release 3.4 03/2020
Managing configuration profiles
5.2 Saving the settings

configure Change to the Configuration mode.


config profile select nvm 1 Identifier of the configuration profile.
Take note of the adjacent name of the
configuration profile.
save Save the settings in the non-volatile memory (nvm)
in the “selected” configuration profile.

5.2.2 Saving the configuration profile in the external memory

When an external memory is connected and you save a configuration profile, the device
automatically saves a copy in the Selected external memory. In the default setting, the function is
enabled. You can disable this function.

Perform the following steps:

 Open the Basic Settings > External Memory dialog.


 Mark the checkbox in the Backup config when saving column in order to enable the device to
automatically save a copy in the external memory during the saving process.
 To deactivate the function, unmark the checkbox in the Backup config when saving column.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
config envm config-save usb Enable the function.
When you save a configuration profile, the device
saves a copy in the external memory.
usb = External USB memory
save Save the settings in the non-volatile memory (nvm)
in the “selected” configuration profile.

5.2.3 Exporting a configuration profile

The device lets you save a configuration profile to a server as an XML file. If you use the Graphical
User Interface, then you have the option to save the XML file directly to your PC.

Prerequisites:
 To save the file on a server, you need a configured server on the network.
 To save the file to an SCP or SFTP server, you also need the username and password for
accessing this server.

Perform the following steps:

 Open the Basic Settings > Load/Save dialog.


 In the table, select the entry of the required configuration profile.

76 UM Config EAGLE
Release 3.4 03/2020
Managing configuration profiles
5.2 Saving the settings

To export the configuration profile to your PC, perform the following steps:

 Click the link in the Profile name column.


 Select the storage location and specify the file name.
 Click the Ok button.
The configuration profile is now saved as an XML file in the specified location.

To export the configuration profile to a remote server, perform the following steps:

 Click the button and then the Export... item.


The dialog displays the Export... window.
 In the URL field, specify the file URL on the remote server:

 Click the Ok button.
The configuration profile is now saved as an XML file in the specified location.

show config profiles nvm Displays the configuration profiles contained in the
non-volatile memory (nvm).
enable Change to the Privileged EXEC mode.
copy config nvm remote sftp:// Save the selected configuration profile in the non-
<user_name>:<password>@<IP_address>/ volatile memory (nvm) on a SFTP server.
<path>/<file_name>

UM Config EAGLE 77
Release 3.4 03/2020
Managing configuration profiles
5.3 Loading settings

5.3 Loading settings

If you save multiple configuration profiles in the memory, then you have the option to load a different
configuration profile.

5.3.1 Activating a configuration profile

The non-volatile memory of the device can contain multiple configuration profiles. If you activate a
configuration profile stored in the non-volatile memory (NVM), then you immediately change the
settings in the device. The device does not require a reboot.

Perform the following steps:

 Open the Basic Settings > Load/Save dialog.


 In the table, select the entry of the required configuration profile.
 Click the button and then the Activate item.
The device copies the settings to the memory (RAM) and disconnects from the Graphical User
Interface. The device immediately uses the settings of the configuration profile.
 Reload the Graphical User Interface.
 Log in again.
In the Selected column, the checkbox of the configuration profile that was activated before is
marked.

show config profiles nvm Displays the configuration profiles contained in the
non-volatile memory (nvm).
enable Change to the Privileged EXEC mode.
copy config nvm profile config3 Activate the settings of the configuration profile
running-config config3 in the non-volatile memory (nvm).
The device copies the settings into the volatile
memory and disconnects the connection to the
Command Line Interface. The device immediately
uses the settings of the configuration profile
config3.

78 UM Config EAGLE
Release 3.4 03/2020
Managing configuration profiles
5.3 Loading settings

5.3.2 Loading the configuration profile from the external memory

If an external memory is connected, then the device loads a configuration profile from the external
memory upon restart automatically. The device lets you save these settings in a configuration
profile in non-volatile memory.

When the external memory contains the configuration profile of an identical device, you have the
possibility to transfer the settings from one device to another.

Perform the following steps:


 Verify that the device loads a configuration profile from the external memory upon restart.
In the default setting, the function is enabled. If the function is disabled, enable it again as
follows:

 Open the Basic Settings > External Memory dialog.


 In the Config priority column, select the value first.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
config envm load-priority usb first Enable the function.
Upon reboot, the device loads a configuration
profile from the external memory.
usb = External USB memory
show config envm settings Displays the settings of the external memory (envm).

Type Status Auto Update Save Config Config Load Prio


------ ----------- ----------- ----------- ----------------
usb ok [x] [x] first

save Save the settings in a configuration profile in the


non-volatile memory (NVM) of the device.

Using the Command Line Interface, the device lets you copy the settings from the external memory
directly into the non-volatile memory (NVM).

show config profiles nvm Displays the configuration profiles contained in the
non-volatile memory (nvm).
enable Change to the Privileged EXEC mode.
copy config envm profile config3 nvm Copy the configuration profile config3 from the
external memory (envm) to the non-volatile memory
(nvm).

UM Config EAGLE 79
Release 3.4 03/2020
Managing configuration profiles
5.3 Loading settings

5.3.3 Importing a configuration profile

The device lets you import from a server a configuration profile saved as an XML file. If you use the
Graphical User Interface, then you can import the XML file directly from your PC.

Prerequisites:
 To save the file on a server, you need a configured server on the network.
 To save the file to an SCP or SFTP server, you also need the username and password for
accessing this server.

Perform the following steps:

 Open the Basic Settings > Load/Save dialog.


 Click the button and then the Import... item.
The dialog displays the Import... window.
 In the Select source drop-down list, select the location from where the device imports the
configuration profile.
– PC/URL
The device imports the configuration profile from the local PC or from a remote server.
– External memory
The device imports the configuration profile from the external memory.

To import the configuration profile from the local PC or from a remote server, perform the following
steps:

 Import the configuration profile:


 When the file is located on your PC or on a network drive, drag and drop the file in the
area. Alternatively click in the area to select the file.
You also have the option of transferring the file from your PC to the device through
SFTP or SCP:
On your PC, open an SFTP or SCP client, for example WinSCP.
Use the SFTP or SCP client to open a connection to the device.
Transfer the file to the directory /nv/cfg in the device.
 In the Destination frame, specify where the device saves the imported configuration profile:
 In the Profile name field, specify the name under which the device saves the
configuration profile.
 In the Storage type field, specify the storage location for the configuration profile.
 Click the Ok button.
The device copies the configuration profile into the specified memory.

If you specified the value ram in the Destination frame, then the device disconnects the
Graphical User Interface and uses the settings immediately.

80 UM Config EAGLE
Release 3.4 03/2020
Managing configuration profiles
5.3 Loading settings

To import the configuration profile from the external memory, perform the following steps:

 In the Import profile from external memory frame, Profile name drop-down list, select the name
of the configuration profile to be imported.
The prerequisite is that the external memory contains an exported configuration profile.
 In the Destination frame, specify where the device saves the imported configuration profile:
 In the Profile name field, specify the name under which the device saves the
configuration profile.
 Click the Ok button.
The device copies the configuration profile into the non-volatile memory (NVM) of the device.

If you specified the value ram in the Destination frame, then the device disconnects the
Graphical User Interface and uses the settings immediately.

enable Change to the Privileged EXEC mode.


copy config remote sftp:// Import and activate the settings of a configuration
<user name>:<password>@<IP_address>/ profile saved on a SFTP server.
<path>/<file_name> running-config
The device copies the settings into the volatile
memory and disconnects the connection to the
Command Line Interface. The device immediately
uses the settings of the imported configuration
profile.

UM Config EAGLE 81
Release 3.4 03/2020
Managing configuration profiles
5.4 Reset the device to the factory defaults

5.4 Reset the device to the factory defaults

If you reset the settings in the device to the delivery state, then the device deletes the configuration
profiles in the volatile memory and in the non-volatile memory.

If an external memory is connected, then the device also deletes the configuration profiles saved
in the external memory.

The device then reboots and loads the factory settings.

5.4.1 Using the Graphical User Interface or Command Line Interface

Perform the following steps:

 Open the Basic Settings > Load/Save dialog.


 Click the button, then Back to factory....
The dialog displays a message.
 Click the Ok button.
The device deletes the configuration profiles in the memory (RAM) and in the non-volatile
memory (NVM).

If an external memory is connected, then the device also deletes the configuration profiles
saved in the external memory.

After a brief period, the device restarts and loads the delivery settings.

enable Change to the Privileged EXEC mode.


clear factory Deletes the configuration profiles from the non-
volatile memory and from the external memory.
If an external memory is connected, then the
device also deletes the configuration profiles saved
in the external memory.
After a brief period, the device restarts and loads
the delivery settings.

5.4.2 Using the System Monitor

Prerequisite:

Your PC is connected with the serial connection of the device using a terminal cable.

Perform the following steps:


 Restart the device.
 To change to the System Monitor, press the <1> key within 3 seconds when prompted during
reboot.
The device loads the System Monitor.
 To change from the main menu to the Manage configurations menu, press the <4> key.
 To execute the Clear configs and boot params command, press the <1> key.

82 UM Config EAGLE
Release 3.4 03/2020
Managing configuration profiles
5.4 Reset the device to the factory defaults

 To load the factory settings, press the <Enter> key.


The device deletes the configuration profiles in the memory (RAM) and in the non-volatile
memory (NVM).
If an external memory is connected, then the device also deletes the configuration profiles saved
in the external memory.
 To change to the main menu, press the <q> key.
 To reboot the device with factory settings, press the <q> key.

UM Config EAGLE 83
Release 3.4 03/2020
Loading software updates
6.1 Software update from the PC

6 Loading software updates

Hirschmann is continually working on improving and developing their software. Check regularly
whether there is an updated version of the software that provides you with additional benefits. You
find information and software downloads on the Hirschmann product pages on the Internet at
[Link].

The device gives you the following options for updating the device software:
 Software update from the PC
 Software update from a server
 Software update from the external memory
 Loading a previous software version

Note: The device settings are kept after updating the device software.

You see the version of the installed device software on the Login page of the Graphical User
Interface. When you are already logged in, perform the following steps to display the version of the
installed software.

 Open the Basic Settings > Software dialog.


The field Running version displays the version number and creation date of the device
software that the device loaded during the last restart and is currently running.

enable Change to the Privileged EXEC mode.


show system info Displays the system information such as the
version number and creation date of the device
software that the device loaded during the last
restart and is currently running.

6.1 Software update from the PC

The prerequisite is that the image file of the device software is saved on a data carrier which is
accessible from your PC.

Perform the following steps:

 Navigate to the folder where the image file of the device software is saved.
 Open the Basic Settings > Software dialog.
 Drag and drop the image file in the area. Alternatively click in the area to select the file.
 To start the update procedure, click the Start button.
As soon as the update procedure is completed successfully, the device displays an
information that the software is successfully updated.
Upon restart, the device loads the installed device software.

84 UM Config EAGLE
Release 3.4 03/2020
Loading software updates
6.1 Software update from the PC

You also have the option of transferring the file from your PC to the device through SFTP or SCP:
 On your PC, open an SFTP or SCP client, for example WinSCP.
 Use the SFTP or SCP client to open a connection to the device.
 Transfer the file to the directory /upload/firmware in the device.
When the file transfer is complete, the device starts updating the device software. When the
update was successful, the device creates an ok file in the directory /upload/firmware and
deletes the image file.
The device loads the device software during the next restart.

UM Config EAGLE 85
Release 3.4 03/2020
Loading software updates
6.2 Software update from a server

6.2 Software update from a server

To update the software using SFTP or SCP you need a server on which the image file of the device
software is saved.

Perform the following steps:

 Open the Basic Settings > Software dialog.


 In the Software update frame, URL field, enter the URL for the image file in the following form:
 To start the update procedure, click the Start button.
The device copies the currently running device software into the backup memory.
As soon as the update procedure is completed successfully, the device displays an
information that the software is successfully updated.
Upon restart, the device loads the installed device software.

86 UM Config EAGLE
Release 3.4 03/2020
Loading software updates
6.3 Software update from the external memory

6.3 Software update from the external memory

6.3.1 Manually—initiated by the administrator

The device lets you update the device software with a few mouse clicks. The prerequisite is that
the image file of the device software is located in the external memory.

Perform the following steps:

 Open the Basic Settings > Software dialog.


 In the table, mark the row which displays the name of the desired image file in the external
memory.
 Right-click to display the context menu.
 To start the update procedure, click in the context menu the Update item.
The device copies the currently running device software into the backup memory.
As soon as the update procedure is completed successfully, the device displays an
information that the software is successfully updated.
Upon restart, the device loads the installed device software.

6.3.2 Automatically—initiated by the device

When the following files are located in the external memory during a restart, the device updates the
device software automatically:
 the image file of the device software
 a text file [Link] with the content autoUpdate=<Image_file_name>.bin

The prerequisite is that in the Basic Settings > External Memory dialog, you mark the checkbox in the
Software auto update column. This is the default setting in the device.

Perform the following steps:


 Copy the image file of the new device software into the main directory of the external memory.
Use only an image file suitable for the device.
 Create a text file [Link] in the main directory of the external memory.
 Open the [Link] file in the text editor and add the following line:
autoUpdate=<Image_file_name>.bin
 Install the external memory in the device.
 Restart the device.
During the booting process, the device checks automatically the following criteria:
– Is an external memory connected?
– Is a [Link] file in the main directory of the external memory?
– Does the image file exist which is specified in the [Link] file?
– Is the software version of the image file more recent than the software currently running in
the device?
When the criteria are fulfilled, the device starts the update procedure.
The device copies the currently running device software into the backup memory.
As soon as the update procedure is completed successfully, the device reboots automatically
and loads the new software version.

UM Config EAGLE 87
Release 3.4 03/2020
Loading software updates
6.3 Software update from the external memory

Check the result of the update procedure. The log file in the Diagnostics > Report > System Log dialog
contains one of the following messages:
 S_watson_AUTOMATIC_SWUPDATE_SUCCESS
Software update completed successfully
 S_watson_AUTOMATIC_SWUPDATE_ABORTED
Software update aborted
 S_watson_AUTOMATIC_SWUPDATE_ABORTED_WRONG_FILE
Software update aborted due to wrong image file
 S_watson_AUTOMATIC_SWUPDATE_ABORTED_SAVING_FILE
Software update aborted because the device did not save the image file.

88 UM Config EAGLE
Release 3.4 03/2020
Loading software updates
6.4 Loading a previous software version

6.4 Loading a previous software version

The device lets you replace the device software with a previous version. The basic settings in the
device are kept after replacing the device software.

Note: Only the settings for functions which are available in the newer device software version are
lost.

UM Config EAGLE 89
Release 3.4 03/2020
Configuring the ports
7.1 Enabling/disabling the port

7 Configuring the ports

The following port configuration functions are available.


 Enabling/disabling the port
 Selecting the operating mode

7.1 Enabling/disabling the port

In the default setting, every port is enabled. For a higher level of access security, disable
unconnected ports.

Perform the following steps:

 Open the Basic Settings > Port dialog, Configuration tab.


 To enable a port, mark the checkbox in the Port on column.
 To disable a port, unmark the checkbox in the Port on column.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
interface 1/1 Change to the interface configuration mode of
interface 1/1.
no shutdown Enable the interface.

90 UM Config EAGLE
Release 3.4 03/2020
Configuring the ports
7.2 Selecting the operating mode

7.2 Selecting the operating mode

In the default setting, the ports are set to Automatic configuration operating mode.

Note: The active automatic configuration has priority over the manual configuration.

Perform the following steps:

 Open the Basic Settings > Port dialog, Configuration tab.


 If the device connected to this port requires a fixed setting, then perform the following
steps:
 Deactivate the function. Unmark the checkbox in the Automatic configuration column.
 In the Manual configuration column, enter the desired operating mode (transmission rate,
duplex mode).
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
interface 1/1 Change to the interface configuration mode of
interface 1/1.
no auto-negotiate Disable the automatic configuration mode.
speed 100 full Port speed 100 MBit/s, full duplex

UM Config EAGLE 91
Release 3.4 03/2020
Assistance in the protection from unauthorized access
8.1 Changing the SNMPv1/v2 community

8 Assistance in the protection from unauthorized access

The device offers functions that help you protect the device against unauthorized access.

After you set up the device, carry out the following steps in order to reduce possible unauthorized
access to the device.
 Changing the SNMPv1/v2 community
 Disabling SNMPv1/v2
 Disabling HTTP
 Using your own HTTPS certificate
 Using your own SSH key
 Disabling HiDiscovery
 Enable IP access restriction
 Adjusting the session timeouts

8.1 Changing the SNMPv1/v2 community

SNMPv1/v2 works unencrypted. Every SNMP packet contains the IP address of the sender and the
plaintext community name with which the sender accesses the device. If SNMPv1/v2 is enabled,
then the device lets anyone who knows the community name access the device.

The community names public for read accesses and private for write accesses are preset. If you
are using SNMPv1 or SNMPv2, then change the default community name. Treat the community
names with discretion.

Perform the following steps:

 Open the Device Security > Management Access > SNMPv1/v2 Community dialog.
The dialog displays the communities that are set up.
 For the Write community, specify in the Name column the community name.
 Up to 32 alphanumeric characters are allowed.
 The device differentiates between upper and lower case.
 Specify a different community name than for read access.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
snmp community rw <community name> Specify the community for read/write access.
show snmp community Display the communities that have been
configured.
save Save the settings in the non-volatile memory (nvm)
in the “selected” configuration profile.

92 UM Config EAGLE
Release 3.4 03/2020
Assistance in the protection from unauthorized access
8.2 Disabling SNMPv1/v2

8.2 Disabling SNMPv1/v2

If you need SNMPv1 or SNMPv2, then use these protocols only in environments protected from
eavesdropping. SNMPv1 and SNMPv2 do not use encryption. The SNMP packets contain the
community in clear text. We recommend using SNMPv3 in the device and disabling the access
using SNMPv1 and SNMPv2.

Perform the following steps:

 Open the Device Security > Management Access > Server dialog, SNMP tab.
The dialog displays the settings of the SNMP server.
 To deactivate the SNMPv1 protocol, you unmark the SNMPv1 checkbox.
 To deactivate the SNMPv2 protocol, you unmark the SNMPv2 checkbox.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
no snmp access version v1 Deactivate the SNMPv1 protocol.
no snmp access version v2 Deactivate the SNMPv2 protocol.
show snmp access Display the SNMP server settings.
save Save the settings in the non-volatile memory (nvm)
in the “selected” configuration profile.

UM Config EAGLE 93
Release 3.4 03/2020
Assistance in the protection from unauthorized access
8.3 Disabling HTTP

8.3 Disabling HTTP

The web server provides the Graphical User Interface with the protocol HTTP or HTTPS. HTTPS
connections are encrypted, while HTTP connections are unencrypted.

The HTTP protocol is enabled by default. If you disable HTTP, then no unencrypted access to the
Graphical User Interface is possible.

Perform the following steps:

 Open the Device Security > Management Access > Server dialog, HTTP tab.
 To disable the HTTP protocol, select the Off radio button in the Operation frame.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
no http server Disable the HTTP protocol.

If the HTTP protocol is disabled, then you can reach the Graphical User Interface of the device only
by HTTPS. In the address bar of the web browser, enter the string https:// before the IP address
of the device.

If the HTTPS protocol is disabled and you also disable HTTP, then the Graphical User Interface is
unaccessible. To work with the Graphical User Interface, enable the HTTPS server using the
Command Line Interface.

Perform the following steps:

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
https server Enable the HTTPS protocol.

94 UM Config EAGLE
Release 3.4 03/2020
Assistance in the protection from unauthorized access
8.4 Disabling the HiDiscovery access

8.4 Disabling the HiDiscovery access

HiDiscovery lets you assign IP parameters to the device over the network during commissioning.
HiDiscovery communicates in the device management VLAN without encryption and
authentication.

After the device is commissioned, we recommend to setHiDiscoveryto read-only or to disable


HiDiscovery access completely.

Perform the following steps:

 Open the Basic Settings > Network dialog.


 To take away write permission from the HiDiscovery software, in the HiDiscovery protocol v1/
v2 frame, specify the value readOnly in the Access field.
 To disable HiDiscovery access completely, select the Off radio button in the HiDiscovery
protocol v1/v2 frame.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


network hidiscovery mode read-only Disable write permission of the HiDiscovery
software.
no network hidiscovery operation Disable HiDiscovery access.

UM Config EAGLE 95
Release 3.4 03/2020
Assistance in the protection from unauthorized access
8.5 Activating the IP access restriction

8.5 Activating the IP access restriction

In the default setting, you access the device management from any IP address and with the
supported protocols.

The IP access restriction lets you restrict access to the device management to selected IP address
ranges and selected IP-based protocols.

Example:

The device is to be accessible only from the company network using the Graphical User Interface.
The administrator has additional remote access using SSH. The company network has the address
range [Link]/24 and remote access from a mobile network with the IP address range
[Link]/24. The SSH application program knows the fingerprint of the RSA key.

Table 12: Parameters for the IP access restriction

Parameter Company network Mobile phone network


Network address [Link] [Link]
Netmask 24 24
Desired protocols https, snmp ssh

96 UM Config EAGLE
Release 3.4 03/2020
Assistance in the protection from unauthorized access
8.5 Activating the IP access restriction

Perform the following steps:

 Open the Device Security > Management Access > IP Access Restriction dialog.
 Unmark the checkbox in the Active column for the entry.
This entry lets users have access to the device from any IP address and the supported
protocols.
Address range of the company network:
 To add a table entry, click the button.
 Specify the address range of the company network in the IP address range column:
[Link]/24
 For the address range of the corporate network, deactivate the undesired protocols. The
HTTPS, SNMP, and Active checkboxes remain marked.
Address range of the mobile phone network:
 To add a table entry, click the button.
 Specify the address range of the mobile network in the IP address range column:
[Link]/24
 For the address range of the mobile network, deactivate the undesired protocols. The SSH
and Active checkboxes remain marked.
Before you enable the function, verify that at least one active entry in the table lets you have
access. Otherwise, if you change the settings, then the connection to the device terminates.
Access to the device management is only possible using the Command Line Interface through
the serial interface of the device.
 To enable IP access restriction, select the On radio button in the Operation frame.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


show network management access global Displays whether IP access restriction is enabled
or disabled.
show network management access rules Display the entries that have been configured.

no network management access operation Disable the IP access restriction.

network management access add 2 Create the entry for the address range of the
company network.
Number of the next available index in this example:
2.
network management access modify 2 ip Specify the IP address of the company network.
[Link]
network management access modify 2 mask Specify the netmask of the company network.
24
network management access modify 2 ssh Deactivate SSH for the address range of the
disable company network.
Repeat the operation for every unwanted protocol.

network management access add 3 Create an entry for the address range of the mobile
phone network.
Number of the next available index in this example:
3.

UM Config EAGLE 97
Release 3.4 03/2020
Assistance in the protection from unauthorized access
8.5 Activating the IP access restriction

network management access modify 3 ip Specify the IP address of the mobile phone
[Link] network.
network management access modify 3 mask Specify the netmask of the mobile phone network.
24
network management access modify 3 snmp Deactivate SNMP for the address range of the
disable mobile phone network.
Repeat the operation for every unwanted protocol.

no network management access status 1 Deactivate the default entry.


This entry lets users have access to the device
from any IP address and the supported protocols.
network management access status 2 Activate an entry for the address range of the
company network.
network management access status 3 Activate an entry for the address range of the
mobile phone network.

show network management access rules Display the entries that have been configured.

network management access operation Enable the IP access restriction.

98 UM Config EAGLE
Release 3.4 03/2020
Assistance in the protection from unauthorized access
8.6 Adjusting the session timeouts

8.6 Adjusting the session timeouts

The device lets you automatically terminate the session upon inactivity of the logged-on user. The
session timeout is the period of inactivity after the last user action.

You can specify a session timeout for the following applications:


 Command Line Interface sessions using an SSH connection
 Command Line Interface sessions using a serial connection
 Graphical User Interface

Timeout for Command Line Interface sessions using a SSH connection

Perform the following steps:

 Open the Device Security > Management Access > Server dialog, SSH tab.
 Specify the timeout period in minutes in the Configuration frame, Session timeout [min] field.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
ssh timeout <0..160> Specify the timeout period in minutes for Command
Line Interface sessions using an SSH connection.

Timeout for Command Line Interface sessions using a serial connection

Perform the following steps:

 Open the Device Security > Management Access > CLI dialog, Global tab.
 Specify the timeout period in minutes in the Configuration frame, Serial interface timeout [min]
field.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


cli serial-timeout <0..160> Specify the timeout period in minutes for Command
Line Interface sessions using a serial connection.

UM Config EAGLE 99
Release 3.4 03/2020
Assistance in the protection from unauthorized access
8.6 Adjusting the session timeouts

Session timeout for the Graphical User Interface

Perform the following steps:

 Open the Device Security > Management Access > Web dialog.
 Specify the timeout period in minutes in the Configuration frame, Web interface session timeout
[min] field.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


network management access web timeout Specify the timeout period in minutes for Graphical
<0..160> User Interface sessions

100 UM Config EAGLE


Release 3.4 03/2020
Controlling the data traffic

9 Controlling the data traffic

The device checks the data packets to be forwarded in accordance with defined rules. Data packets
to which the rules apply are either forwarded by the device or blocked. If data packets do not
correspond to any of the rules, then the device blocks the packets.

Routing ports to which no rules are assigned allow packets to pass. As soon as a rule is assigned,
the assigned rules are processed first. After that, the specified standard action of the device takes
effect.

The device provides the following functions for controlling the data stream:
 Checking the contents and states of data packets (packet filter)
 Service request control (Denial of Service, DoS)

The device observes and monitors the data stream. The device takes the results of the observation
and the monitoring and combines them with the rules for the network security to create what is
known as a status table. Based on this status table, the device decides whether to accept, drop or
reject data.

UM Config EAGLE 101


Release 3.4 03/2020
Controlling the data traffic

The data packets go through the filter functions of the device in the following sequence:

Operating System

Destination Address Modification Ingress Egress Source Address Modification


1:1 NAT Packet Policy Routing Packet Masquerading NAT
Destination NAT Filter Filter Double NAT
Double NAT

MAC-based ACL

IP-based ACL

DoS
Switching Chip

Network 1 Network 2

Figure 18: Processing sequence of the data packets in the device

Note: The device uses hardware to filter the data stream through the packet filters. This causes the
device to process the data stream at a slow rate. For this reason, when you expect high volumes,
use ACLs. To track the “connection state“, use packet filters.

The data packets go through the filter functions of the device in the following sequence:

Operating System

Destination Address Modification Ingress Egress Source Address Modification


1:1 NAT Packet Policy Routing Packet Masquerading NAT
Destination NAT Filter Filter Double NAT
Double NAT

MAC-based ACL

IP-based ACL

DoS
Switching Chip

Network 1 Network 2

Figure 19: Processing sequence of the data packets in the device

102 UM Config EAGLE


Release 3.4 03/2020
Controlling the data traffic
9.1 Packet filter

9.1 Packet filter

9.1.1 Description of the Packet Filter function

The packet filter lets you 2 filter types for data traffic. The filtering naturally includes checking and
evaluation of the data traffic. The device contains a stateful firewall. A stateful firewall tracks the
state of the connections transversing it.

The firewall filters both the contents and the status of the conveyed data packets. For each type,
you have different criteria that you compile into individual rules as required.

In case of filtering for the content of a packet, the device checks the following criteria:
 IP header (source address, target address, protocol)
 TCP/UDP header (source port, target port)

You can configure the corresponding values in the table of the Network Security > Packet Filter > Rule
dialog.

When filtering according to the status of a packet, the firewall checks the criteria, which you can
optionally configure in the Network Security > Packet Filter > Rule dialog, Parameters field.

When you create a rule in this dialog, the value in the Parameters column is none initially. This
default value causes filtering according to the status or the Ethernet header of a packet.

In order to activate optional, status or content filter criteria, you can enter different parameters,
which each have the form key=<value>. Which keys are valid depends in part on the protocol of
the rule. The keys mac=<value> and state=<value> apply everywhere and are independent of the
protocol. The keys type=<value> and code=<value> are permitted only for the ICMP protocol; the
key flags=<value> is only permitted for the TCP protocol.

In the table below, you will find several examples for entries in the Parameters column and their
effect on filtering. You have the option to enter several keys separated by commas. You can also
enter several values separated by dashes. In addition, you can also enter different keys with
several values in each case.

Table 13: Possible entries in the Parameters column

Entry Meaning
mac=de:ad:de:ad:be:ef This rule only applies to packets with the source MAC address
de:ad:de:ad:be:ef.
state=new This rule only applies to packets coming from a new connection.
state=est This rule only applies to packets coming from a connection that
already exists.
state=new|est This rule applies to every packet coming from a new connection or a
connection that already exists.
type=5 This rule only applies to packets with ICMP type 5.
flags=syn This rule only applies to packets for which the SYN flag is set.
state=new|rel,flags=rst This rule applies to every packet coming from a new or relative
connections and that has the RST flag set.

You find more information on valid entries in the Parameters column in the "Graphical User Interface"
reference manual.

UM Config EAGLE 103


Release 3.4 03/2020
Controlling the data traffic
9.1 Packet filter

Since the device enables simultaneous filtering according to content and status of data packets,
you can compile any combinations of both types of filtering into individual rules. The packet filter
lets you configure up to 2048 individual rules.

Upon receipt of a data packet to be routed, the device generally applies the packet filer rules to the
data packet. The device executes 1 rule after another, until the data packet reaches the first rule
that applies to it. The rules that follow are ignored.

To remove a rule, highlight the affected table entry and click the button.

When none of the rules you configured applies to a data packet or you have not configured
individual rules, the packet filter applies a standard rule. Three possible standard rules are available
here:

Table 14: Handling filtered data packets

Rule Operation
accept The device forwards the data packet in accordance with the address
information.
drop The device deletes the data packet without informing the sender.
reject The device deletes the data packet and informs the sender.

Note: In the default setting, the device applies the accept action. You can change this setting in
the Network Security > Packet Filter > Global dialog, Default policy field.

The packet filter adheres to a two-level concept for activating newly configured or changed rules. If
you click the button, then the rules listed in the table are initially saved without activation taking
place.

To transfer the rules and apply them to the device, in the Network Security > Packet Filter > Global
dialog, click the button and then the Commit changes item.

When you have configured and activated the status-dependent filter criteria, you can have the
corresponding effects displayed in the status table. You can find this table with the name “Firewall
state (connection tracking) table” on the bottom of the Diagnostics > System > System Information
dialog. Based on the entries listed there, you can check which connections are currently
established. Verify that the data packets permitted by you actually pass through the firewall, for
example.

Note: To delete the information from the firewall state table, click in the Basic Settings > Restart dialog
the Clear firewall table button.

9.1.2 Application example for Packet Filter

The figure displays a typical application case:

A production controller wants to request data from a production robot.

104 UM Config EAGLE


Release 3.4 03/2020
Controlling the data traffic
9.1 Packet filter

The production robot is located in a production cell which a firewall keeps separate from the
company network. The firewall is to help prevent data stream between the production cell and the
rest of the company network. Only the data stream between the robot and the production
controller’s PC is allowed to flow freely.

The following is known:

Parameter Robot Firewall PC


IP address interface 1/1 [Link]
IP address interface 1/4 [Link]
IP address [Link] [Link]
Gateway [Link] [Link]

Prerequisite for further configuration:


 The firewall is in router mode.
 The IP parameters of the firewall router interface are configured.
 The devices in the internal network have the IP address of port 1 of the firewall as their Gateway.
 The Gateway and the IP address of the PC and the robot are configured.

UM Config EAGLE 105


Release 3.4 03/2020
Controlling the data traffic
9.1 Packet filter

[Link]/24

[Link]/24

[Link]
Port 1 Port 4
[Link] [Link] [Link]
Figure 20: Application example for Packet Filter

 Create a rule for incoming IP packets.

 Open the Network Security > Packet Filter > Rule dialog.
By default, no interface is assigned an explicit rule. In the Default policy field, the value accept
is specified. Consequently, the data stream passes through the device without restriction.
Creating a rule and assigning it to the relevant interface changes this condition.
 Create a new rule.
 Specify the following settings for the rule:
 The value [Link] or [Link]/32 in the Source address column
 The value any in the Source port column
 The value [Link] or [Link]/32 in the Destination address column
 The value any in the Destination port column
 The value any in the Protocol column
 The value accept in the Action column
The device lets you limit the rule to IP packets that fulfill certain ICMP criteria. Additionally,
specify the following settings for the rule:
 The value icmp in the Protocol column
 The value type=3,code=1 in the Parameters column
type=3 = Destination Unreachable
code=1 = Host Unreachable
The values behind type and code are 1- to 3-digit decimal values. For the possible
values, see the "Graphical User Interface" reference manual. Entering an ICMP code
is optional.
 To activate the rule, mark the checkbox in the Active column.
 To save the changes temporarily, click the button.
 Open the Network Security > Packet Filter > Assignment dialog.
 To assign the rule to an interface, click the button and then the Assign item.
 In the Interface field, specify the value 1/4.
 In the Direction field, specify the value ingress to activate this rule for incoming data
traffic.
 In the Rule index column, specify the index number of the rule.
 To save the changes temporarily, click the button.
 Open the Network Security > Packet Filter > Global dialog.
 To apply this rule to the data stream, click the button and then the Commit changes item.

 Create rules for sending IP packets.

106 UM Config EAGLE


Release 3.4 03/2020
Controlling the data traffic
9.1 Packet filter

 Open the Network Security > Packet Filter > Rule dialog.
 Create a new rule drop everything that drops every IP packet.
Specify the following settings for the rule:
 The value drop everything in the Description column
 The value any in the Source address column
 The value any in the Source port column
 The value any in the Destination address column
 The value any in the Destination port column
 The value any in the Protocol column
 The value drop in the Action column
 Unmarking the checkbox in the Log column
 Create a new rule filter data that explicitly allows to send selected IP packets.
Specify the following settings for the rule:
 The value filter data in the Description column
 The value [Link]/32 in the Source address column
 The value any in the Source port column
 The value [Link]/32 in the Destination address column
 The value any in the Destination port column
 The value any in the Protocol column
 The value accept in the Action column
 To save the changes temporarily, click the button.
 Open the Network Security > Packet Filter > Assignment dialog.
 To assign the rule to an interface, click the button and then the Assign item.
 In the Interface field, specify the interface to which you want the rule assigned.
 In the Direction field, specify the value egress to activate this rule for outbound data
traffic.
 In the Rule index column, specify the index number of the filter data rule.
 Repeat these steps to allocate the rule drop everything to the interface.
 Specify the priority of the rules in the Priority column:
 The value 1 for the filter data rule
 The value 2 for the drop everything rule
 To activate the rules, mark the checkbox in the Active column.
 To save the changes temporarily, click the button.
 Open the Network Security > Packet Filter > Global dialog.
 To apply the rules to the data traffic, click the button and then the Commit changes item.

UM Config EAGLE 107


Release 3.4 03/2020
Controlling the data traffic
9.2 Helping protect against unauthorized access

9.2 Helping protect against unauthorized access

With this function, the device supports you in helping protect against invalid or falsified data packets
targeted at causing the failure of certain services or devices. You have the option of specifying
filters in order to restrict data stream for protection against denial-of-service attacks. The activated
filters check incoming data packets and discard them as soon as a match with the filter criteria is
found.

The Network Security > DoS > Global dialog contains 2 frames in which you activate different filters.
To activate them, mark the corresponding checkboxes.

In the TCP/UDP frame, you activate up to 4 filters that only influence TCP and UDP packets. Using
this filter, you deactivate port scans, which attackers use to try to recognize devices and services
offered. The filters operate as follows:

Table 15: DoS filters for TCP packets

Filter Action
Activate Null Scan Filter The device detects and discards TCP packets for which no TCP flags
are set.
Activate Xmas Filter The device detects and discards TCP packets for which the TCP flags
FIN, URG and PUSH are simultaneously set.
Activate SYN/FIN Filter The device detects and discards TCP packets for which the TCP flags
SYN and FIN are simultaneously set.
Activate Minimal Header The device detects and discards TCP packets for which the TCP
Filter header is too short.

The ICMP frame offers you 2 filter options for ICMP packets. Fragmentation of incoming ICMP
packets is a sign of an attack. If you activate this filter, then the device detects fragmented ICMP
packets and discards them. Using the Allowed payload size [byte] parameter, you can also specify the
maximum permissible size of the payload of the ICMP packets. The device discards data packets
that exceed this byte specification.

Note: You can combine the filters in any way in the Network Security > DoS > Global dialog. When
several filters are selected, a logical Or applies: If the first or second (or the third, etc.) filter applies
to a data packet, then the device discards it.

108 UM Config EAGLE


Release 3.4 03/2020
Controlling the data traffic
9.3 Deep Packet Inspection

9.3 Deep Packet Inspection

The Deep Packet Inspection function (DPI) lets you monitor and filter data packets. The function
supports you in protecting your network from undesirable content, such as spam or viruses.

The Deep Packet Inspection function inspects data packets for undesirable characteristics and
protocol violations. The protocol inspects the header and the payload of the data packets.

9.3.1 Description of the Deep Packet Inspection - Modbus Enforcer function

The Modbus protocol widely used in the Automation sector.


 The protocol is based on Function code, the commands.
 Some of the Function code let you specify register or coil address ranges.

The device blocks data packets that violate the specified rules. If an error is detected, then the
device terminates the Modbus or TCP connection on request.
 Violation of the Modbus standard (Sanity check).
 Violation of the specified Function code.

Meaning of the Function code values

# Meaning Address range


1 Read Coils <0..65535> -
2 Read Diskrete Inputs <0..65535> -
3 Read Holding Registers <0..65535> -
4 Read Input Registers <0..65535> -
5 Write Single Coil <0..65535> -
6 Write Single Register <0..65535> -
7 Read Eception Status - -
8 Diagnostic - -
11 Get Comm Event Counter - -
12 Get Comm Event Log - -
13 Program (584/984) - -
14 Poll (584/984) - -
15 Write Multiple Coils <0..65535> -
16 Write Multiple Registers <0..65535> -
17 Report Slave ID - -
20 Read File Record - -
21 Write File Record - -
22 Mask Write Register <0..65535> -
23 Read/Write Multipple Registers <0..65535> <0..65535>
24 Read FIFO Queue <0..65535> -
40 Program (ConCept) - -

UM Config EAGLE 109


Release 3.4 03/2020
Controlling the data traffic
9.3 Deep Packet Inspection

# Meaning Address range


42 Concept Symbol Table - -
43 Encapsulated Interface Transport - -
48 Advantech Co. Ltd. - Management Functions - -
66 Scan Data Inc. - Expanded Read Holding - -
Registers
67 Scan Data Inc. - Expanded Write Holding - -
Registers
90 unity Programming/OFS - -
100 Scattered Register Read - -
125 Schneider Electric - Firmware Replacement - -
126 Schneider Electric - Program - -

9.3.2 Application example for Modbus Enforcer

Header+
Payload

Modbus Master Modbus Client

DPI Modbus Enforcer


Figure 21: Deep Packet Inspection - Modbus Enforcer

The device monitors the data traffic between the Modbus master and Modbus client. The function
Deep Packet Inspection inspects the data packets for the specified characteristics.

Example:

The device only permits data packets with the following characteristics:
 Function code = 1 (Read Coils)
 Function code = 2 (Read Discrete Inputs)
 Function code = 3 (Read Holding Registers)
 Function code = 23|128-255|512-1023 (Read/Write Multiple Registers), read address
range 128..255, write address range 512..1023.
 Unit identifier = 254,255

110 UM Config EAGLE


Release 3.4 03/2020
Controlling the data traffic
9.3 Deep Packet Inspection

9.3.3 Create and edit Modbus Enforcer rules

Specify a rule with Index = 1, the name my-modbus and Function code list as well as Unit identifier list
according to the example above.

Perform the following steps:

 Open the Network Security > DPI > Modbus Enforcer dialog.
 Create a new rule:
 Click the button.
The dialog displays the Create window.
 In the Index field, specify the value 1.
 Click the Ok button.
Result:
The device creates a new rule with the following properties:
 Index column = 1
 Description column = modbus
 Function type column = readonly
 Function code column = 1,2,3,4,7,11,12,17,20,24
 Unit identifier column = none
 Checkbox in the Sanity check column = marked
 Checkbox in the Exception column = unmarked
 Checkbox in the Reset column = marked
 Checkbox in the Profile active column = unmarked
 To specify the user-specific name my-modbus for the DPI Modbus Enforcer entry, you
double-click in the Description column and specify the desired string.
 To apply the changes, click the Finish button.
 To edit the Function code, specify the value advanced in the Function type column.
 To edit the Function code, open the Function code configurator dialog. Click the Function code
configurator button.
 To specify the Function code = 1,2,3,23, you proceed as follows:
– In the right column, highlight the values 4,7,11,12,17,20,24.
– Move the highlighted values to the left column by clicking the < button.
– In the left column, highlight the value 23.
– Move the highlighted value to the right column by clicking the > button.
– Click the Ok button.
 Alternatively, proceed as follows:
– In the Function code column, specify the value 1,2,3,23.
– To save the changes temporarily, click the button.

Result:

The device displays the value 1,2,3,23 in the Function code column.
 To specify for Function code = 23 the address range = 128-255|512-1023, proceed as
follows:
– You separate address ranges with vertical lines.
In the Function code column, specify the value |128-255|512-1023.
– To save the changes temporarily, click the button.
 To allow only data packets with Unit identifier = 254,255, enter this value in the Unit identifier
column.

UM Config EAGLE 111


Release 3.4 03/2020
Controlling the data traffic
9.3 Deep Packet Inspection

 To save the changes temporarily, click the button.


 To activate the profile, mark the checkbox in the Profile active column.
 To tell the device to apply the specified DPI Modbus Enforcer rules to the data stream and
to reload what is displayed in the Function code column, click the Commit changes button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
dpi modbus addprofile 1 description my- Adds another rule to the DPI Modbus table.
modbus function-type advanced function- • dpi modbus addprofile 1
code-list 1,2,3,23|128-255|512-1023
unit-identifier-list 254,255
Adds profile with index number 1.
• description my-modbus
Specifying an user-specific Description = my-
modbus for the rule.
• function-type advanced
Specifying Function type = advanced.
• function-code-list 1,2,3,23
Specifying Function code list = 1,2,3,23.
For Function code = 23, specify the Read address
range 128-255 and Write address range 512-
1023.
• unit-identifier-list 254,255
Specifying the Modbus Unit identifier = 254,255.
dpi modbus enableprofile 1 Activate DPI Modbus rule 1.
After you activate the rule, the device helps prevent
rule modifications.
show dpi modbus profiletable Display the specified DPI Modbus rules in a table.
show dpi modbus pending Display whether the DPI Modbus Enforcer rules
applied to the data stream differ from the rules
saved in the device.
dpi modbus commit Apply the specified DPI Modbus Enforcer rules.

112 UM Config EAGLE


Release 3.4 03/2020
Synchronizing the system time in the network

10 Synchronizing the system time in the network

Many applications rely on a time that is as correct as possible. The necessary accuracy, and thus
the allowable deviation from the actual time, depends on the application area.

Examples of application areas include:


 Log entries
 Time stamping of production data
 Process control

The device lets you synchronize the time on the network using the following options:
 The Network Time Protocol (NTP) is accurate to the order of sub-milliseconds.

UM Config EAGLE 113


Release 3.4 03/2020
Synchronizing the system time in the network
10.1 Basic settings

10.1 Basic settings

In the Time > Basic Settings dialog, you specify general settings for the time.

10.1.1 Setting the time

When no reference time source is available to you, you have the option to set the time in the device.

After a cold start or reboot, if no real-time clock is available or the real-time clock contains an invalid
time, then the device initializes its clock with January 1, 00:00h. After the power supply is switched
off, the device buffers the settings of the real-time clock up to 24 hours.

Alternatively, you configure the settings in the device so that it automatically obtains the current
time from an NTP server.

Perform the following steps:

 Open the Time > Basic Settings dialog.


 The System time (UTC) field displays the current UTC (Universal Time Coordinated) of the
device. UTC is the time relating to the coordinated world time measurement. UTC is the
same worldwide and does not take local time shifts into account.
 The time in the System time field comes from the System time (UTC) plus the Local offset [min]
value and a possible shift due to daylight saving time.
 In order to cause the device to apply the time of your PC to the System time field, click the
Set time from PC button.
Based on the value in the Local offset [min] field, the device calculates the time in the System
time (UTC) field: The System time (UTC) comes from the System time minus the Local offset
[min] value and a possible shift due to daylight saving time.
 The Time source field displays the origin of the time data. The device automatically selects
the source with the greatest accuracy.
The source is initially local.
When NTP is active and the device receives a valid NTP packet, the device sets its time
source to ntp.
 The Local offset [min] value specifies the time difference between the local time and the
System time (UTC).
 In order to cause the device to determine the time zone on your PC, click the Set time from
PC button. The device calculates the local time difference from UTC and enters the
difference into the Local offset [min] field.
Note: The device provides the option to obtain the local offset from a DHCP server.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
clock set <YYYY-MM-DD> <HH:MM:SS> Set the system time of the device.
clock timezone offset <-780..840> Enter the time difference between the local time
and the received UTC time in minutes.
save Save the settings in the non-volatile memory (nvm)
in the “selected” configuration profile.

114 UM Config EAGLE


Release 3.4 03/2020
Synchronizing the system time in the network
10.1 Basic settings

10.1.2 Automatic daylight saving time changeover

When you operate the device in a time zone in which there is a summer time change, you set up
the automatic daylight saving time changeover on the Daylight saving time tab.

When daylight saving time is enabled, the device sets the local system time forward by 1 hour at
the beginning of daylight saving time. At the end of daylight saving time, the device sets the local
system time back again by 1 hour.

Perform the following steps:

 Open the Time > Basic Settings dialog, Daylight saving time tab.
 To select a preset profile for the start and end of daylight saving time, click the Profile...
button in the Operation frame.
 When no matching daylight saving time profile is available, you specify the changeover
times in the Summertime begin and Summertime end fields.
For both time points, you specify the month, the week within this month, the weekday, and
the time of day.
 To enable the function, select the On radio button in the Operation frame.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
clock summer-time mode Configure the automatic daylight saving time
<disable|recurring|eu|usa> changeover: enable/disable or activate with a
profile.
clock summer-time recurring start Enter the start time for the changeover.
clock summer-time recurring end Enter the end time for the changeover.
save Save the settings in the non-volatile memory (nvm)
in the “selected” configuration profile.

UM Config EAGLE 115


Release 3.4 03/2020
Synchronizing the system time in the network
10.2 NTP

10.2 NTP

The Network Time Protocol (NTP) enables you to synchronize the system time in your network. The
device supports the NTP client and the NTP server function.

NTP uses levels, or hierarchies, of clock sources called stratum layers. Stratum layers define the
distance from the reference clock. The layers start with zero as the top layer. The stratum zero layer
consists of clock devices such as radio clocks, atomic clocks, or GPS clocks. The device operates
at stratum layers 1 through 16.

Furthermore, an NTP device operates as a primary server, secondary server, or client. Synchronize
the primary NTP-Server directly to the stratum zero layer.

A secondary NTP-Server synchronizes to one or more servers and provides a synchronization


signal for one or more servers or clients. When you use the device in client mode, the device
sends requests to the active NTP-Servers listed in the Time > NTP > Server dialog. In the client-
server mode, the device also answers requests sent from dependent servers and clients.

An NTP-Client synchronizes to one or more upstream NTP-Servers. In order to synchronize to the


NTP-Server, configure the client devices to send Unicast requests or listen for Broadcasts.

Note: To obtain as accurate a system time distribution as possible, use multiple NTP servers for
an NTP client.

116 UM Config EAGLE


Release 3.4 03/2020
Synchronizing the system time in the network
10.2 NTP

10.2.1 Preparing the NTP configuration

Perform the following steps:


 To get an overview of how the time is passed on, draw a network plan with the devices
participating in NTP. When planning, bear in mind that the accuracy of the time depends on the
signal runtime.

GPS PLC

Client

Server Client

[Link]
Switch 1 Switch 2 Switch 3

Client Server Client Server Client Server


[Link] [Link] [Link]
Figure 22: NTP cascading

Table 16: Settings for the example

Device [Link] [Link] [Link]

Client only frame


Client Off Off Off
Mode unicast

Client and server frame


Server On Off On
Mode client-server client-server
ServerAddress [Link] [Link] [Link]

 Enable the NTP function in the devices whose time you want to set using NTP. The NTP server
of the device responds to received Unicast requests and sends Broadcast requests as soon as
it is configured and enabled.
 If no reference clock is available, then specify a device as the reference clock and set its system
time as accurately as possible.

10.2.2 NTP configuration

In the Client only frame:


 Client – Enable/disable the function
 Mode – In the unicast mode the device sends a request to a designated Unicast server and
expects a reply from that server. In the broadcast mode, the device sends no request and waits
for a Broadcast from one or more Broadcast servers.

UM Config EAGLE 117


Release 3.4 03/2020
Synchronizing the system time in the network
10.2 NTP

In the Client and server frame:


 Server – Enable/disable the function
 Mode – Set the connection parameters
 Stratum – This setting helps prevent other clients from using the device as a reference time
source (default setting: 12).

Configuration of an NTP client (using the example for switch 2)

Perform the following steps:

 Open the Time > NTP > Global dialog.


 Before you enable the Client function, disable the Server function. Select the Off radio
button in the Client and server frame.
To enable the function, select the On radio button in the Client only frame.
 In the Mode field, specify the value unicast.
 To save the changes temporarily, click the button.
 Open the Time > NTP > Server dialog.
 To create an entry, click the button.
 For switch 2:
In the Address column, specify the value [Link].
 To activate the entry, mark the checkbox in the Active column.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
ntp server operation disable Disable the NTP server.
ntp client operation enable Enable the NTP client.
ntp client operating-mode unicast Enable NTP client in Unicast operating mode.
ntp peers add 1 ip [Link] Add index 1 with an ip address of [Link] as a
NTP server to which the device sends requests.

Configuration of an NTP client server (using the example for switch 1 and 3)

Perform the following steps:

 Open the Time > NTP > Global dialog.


 Before you enable the Server function, disable the Client function. Select the Off radio
button in the Client only frame.
To enable the function, select the On radio button in the Client and server frame.
 In the Mode field, specify the value client-server.
 To save the changes temporarily, click the button.
 Open the Time > NTP > Server dialog.
 To create an entry, click the button.

118 UM Config EAGLE


Release 3.4 03/2020
Synchronizing the system time in the network
10.2 NTP

 For switch 1 and switch 3:


In the Address column, specify the value [Link].
 To activate the entry, mark the checkbox in the Active column.
 To save the changes temporarily, click the button.

Configure both switch 1 and 3 with the following commands.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
ntp client operation enable Enable the NTP client.
ntp server operation enable Enable the NTP server.
ntp server operating-mode client-server Enable NTP server in client-server operating
mode.
ntp peers add 1 ip [Link] Add index 1 with an ip address of [Link] as
a NTP server to which the device sends requests.

10.2.3 Multicast-Groups

The device also processes Multicasts synchronization.

Table 17: Destination address classes for SNTP and NTP packets

IP destination address Send NTP packet to


[Link] Nobody
Multicast-address Multicast Address range
([Link] .. [Link]), especially
[Link] (NTP address)
[Link] Broadcast address

Perform the following steps:

 Open the Time > NTP > Global dialog.


 Before you enable the Client function, disable the Server function. Select the Off radio
button in the Client and server frame.
To enable the function, select the On radio button in the Client only frame.
 In the Mode field, specify the value broadcast.
 Open the Time > NTP > Multicast Groups dialog.
 To create an entry, click the button.
 In the Address column, specify the value [Link].
 In the Port column, specify the value 123.
 To activate the entry, mark the checkbox in the Active column.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
ntp server operation disable Disable the NTP server.

UM Config EAGLE 119


Release 3.4 03/2020
Synchronizing the system time in the network
10.2 NTP

ntp client operation enable Enable the NTP client.


ntp client operating-mode broadcast Enable NTP client in Broadcast operating mode.
ntp client multicast add 1 ip [Link] Add index 1 with IP address [Link] as a
Multicast address.

120 UM Config EAGLE


Release 3.4 03/2020
Network load control
11.1 Direct packet distribution

11 Network load control

The device features a number of functions that reduce the network load:
 Direct packet distribution
 Rate limiter

11.1 Direct packet distribution

The device reduces the network load with direct packet distribution.

On each of its ports, the device learns the sender MAC address of received data packets. The
device stores the combination “port and MAC address” in its MAC address table (FDB).

By applying the “Store and Forward” method, the device buffers data received and checks it for
validity before forwarding it. The device rejects invalid and defective data packets.

11.1.1 Learning MAC addresses

When the device receives a data packet, it checks whether the MAC address of the sender is
already stored in the MAC address table (FDB). When the MAC address of the sender is unknown,
the device generates a new entry. The device then compares the destination MAC address of the
data packet with the entries stored in the MAC address table (FDB):
 The device forwards packets with a known destination MAC address directly to ports that have
already received data packets from this MAC address.
 The device floods data packets with unknown destination addresses, that is, the device forwards
these data packets to every port.

11.1.2 Aging of learned MAC addresses

Addresses that have not been detected by the device for an adjustable period of time (aging time)
are deleted from the MAC address table (FDB) by the device. A reboot or resetting of the MAC
address table deletes the entries in the MAC address table (FDB).

UM Config EAGLE 121


Release 3.4 03/2020
Network load control
11.1 Direct packet distribution

11.1.3 Static address entries

In addition to learning the sender MAC address, the device also provides the option to set MAC
addresses manually. These MAC addresses remain configured and survive resetting of the MAC
address table (FDB) as well as rebooting of the device.

Static address entries allow the device to forward data packets directly to selected ports. If you do
not specify a destination port, then the device discards the corresponding data packets.

You manage the static address entries in the Graphical User Interface or in the Command Line
Interface.

Perform the following steps:


 Create a static address entry.

 Open the Switching > Filter for MAC Addresses dialog.


 Add a user-configurable MAC address:
 Click the button.
The dialog displays the Create window.
 In the Address field, specify the destination MAC address.
 In the VLAN ID field, specify the ID of the VLAN.
 In the Port list, select the ports to which the device forwards data packets with the
specified destination MAC address in the specified VLAN.
When you have defined a Unicast MAC address in the Address field, select only one
port.
When you have defined a Multicast MAC address in the Address field, select one or
more ports.
If you want the device to discard data packets with the destination MAC address, then
do not select any port .
 Click the Ok button.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
mac-filter <MAC address> <VLAN ID> Create the MAC address filter, consisting of a MAC
address and VLAN ID.
interface 1/1 Change to the interface configuration mode of
interface 1/1.
mac-filter <MAC address> <VLAN ID> Assign the port to a previously created MAC
address filter.
save Save the settings in the non-volatile memory (nvm)
in the “selected” configuration profile.

 Convert a learned MAC address into a static address entry.

 Open the Switching > Filter for MAC Addresses dialog.


 To convert a learned MAC address into a static address entry, select the value permanent
in the Status column.
 To save the changes temporarily, click the button.

 Disable a static address entry.

122 UM Config EAGLE


Release 3.4 03/2020
Network load control
11.1 Direct packet distribution

 Open the Switching > Filter for MAC Addresses dialog.


 To disable a static address entry, select the value invalid in the Status column.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
interface 1/1 Change to the interface configuration mode of
interface 1/1.
no mac-filter <MAC address> <VLAN ID> Cancel the assignment of the MAC address filter
on the port.
exit Change to the Configuration mode.
no mac-filter <MAC address> <VLAN ID> Deleting the MAC address filter, consisting of a
MAC address and VLAN ID.
exit Change to the Privileged EXEC mode.
save Save the settings in the non-volatile memory (nvm)
in the “selected” configuration profile.

 Delete learned MAC addresses.

 To delete the learned addresses from the MAC address table (FDB), open the Basic
Settings > Restart dialog and click the Reset MAC address table button.

clear mac-addr-table Delete the learned MAC addresses from the MAC
address table (FDB).

UM Config EAGLE 123


Release 3.4 03/2020
Network load control
11.2 Rate limiter

11.2 Rate limiter

The rate limiter function helps ensure stable operation even with high traffic volumes by limiting
traffic on the ports. The rate limitation is performed individually for each port, as well as separately
for inbound and outbound traffic.

If the data rate on a port exceeds the defined limit, then the device discards the overload on this
port.

Rate limitation occurs entirely on Layer 2. In the process, the rate limiter function ignores protocol
information on higher levels such as IP or TCP. This can affect the TCP traffic.

To minimize these effects, use the following options:


 Limit the rate limitation to certain packet types, for example, Broadcasts, Multicasts, and
Unicasts with an unknown destination address.
 Limit the outbound data traffic instead of the inbound traffic. The outbound rate limitation works
better with TCP flow control due to device-internal buffering of the data packets.
 Increase the aging time for learned Unicast addresses.

Perform the following steps:

 Open the Switching > Rate Limiter dialog.


 Activate the rate limiter and set limits for the data rate. The settings apply on a per port
basis and are broken down by type of traffic:
 Received Broadcast data packets
 Received Multicast data packets
 Received Unicast data packets with an unknown destination address
To activate the rate limiter on a port, mark the checkbox for at least one category. In the
Threshold unit column, you specify whether the device interpretes the threshold values as
percent of the port bandwidth or as packets per second. The threshold value 0 deactivates
the rate limiter.
 To save the changes temporarily, click the button.

124 UM Config EAGLE


Release 3.4 03/2020
Routing
12.1 Configuration

12 Routing

12.1 Configuration

Because the configuration of a router is very dependent on the conditions in your network, you are
first provided with a general list of the individual configuration steps. To optimally cover the large
number of options, this list is followed by examples of networks that usually occur in the industry
sector.

The configuration of the Routing function usually contains the following steps:
 Drawing a network plan
Create a picture of your network so that you can clearly see the division into subnetworks and
the related distribution of the IP addresses. This step is necessary. Good planning of the
subnetworks with the corresponding network masks makes the router configuration much
easier.
 Router basic settings
Along with the global switching on of the Routing function, the router basic settings also contain
the assignment of IP addresses and network masks to the router interfaces.

Note: Adhere to the sequence of the individual configuration steps so that the configuration
computer has access to every Layer 3 device throughout the entire configuration phase.

Note: When you assign an IP address from the subnetwork of the device management IP address
to a router interface, the device deletes the IP address of the device management. You access the
device management via the IP address of the router interface.

Activate the routing globally before you assign an IP address from the subnetwork of the device
management IP address to a router interface.

Note: When you assign the VLAN ID of the device management VLAN to a router interface, the
device deactivates the IP address of the device management. You access the device management
via the IP address of the router interface. The device management VLAN is the VLAN by means of
which you access the device management of every device.

Note: Depending on your configuration steps, it can be necessary to change the IP parameters of
your configuration computer to enable access to the Layer 3 devices.

 Selecting a routing procedure


On the basis of the network plan and the communication requirements of the connected
devices, you select the optimal routing procedure (static routes , OSPF) for your situation. In
doing so, consider which routing procedures the routers can use along a route.
 Configuring a routing procedure
Configure the selected routing procedure.

UM Config EAGLE 125


Release 3.4 03/2020
Routing
12.2 Routing - Basics

12.2 Routing - Basics

A router is a node for exchanging data on the Layer 3 of the ISO/OSI reference model.

This ISO/OSI reference model had the following goals:


 To define a standard for information exchange between open systems;
 To provide a common basis for developing additional standards for open systems;
 To provide international teams of experts with functional framework as the basis for independent
development of every layer of the model;
 To include in the model developing or already existing protocols for communications between
heterogeneous systems;
 To leave sufficient room and flexibility for the inclusion of future developments.

The OSI reference model consists of 7 layers, ranging from the application layer to the physical
layer.

Table 18: OSI reference model

7 Application Access to communication services from an application program


6 Presentation Definition of the syntax for data communication
5 Session Set up and breakdown of connections by synchronization and organization
of the dialog
7 Transport Specification of the terminal connection, with the necessary transport
quality
3 Network Transparent data exchange between two transport entities
2 Data-Link Access to physical media and detection of transmission errors
1 Physical Transmission of bit strings via physical media

What does the data exchange on the Layer 3 mean in comparison with the data exchange on the
Layer 2?

Layer 7 Layer-2-Switch Layer 7 Layer 7 Layer-3-Switch/ Layer 7


Layer 6 Layer 6 Layer 6 Router Layer 6
Layer 5 Layer 5 Layer 5 Layer 5
Layer 4 Layer 4 Layer 4 Layer 4
Layer 3 Layer 3 Layer 3 Layer 3 Layer 3
Layer 2 Layer 2 Layer 2 Layer 2 Layer 2 Layer 2
Layer 1 Layer 1 Layer 1 Layer 1 Layer 1 Layer 1

Figure 23: Data Transport by a Switch and a Router in the OSI Reference Model‘s Layers

On the Layer 2, the MAC address signifies the destination of a data packet. The MAC address is
an address tied to the hardware of a device. The Layer 2 expects the receiver in the connected
network. The data exchange to another network is the task of Layer 3. Layer 2 data traffic is spread
over the entire network. Every subscriber filters the data relevant for him from the data stream.
Layer 2 devices are capable of steering the data traffic that is intended for a specific MAC address.
It thus relieves some of the load on the network. Broadcast and multicast data packets are
forwarded by the Layer 2 devices on every port.

126 UM Config EAGLE


Release 3.4 03/2020
Routing
12.2 Routing - Basics

IP is a protocol on the Layer 3. IP provides the IP address for addressing data packets. The IP
address is assigned by the network administrator. By systematically assigning IP addresses, he
can thus structure his network, breaking it down into subnets (see on page 129 “CIDR”). The bigger
a network gets, the greater the data volume. Because the available bandwidth has physical
limitations, the size of a network is also limited. Dividing large networks into subnets limits the data
volume on these subnets. Routers divide the subnets from each other and only transmit the data
that is intended for another subnet.

Figure 24: MAC Data Transmission: Unicast Data Packet (left) and Broadcast Data Packet (right)

This illustration clearly shows that broadcast data packets can generate a considerable load on
larger networks. You also make your network easier to understand by forming subnets, which you
connect with each other using routers and, strange as it sounds, also separate securely from each
other.

A switch uses the MAC destination address to transmit, and thus uses Layer 2. A router uses the
IP destination address to transmit, and thus uses Layer 3.

The subscribers associate the MAC and IP addresses using the Address Resolution Protocol
(ARP).

12.2.1 ARP

The Address Resolution Protocol (ARP) determines the MAC address that belongs to an IP
address. What is the benefit of this?

Let’s suppose that you want to configure the device using the Web-based interface. You enter the
IP address of the device in the address line of your browser. But which MAC address will your PC
now use to display the information in the device in your browser window?

If the IP address of the device is in the same subnetwork as your PC, then your PC sends what is
known as an ARP request. This is a MAC broadcast data packet that requests the owner of the IP
address to send back his MAC address. The device replies with a unicast data packet containing
its MAC address. This unicast data packet is called an ARP reply.

Query to everyone:
Whoever has the
IP address [Link]
please send me your MAC address.
[Link]
00:80:63:10:11:12

[Link]
00:80:63:10:11:25
Reply to PC:
My MAC address is
00:80:63:10:11:25.

Figure 25: ARP request and reply

UM Config EAGLE 127


Release 3.4 03/2020
Routing
12.2 Routing - Basics

When the IP address of the device is in a different subnetwork, the PC asks for the MAC address
of the gateway entered in the PC. The gateway/router replies with its MAC address.

Now the PC packs the IP data packet with the IP address of the device, the final destination, into a
MAC frame with the MAC destination address of the gateway/router and sends the data.

The router receives the data and releases the IP data packet from the MAC frame, so that it can
then forward it in accordance with its transmission rules.

Preamble
MAC destination address
MAC source address Layer 2
Type/length field

IP header with
IP source address and
IP destination address
Layer 3

Data

Layer 4 und höher

Frame Check Sequence/CRC


Figure 26: Structure of a data packet from the ISO/OSI reference model perspective

All end devices still working with IPs of the first generation, for example, are not yet familiar with the
term 'subnet'. When they are looking for the MAC address for an IP address in a different subnet,
they also send an ARP request. They neither have a network mask with which they could recognize
that the subnet is a different one, nor do they have a gateway entry. In the example below, the left
PC is looking for the MAC address of the right PC, which is in a different subnet. In this example,
it would normally not get a reply.

Because the router knows the route to the right PC, the Proxy ARP function replies to this router
interface on behalf of the right PC with its own MAC address. Thus the left PC can address its data
to the MAC address of the router, which then forwards the data to the right PC.

Query to everyone:
Whoever has the
IP address [Link].

[Link] [Link]
00:80:63:10:11:12
Prox-ARP
00:80:63:10:22:25

Reply to PC:
The IP address [Link]
has the MAC address
00:80:63:10:22:25.

Figure 27: Proxy ARP function

The Proxy ARP function is available on the router interfaces on which you enable the proxy ARP.

Note: The 1:1 NAT function also lets you integrate the devices into a larger L3 network.

128 UM Config EAGLE


Release 3.4 03/2020
Routing
12.2 Routing - Basics

12.2.2 CIDR

The original class allocation of the IP addresses only planned for three address classes to be used
by the users.

Since 1992, five classes of IP address have been defined in the RFC 1340.

Table 19: IP address classes

Class Network part Host part Address range


A 1 byte 3 bytes [Link] … [Link]
B 2 bytes 2 bytes [Link] … [Link]
C 3 bytes 1 byte [Link] … [Link]
D [Link] … [Link]
E [Link] … [Link]

Class C with a maximum of 254 addresses was too small, and class B with a maximum of 65534
addresses was too large for most users, as they would not require so many addresses. This
resulted in ineffective usage of the class B addresses available.

Class D contains reserved multicast addresses. Class E is reserved for experimental purposes. A
gateway not participating in these experiments ignores datagrams with this destination address.

The Classless Inter-Domain Routing (CIDR) provides a solution to these problems. The CIDR
overcomes these class boundaries and supports classless address ranges.

With CIDR, you enter the number of bits that designate the IP address range. You represent the IP
address range in binary form and count the mask bits that designate the network mask. The
network mask indicates the number of bits that are identical for every IP address, the network part,
in a given address range. Example:

IP address, decimal Network mask, IP address, binary


decimal
[Link] [Link] 10010101 11011010 01110000 00000001
[Link] 10010101 11011010 01110000 01111111
25 mask bits
CIDR notation: [Link]/25
Mask bits

The combination of a number of class C address ranges is known as “supernetting”. This enables
you to subdivide class B address ranges to a very fine degree.

Using mask bits simplifies the routing table. The router determines in that direction in which most
of the mask bits match (longest prefix match).

12.2.3 Multinetting

Multinetting lets you connect a number of subnets to one router port. When you want to connect
existing subnets to a router within a physical medium, multinetting provides a solution. In this case
you can use multinetting to assign a number of IP addresses for the different subnets to the routing
port to which you are connecting the physical medium.

UM Config EAGLE 129


Release 3.4 03/2020
Routing
12.2 Routing - Basics

For a long-term solution, other network design strategies provide more advantages with regard to
problem solving and bandwidth management.

[Link]/24 [Link]/24
[Link]/24
[Link]/24

[Link]/24 [Link]/24
[Link]/24

Figure 28: Example of multinetting

130 UM Config EAGLE


Release 3.4 03/2020
Routing
12.3 Static Routing

12.3 Static Routing

Static routes are user-defined routes which the router uses to transmit data from one subnet to
another.

The user specifies to which router (next hop) the local router forwards data for a particular subnet.
Static routes are kept in a table which is permanently stored in the router.

Compared to dynamic routing, the advantage of this transparent route selection is offset by the
increased workload involved in configuring the static routes. Static routing is therefore suited to very
small networks or to selected areas of larger networks. Static routing makes the routes transparent
for the administrator and can be easily configured in small networks.

If, for example, a line interruption causes the topology to change, then the dynamic routing can
react automatically to this, in contrast to the static routing. When you combine static and dynamic
routing, you can configure the static routes in such a way that they have a higher priority than a
route selected by a dynamic routing procedure.

The first step in configuring the router is to globally enable the Routing function and configure the
router interfaces.

The device lets you define port-based and VLAN-based router interfaces (see figure 29).

Example: Connecting two production cells

Configuration PC Port-based VLAN-based

SN 10 A
SN 11
VLAN ID 2

Figure 29: Static routes

12.3.1 Port-based Router Interface

A characteristic of the port-based router interface is that a subnet is connected to a port (see
figure 29).

Special features of port-based router interfaces:


 When there is no active connection, the entry is omitted from the routing table, because the
router transmits only to those ports for which the data transfer is likely to be successful.
The entry in the interface configuration table remains.
 A port-based router interface does not recognize VLANs, which means that the router rejects
tagged packets which it receives on a port-based router interface.
 A port-based router interface rejects the non-routable packets.

Below (see figure 30) you will find an example of the simplest case of a routing application with port-
based router interfaces.

UM Config EAGLE 131


Release 3.4 03/2020
Routing
12.3 Static Routing

Configuration of the router interfaces

[Link]/24 [Link]/24
Interface 2.1 Interface 2.2
IP=[Link]/24 IP=[Link]/24
Figure 30: Simplest case of a route

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.

interface 2/1 Change to the interface configuration mode of


interface 2/1.
ip address primary [Link] Assign the interface its primary IP parameters.
[Link]
ip routing Activate the Routing function on this interface.
exit Change to the Configuration mode.

interface 2/2 Change to the interface configuration mode of


interface 2/2.
ip address primary [Link] Assign the interface its IP parameters.
[Link]
ip routing Activate the Routing function on this interface.
exit Change to the Configuration mode.
ip routing Enable the Routing function globally.
exit Change to the Privileged EXEC mode.
show ip interface 2/1 Check the entries on interface 2/1.
Routing Mode............................. enabled
Admin mode............................... manual
IP address............................... [Link]/[Link]
Secondary IP address (es)................ none
Proxy ARP................................ diabled
MAC Address.............................. EC:E5:55:F6:3E:09
IP MTU................................... 1500
ICMP Redirect............................ enabled
ICMP Unreachable......................... enabled
Netdirected Broadcast.................... disabled(int2/2 enabled)
Admin State.............................. enabled
Link State............................... up
show ip route all Verify the routing table:
Network Address Protocol Next Hop IP Next Hop If Pref Active----------------- -----
--- ---------- ----------- ---- -----
[Link]/24 Local [Link] 2/1 0 [x]
[Link]/24 Local [Link] 2/2 0 [x]

Note: To be able to see these entries in the routing table, you need an active connection on the
interfaces.

132 UM Config EAGLE


Release 3.4 03/2020
Routing
12.3 Static Routing

12.3.2 VLAN-based Router-Interface

A characteristic of the VLAN-based router interface is that a number of devices in a VLAN are
connected to different ports.

Within a VLAN, the switch exchanges data packets on Layer 2.

Terminal devices address data packets with a destination address in another subnet to the router.
The device then exchanges the data packets on Layer 3.

Below you will find an example of the simplest case of a routing application with VLAN-based router
interfaces. For VLAN 2, the router combines interfaces 3/1 and 3/2 into the VLAN router interface
vlan/2. A VLAN router interface remains in the routing table as long as at least one port of the
VLAN has a connection.

VLAN 1 [Link]/24
[Link]/24 Port 3.1
Interface 9.1 VLAN 2
A IP=[Link]/24
Interface 2.1
IP=[Link]/24 Port 3.2 [Link]/24

Figure 31: VLAN-based router interface

Use the following steps and tables to configure a VLAN router interface:
 Create a VLAN and assign ports to the VLAN.
 Create a VLAN-based router interface.
 Assign an IP address to the VLAN-based router interface.

UM Config EAGLE 133


Release 3.4 03/2020
Routing
12.3 Static Routing

 Activate routing on the VLAN-based router interface.


 Enable the Routing function globally.

enable Change to the Privileged EXEC mode.


vlan database Change to the VLAN configuration mode.
vlan add 2 Create a VLAN by entering the VLAN ID. The
VLAN ID range is between 1 to 4042.
name 2 VLAN2 Assign the name VLAN2 to the VLAN.
routing add 2 Create a virtual router interface and activate the
Routing function on this interface.
exit Change to the Privileged EXEC mode.

show ip interface Check the entry for the virtual router interface.

Interface IP Address IP Mask


--------- --------------- ---------------
vlan/2 [Link] [Link]

configure Change to the Configuration mode.


interface vlan/2 Change to the interface configuration mode of
interface vlan/2.

ip address primary [Link] Assign the IP parameters to the virtual router


[Link] interface.
ip routing Activate the Routing function on this interface.
exit Change to the Configuration mode.

interface 3/1 Change to the interface configuration mode of


interface 3/1.
vlan participation exclude 1 Remove port 3/1 from VLAN 1. In the default
setting, every port is assigned to VLAN 1.
vlan participation include 2 Declare port 3/1 a member of VLAN 2.
vlan pvid 2 Specify port VLAN ID 2. Therefore, the device
assigns data packets that the port receives without
a VLAN tag to VLAN 2.
exit Change to the Configuration mode.

interface 3/2 Change to the interface configuration mode of


interface 3/2.
vlan participation exclude 1 Remove port 3/2 from VLAN 1. In the default
setting, every port is assigned to VLAN 1.
vlan participation include 2 Declare port 3/2 a member of VLAN 2.
vlan pvid 2 Specify port VLAN ID 2. Therefore, the device
assigns data packets that the port receives without
a VLAN tag to VLAN 2.
exit Change to the Configuration mode.
ip routing Enable the Routing function globally.
exit Change to the Privileged EXEC mode.

134 UM Config EAGLE


Release 3.4 03/2020
Routing
12.3 Static Routing

show vlan id 2 Check your entries in the static VLAN table.

VLAN ID...........................2
VLAN Name.........................VLAN002
VLAN Creation TIme................0 days, 01:47:17
VLAN Type.........................static

Interface Current Configured Tagging


---------- -------- ----------- --------
...
3/1 Include Include Untagged
3/2 Include Include Untagged
3/3 Exclude Autodetect Untagged
3/4 Exclude Autodetect Untagged
...

show vlan port Check the VLAN-specific port settings.


Port Acceptable IngressInterface VLAN ID Frame Types Filtering Priority
--------- ------- ------------ ----------- --------
...
3/1 2 admit all disable 0
3/2 2 admit all disable 0
3/3 1 admit all disable 0
3/4 1 admit all disable 0
...

UM Config EAGLE 135


Release 3.4 03/2020
Routing
12.3 Static Routing

 Open the Routing > Interfaces > Configuration dialog.


 Click the button.
The dialog displays the Configure VLAN router interface window.
 In the VLAN ID field, specify a number in the range between 1 and 4042.
For this example, specify the value 2.
 Click the Next button.
 In the Name field, specify the name of the VLAN. For this example, specify the value
VLAN002.
 In the Member column, mark the check box of the ports which will belong to this VLAN.
For this example, mark the check box of port 3/1 and port 3/2.
 Click the Next button.
 In the Primary address frame, Address field, specify the IP address for the router interface.
For this example, specify the value [Link].
 In the Primary address frame, Netmask field, specify the corresponding netmask.
For this example, specify the value [Link].
 To apply the changes, click the Finish button.
In the Routing > Interfaces > Configuration dialog, the table displays the virtual router interface
vlan/2.
In the Switching > VLAN > Configuration dialog, the table displays the VLAN VLAN002.
 In the Routing > Interfaces > Configuration dialog, mark the check box in the Netdirected
broadcasts column for router interface vlan/2.
 To save the changes temporarily, click the button.

You delete a router interface highlighted in the Routing > Interfaces > Configuration dialog by clicking
the button.
 After deleting a VLAN router interface the associated VLAN is maintained. In the Switching >
VLAN > Configuration dialog, the table still displays the VLAN.
 After deleting a VLAN in the Switching > VLAN > Configuration dialog, the device also deletes the
associated VLAN router interface.

12.3.3 Configuration of a Static Route

In the example below, router A requires the information that it can reach the subnet [Link]/24 via
the router B (next hop). It can obtain this information via a dynamic routing protocol or via a static
routing entry. With this information, router A can transmit data from subnet [Link]/24 via router B
into subnet [Link]/24.

Vice versa to be able to forward data of subnet [Link]/24 router B also needs an equivalent route.

Subnet [Link]/24 Subnet [Link]/24


Interface 2.1
[Link]/24 IP=[Link] [Link]/24

A B Interface 2.2
Interface 2.1
IP=[Link] Interface 2.2 IP=[Link]
IP=[Link]
Figure 32: Static Routing

You can enter static routing for port-based and VLAN-based router interfaces.

136 UM Config EAGLE


Release 3.4 03/2020
Routing
12.3 Static Routing

Configuration of a simple static route

Enter a static route for router A based on the configuration of the router interface in the previous
example (see figure 30):

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
ip route add [Link] [Link] Create the static routing entry
[Link]
ip routing Enable the Routing function globally.
exit Change to the Privileged EXEC mode.

show ip route all Verify the routing table:

Network Address Protocol Next Hop IP Next Hop If Pref Active


--------------- -------- ------------ ------------ ---- -------
[Link] Local [Link] 2/1 1 [x]
[Link] Local [Link] 2/2 1 [x]
[Link] Static [Link] 2/2 1 [x]

 Configure router B in the same way.

Configuration of a redundant static route

To establish a stable connection between the two routers, you can connect the two routers with two
or more links.

Subnet [Link]/24 Subnet [Link]/24


Interface 2.3 Interface 2.3
[Link]/24 IP=[Link] IP=[Link] [Link]/24

A B Interface 2.2
Interface 2.1
IP=[Link] Interface 2.2 Interface 2.1 IP=[Link]
IP=[Link] IP=[Link]
Figure 33: Redundant static route

UM Config EAGLE 137


Release 3.4 03/2020
Routing
12.3 Static Routing

You have the option of assigning Preference (distance) to a route. When there are a number of
routes to a destination, the router chooses the route with the highest Preference.
 Configure router A.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
interface 2/3 Select the port at which you want to connect the
redundant route.
ip address primary [Link] Assign the IP parameters to the port.
[Link]
ip routing Activate the Routing function on this interface.
exit Change to the Configuration mode.
ip route add [Link] [Link] Create the static routing entry for the redundant
[Link] preference 2 route. The value 2 at the end of the command
indicates the Preference value.
When both routes are available, the router uses the
route via subnetwork [Link]/24, because this
route has the higher preference (see on page 137
“Configuration of a simple static route”).

You have the option of changing the default value of the Preference. When you do not assign a value
for the Preference during the configuration, the router uses the default value.

ip route distance Sets the default preference for static routes.


(default setting: 1)

show ip route all Verify the routing table:

Network Address Protocol Next Hop IP Next Hop If Pref Active


--------------- -------- ------------ ------------ ---- -------
[Link] Local [Link] 2/1 1 [x]
[Link] Local [Link] 2/2 1 [x]
[Link] Static [Link] 2/2 1 [x]
[Link] Static [Link] - 2 [ ]
[Link] Local [Link] 2/3 1 [x]

 Configure router B in the same way.

Configuration of a redundant static route with load sharing

When the routes have the same Preference(distance), the router shares the load between the 2
routes (load sharing).

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
ip route modify [Link] [Link] Assigns a Preference of 2 to the existing static
[Link] preference 2 routing entry (see on page 137 “Configuration of a
simple static route”).
When both routes are available, the router uses
both routes for the data transmission.

138 UM Config EAGLE


Release 3.4 03/2020
Routing
12.3 Static Routing

show ip route all Verify the routing table:

Network Address Protocol Next Hop IP Next Hop If Pref Active


--------------- -------- ------------ ------------ ---- -------
[Link] Local [Link] 2/1 1 [x]
[Link] Local [Link] 2/2 1 [x]
[Link] Static [Link] 2/2 2 [x]
[Link] Static [Link] 2/3 2 [x]
[Link] Local [Link] 2/3 1 [x]

12.3.4 Static route tracking

Description of the static route tracking function

With static routing, when there are a number of routes to a destination, the router chooses the route
with the highest preference. The router detects an existing route by the state of the router interface.
While connection L 1 on the router interface can be fine, the connection to remote router B via L 2
can be interrupted. In this case, the router continues transmitting via the interrupted route.

[Link]/24 [Link]/24 [Link]/24

L1 L2
A B

L3 [Link]/24

Figure 34: Example of static route tracking

With the static route tracking function, the router uses a tracking object such as a ping tracking
object to detect the connection interruption. The active static route tracking function then deletes
the interrupted route from the current routing table. When the tracking object returns to the up state,
the router enters the static route in the current routing table again.

Application example for the static route tracking function

The figure displays an example of the static route tracking function (see figure 35).

Router A monitors the best route via L 1 with ping tracking. If there is a connection interruption, then
router A transmits using the redundant connection L 3.

For the example the following information is known:

UM Config EAGLE 139


Release 3.4 03/2020
Routing
12.3 Static Routing

Parameter Router A
IP address interface (IF) 1/1 [Link]

IP address interface (IF) 1/2 [Link]

IP address interface (IF) 1/4 [Link]

Netmask [Link]

Parameter Router B
IP address interface (IF) 1/2 [Link]

IP address interface (IF) 1/3 [Link]

IP address interface (IF) 2/2 [Link]

Netmask [Link]

[Link]/24 [Link]/24 [Link]/24


IF 1/4 IF 1/2 IF 1/3 IF 2/2
L1 L2
A B
IF 1/1 IF 1/2
L3 [Link]/24

Figure 35: Configuring static route tracking

140 UM Config EAGLE


Release 3.4 03/2020
Routing
12.3 Static Routing

The following list contains prerequisites for further configuration:


 The IP parameters of the router interfaces are configured.
(see on page 132 “Configuration of the router interfaces”)
 The Routing function is activated globally and on the router interface.
 Ping tracking on interface 1/2 of router A is configured (see on page 156 “Ping tracking”).
 Create the tracking objects on router A for the routes to the destination network [Link]/24.
The default values, entered in the other cells, remain unchanged for this example.

 Open the Routing > Tracking > Configuration dialog.


 Click the button.
The dialog displays the Create window.
 Enter the data for the first tracking rule:
Type: ping
Track ID: 1
 Click the Ok button.
 In the ping-1 row, IP address column, specify the IP address [Link].
 In the ping-1 row, Ping port column, specify the interface 1/2.
 To activate the row, mark the Active checkbox.
 Click the button.
The dialog displays the Create window.
 Enter the data for the first static route:
Type: ping
Track ID: 2
 Click the Ok button.
 In the ping-2 row, IP address column, specify the IP address [Link].
 In the ping-2 row, Ping port column, specify the interface 1/1.
 To activate the row, mark the Active checkbox.
 To temporarily save the settings, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
track add ping 1 Create a tracking object with track ID 1.
track modify ping 1 address [Link] Modify the ping-1 entry with the IP address
[Link].
track modify ping 1 interface 1/2 Set the source interface number of the ping
tracking instance to 1/2.
track enable ping 1 Activate the tracking object.
track add ping 2 Create a tracking object with track ID 2.
track modify ping 2 address [Link] Modify the ping-2 entry with the IP address
[Link].
track modify ping 2 interface 1/1 Set the source interface number of the ping
tracking instance to 1/1.
track enable ping 2 Activate the tracking object.
exit Change to the Privileged EXEC mode.

UM Config EAGLE 141


Release 3.4 03/2020
Routing
12.3 Static Routing

show track ping Verify the entries in the tracking table.

Name Interface Intv [ms] Succ TTL BR-If State Active Inet-Address Timeout
Miss
------ ------------- --------- ----- ------- -------- ----- ------
ping-1 1/2 1000 2 128 0 up [x] [Link] 100 3
ping-2 1/1 1000 2 128 0 down [x] [Link] 100 3

142 UM Config EAGLE


Release 3.4 03/2020
Routing
12.3 Static Routing

Note: In order to activate the row, verify that the link on the interface is up.

 Next enter the routes to the destination network [Link]/24 in the static routing table of router A.

 Open the Routing > Routing Table dialog.


 Click the button.
The dialog displays the Create window.
 Enter the data for the first static route:
Network address: [Link]
Netmask: [Link]
Next hop IP address: [Link]
Preference: 1
Track name: ping-1
 Click the Ok button.
 Click the button.
The dialog displays the Create window.
 Enter the data for the first static route:
Network address: [Link]
Netmask: [Link]
Next hop IP address: [Link]
Preference: 2
Track name: ping-2
 Click the Ok button.
 To temporarily save the settings, click the button.
Note: To make the configuration available even after a restart, save the settings permanently
in the Basic Settings > Load/Save dialog.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
ip route add [Link] [Link] Create a static routing entry with the default
[Link] preference.
ip route add [Link] [Link] Create a static routing entry with preference 2.
[Link] preference 2
exit Change to the Privileged EXEC mode.

show ip route all Verify the routing table:

Network Address Protocol Next Hop IP Next Hop If Pref Active


--------------- -------- ------------ ------------ ---- -------
[Link] Local [Link] 1/4 1 [x]
[Link] Local [Link] 1/2 1 [x]
[Link] Static [Link] 1/2 1 [x]
[Link] Static [Link] 1/2 2 [x]

 On router B, create a ping tracking object with the track ID, for example 22, for IP address
[Link].
 Enter the two routes to destination network [Link]/24 in the static routing table of router B.

UM Config EAGLE 143


Release 3.4 03/2020
Routing
12.3 Static Routing

Table 20: Static routing entries for router B

Destination Destination Next Hop Preference Track ID


Network Netmask
[Link] [Link] [Link] 1 22
[Link] [Link] [Link] 2

144 UM Config EAGLE


Release 3.4 03/2020
Routing
12.4 NAT – Network Address Translation

12.4 NAT – Network Address Translation

The Network Address Translation (NAT) protocol describes a procedure for automatically and
transparently changing IP address information in data packets while still transmitting the data
packets to their precise destination.

When you do not want IP addresses of an internal network to be visible from outside, use NAT. The
reasons for this can include, for example:
 Keeping the structure of the internal network hidden from the outside world.
 Keeping private IP addresses hidden.
 Using IP addresses multiple times – by forming identical production cells, for example.

Depending on your reason for using NAT, it offers you various procedures for using the IP address
information. In the following sections, you will find additional information on this process.

12.4.1 Applying the NAT Rules

The device provides a multi-step approach for setting up and applying the NAT rules:
 Create rule.
 Assign rule to a router interface.
Up to this step, changes have no effect on the behavior of the device and the data stream.
 Apply the rule to the data stream.

The data packets go through the filter functions of the device in the following sequence:

Operating System

Destination Address Modification Ingress Egress Source Address Modification


1:1 NAT Packet Policy Routing Packet Masquerading NAT
Destination NAT Filter Filter Double NAT
Double NAT

MAC-based ACL

IP-based ACL

DoS
Switching Chip

Network 1 Network 2

Figure 36: Processing sequence of the data packets in the device

UM Config EAGLE 145


Release 3.4 03/2020
Routing
12.4 NAT – Network Address Translation

12.4.2 1:1 NAT

The 1:1 NAT function lets you establish communication links within a local network to devices that
are actually located in other networks. The NAT router virtually “shifts” the devices into the public
network. To do this, the NAT router replaces the virtual with the actual IP address in the data packet
while sending it. A typical application is the connecting of several identically structured production
cells with the same IP address to a server farm.

The prerequisite for the 1:1 NAT process is that the NAT router itself responds to ARP requests. To
make this happen, activate the Proxy ARP function on the ingress interface.

1:1 NAT
Zieladresse Neue Zieladresse
Destination Address New Destination Address
Ingress Egress
Interface Interface
[Link] [Link]
Proxy ARP

[Link]/24
[Link]/24
Regel

dest [Link]
Rule

new dest [Link]

[Link]

Figure 37: How the 1:1 NAT method works

Note: With 1:1 NAT the device responds to ARP requests from the external network to addresses
which it maps from the internal network. This is also the case where no device with the IP address
exists in the internal network. Therefore, in the external network, only allocate to devices IP
addresses located outside the area which 1:1 NAT maps from the internal network to the external
network.

Application example for 1:1 NAT

You have multiple identical production cells and want to connect them with the host computer. As
even the IP addresses used in the production cells are identical, you convert the IP addresses using
the 1:1 NAT function.

Zieladresse Neue Zieladresse


Destination Address New Destination Address
Ingress Egress
Interface Interface
[Link]
Proxy ARP
[Link]

[Link]/24
NAT Router 1

[Link]

[Link]
Proxy ARP
[Link]

[Link]/24 [Link]/24
NAT Router 2

Figure 38: Connect identical production cells with the host computer (application example)

Prerequisites for further configuration:


 You need two NAT routers.
 The Routing function is enabled in every device.

146 UM Config EAGLE


Release 3.4 03/2020
Routing
12.4 NAT – Network Address Translation

 Two router interfaces are configured in every device. One router interface is connected to the
company network and one to the network of the production cell.
 The IP address and gateway are set in the devices of the production cell. The devices use the
IP address of the egress interface of the NAT router as the gateway.

Perform the following steps:


 Activate the Proxy ARP function on the ingress interfaces.

 Open the Routing > Interfaces > Configuration dialog.


 On the router interface that is connected to the company network, mark the checkbox in
the Proxy ARP field.
 To save the changes temporarily, click the button.

 Generate rule.

 Open the Routing > NAT > 1:1 NAT > Rule dialog.
 To add a table entry, click the button.
 In the Rule name column, specify the name of the NAT rule.
 In the Priority column, specify any value between 1 and 6500.
 In the Ingress interface column, select the router interface that is connected to the company
network.
 In the Destination address column, specify the virtual IP address of the device in the
production cell; in the example this is [Link] in NAT router 1 and [Link]
in NAT router 2.
 In the Egress interface column, select the router interface connected with the production cell.
 In the New destination address column, specify the IP address of the device in the production
cell; in the example this is [Link] in NAT router 1 and in NAT router 2.
 Activate the rule:
Mark the checkbox in the Active column.
 To save the changes temporarily, click the button.

 Apply the rule to the data stream.

 Open the Routing > NAT > NAT Global dialog.


 Click the button and then the Commit changes item.
When changes to the rules affect existing entries in the state table of the firewall, it helps to
clear the state table. See the Clear firewall table button in the Basic Settings > Restart dialog. It is
possible, that the device interrupts open communication connections.

UM Config EAGLE 147


Release 3.4 03/2020
Routing
12.4 NAT – Network Address Translation

12.4.3 Destination NAT

The Destination NAT method lets you divert the data stream of outgoing communication links to or
through a server in a local network.

A special form of the Destination NAT method is port forwarding. You use port forwarding to hide
the structure of a network from the outside while still allowing communication links from the outside
into the network. A typical application is remote control of a PC in a production cell. The
maintenance station establishes the communication link to the NAT router, and Destination NAT
takes care of the routing to the production cell.

src <any>
dest <any> Destination NAT
Regel
Rule
new dest [Link]
proto tcp
dest port 80,20,21
[Link]/24
Zieladresse
Destination Address
<any>
[Link] Ingress
Interface
Quelladresse DMZ
Source Address

[Link]

Neue Zieladresse
New Destination Address

(Port Forwarding)

Ingress [Link]/24
Interface

[Link]:80
[Link]:8080
Zieladresse Neue Zieladresse
Destination Address New Destination Address

Figure 39: How the Destination NAT method works

Application example for port forwarding

You have a production cell. The network of the production cell is not visible on the company
network. The NAT router establishes the connection between the production cell and the company
network. To allow an administrator from the company network to manage a server in the production
cell, use the port forwarding function.

Parameter Administrator PC NAT router Server


IP Address Port 1 [Link]

IP Address Port 4 [Link]

IP Address [Link] [Link]

Gateway [Link] [Link]

148 UM Config EAGLE


Release 3.4 03/2020
Routing
12.4 NAT – Network Address Translation

Prerequisites for further configuration:


 The Routing function is enabled in the device.
 In the device, a router interface is set up and connected to the company network.
 In the devices in the production cell, the IP address and gateway are defined. The devices use
the IP address of port 1 of the NAT router as the gateway.

Perform the following steps:


 Generate rule.

 Open the Routing > NAT > Destination NAT > Rule dialog.
 Click the button.
The dialog displays the Create window.
 In the Rule name field, specify the name of the NAT rule.
 In the Destination address field, specify the IP address of the router interface in the company
network; in the example it is [Link]. The PC of the administrator establishes the
connection to this address.
 In the Destination port field, specify the port number; in this example it is 8080. The PC of
the administrator establishes the connection to this port.
 In the New destination address field, specify the IP address of the server in the production
cell; in the example it is [Link]. The NAT router forwards the connection to this
address.
 In the New destination port field, specify the port number; in this example it is 80. The NAT
router forwards the connection to this port.
 To forward connections only from the PC of the administrator to the server in the
production cell, change the value in the Source address field to the IP address of the PC; in
the example it is [Link]. Otherwise, leave the value any.
 To forward only TCP data packets to the server in the production cell, change the value in
the Protocol field to tcp. Otherwise, leave the value any.
 Click the Ok button.

 Activate the rule.

 Mark the checkbox in the Active field to enable the created rule.
 To save the changes temporarily, click the button.

 Assign rule to a router interface.

 Open the Routing > NAT > Destination NAT > Mapping dialog.
 Click the Assign button.
 In the Port field, select the router interface that is connected to the company network.
 Select the created rule in the Rule index field.
 Click the Ok button.

 Activate assignment of the rule to the router interface.

UM Config EAGLE 149


Release 3.4 03/2020
Routing
12.4 NAT – Network Address Translation

 Select the checkbox in the Active field to activate assignment of the rule to the router
interface.
 To save the changes temporarily, click the button.

 Apply the rule to the data stream.

 Open the Routing > NAT > NAT Global dialog.


 Click the button and then the Commit changes item.
When changes to the rules affect existing entries in the state table of the firewall, it helps to
clear the state table. See the Clear firewall table button in the Basic Settings > Restart dialog. It is
possible, that the device interrupts open communication connections.

12.4.4 Masquerading NAT

The Masquerading NAT method hides any number of devices behind the IP address of the NAT
router and thus hides the structure of a network from other networks. To do this, the NAT router
replaces the sender address in the data packet with its own IP address. In addition, the NAT router
replaces the source port in the data packet with its own value in order to send the response data
packets back to the original sender at a later point.

Adding the port information also gave the IP Masquerading the name “Network Address Port
Translation” (NAPT).

The devices establish communication links to the outside from the hidden network by converting
the IP address. However, it is not possible to establish a connection in the other direction, because
the devices outside only know the external IP address of the NAT router.

Quelladresse
Source Address

Masquerading NAT
[Link]
[Link]/24

[Link]

[Link]/24 [Link]
Egress
[Link] Interface

Figure 40: How the Masquerading NAT method works

Note: If you enable the VRRP function on a router interface, then the Masquerading NAT function is
ineffective on this router interface.

150 UM Config EAGLE


Release 3.4 03/2020
Routing
12.4 NAT – Network Address Translation

12.4.5 Double NAT

The Double NAT method lets you establish communication links between end devices located in
different IP networks, which have no way to specify a default gateway or default route. The NAT
router virtually “shifts” the devices into the other network. To do this, the NAT router replaces the
source address and the destination address in the data packet during sending. A typical application
is the linking of controllers located in different networks.

The Double NAT method requires that the NAT router itself responds to ARP requests from the
respective network. To make this happen, activate the Proxy ARP function on the ingress interface
and on the egress interface.

Lokale interne IP-Adresse Lokale externe IP-Adresse


Local Internal IP Address Local External IP Address

Double NAT
[Link] [Link]
Proxy ARP
Egress
Interface

Ingress
[Link]/24 [Link]/24
Interface
[Link] Proxy ARP [Link]

Entfernte externe IP-Adresse Entfernte interne IP-Adresse


Remote External IP Address Remote Internal IP Address

Figure 41: How the Double NAT method works

The figure shows which IP addresses the devices use to communicate with each other and how the
NAT router changes the IP addresses:
 The device on the left sends a data packet to the device on the right.
– The data packet contains the source address [Link] and the destination address
[Link].
– The NAT router replaces both addresses.
– The data packet that the device on the right receives contains the source address
[Link] and the destination address [Link].
 In the reverse direction, the device on the right sends a data packet to the device on the left.
– The data packet contains the source address [Link] and the destination address
[Link].
– The NAT router replaces both addresses.
– The data packet that the device on the left receives contains the source address
[Link] and the destination address [Link].

The NAT router changes the source and destination addresses in the data packets. Both devices
communicate with each other in the same network, even though they are actually in different
networks.

UM Config EAGLE 151


Release 3.4 03/2020
Routing
12.4 NAT – Network Address Translation

Application example for Double NAT

You want to connect the device on the left (a workstation in the company network, for example) with
the device to the right (a robot controller in the production cell, for example). The robot controller
only communicates with devices on the same logical network. When communicating between the
networks, the NAT router translates the IP addresses.

Parameter Device on the left Device on the right


Local internal IP address [Link]
Local external IP address [Link] (virtual)
Remote internal IP address [Link]
Remote external IP address [Link] (virtual)

152 UM Config EAGLE


Release 3.4 03/2020
Routing
12.4 NAT – Network Address Translation

Prerequisites for further configuration:


 The Routing function is enabled in the device.
 Two router devices are configured in the device. One router interface is connected to the
company network and one to the network of the production cell.
 The IP address is set in the device on the left and in the device on the right.

Perform the following steps:


 Activate the Proxy ARP function on the router interfaces.

 Open the Routing > Interfaces > Configuration dialog.


 On the router interfaces that are connected to the company network and to the production
cell, mark the checkbox in the Proxy ARP field.
 To save the changes temporarily, click the button.

 Generate rule.

 Open the Routing > NAT > Double NAT > Rule dialog.
 Click the button.
The dialog displays the Create window.
 In the Rule name field, specify the name of the NAT rule.
 In the Local internal IP address field, specify the IP address of the device on the left in the
company network; in the example it is [Link].
 In the Local external IP address field, specify the virtual IP address of the device on the left
in the production cell; in the example it is [Link].
 In the Remote internal IP address field, specify the IP address of the device on the right in the
production cell; in the example it is [Link].
 In the Remote external IP address field, specify the virtual IP address of the device on the
right in the company network; in the example it is [Link].
 Click the Ok button.

 Activate the rule.

 Mark the checkbox in the Active field to enable the created rule.
 To save the changes temporarily, click the button.

 Assign the rule to the ingress interface connected to the company network.

 Open the Routing > NAT > Double NAT > Mapping dialog.
 Click the Assign button.
 In the Port field, select the router interface that is connected to the company network.
 Select the value ingress in the Direction field.
 Select the created rule in the Rule index field.
 Click the Ok button.

 Assign the rule to the egress interface connected to the production cell.

UM Config EAGLE 153


Release 3.4 03/2020
Routing
12.4 NAT – Network Address Translation

 Open the Routing > NAT > Double NAT > Mapping dialog.
 Click the Assign button.
 In the Port field, select the router interface connected with the production cell.
 Select the value egress in the Direction field.
 Select the created rule in the Rule index field.
 Click the Ok button.

 Activate assignment of the rule to the router interface.

 Select the checkbox in the Active field to activate assignment of the rule to the router
interface.
 To save the changes temporarily, click the button.

 Apply the rule to the data stream.

 Open the Routing > NAT > NAT Global dialog.


 Click the button and then the Commit changes item.
When changes to the rules affect existing entries in the state table of the firewall, it helps to
clear the state table. See the Clear firewall table button in the Basic Settings > Restart dialog. It is
possible, that the device interrupts open communication connections.

154 UM Config EAGLE


Release 3.4 03/2020
Routing
12.5 Tracking

12.5 Tracking

The tracking function lets you monitor certain objects, such as the availability of an interface or
reachablility of a network.

A special feature of this function is that it forwards an object status change to an application, for
example VRRP, which previously registered as an interested party for this information.

Tracking can monitor the following objects:


 Link status of an interface (interface tracking)
 Accessibility of a device (ping tracking)
 Result of logical connections of tracking entries (logic tracking)

An object can have the following statuses:


 up (OK)
 down (not OK)
 notReady (not enabled)

The definition of "up" and "down" depends on the type of the tracking object (for example interface
tracking).

Tracking can forward the state changes of an object to the following applications:
 VRRP
 Static routing

12.5.1 Interface tracking

With interface tracking the device monitors the link status of:
 physical ports
 Link Aggregation interfaces
 VLAN router interfaces

S1 S2
L1 L2
A PC B

PC A
VR
B

Figure 42: Monitoring a line with interface tracking

Ports/interfaces can have the following link statuses:


 interrupted physical link (link down)
 existing physical link (link up)

If the link to the participating ports is interrupted, then a Link Aggregation interface has link status
“down”.

If the link is interrupted from the physical ports/Link Aggregation interfaces that are members of the
corresponding VLAN, then the VLAN router interface has the link status “down”.

Setting a delay time enables you to insert a delay before informing the application about an object
status change.

UM Config EAGLE 155


Release 3.4 03/2020
Routing
12.5 Tracking

If the physical link interruption remains for longer than the “link down delay” delay time, then the
interface tracking object has the status “down”.

When the physical link holds for longer than the “link up delay” delay time, the interface tracking
object has the status “up”.

State on delivery: delay times = 0 seconds.

This means that in case where a status changes, the registered application is informed
immediately.

You can set the “link down delay” and “link up delay” delay times independently of each other in the
range from 0 to 255 seconds.

You can define an interface tracking object for each interface.

12.5.2 Ping tracking

With ping tracking, the device uses ping requests to monitor the link status to other devices.

S2
L1 L2
A PC B

PC A

Figure 43: Monitoring a line with ping tracking

The device sends ping requests to the device with the IP address that you entered in the IP address
column.

The Ping interval [ms] column lets you define the frequency for sending ping requests, and thus the
additional network load.

When the response comes back within the time entered in the Ping timeout [ms] column, this
response is a valid Ping replies to receive.

When the response comes back after the time entered in the Ping timeout [ms] column, or not at all,
this response is evaluated as Ping replies to lose.

Ping tracking objects can have the following statuses:


 the number of Ping replies to lose is greater than the number entered (down)
 the number of Ping replies to receive is greater than the number entered (up)
 the instance is inactive (notReady)

Entering a number for unreceived or received ping responses enables you to set the sensitivity of
the ping behavior of the device. The device informs the application about an object status change.

Ping tracking enables you to monitor the accessibility of specified devices. As soon as a monitored
device can no longer be accessed, the device can choose to use an alternative path.

156 UM Config EAGLE


Release 3.4 03/2020
Routing
12.5 Tracking

12.5.3 Logical tracking

Logical tracking enables you to logically link multiple tracking objects with each other and thus
perform relatively complex monitoring tasks.

You can use logical tracking, for example, to monitor the link status for a network node to which
redundant paths lead (see on page 160 “Application example for logical tracking”).

The device provides the following options for a logical link:


 and
 or

For a logical link, you can combine up to 2 operands with one operator.

Logical tracking objects can have the following statuses:


 The result of the logical link is incorrect (down).
 The result of the logical link is correct (up).
 The monitoring of the tracking object is inactive (notReady).

When a logical link delivers the result down, the device can choose to use an alternative path.

12.5.4 Configuring the tracking

You configure the tracking by setting up tracking objects. The following steps are required to set up
a tracking object:
 Enter the tracking object ID number (track ID).
 Select a tracking type, for example interface.
 Depending on the track type, enter additional options such as “port” or “link up delay” in the
interface tracking.

Note: The registration of applications (for example VRRP) to which the tracking function reports
status changes is performed in the application itself.

UM Config EAGLE 157


Release 3.4 03/2020
Routing
12.5 Tracking

Configuring interface tracking


 Set up interface tracking on port 1/1 with a link down delay of 0 seconds and a link up delay of
3 seconds.

 Open the Routing > Tracking > Configuration dialog.


 Click the button.
The dialog displays the Create window.
Select type:
 Enter the values you desire, for example:
Type: interface
Track ID: 11
 Click the Ok button.
Properties:
 Enter the values you desire, for example:
Port: 1/1
Link up delay [s]: 3
Link down delay [s]: 0
 To temporarily save the settings, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
track add interface 11 Enter a tracking object in the table.
track modify interface 11 ifnumber 1/1 Specify the parameters for this tracking object.
link-up-delay 3 link-down-delay 0
track enable interface 11 Activate the tracking object.
Tracking ID interface-11 created Target interface set to 1/1
Link Up Delay for target interface set to 3 sec
Link Down Delay for target interface set to 0 sec
Tracking ID 11 activated
exit Change to the Privileged EXEC mode.
show track interface Display the configured tracks.
Name If-Number Link-Up-Delay Link-Down-Delay State Active
-------- ---------- ------------- --------------- ----- ------
if-11 1/1 0 3 up [x]

158 UM Config EAGLE


Release 3.4 03/2020
Routing
12.5 Tracking

Application example for ping tracking

While the interface tracking monitors the directly connected link (see figure 42), the ping tracking
monitors the entire link to device S2 (see figure 43).
 Set up ping tracking at port 1/2 for IP address [Link] with the preset parameters.

 Open the Routing > Tracking > Configuration dialog.


 To add a table entry, click the button.
Select type:
 Enter the values you desire, for example:
Type: 21
Track ID: ping
 Click Ok.
Properties:
 Enter the values you desire, for example:
Port: 1/2
IP address: [Link]
Ping interval [ms]: 500
Ping replies to lose: 3
Ping replies to receive: 2
Ping timeout [ms]: 100
 To temporarily save the settings, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
track add ping 21 Enter a tracking object in the table.
track modify ping 21 ifnumber 1/2 Specify the parameters for this tracking object.
address [Link]
interval 500
miss 3
success 2
timeout 100
track enable ping 21 Activate the tracking object.
Tracking ID ping-21 created
Target IP address set to [Link]
Interface used for sending pings to target set to 1/2
Ping interval for target set to 500 ms
Max. no. of missed ping replies from target set to 3
Min. no. of received ping replies from target set to 2
Timeout for ping replies from target set to 100 ms
Tracking ID 21 activated

UM Config EAGLE 159


Release 3.4 03/2020
Routing
12.5 Tracking

exit Change to the Privileged EXEC mode.


show track Display the configured tracks.
Ping Tracking Instance
-----------------------------------
Name...........................................ping-21
Interface Number of outgoing ping packets......1/2
Target router network address..................[Link]
Interval of missed repl. the state is down.....3
Interval of received repl. the state is up.....2
Maximal roundtrip-time ........................100
Time-To-Live for a transmitted ping request....128
Ifnumber which belongs to the best route.......
State..........................................down
Send State Change trap.........................disabled
Number of state changes........................0
Time of last change............................2014-06-18 14:00:03
Description....................................

Application example for logical tracking

The figure (see figure 44) displays an example of monitoring the connection to a redundant ring.

By monitoring lines L 2 and L 4, you can detect a line interruption from router A to the redundant
ring.

With a ping tracking object on port 1/1 of router A, you monitor the connection to device S2.

With an additional ping tracking object on port 1/1 of router A, you monitor the connection to
device S4.

Only the OR link of both ping tracking objects delivers the precise result that router A has no
connection to the ring.

One ping tracking object for device S3 could indicate an interrupted connection to the redundant
ring, but in this case there could be another reason for the lack of a ping response from device S3.
For example, there could be a power failure at device S3.

The following is known:

Parameter Value
Operand No. 1 (track ID) 21

Operand No. 2 (track ID) 22

Prerequisites for further configuration:


 The ping tracking objects for operands 1 and 2 are configured (see on page 159 “Application
example for ping tracking”).

160 UM Config EAGLE


Release 3.4 03/2020
Routing
12.5 Tracking

S1 S2
L2
L1
PC B
L4 L3
A

PC A S4 S3
VR
B

S5
S6

Figure 44: Monitoring the accessibility of a device in a redundant ring

 Set up a logical tracking object as an OR link.

 Open the Routing > Tracking > Configuration dialog.


 Click the button.
The dialog displays the Create window.
Select type:
 Enter the values you desire, for example:
Type: 31
Track ID: logical
 Click the Ok button.
Properties:
 Enter the values you desire, for example:
Logical operand A: ping-21
Logical operand B: ping-22
Operator: or
 To temporarily save the settings, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
track add logical 31 Enter a tracking object in the table.
track modify logical 31 ping-21 or ping- Enter the parameters for the tracking object.
22
track enable logical 31 Activate the tracking object.
Tracking ID logical-31 created Logical Instance ping-21 included
Logical Instance ping-22 included
Logical Operator set to or
Tracking ID 31 activated
exit Change to the Privileged EXEC mode.
show track ping 21 Display the configured tracks.

UM Config EAGLE 161


Release 3.4 03/2020
Routing
12.5 Tracking

Ping Tracking Instance-----------------------------------


Name...........................................ping-21
Interface Number of outgoing ping packets......1/2
Target router network address..................[Link]
Interval of missed repl. the state is down.....3
Interval of received repl. the state is up.....2
Maximal roundtrip-time ........................100
Time-To-Live for a transmitted ping request....128
Ifnumber which belongs to the best route.......
State..........................................down
Send State Change trap.........................disabled
Number of state changes........................0
Time of last change............................2014-06-18 14:23:22
Description....................................
show track ping 22 Display the configured tracks.
Ping Tracking Instance-----------------------------------
Name...........................................ping-22
Interface Number of outgoing ping packets......1/3
Target router network address..................[Link]
Interval of missed repl. the state is down.....3
Interval of received repl. the state is up.....2
Maximal roundtrip-time ........................100
Time-To-Live for a transmitted ping request....128
Ifnumber which belongs to the best route.......
State..........................................up
Send State Change trap.........................disabled
Number of state changes........................0
Time of last change............................2014-06-18 14:23:55
Description....................................
show track logical 31 Display the configured tracks.
Logical Tracking Instance-----------------------------------
Name...........................................logical-31
Operand A......................................ping-21
Operand B......................................ping-22
Operator.......................................or
State..........................................up
Send State Change trap.........................disabled
Number of state changes........................0
Time of last change............................2014-06-18 14:24:25
Description....................................

Application example for logical tracking

The figure (see figure 44) displays an example of monitoring the connection to a redundant ring.

By monitoring lines L 2 and L 4, you can detect a line interruption from router A to the redundant
ring.

With a ping tracking object on port 1/1 of router A, you monitor the connection to device S2.

With an additional ping tracking object on port 1/1 of router A, you monitor the connection to
device S4.

162 UM Config EAGLE


Release 3.4 03/2020
Routing
12.5 Tracking

Only the OR link of both ping tracking objects delivers the precise result that router A has no
connection to the ring.

One ping tracking object for device S3 could indicate an interrupted connection to the redundant
ring, but in this case there could be another reason for the lack of a ping response from device S3.
For example, there could be a power failure at device S3.

The following is known:

Parameter Value
Operand No. 1 (track ID) 21

Operand No. 2 (track ID) 22

Prerequisites for further configuration:


 The ping tracking objects for operands 1 and 2 are configured (see on page 159 “Application
example for ping tracking”).

S1 S2
L2
L1
PC B
L4 L3
A

PC A S4 S3
VR
B

S5
S6

Figure 45: Monitoring the accessibility of a device in a redundant ring

 Set up a logical tracking object as an OR link.

 Open the Routing > Tracking > Configuration dialog.


 Click the button.
The dialog displays the Create window.
Select type:
 Enter the values you desire, for example:
Type: 31
Track ID: logical
 Click the Ok button.
Properties:
 Enter the values you desire, for example:
Logical operand A: ping-21
Logical operand B: ping-22
Operator: or
 To temporarily save the settings, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
track add logical 31 Enter a tracking object in the table.
track modify logical 31 ping-21 or ping- Enter the parameters for the tracking object.
22

UM Config EAGLE 163


Release 3.4 03/2020
Routing
12.5 Tracking

track enable logical 31 Activate the tracking object.


Tracking ID logical-31 created Logical Instance ping-21 included
Logical Instance ping-22 included
Logical Operator set to or
Tracking ID 31 activated
exit Change to the Privileged EXEC mode.
show track ping 21 Display the configured tracks.
Ping Tracking Instance-----------------------------------
Name...........................................ping-21
Interface Number of outgoing ping packets......1/2
Target router network address..................[Link]
Interval of missed repl. the state is down.....3
Interval of received repl. the state is up.....2
Maximal roundtrip-time ........................100
Time-To-Live for a transmitted ping request....128
Ifnumber which belongs to the best route.......
State..........................................down
Send State Change trap.........................disabled
Number of state changes........................0
Time of last change............................2014-06-18 14:23:22
Description....................................

show track ping 22 Display the configured tracks.


Ping Tracking Instance-----------------------------------
Name...........................................ping-22
Interface Number of outgoing ping packets......1/3
Target router network address..................[Link]
Interval of missed repl. the state is down.....3
Interval of received repl. the state is up.....2
Maximal roundtrip-time ........................100
Time-To-Live for a transmitted ping request....128
Ifnumber which belongs to the best route.......
State..........................................up
Send State Change trap.........................disabled
Number of state changes........................0
Time of last change............................2014-06-18 14:23:55
Description....................................
show track logical 31 Display the configured tracks.
Logical Tracking Instance-----------------------------------
Name...........................................logical-31
Operand A......................................ping-21
Operand B......................................ping-22
Operator.......................................or
State..........................................up
Send State Change trap.........................disabled
Number of state changes........................0
Time of last change............................2014-06-18 14:24:25
Description....................................

164 UM Config EAGLE


Release 3.4 03/2020
Routing
12.6 VRRP

12.6 VRRP

End devices usually let you enter 1 default gateway for transmitting data packets in external
subnetworks. Here the term “Gateway” applies to a router with which end devices communicate
with other subnetworks.

If this router fails, then the end device cannot send any more data to the external subnetworks.

In this case, the Virtual Router Redundancy Protocol (VRRP) provides assistance.

VRRP is a type of “gateway redundancy”. VRRP describes a process that groups multiple routers
into 1 virtual router. End devices constantly address the virtual router, and VRRP helps ensure that
a physical router belonging to the virtual router transmits the data.

When a physical router fails, VRRP helps ensure that another physical router continues to route the
data as part of the virtual router.

When a physical router fails, VRRP has a typical failover time of 3 to 4 seconds.

Note: The device supports only VRRP packets without authentication information. In order for the
device to operate in conjunction with other devices that support VRRP authentication, verify that on
those devices the VRRP authentication is not applied.

12.6.1 VRRP

The routers within a network on which VRRP is active specify among themselves which router is
the master. The master router controls the IP and MAC address of the virtual router. The devices
in the network that have entered this virtual IP address as the default gateway use the master as
the default gateway.

Redundancy
through VRRP

[Link]

[Link] [Link]
Default Gateway A
[Link] [Link] [Link] VR
B
[Link]
[Link]

Figure 46: Illustration of the virtual router

When the master fails, then the remaining backup routers use VRRP to specify a new master. The
backup router that wins the election process then controls the IP address and MAC address of the
virtual router. Thus, the devices find the route through the default gateway, as before. The devices
see only the master router with the virtual MAC and IP addresses, regardless of which physical
router is actually behind this virtual address.

The administrator assigns the virtual router IP address.

UM Config EAGLE 165


Release 3.4 03/2020
Routing
12.6 VRRP

VRRP specifies the virtual MAC address with: 00:00:5e:00:01:<VRID>.

The first 5 octets form the fixed part in accordance with RFC 3768. The last octet is the virtual router
ID (VRID). The VRID is a number from 1 through 255. Based on the number of VRIDs, VRRP lets
the administrator specify up to 255 virtual routers within a network.

00:00:5e:00:01:xx

variable element = VRID


constant element
Figure 47: Virtual MAC address

In order to determine the master, a VRRP router sends IP Multicast messages to the IP Multicast
address [Link]. The physical router with the higher VRRP priority becomes the master. The
administrator specifies the VRRP priority of each physical router. When the VRRP priorities are the
same, the physical router with higher IP interface address in the VRRP domain becomes the
master. When the virtual IP address is the same as the IP address of a router interface, this router
is the IP address owner. VRRP sets the VRRP priority of an IP address owner to the value of 255
and thus declares this router the master. When there is no IP address owner, VRRP declares the
router with the higher VRRP priority the master.

In order to signal that the master router is ready for operation, the master router sends IP Multicast
advertisements in regular intervals (default: 1 s) to the other VRRP routers (backup routers). When
3 intervals pass without the other VRRP routers receiving an advertisement, VRRP initiates the
master router election process. The VRRP backup router with the higher VRRP priority declares
itself the new master.

Table 21: Who shall be the master?

1. The IP address owner as it has the higher VRRP priority (255) by definition.
2. The VRRP router with the higher VRRP priority.
3. When the priorities are the same, the VRRP router with the higher IP address.

VRRP terms:
 Virtual router
A virtual router is a physical router or group of physical routers that act as the default gateway
in a network using the Virtual Router Redundancy Protocol.
 VRRP router
A VRRP router is a physical router with VRRP enabled. The VRRP router is part of 1 or more
virtual routers.
 Master router
The master router is the physical router within a virtual domain that is responsible for forwarding
data packets and responding to ARP queries. The master router periodically sends messages
(advertisements) to the backup routers in the virtual domain to inform them about its existence.
The backup routers save the advertisement interval and VRRP priority contained in the master
router advertisements to calculate the master down time and skew time.
 IP address owner
The IP address owner is the VRRP router whose IP address is identical to the IP address of the
virtual router. By definition, it has the VRRP priority of 255 and is thus automatically the master
router.
 Backup router
When the master router fails, the backup router is a VRRP router providing a stand-by route for
the master router. The backup router is ready to take over the master role.
 VRRP priority
The VRRP priority is a number from 1 through 255. VRRP uses the priority number to determine
the master router. VRRP reserves the priority value 255 for the IP address owner.

166 UM Config EAGLE


Release 3.4 03/2020
Routing
12.6 VRRP

 VRID
The virtual router ID (VRID) uniquely identifies a virtual router. The VRID defines the last octet
of the virtual router MAC address.
 Virtual router MAC address
The MAC address of the virtual router instance (see figure 47).
 Virtual router IP address
The IP address of the virtual router instance.
 Advertisement interval
The advertisement interval describes the frequency with which the master router sends
advertisements to the backup routers within the same virtual router. The values for the
advertisement interval are from 1 through 255 seconds. The default interval value for VRRP
advertisements is 1 second.
 Skew time
The skew time uses the VRRP priority of the master router to determine how long a backup
router waits, after declaring the master down, until it initiates the master router election process.
Skew time = ((256 - VRRP priority) / 256) * 1 second
 Master down interval
The master down interval uses the advertisement interval of the master router to specify the time
that elapses before a backup router declares the master down.
Master down interval = 3 * advertisement interval + skew time

Configuration of VRRP

The configuration of VRRP requires the following steps:


 Enable the Routing function globally.
 Enable VRRP globally.
 Assign an IP address and subnet mask to the port.
 Enable VRRP on the port.
 Create the virtual router ID (VRID), because you have the option of activating multiple virtual
routers on each port.
 Assign the virtual router IP address.
 Enable the virtual router.
 Assign the VRRP priority.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
ip routing Enable the Routing function globally.
ip vrrp operation Enables VRRP globally.
interface 1/3 Change to the interface configuration mode of
interface 1/3.
ip address primary [Link] Specifies the primary IP address and the netmask
[Link] of the router interface.
ip routing Enables the Routing function on this interface.
ip vrrp add 1 Creates the VRID for the first virtual router on this
port.
ip vrrp virtual-address add 1 Assigns virtual router 1 its IP address.
[Link]
ip vrrp 1 priority 200 Assigns virtual router 1 the router priority 200.

 You specify every active VRRP port the same way.


 You also perform the same configuration on the backup router.

UM Config EAGLE 167


Release 3.4 03/2020
Routing
12.6 VRRP

12.6.2 VRRP with load sharing

With the simple configuration, a router performs the gateway function for the end devices. The
capacity of the backup router lies idle. VRRP lets you also use the capacity of the backup router.
Setting up a number of virtual routers lets you enter different default gateways on the connected
end devices and thus steer the data flow.

When both routers are active, the data flows through the router on which the IP address of the
default gateway has the higher VRRP priority. When a router fails, the data flows through the
remaining routers.

Default Gateway Default Gateway


[Link] [Link]

S1 Priority=200
[Link] [Link]
A
[Link] VR VR [Link]

B
[Link]
Priority=100

Figure 48: Virtual router with load sharing

To use load sharing, you perform the following configuration steps:


 Define a second VRID for the same router interface.
 Assign the router interface its own IP address for the second VRID.
 Assign the second virtual router a lower priority than the first virtual router.
 When configuring the backup router, verify that you assign the second virtual router a higher
priority than the first.
 Give the end devices one of the virtual router IP addresses as a default gateway.

12.6.3 VRRP with Multinetting

The router lets you combine VRRP with Multinetting.

[Link] IP=[Link]
IP=[Link]
Default Gateway
[Link] [Link]
A
[Link] [Link]
[Link] VR
B
Default Gateway
[Link] [Link]
IP=[Link]
IP=[Link]
Figure 49: Virtual router with multinetting

To use VRRP with multinetting, you perform the following configuration steps on the basis of an
existing VRRP configuration (see figure 46):
 Assign a second (secondary) IP address to the port.
 Assign a second (secondary) IP address to the virtual router.

168 UM Config EAGLE


Release 3.4 03/2020
Routing
12.6 VRRP

Interface 2/3 Select the port at which you want to configure


multinetting.
ip address secondary [Link] Assign the second IP address to the port.
[Link]
ip vrrp virtual-address add 1 Assign a second IP address to the virtual router
[Link] with the VRID 1.

 Perform the same configuration on the backup router.

UM Config EAGLE 169


Release 3.4 03/2020
Routing
12.7 OSPF

12.7 OSPF

Open Shortest Path First (OSPF) is a dynamic routing protocol based on the Link State Algorithm.
This algorithm is based on the link states between the routers involved.

The significant metric in OSPF is the "OSPF costs", which is calculated from the available bit rate
of a link.

OSPF was developed by IETF. OSPF is currently specified as OSPFv2 in RFC 2328. Along with
many other advantages of OSPF, the fact that it is an open standard has contributed to the wide
usage of this protocol. OSPF has replaced the Routing Information Protocol (RIP) as the standard
Interior Gateway Protocol (IGP) in large networks.

OSPF has a number of significant advantages to offer:


 Cost-based routing metrics: In contrast to RIP, OSPF provides clear metrics based on the
bandwidth of each individual network connection. OSPF provides major flexibility in designing a
network, because the user can change these costs.
 Routing using multiple paths (equal cost multiple path/ECMP): OSPF is able to support a
number of equal paths to a given destination. OSPF thus provides efficient utilization of the
network resources (load distribution) and improves the availability (redundancy).
 Hierarchical routing: By logically dividing the network into areas, OSPF shortens the time
required to distribute routing information. The messages about changes in a subnetwork remain
within the subnetwork, without putting any load on the rest of the network.
 Support of Classless Inter-Domain Routing (CIDR) and Variable Length Subnet Mask (VLSM):
This lets the network administrator assign the IP address resources efficiently.
 Fast tuning time: OSPF supports the fast distribution of messages about route changes. This
speeds up the tuning time for updating the network topology.
 Saving network resources / bandwidth optimization: Because OSPF, in contrast to RIP, does
not exchange the routing tables at regular, short intervals, no bandwidth is unnecessarily
“wasted” between the routers.
 Support of authentication: OSPF supports the authentication of nodes that send routing
information.

Table 22: Advantages and disadvantages of Link State Routing

Advantages Disadvantages
Every router calculates its routes independently Complicated to implement
of the other routers.
The routers have the same basic information. Complex administration due to the large number
of options.
Rapid detection of link interruptions and rapid
calculation of alternative routes.
The data volume for router information is
relatively small, because information is only sent
in cases where it is required, and only the
information that applies to the immediate
neighbors.
Optimal path selection through evaluation of the
link quality.

OSPF is a routing protocol based on the states of the links between the routers.

Using the link states collected from every router and the Shortest Path First algorithm, an OSPF
router dynamically creates its routing table.

170 UM Config EAGLE


Release 3.4 03/2020
Routing
12.7 OSPF

12.7.1 OSPF-Topology

OSPF is hierarchically structured in order to limit the scope of the OSPF information to be
exchanged in large networks. You divide up your network using what are known as areas.

Autonomous System

An Autonomous System (AS) is a number of routers that are managed by a single administration
and use the same Interior Gateway Protocol (IGP). Exterior Gateway Protocols (EGP), on the other
hand, are used to connect a number of autonomous systems. OSPF is an Interior Gateway
Protocol.

Autonomous System

Area [Link]
Area [Link]

ABR ASBR

ABR

Backbone Area [Link]

RIP

Figure 50: Autonomous System

An AS uses an “Autonomous System Boundary Router” (ASBR) to connect with the outside world.
An ASBR understands multiple protocols and serves as a gateway to routers outside the areas. An
ASBR is able to transfer routes from different protocols into OSPF. This process is known as
redistribution.

Router ID

The router ID in the form of an IP address is used to uniquely identify every router within an
autonomous system. To improve the transparency, it is necessary to manually configure the router
ID of every OSPF router. Thus there is no automatic function that selects the router ID from the IP
interfaces of the router.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
ip ospf router-id [Link] Assign router ID, for example [Link].
ip ospf operation Enable OSPF globally.

UM Config EAGLE 171


Release 3.4 03/2020
Routing
12.7 OSPF

Areas

Each area first forms its own database using the link states within the area. The data exchange
required for this remains within the area. Each area uses an Area Border Router (ABR) to link to
other areas. The routing information is summarized as much as possible between the areas (route
summarization).

Every OSPF router has to be a member of at least one area.

An individual router interface can only be assigned to one area. By default, every router interface
is assigned to the backbone area.

172 UM Config EAGLE


Release 3.4 03/2020
Routing
12.7 OSPF

OSPF distinguishes between the following particular area types:


 Backbone Area:
This is by definition the area [Link]. An OSPF network consists of at least the backbone area.
It is the central area, which is linked to the other areas directly. The backbone area receives the
routing information and is responsible for forwarding this information.
 Stub Area:
When external LSAs are not to be flooded into the area, you define an area as a stub area.
External means outside the autonomous system. These external LSAs are the yellow and
orange links in the See figure 51 on page 173. illustration. Thus the routers within a stub area
only learn internal routes (blue links – for example no routes that are exported into OSPF from
another log / redistributing). The destinations outside the autonomous system are assigned to
a default route. Stub areas are thus generally used in cases where only 1 router in the area has
a link to outside the area. The use of stub areas keeps the routing table small within the stub
area.
Configuration notes:
 For a stub area, the routers within the stub area have to be specified as stub routers.
 A stub area does not allow passage for a virtual link.
 The backbone area cannot be specified as a stub area.
 Not So Stubby Area (NSSA):
You define an area as NSSA in cases where the external (yellow) routes of a system directly
connected to the NSSA that is outside your autonomous system are to be led into the area
(redistributed). These external (yellow) LSAs then also lead from the NSSA to other areas in
your autonomous system. External (orange) LSAs within your own autonomous system do not,
on the other hand, lead into an NSSA.
By using NSSAs, you can integrate ASBRs into the area without foregoing the advantage of stub
areas, namely that external routes from the backbone are not flooded into the corresponding
area.
Thus NSSAs have the advantage that external routes coming from the backbone are not
entered in the routing tables of the internal routers. At the same time, however, a limited number
of external networks, which can be reached across the boundaries of the NSSA, can be
propagated into the backbone area.

Area [Link]
Autonomous System

NSSA
ASBR

BGP
Area [Link]

BGP = Border
Gateway Protocol RIP

Stub

Figure 51: LSA distribution into the area types

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
ip ospf area [Link] nssa add import- Specifies area [Link] as NSSA.
nssa
ip ospf area [Link] stub add 0 Specifies area [Link] as stub area.
ip ospf area [Link] stub modify 0 Instruct the ABR to inject the default route with the
default-cost 10 metric 10 into the stub area.

UM Config EAGLE 173


Release 3.4 03/2020
Routing
12.7 OSPF

Virtual Link

OSPF requires that the backbone area to be connected to every area. However, when this is not
actually possible, OSPF provides a virtual link (VL) to connect parts of the backbone area with each
other See figure 53 on page 174.. A VL even lets you connect an area that is connected with the
backbone area via another area.

Area [Link] Area [Link]

Backbone Area [Link] VL

ABR ABR

Figure 52: Linking a remote area to the backbone area using a virtual link (VL)

Router 2 Router 1
Router-ID: Router-ID:
[Link] [Link]
Area [Link]

Backbone Area [Link] VL Backbone Area [Link]

ABR ABR

Figure 53: Expanding the backbone area using a virtual link (VL)

Configuration for expanding the backbone area (see figure 53):

Router 1:

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
ip ospf area [Link] virtual-link add Enter the neighboring router ID for a virtual link in
[Link] area [Link].

Router 2:

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
ip ospf area [Link] virtual-link add Enter the neighboring router ID for a virtual link in
[Link] area [Link].

174 UM Config EAGLE


Release 3.4 03/2020
Routing
12.7 OSPF

OSPF Router

OSPF distinguishes between the following router types:


 Internal router:
The OSPF interfaces of an internal router are within the same area.
 Area Border Router (ABR):
ABRs have OSPF interfaces in a number of areas, including the backbone area. The ABRs thus
participate in multiple areas. Where possible, you summarize a number of routes and send
“Summary LSAs” to the backbone area.
 Autonomous System Area Border Router (ASBR):
An ASBR is located on the boundary of an autonomous system and links OSPF to other
autonomous systems / routing protocols. These external routes are transferred into OSPF using
what is known as redistribution and are then summarized as “AS-external LSAs” and flooded
into the area.
Enable the redistributing explicitly.
When you want to use subnetting, you enter this explicitly.
In OSPF, the following “routing protocols” can be exported:
– connected (local subnetworks on which OSPF is not switched on)
– static (static routes)

Link State Advertisement

As a basis for building up a database using the link states, OSPF uses Link State Advertisements
(LSA).

An LSA contains the following information:


 the router,
 the connected subnets,
 the routes that can be reached,
 the network masks and
 the metric.

OSPF distinguishes between the following LSA types:


 Router LSAs (type 1 LSAs):
Every router sends a router LSA to every other router in the same area. They describe the state
and the costs of the router links (router interfaces) that the router has in the corresponding area.
Router LSAs are only flooded within the area.
 Network LSAs (type 2 LSAs):
These LSAs are generated by the designated router, DR (see on page 176 “Setting up the
Adjacency”) and are sent for every connected network/subnet within an area.
 Summary LSAs (type 3 /type 4 LSAs)
Summary LSAs are generated by ABRs and describe inter-area destinations, meaning
destinations in different areas of the same autonomous system.
Type 3 LSAs describe targets for IP networks (individual routes or summarized routes).
Type 4 LSAs describe routes to ASBRs.
 AS-external LSAs (type 5 LSAs):
These LSAs are generated by ASBRs and describe routes outside the autonomous system.
These LSAs are flooded everywhere except for stub areas and NSSAs.
 NSSA external LSAs (type 7 LSAs):
A stub area does not flood any external routes (represented by type 5 LSAs) and therefore does
not support any Autonomous System Border Routers (ASBRs) at its boundaries. Thus an ASBR
cannot carry any routes from other protocols into a stub area.
RFC 1587 specifies the NSSAs functions. According to RFC 1587, the ASBRs send type 7
LSAs instead of type 5 LSAs for the external routes within an NSSA. These type 7 LSAs are
then converted into type 5 LSAs by an ABR and flooded into the backbone area. This “translator
role” is negotiated among the ABRs in an NSSA (the router with the highest router ID), but it can
also be configured manually.

UM Config EAGLE 175


Release 3.4 03/2020
Routing
12.7 OSPF

12.7.2 General Operation of OSPF

OSPF was specially tailored to the needs of larger networks and provides a fast convergence and
minimum usage of protocol messages.

The concept of OSPF is based on the creation, maintenance and distribution of what is called the
link state database. This data base describes
 every router within a routing domain (area) and
 their active interfaces and routes,
 how they are linked to each other and
 the costs of these links.

The routers within an area have an identical data base, which means that every router knows the
exact topology within its area.

Every router plays its part in setting up the respective data base by propagating its local viewpoint
as Link State Advertisements (LSAs). These LSAs are then flooded to the other routers within an
area.

OSPF supports a range of different network types such as point-to-point networks (for example,
packet over SONET/SDH), broadcast networks (Ethernet) or non-broadcast networks.

Broadcast networks are distinguished by the fact that a number of systems (end devices, switches,
routers) are connected to the same segment and thus can be addressed simultaneously using
broadcasts/multicasts.

OSPF generally performs the following steps in carrying out its tasks in the network:
 Setting up the Adjacencies using the Hello protocol
 Synchronizing the link state database
 Route calculation

12.7.3 Setting up the Adjacency

When a router boots, it uses what are called Hello packets to contact its neighboring routers. With
these Hello packets, an OSPF router finds out which OSPF routers are near it and whether they
are suitable for setting up an adjacency.

In broadcast networks such as Ethernet, the number of neighbors increases with the number of
routers connected, as does the information exchange for clarifying and maintaining the Adjacency.
To reduce these volumes within an area, OSPF uses the “Hello” protocol to determine a designated
router (DR) within the corresponding area. Thus every router in an area only sets up the Adjacency
with its designated router, instead of with every neighbor. The designated router is responsible for
the distribution of the link state information to its neighbor routers.

176 UM Config EAGLE


Release 3.4 03/2020
Routing
12.7 OSPF

For security reasons, OSPF provides for the selection of a backup designated router (BDR), which
takes over the tasks of the DR in case the DR fails. The OSPF router with the highest router priority
is the DR. The router priority is specified by the administrator. When routers have the same priority,
the router with the higher router ID is selected. The router ID is the smallest IP address of a router
interface. You configure this router ID manually during booting of the OSPF router “Router ID” on
page 171.

DR BDR

Figure 54: LSA distribution with designated router and backup designated router

To exchange information, OSPF uses reserved multicast addresses.

Table 23: OSPF - multicast addresses

Destination Multicast IP address Mapped Multicast MAC address


Every OSPF router [Link] 01:00:5E:00:00:05
Designated routers [Link] 01:00:5E:00:00:06

UM Config EAGLE 177


Release 3.4 03/2020
Routing
12.7 OSPF

Hello packets are also used to check the configuration within an area (area ID, timer values,
priorities) and to monitor the Adjacencies. Hello packets are sent cyclically (Hello interval). When
Hello packets are not received for a specific period (Dead interval), the Adjacency is terminated and
the corresponding routes are deleted.

The Hello interval (default setting: 10 seconds) and the Dead interval (default setting: 40 seconds)
can be configured for each router interface. When reconfiguring the timers, verify that they are
uniform within an area.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
interface 1/1 Change to the interface configuration mode of
interface 1/1.
ip ospf hello-interval 20 Specifies the Hello interval as 20 seconds.
ip ospf dead-interval 60 Specifies the Dead interval as 60 seconds.
exit Change to the Configuration mode.
exit Change to the Privileged EXEC mode.
show ip ospf neighbor 1/1 Displays the Adjacencies of the router.
Neighbor ID IP Address Interface State Dead Time
------------ ----------- ----------- ------ ----------
[Link] [Link] 1/1 Full
[Link] [Link] 1/2 Full
[Link] [Link] 1/3 Full
[Link] [Link] 1/4 Full

The following list contains the states of the Adjacencies:

Down No Hello packets received yet


Init Receiving Hello packets
2-way Bidirectional communication, determination of the DR and the BDR
Exstart Determination of master/slave for LSA exchange
Exchange LSAs are exchanged or flooded
Loading Completion of the LSA exchange
Full Data basis complete and uniform in the area. Routes can now be calculated

12.7.4 Synchronization of the LSDB

The central part of the OSPF is the link state database (LSDB). This database contains a
description of the network and the states of every router. The LSDB is the source for calculating the
routing table and reflects the topology of the network. The LSDB is set up after the designated
router or the backup designated router has been determined within an area (Broadcast networks).

To set up the LSDB and update any topology changes, the OSPF router sends link status
advertisements (LSA) to the directly accessible OSPF routers. These link state advertisements
consist of the interfaces and the neighbors of the sending OSPF router reachable through these
interfaces. OSPF routers put this information into their databases and flood the information to the
ports.

When no topology changes occur, the routers send a LSA every 30 minutes.

178 UM Config EAGLE


Release 3.4 03/2020
Routing
12.7 OSPF

You can view the content of the Link State Database with the command show ip ospf database using
the Command Line Interface, whereby the entries are output in accordance with the areas.

enable Change to the Privileged EXEC mode.


show ip ospf database internal Displays the internal Adjacencies of the router.
LSDB type Link ID
Area ID Adv Router Age Sequence Checksum
----------- --------------- ----- -------- ------
router link [Link] 122 80000007 0x5380
[Link] [Link]
router link [Link] 120 80000007 0xbf0e
[Link] [Link]
show ip ospf database external Displays the external Adjacencies of the router.
Area ID Adv Router Age Sequence Checksum
----------- --------------- ----- -------- ------
[Link] [Link] 178 80000002 0xcalc

12.7.5 Route Calculation

After the LSDs are learned and the neighbor relationships go to the full state, every router
calculates a path to every destination using the Shortest Path First (SPF) algorithm. After the
optimal path to every destination has been determined, these routes are entered in the routing
table. The route calculation is generally based on the accessibility of a hop and the metric (costs).
The costs are added up for every hop to the destination.

The cost of individual router interfaces are based on the available bandwidth of this link. The
calculation for the standard setting is based on the following formula:

Metric = Autocost reference bandwidth/ bandwidth (bits/sec)

For Ethernet, this leads to the following costs:

10 Mbit 10
100 Mbit 1
1000 Mbit 1 (0.1 rounded up to 1)

The table displays that this form of calculation in the standard configuration does not permit any
distinction between Fast Ethernet and Gigabit Ethernet.

You can change the standard configuration by assigning a different value for the costs to each
OSPF interface. This enables you to differentiate between Fast Ethernet and Gigabit Ethernet.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
interface 1/1 Change to the interface configuration mode of
interface 1/1.
ip ospf cost 2 Assigns the value 1/1 to port 2 for the OSPF costs.

UM Config EAGLE 179


Release 3.4 03/2020
Routing
12.7 OSPF

12.7.6 Configuring OSPF

In the delivery state, the default values are selected so that you can configure simple OSPF
functions in a few steps. After the router interface is specified and OSPF is enabled, OSPF
automatically enters the required routes in the routing table.

The example below displays a simple OSPF configuration. Area [Link] is already specified by
default. The end devices do not have an OSPF function, so you do not have to activate OSPF on
the corresponding router interface. By activating the Redistribution function, you can inject the routes
to the end devices into the OSPF.

Subnetz [Link]/24 Subnetz [Link]/24


IP=[Link]/24 Interface 2.1
IP=[Link]/24
GW=[Link] IP=[Link]
GW=[Link]
A B Interface 2.2
Interface 2.1
IP=[Link] Interface 2.2 IP=[Link]
IP=[Link]
Figure 55: Example of the configuration of OSPF

The configuration of OSPF requires the following steps:


 Configure router interfaces – assign IP address and network mask.
 Activate OSPF on the port.
 Enable OSPF globally.
 Enable routing globally (if this has not already been done).

180 UM Config EAGLE


Release 3.4 03/2020
Routing
12.7 OSPF

Configuration for Router B

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
interface 2/2 Change to the interface configuration mode of
interface 2/2.
ip address primary [Link] Assign the IP parameters to the port.
[Link]
ip routing Activate routing on this port.
ip ospf operation Activate OSPF on this port.
exit Change to the Configuration mode.

interface 2/1 Change to the interface configuration mode of


interface 2/1.
ip address primary [Link] Assign the IP parameters to the port.
[Link]
ip routing Activate routing on this port.
ip ospf operation Activate OSPF on this port.
exit Change to the Configuration mode.

ip ospf router-id [Link] Assign router ID [Link] to router B.


ip ospf operation Enable OSPF globally.
ip ospf re-distribute connected Specify the OSPF parameters for the following
[subnets] actions:
 send the routes of the locally connected
interfaces
 include subnetworks without OSPF in OSPF
(CIDR).
exit Change to the Configuration mode.
exit Change to the Privileged EXEC mode.

show ip ospf global Display the settings for the global OSPF
configuration.

UM Config EAGLE 181


Release 3.4 03/2020
Routing
12.7 OSPF

OSPF Admin Mode................................ enabled


Router ID...................................... [Link]
ASBR Mode...................................... enabled
RFC 1583 Compatibility......................... enabled
ABR Status..................................... disabled
Exit Overflow Interval......................... 0
External LSA Count............................. 0
External LSA Checksum.......................... 0
New LSAs Originated............................ 0
LSAs Received.................................. 0
External LSDB Limit............................ no limit
SFP delay time................................. 5
SFP hold time.................................. 10
Auto cost reference bandwidth...................100
Default Metric................................. not configured
Default Route Advertise........................ disabled
Always......................................... false
Metric......................................... 0
Metric Type.................................... external-type2
Maximum Path................................... 4
Trap flags..................................... disabled
--More-- or (q)uit

show ip ospf interface 2/1 Display the settings for the OSPF interface
configuration.

IP address..................................... [Link]
OSPF admin mode................................ enabled
OSPF area ID................................... [Link]
Transmit delay................................. 1
Hello interval................................. 10
Dead interval.................................. 40
Re-transmit interval........................... 5
Authentification type.......................... none
OSPF interface type............................ broadcast
Status......................................... not Ready
Designated Router.............................. [Link]
Backup designated Router....................... [Link]
State.......................................... down
MTU ignore flag................................ disabled
Metric cost.................................... 1

configure Change to the Configuration mode.


ip routing Enable the Routing function globally.
exit Change to the Privileged EXEC mode.

 Also perform the corresponding configuration on the other OSPF routers.

show ip ospf neighbor brief Display the OSPF Adjacencies.


Neighbor ID IP Address Interface State Dead Time
------------ ----------- ----------- ------ ----------
[Link] [Link] 2/1 Full

182 UM Config EAGLE


Release 3.4 03/2020
Routing
12.7 OSPF

show ip route all Display the router table:

Network Address Protocol Next Hop IP Next Hop If Pref Active


--------------- -------- --- ------- ----------- ---- ------
[Link] OSPF [Link] 2/1 110 [x]

12.7.7 Limiting the distribution of the routes using an ACL

With Redistributing enabled, OSPF distributes every static route configured in the device without
further interference. The distribution of the rip routes and connected routes is analogous. You can
restrict this behavior using Access Control Lists.

Using IP rules, you specify which routes the device distributes to other devices in OSPF:
 To distribute a few routes in OSPF, you use the explicit permit rules. Using the permit rules, you
specify exactly which routes the device distributes in OSPF.
 To distribute many routes in OSPF, you use the explicit deny rules, combined with an explicit
permit rule. The device then distributes every route except those specified with a deny rule.

In the following example, you restrict the distribution of static routes in OSPF using Access Control
Lists.

The example contains the following sections:


 Setting up and distributing routes
 Explicitly enabling a route using a permit rule
 Explicitly disabling a route using a deny rule

Setting up and distributing routes

On Router A, you configure 2 static routes for the subnets [Link]/24 and [Link]/24. Router A
distributes these routes in OSPF to Router B. On router B, you check the distribution of the routes
configured on router A.

[Link]/24

.2 .1 A [Link]/24 .2
B
[Link]/24 1/2
1/1 2/2
1/3 OSPF OSPF
.1
OSPF
[Link]/24
.4

UM Config EAGLE 183


Release 3.4 03/2020
Routing
12.7 OSPF

Router A
 Enable routing globally.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
ip routing Enable routing globally.

 Setting up the first router interface [Link]/24.


Activate routing.
Activate OSPF on the router interface.

interface 1/1 Change to the interface configuration mode of


interface 1/1.
ip address primary [Link] Specify the IP address and subnet mask.
[Link]
ip routing Activate routing.
ip ospf operation Activate OSPF on the router interface.
exit Change to the Configuration mode.

 Setting up the second router interface [Link]/24.


Activate routing.
Activate OSPF on the router interface.

interface 1/2 Change to the interface configuration mode of


interface 1/2.
ip address primary [Link] Specify the IP address and subnet mask.
[Link]
ip routing Activate routing.
ip ospf operation Activate OSPF on the router interface.
exit Change to the Configuration mode.

 Enable OSPF globally.

ip ospf router-id [Link] Assign the router ID (for example [Link]).


ip ospf operation Enable OSPF globally.
show ip route all
Network Address Protocol Next Hop IP Next Hop If Pref Active
--------------- -------- -------------- ----------- ---- ------
[Link]/24 Local [Link] 1/1 0 [x]
[Link]/24 Local [Link] 1/2 0 [x]

 Configure and distribute static routes

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.

184 UM Config EAGLE


Release 3.4 03/2020
Routing
12.7 OSPF

ip route add [Link] [Link] Configure the static route [Link] through the
[Link] gateway [Link].
ip route add [Link] [Link] Configure the static route [Link] through the
[Link] gateway [Link].
ip ospf re-distribute static subnets Distribute the configured routes in OSPF.
enable

UM Config EAGLE 185


Release 3.4 03/2020
Routing
12.7 OSPF

Router B
 Enable routing globally.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
ip routing Enable routing globally.

 Setting up the router interface [Link]/24.


Activate routing.
Activate OSPF on the router interface.

interface 2/2 Change to the interface configuration mode of


interface 2/2.
ip address primary [Link] Specify the IP address and subnet mask.
[Link]
ip routing Activate routing.
ip ospf operation Activate OSPF on the router interface.
exit Change to the Configuration mode.
show ip route all
Network Address Protocol Next Hop IP Next Hop If Pref Active
--------------- -------- ------------ ----------- ---- ------
[Link]/24 Local [Link] 2/2 0 [x]

 Enable OSPF globally.

ip ospf router-id [Link] Assign the router ID (for example [Link]).


ip ospf operation Enable OSPF globally.

 Directly connect the port of the router interface [Link] to the first router interface of router A.
Check the availability of the OSPF neighbors.

show ip ospf neighbor Checking the router table:


Neighbor ID IP address Interface State Dead Time
-------------- -------------- ---------- -------------- ---------
[Link] [Link] 2/2 full 00:00:34

 Check the distribution of the routes configured on router A


Router A distributes both configured routes.

show ip route all Checking the the router table:


Network Address Protocol Next Hop IP Next Hop If Pref Active
--------------- -------- ------------ ----------- ---- ------
[Link]/24 OSPF [Link] 2/2 0 [x]
[Link]/24 OSPF [Link] 2/2 0 [x]
[Link]/24 Local [Link] 2/2 0 [x]
[Link]/24 OSPF [Link] 2/2 0 [x]

186 UM Config EAGLE


Release 3.4 03/2020
Routing
12.7 OSPF

To explicitly enable a route with a permit rule, refer to the “Explicitly enabling a route using a permit
rule” on page 187 section.

To explicitly disable a route with a deny rule, refer to the “Explicitly disabling a route using a deny
rule” on page 189 section.

Explicitly enabling a route using a permit rule

The route for the [Link]/24 subnet is enabled for distribution in OSPF.
 Using a permit rule, you explicitly enable the route for the [Link]/24 subnet.
 Due to the implicit deny rule embedded in the device, every other route is disabled for distribution
in OSPF.

permit

implicit
deny
[Link]/24 ACL

.2 .1
1 A [Link]/24 .2
B
[Link]/24 2
1/2
1/1 2/2
1/3 OSPF OSPF
.1
OSPF
[Link]/24
.4

UM Config EAGLE 187


Release 3.4 03/2020
Routing
12.7 OSPF

Router A
 Set up an Access Control List with an explicit permit rule.

ip access-list extended name OSPF-rule Create the OSPF-rule Access Control List and set up
permit src [Link]-[Link] dst a permit rule for the [Link] subnet.
[Link]-[Link] proto ip
• src [Link]-[Link] = address of the destination
network and inverse mask
• dst [Link]-[Link] = mask of the
destination network and inverse mask
The device lets you assign the address and
mask of the destination network with bit-level
accuracy using the inverse mask.

 Check the configured rules.

show access-list ip Display the configured Access Control Lists and


rules.
Index AclName RuleNo Action SrcIP
DestIP
----- --------------------------- ------ ------ -----------
1000 OSPF-rule 1 Permit [Link]
[Link]
show access-list ip OSPF-rule 1 Display the rule 1 (explicit permit rule) in the OSPF-
rule Access Control List.
IP access-list rule detail
--------------------------
IP access-list index........................1000
IP access-list name.........................OSPF-rule
IP access-list rule index...................1
Action......................................Permit
Match every ................................False
Protocol....................................IP
Source IP address...........................[Link]
Source IP mask..............................[Link]
Source L4 port operator.....................eq
Source port.................................-1
Destination IP address......................[Link]
Destination IP mask.........................[Link]
Source L4 port operator.....................eq
Destination port............................-1
Flag Bits...................................-1
Flag Mask...................................-1
Established.................................False
ICMP Type...................................0
ICMP Code...................................0
--More-- or (q)uit

 Apply the Access Control List to OSPF.

ip ospf distribute-list out static Apply the OSPF-rule Access Control List to OSPF.
OSPF-rule

188 UM Config EAGLE


Release 3.4 03/2020
Routing
12.7 OSPF

Router B
 Check the distribution of the routes configured on router A
Router A only distributes the route for the subnet [Link]/24 due to the configured Access
Control List.

show ip route all Checking the router table:


Network Address Protocol Next Hop IP Next Hop If Pref Active
--------------- -------- ------------ ----------- ---- ------
[Link]/24 OSPF [Link] 2/2 0 [x]
[Link]/24 Local [Link] 2/2 0 [x]
[Link]/24 OSPF [Link] 2/2 0 [x]

Explicitly disabling a route using a deny rule

The route for the [Link]/24 subnet is disabled for distribution in OSPF.
 Using an explicit permit-rule, you enable every rule for distribution in OSPF.
 Using a deny rule, you explicitly disable the route for the [Link]/24 subnet.

permit

deny

[Link]/24
ACL

.2 .1
1 A [Link]/24 .2
B
[Link]/24 1/2
2
1/1 2/2
1/3 OSPF OSPF
.1
OSPF
[Link]/24
.4

UM Config EAGLE 189


Release 3.4 03/2020
Routing
12.7 OSPF

Router A
 Delete permit rule.
These steps are necessary only in case you have configured a permit rule, as described in
section “Explicitly enabling a route using a permit rule” on page 187.

no ip ospf distribute-list out static Separate the OSPF-rule Access Control List from
OSPF-rule OSPF.
ip access-list extended del OSPF-rule Delete the Access Control List OSPF-rule and the
associated rules.

 Set up an Access Control List with an explicit deny rule.

ip access-list extended name OSPF-rule Create the OSPF-rule Access Control List and set up
deny src [Link]-[Link] dst a deny rule for the [Link] subnet.
[Link]-[Link] proto ip
• src [Link]-[Link] = address of the destination
network and inverse mask
• dst [Link]-[Link] = mask of the
destination network and inverse mask
The device lets you assign the address and
mask of the destination network with bit-level
accuracy using the inverse mask.

 Apply the Access Control List to OSPF.

ip ospf distribute-list out static Apply the OSPF-rule rule to OSPF.


OSPF-rule

Router B
 Check the distribution of the routes configured on router A
Due to the implicit deny rule embedded in the device, Router A does not distribute routes.

show ip route all Checking the router table:


Network Address Protocol Next Hop IP Next Hop If Pref Active
--------------- -------- ------------ ----------- ---- ------
[Link]/24 OSPF [Link] 2/2 0 [x]
[Link]/24 Local [Link] 2/2 0 [x]
[Link]/24 OSPF [Link] 2/2 0 [x]

The route [Link]/24 remains available because the Access Control List helps prevent only the
distribution of static routes.

190 UM Config EAGLE


Release 3.4 03/2020
Routing
12.7 OSPF

Router A
 Adding the explicit permit rule to Access Control List.

ip access-list extended name OSPF-rule Add a permit rule for every subnet to the OSPF-rule
permit src any dst any proto ip Access Control List.

 Check the configured rules.

show access-list ip Display the configured Access Control Lists and


rules.
Index AclName RuleNo Action SrcIP
DestIP
----- --------------------------- ------ ------ -----------
1000 OSPF-rule 1 Deny [Link]
[Link]
1000 OSPF-rule 2 Permit [Link]
[Link]
show access-list ip OSPF-rule 1 Display the rule 1 (explicit deny rule) in the OSPF-rule
Access Control List.

UM Config EAGLE 191


Release 3.4 03/2020
Routing
12.7 OSPF

IP access-list rule detail


--------------------------
IP access-list index........................1000
IP access-list name.........................OSPF-rule
IP access-list rule index...................1
Action......................................Deny
Match every ................................False
Protocol....................................IP
Source IP address...........................[Link]
Source IP mask..............................[Link]
Source L4 port operator.....................eq
Source port.................................-1
Destination IP address......................[Link]
Destination IP mask.........................[Link]
Source L4 port operator.....................eq
Destination port............................-1
Flag Bits...................................-1
Flag Mask...................................-1
Established.................................False
ICMP Type...................................0
ICMP Code...................................0
--More-- or (q)uit
show access-list ip OSPF-rule 2 Display the rule 2 (explicit permit rule) in the OSPF-
rule Access Control List.
IP access-list rule detail
--------------------------
IP access-list index........................1000
IP access-list name.........................OSPF-rule
IP access-list rule index...................2
Action......................................Permit
Match every ................................False
Protocol....................................IP
Source IP address...........................[Link]
Source IP mask..............................[Link]
Source L4 port operator.....................eq
Source port.................................-1
Destination IP address......................[Link]
Destination IP mask.........................[Link]
Source L4 port operator.....................eq
Destination port............................-1
Flag Bits...................................-1
Flag Mask...................................-1
Established.................................False
ICMP Type...................................0
ICMP Code...................................0
--More-- or (q)uit

192 UM Config EAGLE


Release 3.4 03/2020
Routing
12.7 OSPF

Router B
 Check the distribution of the routes configured on router A
Router A only distributes the route for the subnet [Link]/24 due to the configured Access
Control List.

show ip route all Checking the router table:


Network Address Protocol Next Hop IP Next Hop If Pref Active
--------------- -------- ------------ ----------- ---- ------
[Link]/24 OSPF [Link] 2/2 0 [x]
[Link]/24 Local [Link] 2/2 0 [x]
[Link]/24 OSPF [Link] 2/2 0 [x]

UM Config EAGLE 193


Release 3.4 03/2020
Routing
12.8 Entering the IP Parameters

12.8 Entering the IP Parameters

see OSPF

Area 0

see “Port-based Router-Interface” see “VLAN-based Router-Interface”

SN 10 SN 11
A VLAN ID 2

C B

VRRP SN 12

SN 13
see “VRRP”

SN 14

Figure 56: Network plan

To configure the Layer 3 function, you require access to the device management.

Depending on your own application, you will find many options for assigning IP addresses to the
devices. The following example describes one option that often arises in practice. Although you
have other prerequisites, this example shows the general method for entering the IP parameters
and points out significant things that you should note.

The prerequisites for the following example are:


 All Layer 2 and Layer 3 devices have the IP address [Link] (= default setting)
 The IP addresses of the devices and router interfaces and the gateway IP addresses are
specified in the network plan.
 The devices and their connections are installed.
 Redundant connections are open (see VRRP). To help avoid loops in the configuration phase,
close the redundant connections only after the configuration phase.

194 UM Config EAGLE


Release 3.4 03/2020
Routing
12.8 Entering the IP Parameters

IP = [Link]/24

IP = [Link]/24 Area 0 IP = [Link]/24


=> [Link]/24 GW: [Link]
GW: [Link]
=> [Link]
IP = [Link]/24 IP = [Link]/24
GW: [Link] Management-IP= GW: [Link]
[Link]

SN 10
[Link] A SN 11
IP = [Link]/24 [Link]
GW: [Link] VLAN 2

SN 100
[Link] Management-IP=
Management-IP= [Link]
[Link] VLAN 100

IP = [Link]/24 C B
GW: [Link] SN 12
VRRP [Link]
SN 13
[Link]
IP = [Link]/24
GW: [Link]
IP = [Link]/24
GW: [Link]
IP = [Link]/24
IP = [Link]/24 GW: [Link]
GW: [Link]
SN 14
[Link]

IP = [Link]/24 IP = [Link]/24
GW: [Link] GW: [Link]

Figure 57: Network plan with management IP addresses

 Assign the IP parameters to your configuration computer. During the configuration phase, the
configuration computer is located in subnet 100. This is necessary, so that the configuration
computer has access to the Layer 3 devices throughout the entire configuration phase.
 Start HiDiscovery on your configuration computer.
 Assign the IP parameters to every Layer 2 and Layer 3 device in accordance with the network
plan.
When you have completed the following router configuration, you can access the devices in
subnets 10 to 14 again.
 Configure the Routing function for the Layer 3 devices.
Note the sequence:
First the Layer 3 device C.
Then the Layer 3 device B.
The sequence is necessary; you thus retain access to the devices.
When you assign an IP address from the subnetwork of the device management IP address
(= SN 100) to a router interface, the device deletes the IP address of the device management.
You access the device management via the IP address of the router interface.

UM Config EAGLE 195


Release 3.4 03/2020
Routing
12.8 Entering the IP Parameters

IP = [Link]/24

Port 2.2:
IP = [Link]/24
Port 2.1: GW: [Link]
VLAN 1 (Management IP=[Link])
--> IP= [Link]/24
GW: [Link] Port 3.1 - Port 3.4:
VLAN 2
Interface vlan/2
A IP = [Link]/24
GW: [Link]

SN 100
Port 1.1: [Link]
VLAN 100 VLAN 100 Port 1.2:
Interface vlan/100 VLAN 100
IP = [Link]/24 Interface vlan/100
GW: [Link] IP = [Link]/24
GW: [Link]
Figure 58: IP parameters for Layer 3 device A

 Configure the Routing function for Layer 3 device A.


You first configure the router interface at a port to which the configuration computer is
connected. The result of this is that in future you will access the Layer 3 device via subnet 10.
 Change the IP parameters of your configuration computer to the values for subnetwork 10. You
thus access Layer 3 device A again, namely via the IP address of the router interface set up
beforehand.
 Finish the router configuration for Layer 3 device A (see figure 58).

After configuring the Routing function on every Layer 3 device, you have access to every device.

196 UM Config EAGLE


Release 3.4 03/2020
Operation diagnosis
13.1 Sending SNMP traps

13 Operation diagnosis

The device provides you with the following diagnostic tools:


 Sending SNMP traps
 Monitoring the Device Status
 Out-of-Band signaling using the signal contact
 Port status indication
 Event counter at port level
 Detecting non-matching duplex modes
 Auto-Disable
 Displaying the SFP status
 Topology discovery
 Detecting IP address conflicts
 Detecting loops
 Reports
 Monitoring data traffic on a port (port mirroring)
 Syslog
 Event log
 Cause and action management during selftest

13.1 Sending SNMP traps

The device immediately reports unusual events which occur during normal operation to the network
management station. This is done by messages called SNMP traps that bypass the polling
procedure (“polling” means querying the data stations at regular intervals). SNMP traps allow you
to react quickly to unusual events.

Examples of such events are:


 Hardware reset
 Changes to the configuration
 Segmentation of a port

The device sends SNMP traps to various hosts to increase the transmission reliability for the
messages. The unacknowledged SNMP trap message consists of a packet containing information
about an unusual event.

The device sends SNMP traps to those hosts entered in the trap destination table. The device lets
you configure the trap destination table with the network management station using SNMP.

UM Config EAGLE 197


Release 3.4 03/2020
Operation diagnosis
13.1 Sending SNMP traps

13.1.1 List of SNMP traps

The following table displays possible SNMP traps sent by the device.

Table 24: Possible SNMP traps

Name of the SNMP trap Meaning


authenticationFailure When a station attempts to access an agent without
authorisation, this trap is sent.
coldStart Sent after a restart.
hm2DevMonSenseExtNvmRemova When the external memory has been removed, this trap is sent.
l
linkDown When the connection to a port is interrupted, this trap is sent.
linkUp When connection is established to a port, this trap is sent.
hm2DevMonSensePSState When the status of a power supply unit changes, this trap is sent.
hm2SigConStateChange When the status of the signal contact changes in the operation
monitoring, this trap is sent.
newRoot When the sending agent becomes the new root of the spanning
tree, this trap is sent.
topologyChange When the port changes from blocking to forwarding or from
forwarding to blocking, this trap is sent.
alarmRisingThreshold When the RMON input exceeds its upper threshold, this trap is
sent.
alarmFallingThreshold When the RMON input goes below its lower threshold, this trap
is sent.
hm2AgentPortSecurityViolat When a MAC address detected on this port does not match the
ion current settings of the parameter
hm2AgentPortSecurityEntry, this trap is sent.
hm2DiagSelftestActionTrap When a self test for the four categories “task”, “resource”,
“software”, and “hardware” is performed according to the
configured settings, this trap is sent.
hm2MrpReconfig When the configuration of the MRP ring changes, this trap is
sent.
hm2DiagIfaceUtilizationTra When the threshold of the interface exceeds or undercuts the
p upper or lower threshold specified, this trap is sent.
hm2LogAuditStartNextSector When the audit trail after completing one sector starts a new
one, this trap is sent.
hm2ConfigurationSavedTrap After the device has successfully saved its configuration locally,
this trap is sent.
hm2ConfigurationChangedTra When you change the configuration of the device for the first
p time after it has been saved locally, this trap is sent.
hm2PlatformStpInstanceLoop When the port in this STP instance changes to the “loop
InconsistentStartTrap inconsistent” status, this trap is sent.
hm2PlatformStpInstanceLoop When the port in this STP instance leaves the “loop inconsistent”
InconsistentEndTrap status receiving a BPDU packet, this trap is sent.

198 UM Config EAGLE


Release 3.4 03/2020
Operation diagnosis
13.1 Sending SNMP traps

13.1.2 SNMP traps for configuration activity

After you save a configuration in the memory, the device sends a hm2ConfigurationSavedTrap.
This SNMP trap contains both the state variables of non-volatile memory (NVM) and external
memory (ENVM) indicating whether the running configuration is in sync with the non-volatile
memory, and with the external memory. You can also trigger this SNMP trap by copying a
configuration file to the device, replacing the active saved configuration.

Furthermore, the device sends a hm2ConfigurationChangedTrap, whenever you change the local
configuration, indicating a mismatch between the running and saved configuration.

13.1.3 SNMP trap setting

The device lets you send an SNMP trap as a reaction to specific events. Create at least 1 trap
destination that receives SNMP traps.

Perform the following steps:

 Open the Diagnostics > Status Configuration > Alarms (Traps) dialog.
 Click the button.
The dialog displays the Create window.
 In the Name frame, specify the name that the device uses to identify itself as the source of
the SNMP trap.
 In the Address frame, specify the IP address of the trap destination to which the device
sends the SNMP traps.
 In the Active column you select the entries that the device should take into account when it
sends SNMP traps.
 To save the changes temporarily, click the button.

For example, in the following dialogs you specify when the device triggers an SNMP trap:
 Basic Settings > Port dialog
 Network Security > Packet Filter > Rule dialog
 Routing > OSPF > Global dialog
 Routing > Tracking > Configuration dialog
 Routing > L3-Redundancy > VRRP > Configuration dialog
 Routing > NAT > 1:1 NAT > Rule dialog
 Routing > NAT > Destination NAT > Rule dialog
 Routing > NAT > Masquerading NAT > Rule dialog
 Routing > NAT > Double NAT > Rule dialog
 Diagnostics > Status Configuration > Device Status dialog
 Diagnostics > Status Configuration > Security Status dialog
 Diagnostics > Status Configuration > Signal Contact dialog
 Diagnostics > System > Selftest dialog

UM Config EAGLE 199


Release 3.4 03/2020
Operation diagnosis
13.1 Sending SNMP traps

13.1.4 ICMP messaging

The device lets you use the Internet Control Message Protocol (ICMP) for diagnostic applications,
for example ping and trace route. The device also uses ICMP for time-to-live and discarding
messages in which the device forwards an ICMP message back to the packet source device.

Use the ping network tool to test the path to a particular host across an IP network. The traceroute
diagnostic tool displays paths and transit delays of packets across a network.

200 UM Config EAGLE


Release 3.4 03/2020
Operation diagnosis
13.2 Monitoring the Device Status

13.2 Monitoring the Device Status

The device status provides an overview of the overall condition of the device. Many process
visualization systems record the device status for a device in order to present its condition in
graphic form.

The device displays its current status as error or ok in the Device status frame. The device
determines this status from the individual monitoring results.

The device enables you to:


 Out-of-Band signalling using a signal contact
 signal the changed device status by sending an SNMP trap
 detect the device status in the Basic Settings > System dialog of the Graphical User Interface
 query the device status in the Command Line Interface

The Global tab of the Diagnostics > Status Configuration > Device Status dialog lets you configure the
device to send a trap to the management station for the following events:
 Incorrect supply voltage
– at least one of the 2 supply voltages is not operating
– the internal supply voltage is not operating
 When the device is operating outside of the user-defined temperature threshold
 The interruption of link connection(s)
Configure at least one port for this feature. When the link is down, you specify which ports the
device signals in the Port tab of the Diagnostics > Status Configuration > Device Status dialog in the
Propagate connection error row.
 The removal of the external memory.
 The configuration in the external memory is out-of-sync with the configuration in the device.

Select the corresponding entries to decide which events the device status includes.

Note: With a non-redundant voltage supply, the device reports the absence of a supply voltage. To
disable this message, feed the supply voltage over both inputs or ignore the monitoring.

13.2.1 Events which can be monitored

Table 25: Device Status events

Name Meaning
Temperature Monitors in case the temperature exceeds or falls below the value
specified.
Connection errors Enable this function to monitor every port link event in which the Propagate
connection error checkbox is active.
External memory Enable this function to monitor the presence of an external storage device.
removal
External memory not in The device monitors synchronization between the device configuration and
sync the configuration stored in the external memory (ENVM).
Power supply Enable this function to monitor the power supply.

UM Config EAGLE 201


Release 3.4 03/2020
Operation diagnosis
13.2 Monitoring the Device Status

13.2.2 Configuring the Device Status

Perform the following steps:

 Open the Diagnostics > Status Configuration > Device Status dialog, Global tab.
 For the parameters to be monitored, mark the checkbox in the Monitor column.
 To send an SNMP trap to the management station, activate the Send trap function in the
Traps frame.
 In the Diagnostics > Status Configuration > Alarms (Traps) dialog, create at least 1 trap
destination that receives SNMP traps.
 To save the changes temporarily, click the button.
 Open the Basic Settings > System dialog.
 To monitor the temperature, at the bottom of the System data frame, you specify the
temperature thresholds.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
device-status trap When the device status changes, send an SNMP
trap.
device-status monitor envm-not-in-sync Monitors the configuration profiles in the device
and in the external memory.
The Device status changes to error in the following
situations:
• The configuration profile only exists in the
device.
• The configuration profile in the device differs
from the configuration profile in the external
memory.
device-status monitor envm-removal Monitors the active external memory. When you
remove the active external memory from the
device, the value in the Device status frame changes
to error.
device-status monitor power-supply 1 Monitors the power supply unit 1. When the device
has a detected power supply fault, the value in the
Device status frame changes to error.
device-status monitor temperature Monitors the temperature in the device. When the
temperature exceeds or falls below the specified
limit, the value in the Device status frame changes to
error.

In order to enable the device to monitor an active link without a connection, first enable the global
function, then enable the individual ports.

Perform the following steps:

 Open the Diagnostics > Status Configuration > Device Status dialog, Global tab.
 For the Connection errors parameter, mark the checkbox in the Monitor column.

202 UM Config EAGLE


Release 3.4 03/2020
Operation diagnosis
13.2 Monitoring the Device Status

 Open the Diagnostics > Status Configuration > Device Status dialog, Port tab.
 For the Propagate connection error parameter, mark the checkbox in the column of the ports
to be monitored.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
device-status monitor link-failure Monitors the ports/interfaces link. When the link
interrupts on a monitored port/interface, the value
in the Device status frame changes to error.
interface 1/1 Change to the interface configuration mode of
interface 1/1.
device-status link-alarm Monitors the port/interface link. When the link
interrupts on the port/interface, the value in the
Device status frame changes to error.

Note: The above commands activate monitoring and trapping for the supported components.
When you want to activate or deactivate monitoring for individual components, you will find the
corresponding syntax in the “Command Line Interface” reference manual or in the help of the
Command Line Interface console. To display the help in Command Line Interface, insert a question
mark ? and press the <Enter> key.

13.2.3 Displaying the Device Status

Perform the following steps:

 Open the Basic Settings > System dialog.

show device-status all In the EXEC Privilege mode: Displays the device
status and the setting for the device status
determination.

UM Config EAGLE 203


Release 3.4 03/2020
Operation diagnosis
13.3 Security Status

13.3 Security Status

The Security Status provides an overview of the overall security of the device. Many processes aid
in system visualization by recording the security status of the device and then presenting its
condition in graphic form. The device displays the overall security status in the Basic Settings >
System dialog, Security status frame.

In the Global tab of the Diagnostics > Status Configuration > Security Status dialog the device displays
its current status as error or ok in the Security status frame. The device determines this status from
the individual monitoring results.

The device enables you to:


 Out-of-Band signalling using a signal contact
 signal the changed security status by sending an SNMP trap
 detect the security status in the Basic Settings > System dialog of the Graphical User Interface
 query the security status in the Command Line Interface

13.3.1 Events which can be monitored


 Specify the events that the device monitors.
For the corresponding parameter, mark the checkbox in the Monitor column.

Table 26: Security Status events

Name Meaning
Password default settings After installation change the passwords to increase security.
unchanged When active and the default passwords remain unchanged, the
device displays an alarm.
Min. password length < 8 Create passwords more than 8 characters long to maintain a
high security posture. When active, the device monitors the Min.
password length setting.
Password policy settings The device monitors the settings located in the Device Security >
deactivated User Management dialog for password policy requirements.
User account password policy The device monitors the settings of the Policy check checkbox.
check deactivated When Policy check is inactive, the device sends an SNMP trap.
HTTP server active The device monitors when you enable the HTTP function.
SNMP unencrypted The device monitors when you enable the SNMPv1 or SNMPv2
function.
Access to system monitor with serial The device monitors the System Monitor status.
interface possible
Saving the configuration profile on The device monitors the possibility to save configurations to the
the external memory possible external non-volatile memory.
Link interrupted on enabled device The device monitors the link status of active ports.
ports
Access with HiDiscovery possible The device monitors when you enable the HiDiscovery read/
write access function.
Load unencrypted config from The device monitors the security settings for loading the
external memory configuration from the external NVM.
Self-signed HTTPS certificate The device monitors the HTTPS server for self-created digital
present certificates.

204 UM Config EAGLE


Release 3.4 03/2020
Operation diagnosis
13.3 Security Status

13.3.2 Configuring the Security Status

Perform the following steps:

 Open the Diagnostics > Status Configuration > Security Status dialog, Global tab.
 For the parameters to be monitored, mark the checkbox in the Monitor column.
 To send an SNMP trap to the management station, activate the Send trap function in the
Traps frame.
 To save the changes temporarily, click the button.
 In the Diagnostics > Status Configuration > Alarms (Traps) dialog, create at least 1 trap
destination that receives SNMP traps.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
security-status monitor pwd-change Monitors the password for the locally set up user
accounts user and admin. When the password for
the user or admin user accounts is the default
setting, the value in the Security status frame
changes to error.
security-status monitor pwd-min-length Monitors the value specified in the Min. password
length policy. When the value for the Min. password
length policy is less than 8, the value in the Security
status frame changes to error.
security-status monitor pwd-policy- Monitors the password policy settings.
config When the value for at least one of the following
policies is specified as 0, the value in the Security
status frame changes to error.
• Upper-case characters (min.)
• Lower-case characters (min.)
• Digits (min.)
• Special characters (min.)
security-status monitor pwd-policy- Monitors the password policy settings. When the
inactive value for at least one of the following policies is
specified as 0, the value in the Security status frame
changes to error.
security-status monitor http-enabled Monitors the HTTP server. When you enable the
HTTP server, the value in the Security status frame
changes to error.
security-status monitor snmp-unsecure Monitors the SNMP server.
When at least one of the following conditions
applies, the value in the Security status frame
changes to error:
• The SNMPv1 function is enabled.
• The SNMPv2 function is enabled.
• The encryption for SNMPv3 is disabled.
You enable the encryption in the Device
Security > User Management dialog, in the SNMP
encryption type field.

UM Config EAGLE 205


Release 3.4 03/2020
Operation diagnosis
13.3 Security Status

security-status monitor sysmon-enabled To monitor the activation of System Monitor 1 in the


device.
security-status monitor extnvm-upd- To monitor the activation of the external non
enabled volatile memory update.
security-status trap When the device status changes, it sends an
SNMP trap.

In order to enable the device to monitor an active link without a connection, first enable the global
function, then enable the individual ports.

Perform the following steps:

 Open the Diagnostics > Status Configuration > Security Status dialog, Global tab.
 For the Link interrupted on enabled device ports parameter, mark the checkbox in the Monitor
column.
 To save the changes temporarily, click the button.
 Open the Diagnostics > Status Configuration > Device Status dialog, Port tab.
 For the Link interrupted on enabled device ports parameter, mark the checkbox in the column
of the ports to be monitored.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
security-status monitor no-link-enabled Monitors the link on active ports. When the link
interrupts on an active port, the value in the Security
status frame changes to error.
interface 1/1 Change to the interface configuration mode of
interface 1/1.
security-status monitor no-link Monitors the link on interface/port 1.

13.3.3 Displaying the Security Status

Perform the following steps:

 Open the Basic Settings > System dialog.

show security-status all In the EXEC Privilege mode, display the security
status and the setting for the security status
determination.

206 UM Config EAGLE


Release 3.4 03/2020
Operation diagnosis
13.4 Out-of-Band signaling

13.4 Out-of-Band signaling

The device uses the signal contact to control external devices and monitor device functions.
Function monitoring enables you to perform remote diagnostics.

The device reports the operating status using a break in the potential-free signal contact (relay
contact, closed circuit) for the selected mode. The device monitors the following functions:
 Incorrect supply voltage
– at least one of the 2 supply voltages is not operating
– the internal supply voltage is not operating
 When the device is operating outside of the user-defined temperature threshold
 The interruption of link connection(s)
Configure at least one port for this feature. In the Propagate connection error frame, you specify
which ports the device signals for a link interruption. In the default setting, link monitoring is
inactive.
 The removal of the external memory.
 The configuration in the external memory does not match the configuration in the device.

Select the corresponding entries to decide which events the device status includes.

Note: With a non-redundant voltage supply, the device reports the absence of a supply voltage. To
disable this message, feed the supply voltage over both inputs or ignore the monitoring.

13.4.1 Controlling the Signal contact

With the Manual setting mode you control this signal contact remotely.

Application options:
 Simulation of an error detected during SPS error monitoring
 Remote control of a device using SNMP, such as switching on a camera

Perform the following steps:

 Open the Diagnostics > Status Configuration > Signal Contact dialog, Global tab.
 To control the signal contact manually, in the Configuration frame, Mode drop-down list,
select the value Manual setting.
 To open the signal contact, you select the open radio button in the Configuration frame.
 To close the signal contact, you select the close radio button in the Configuration frame.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
signal-contact 1 mode manual Select the manual setting mode for signal contact
1.
signal-contact 1 state open Open signal contact 1.
signal-contact 1 state closed Close signal contact 1.

UM Config EAGLE 207


Release 3.4 03/2020
Operation diagnosis
13.4 Out-of-Band signaling

13.4.2 Monitoring the Device and Security Statuses

In the Configuration field, you specify which events the signal contact indicates.
 Device status
Using this setting the signal contact indicates the status of the parameters monitored in the
Diagnostics > Status Configuration > Device Status dialog.
 Security status
Using this setting the signal contact indicates the status of the parameters monitored in the
Diagnostics > Status Configuration > Security Status dialog.
 Device/Security status
Using this setting the signal contact indicates the status of the parameters monitored in the
Diagnostics > Status Configuration > Device Status and the Diagnostics > Status Configuration >
Security Status dialog.

Configuring the operation monitoring

Perform the following steps:

 Open the Diagnostics > Status Configuration > Signal Contact dialog, Global tab.
 To monitor the device functions using the signal contact, in the Configuration frame, specify
the value Monitoring correct operation in the Mode field.
 For the parameters to be monitored, mark the checkbox in the Monitor column.
 To send an SNMP trap to the management station, activate the Send trap function in the
Traps frame.
 To save the changes temporarily, click the button.
 In the Diagnostics > Status Configuration > Alarms (Traps) dialog, create at least 1 trap
destination that receives SNMP traps.
 To save the changes temporarily, click the button.
 You specify the temperature thresholds for the temperature monitoring in the Basic
Settings > System dialog.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
signal-contact 1 monitor temperature Monitors the temperature in the device. When the
temperature exceeds / falls below the threshold
values, the signal contact opens.
signal-contact 1 monitor ring- Monitors the ring redundancy.
redundancy The signal contact opens in the following
situations:
• The redundancy function becomes active (loss
of redundancy reserve).
• The device is a normal ring participant and
detects an error in its settings.
signal-contact 1 monitor link-failure Monitors the ports/interfaces link. When the link
interrupts on a monitored port/interface, the signal
contact opens.
signal-contact 1 monitor envm-removal Monitors the active external memory. When you
remove the active external memory from the
device, the signal contact opens.

208 UM Config EAGLE


Release 3.4 03/2020
Operation diagnosis
13.4 Out-of-Band signaling

signal-contact 1 monitor envm-not-in- Monitors the configuration profiles in the device


sync and in the external memory.
The signal contact opens in the following
situations:
• The configuration profile only exists in the
device.
• The configuration profile in the device differs
from the configuration profile in the external
memory.
signal-contact 1 monitor power-supply 1 Monitors the power supply unit 1. When the device
has a detected power supply fault, the signal
contact opens.
signal-contact 1 monitor module-removal Monitors module 1. When you remove module 1
1 from the device, the signal contact opens.
signal-contact 1 trap Enables the device to send an SNMP trap when the
status of the operation monitoring changes.
no signal-contact 1 trap Disabling the SNMP trap

In order to enable the device to monitor an active link without a connection, first enable the global
function, then enable the individual ports.

Perform the following steps:

 In the Monitor column, activate the Link interrupted on enabled device ports function.
 Open the Diagnostics > Status Configuration > Device Status dialog, Port tab.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
signal-contact 1 monitor link-failure Monitors the ports/interfaces link. When the link
interrupts on a monitored port/interface, the signal
contact opens.
interface 1/1 Change to the interface configuration mode of
interface 1/1.
signal-contact 1 link-alarm Monitors the port/interface link. When the link
interrupts on the port/interface, the signal contact
opens.

Events which can be monitored

Table 27: Device Status events

Name Meaning
Temperature When the temperature exceeds or falls below the value
specified.
Connection errors Enable this function to monitor every port link event in which the
Propagate connection error checkbox is active.

UM Config EAGLE 209


Release 3.4 03/2020
Operation diagnosis
13.4 Out-of-Band signaling

Table 27: Device Status events (cont.)

Name Meaning
External memory not in sync with The device monitors synchronization between the device
NVM configuration and the configuration stored in the external
memory (ENVM).
External memory removed Enable this function to monitor the presence of an external
storage device.
Power supply Enable this function to monitor the power supply.

Displaying the signal contact’s status

The device gives you additional options for displaying the status of the signal contact:
 Display in the Graphical User Interface
 Query in the Command Line Interface

 Open the Basic Settings > System dialog.


The Signal contact status frame displays the signal contact status and informs you about
alarms that have occurred. When an alarm currently exists, the frame is highlighted.

show signal-contact 1 all Displays signal contact settings for the specified
signal contact.

210 UM Config EAGLE


Release 3.4 03/2020
Operation diagnosis
13.5 Port status indication

13.5 Port status indication

Perform the following steps:

 Open the Basic Settings > System dialog.

The dialog displays the device with the current configuration. Furthermore, the dialog indicates the
status of the individual ports with a symbol.

The following symbols represent the status of the individual ports. In some situations, these
symbols interfere with one another. When you position the mouse pointer over the port icon, a
bubble help displays a detailed description of the port state.

Table 28: Symbols identifying the status of the ports

Criterion Symbol
Bandwidth of the port 10 Mbit/s
Port activated, connection okay, full-duplex mode
100 Mbit/s
Port activated, connection okay, full-duplex mode
1000 Mbit/s
Port activated, connection okay, full-duplex mode
Operating state Half-duplex mode enabled
See the Basic Settings > Port dialog, Configuration tab, Automatic configuration
checkbox, Manual configuration field and Manual cable crossing (Auto. conf. off)
field.
Autonegotiation enabled
See the Basic Settings > Port dialog, Configuration tab, Automatic configuration
checkbox.
AdminLink The port is deactivated, connection okay
The port is deactivated, no connection set up
See the Basic Settings > Port dialog, Configuration tab, Port on checkbox and
Link/Current settings field.

UM Config EAGLE 211


Release 3.4 03/2020
Operation diagnosis
13.6 Port event counter

13.6 Port event counter

The port statistics table lets experienced network administrators identify possible detected
problems in the network.

This table displays the contents of various event counters. The packet counters add up the events
sent and the events received. In the Basic Settings > Restart dialog, you can reset the event counters.

Table 29: Examples indicating known weaknesses

Counter Indication of known possible weakness


Received fragments • Non-functioning controller of the connected device
• Electromagnetic interference in the transmission medium
CRC Error • Non-functioning controller of the connected device
• Electromagnetic interference in the transmission medium
• Inoperable component in the network
Collisions • Non-functioning controller of the connected device
• Network over extended/lines too long
• Collision or a detected fault with a data packet

Perform the following steps:

 To display the event counter, open the Basic Settings > Port dialog, Statistics tab.
 To reset the counters, in the Basic Settings > Restart dialog, click the Clear port statistics
button.

13.6.1 Detecting non-matching duplex modes

Problems occur when 2 ports directly connected to each other have mismatching duplex modes.
These problems are difficult to track down. The automatic detection and reporting of this situation
has the benefit of recognizing mismatching duplex modes before problems occur.

This situation arises from an incorrect configuration, for example, deactivatation of the automatic
configuration on the remote port.

A typical effect of this non-matching is that at a low data rate, the connection seems to be
functioning, but at a higher bi-directional traffic level the local device records a lot of CRC errors,
and the connection falls significantly below its nominal capacity.

The device lets you detect this situation and report it to the network management station. In the
process, the device evaluates the error counters of the port in the context of the port settings.

Possible causes of port error events

The following table lists the duplex operating modes for TX ports, with the possible fault events. The
meanings of terms used in the table are as follows:
 Collisions
In half-duplex mode, collisions mean normal operation.
 Duplex problem
Mismatching duplex modes.

212 UM Config EAGLE


Release 3.4 03/2020
Operation diagnosis
13.6 Port event counter

 EMI
Electromagnetic interference.
 Network extension
The network extension is too great, or too many cascading hubs.
 Collisions, Late Collisions
In full-duplex mode, no incrementation of the port counters for collisions or Late Collisions.
 CRC Error
The device evaluates these errors as non-matching duplex modes in the manual full duplex
mode.

Table 30: Evaluation of non-matching of the duplex mode

No. Automatic Current duplex Detected error Duplex modes Possible causes
configuration mode events (≥ 10 after
link up)
1 marked Half duplex None OK
2 marked Half duplex Collisions OK
3 marked Half duplex Late Collisions Duplex problem Duplex problem,
detected EMI, network
extension
4 marked Half duplex CRC Error OK EMI
5 marked Full duplex None OK
6 marked Full duplex Collisions OK EMI
7 marked Full duplex Late Collisions OK EMI
8 marked Full duplex CRC Error OK EMI
9 unmarked Half duplex None OK
10 unmarked Half duplex Collisions OK
11 unmarked Half duplex Late Collisions Duplex problem Duplex problem,
detected EMI, network
extension
12 unmarked Half duplex CRC Error OK EMI
13 unmarked Full duplex None OK
14 unmarked Full duplex Collisions OK EMI
15 unmarked Full duplex Late Collisions OK EMI
16 unmarked Full duplex CRC Error Duplex problem Duplex problem,
detected EMI

UM Config EAGLE 213


Release 3.4 03/2020
Operation diagnosis
13.7 Displaying the SFP status

13.7 Displaying the SFP status

The SFP status display lets you look at the current SFP module connections and their properties.
The properties include:
 module type
 serial number of media module
 temperature in º C
 transmission power in mW
 receive power in mW

Perform the following steps:

 Open the Diagnostics > Ports > SFP dialog.

214 UM Config EAGLE


Release 3.4 03/2020
Operation diagnosis
13.8 Topology discovery

13.8 Topology discovery

IEEE 802.1AB defines the Link Layer Discovery Protocol (LLDP). LLDP lets the user automatically
detect the LAN network topology.

Devices with LLDP active:


 broadcast their connection and management information to neighboring devices on the shared
LAN. When the receiving device has its LLDP function active, evaluation of the devices occur.
 receive connection and management information from neighbor devices on the shared LAN,
provided these adjacent devices also have LLDP active.
 build a management information database and object definitions for storing information about
adjacent devices with LLDP active.

As the main element, the connection information contains an exact, unique identifier for the
connection end point: MAC (Service Access Point). This is made up of a device identifier which is
unique on the entire network and a unique port identifier for this device.
 Chassis identifier (its MAC address)
 Port identifier (its port-MAC address)
 Description of port
 System name
 System description
 Supported system capabilities
 System capabilities currently active
 Interface ID of the management address
 VLAN-ID of the port
 Auto-negotiation status on the port
 Medium, half/full duplex setting and port speed setting
 Information about the VLANs installed in the device (VLAN-ID and VLAN name, irrespective of
whether the port is a VLAN participant).

A network management station can call up this information from devices with activated LLDP. This
information enables the network management station to map the topology of the network.

Non-LLDP devices normally block the special Multicast LLDP IEEE MAC address used for
information exchange. Non-LLDP devices therefore discard LLDP packets. If you position a non-
LLDP capable device between 2 LLDP capable devices, then the non-LLDP capable device
prohibits information exchanges between the 2 LLDP capable devices.

The Management Information Base (MIB) for a device with LLDP capability holds the LLDP
information in the lldp MIB and in the private HM2-LLDP-EXT-HM-MIB and HM2-LLDP-MIB.

13.8.1 Displaying the Topology discovery results

To show the topology of the network:

 Open the Diagnostics > LLDP > Topology Discovery dialog, LLDP tab.

When you use a port to connect several devices, for example via a hub, the table contains a line
for each connected device.

Activating Display FDB Entries at the bottom of the table lets you display devices without active
LLDP support in the table. In this case, the device also includes information from its FDB
(forwarding database).

UM Config EAGLE 215


Release 3.4 03/2020
Operation diagnosis
13.8 Topology discovery

If you connect the port to devices with the topology discovery function active, then the devices
exchange LLDP Data Units (LLDPDU) and the topology table displays these neighboring devices.

When a port connects only devices without an active topology discovery, the table contains a line
for this port to represent the connected devices. This line contains the number of connected
devices.

The FDB address table contains MAC addresses of devices that the topology table hides for the
sake of clarity.

216 UM Config EAGLE


Release 3.4 03/2020
Operation diagnosis
13.9 Reports

13.9 Reports

The following lists reports and buttons available for diagnostics:


 System Log file
The log file is an HTML file in which the device writes device-internal events.
 Audit Trail
Logs successful commands and user comments. The file also includes SNMP logging.
 Persistent Logging
When the external memory is present, the device saves log entries in a file in the external
memory. These files are available after power down. The maximum size, maximum number of
retainable files and the severity of logged events are configurable. After obtaining the user-
defined maximum size or maximum number of retainable files, the device archives the entries
and starts a new file. The device deletes the oldest file and renames the other files to maintain
the configured number of files. To review these files use the Command Line Interface or copy
them to an external server for future reference.
 Download support information
This button lets you download system information as a ZIP archive.

In service situations, these reports provide the technician with the necessary information.

13.9.1 Global settings

Using this dialog you enable or disable where the device sends reports, for example, to a Console,
a Syslog Server, or a connection to the Command Line Interface. You also set at which severity
level the device writes events into the reports.

Perform the following steps:

 Open the Diagnostics > Report > Global dialog.


 To send a report to the console, specify the desired level in the Console logging frame,
Severity field.
 To enable the function, select the On radio button in the Console logging frame.
 To save the changes temporarily, click the button.

The device buffers logged events in 2 separate storage areas so that the device keeps log entries
for urgent events. Specify the minimum severity for events that the device logs to the buffered
storage area with a higher priority.

Perform the following steps:

 To send events to the buffer, specify the desired level in the Buffered logging frame, Severity
field.
 To save the changes temporarily, click the button.

UM Config EAGLE 217


Release 3.4 03/2020
Operation diagnosis
13.9 Reports

When you activate the logging of SNMP requests, the device logs the requests as events in the
Syslog. The Log SNMP get request function logs user requests for device configuration information.
The Log SNMP set request function logs device configuration events. Specify the minimum level for
events that the device logs in the Syslog.

Perform the following steps:

 Enable the Log SNMP get request function for the device in order to send SNMP Read
requests as events to the Syslog server.
To enable the function, select the On radio button in the SNMP logging frame.
 Enable the Log SNMP set request function for the device in order to send SNMP Write
requests as events to the Syslog server.
To enable the function, select the On radio button in the SNMP logging frame.
 Choose the desired severity level for the get and set requests.
 To save the changes temporarily, click the button.

When active, the device logs configuration changes made using the Command Line Interface, to
the audit trail. This feature is based on the IEEE 1686 standard for Substation Intelligent Electronic
Devices.

Perform the following steps:

 Open the Diagnostics > Report > Global dialog.


 To enable the function, select the On radio button in the CLI logging frame.
 To save the changes temporarily, click the button.

The device lets you save the following system information data in one ZIP file on your PC:
 [Link]
 [Link]
 [Link]
 script
 [Link]
 [Link]
 [Link]
 [Link]

The device creates the file name of the ZIP archive automatically in the format
<IP_address>_<system_name>.zip.

Perform the following steps:

 Click the button and then the Download support information item.
 Select the directory in which you want to save the support information.
 To save the changes temporarily, click the button.

218 UM Config EAGLE


Release 3.4 03/2020
Operation diagnosis
13.9 Reports

13.9.2 Syslog

The device enables you to send messages about device internal events to one or more Syslog
servers (up to 8). Additionally, you also include SNMP requests to the device as events in the
Syslog.

Note: To display the logged events, open the Diagnostics > Report > Audit Trail dialog or the
Diagnostics > Report > System Log dialog.

Perform the following steps:

 Open the Diagnostics > Syslog dialog.


 To add a table entry, click the button.
 In the IP address column, enter the IP address of the Syslog server.
 In the Destination UDP port column, specify the UDP port on which the Syslog server expects
the log entries.
 In the Min. severity column, specify the minimum severity level that an event requires for the
device to send a log entry to this Syslog server.
 Mark the checkbox in the Active column.
 To enable the function, select the On radio button in the Operation frame.
 To save the changes temporarily, click the button.

In the SNMP logging frame, configure the following settings for read and write SNMP requests:

Perform the following steps:

 Open the Diagnostics > Report > Global dialog.


 Enable the Log SNMP get request function for the device in order to send SNMP Read
requests as events to the Syslog server.
To enable the function, select the On radio button in the SNMP logging frame.
 Enable the Log SNMP set request function for the device in order to send SNMP Write
requests as events to the Syslog server.
To enable the function, select the On radio button in the SNMP logging frame.
 Choose the desired severity level for the get and set requests.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
logging host add 1 addr [Link] Adds a new recipient in the Syslog servers list. The
severity 3 value 3 specifies the severity level of the event that
the device logs. The value 3 means Error.
logging syslog operation Enable the Syslog function.
exit Change to the Privileged EXEC mode.
show logging host Display the Syslog host settings.

UM Config EAGLE 219


Release 3.4 03/2020
Operation diagnosis
13.9 Reports

No. Server IP Port Max. Severity Type Status


----- -------------- ----- -------------- ---------- -------
1 [Link] 514 error systemlog active

configure Change to the Configuration mode.


logging snmp-requests get operation Logs SNMP GET requests.
logging snmp-requests get severity 5 The value 5 specifies the severity level of the event
that the device logs in case of SNMP GET
requests. The value 5 means Notice.
logging snmp-requests set operation Logs SNMP SET requests.
logging snmp-requests set severity 5 The value 5 specifies the severity level of the event
that the device logs in case of SNMP SET
requests. The value 5 means Notice.
exit Change to the Privileged EXEC mode.
show logging snmp Display the SNMP logging settings.

Log SNMP GET requests : enabled


Log SNMP GET severity : notice
Log SNMP SET requests : enabled
Log SNMP SET severity : notice

13.9.3 System Log

The device lets you call up a log file of the system events. The table in the Diagnostics > Report >
System Log dialog lists the logged events.

Perform the following steps:

 To update the content of the log, click the button.


 To save the content of the log as an html file, click the button and then the Reset item.
 To delete the content of the log, click the button and then the Reset item.
 To search the content of the log for a key word, use the search function of your web
browser.

Note: You have the option to also send the logged events to one or more Syslog servers.

13.9.4 Audit Trail

The Diagnostics > Report > Audit Trail dialog contains system information and changes to the device
configuration performed through the Command Line Interface and SNMP. In the case of device
configuration changes, the dialog displays Who changed What and When. To log changes to the
device configuration, use in the Diagnostics > Report > Audit Trail dialog the functions Log SNMP get
request and Log SNMP set request.

220 UM Config EAGLE


Release 3.4 03/2020
Operation diagnosis
13.9 Reports

The Diagnostics > Syslog dialog lets you specify up to 8 Syslog servers to which the device sends
Audit Trails.

The following list contains log events:


 changes to configuration parameters
 Commands (except show commands) using the Command Line Interface
 Command logging audit-trail <string> using the Command Line Interface which logs the
comment
 Automatic changes to the System Time
 watchdog events
 locking a user after several unsuccessful login attempts
 User login, either locally or remote, using the Command Line Interface
 Manual, user-initiated, logout
 Timed logout after a user-defined period of inactivity in the Command Line Interface
 file transfer operation including a Firmware Update
 Configuration changes using HiDiscovery
 Automatic configuration or firmware updates using the external memory
 Blocked access to the device management due to invalid login
 rebooting
 opening and closing SNMP over HTTPS tunnels
 Detected power failures

UM Config EAGLE 221


Release 3.4 03/2020
Advanced functions of the device
14.1 Using the device as a DNS client

14 Advanced functions of the device

14.1 Using the device as a DNS client

The Domain Name System (DNS) client queries DNS servers to resolve host names and IP
addresses of network devices. Much like a telephone book, the DNS client converts names of
devices into IP addresses. When the DNS client receives a request to resolve a new name, the
DNS client first queries its internal static database, then the assigned DNS servers for the
information. The DNS client saves the queried information in a cache for future requests. The
device lets you configure the DNS client from the DHCP server using the device management
VLAN. The device also lets you assign host names to IP addresses statically.

The DNS client provides the following user functions:


 DNS server list, with space for 4 domain name server IP addresses
 static hostname to IP address mapping, with space for 64 configurable static hosts
 host cache, with space for 128 entries

222 UM Config EAGLE


Release 3.4 03/2020
Advanced functions of the device
14.1 Using the device as a DNS client

14.1.1 Configuring a DNS server example

Name the DNS client and configure it to query a DNS server to resolve host names.

Perform the following steps:

 Open the Advanced > DNS > Client > Static dialog.
 In the Configuration frame, Configuration source field, specify the value user.
 In the Configuration frame, Domain name field, specify the value device1.
 To add a table entry, click the button.
 In the Address column, specify the value [Link] as the IP address of the DNS server.
 Mark the checkbox in the Active column.
 Open the Advanced > DNS > Client > Global dialog.
 To enable the function, select the On radio button in the Operation frame.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
dns client source user Specifying that the user manually configures the
DNS client settings.
dns client domain-name devicel Specifying the string device1 as a unique domain
name for the device.
dns client servers add 1 ip [Link] To add a DNS name server with an IP address of
[Link] as index 1.
dns client adminstate Enable the DNS Client function globally.

Configure the DNS client to map static hosts with IP addresses.

Perform the following steps:

 Open the Advanced > DNS > Client > Static Hosts dialog.
 To add a table entry, click the button.
 In the Name column, enter the value [Link].
This is a name of a device in the network.
 In the IP address column, specify the value [Link].
 Mark the checkbox in the Active column.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
dns client host add 1 name [Link] Add [Link] as a static host with an IP address
ip [Link] of [Link].
dns client adminstate Enable the DNS Client function globally.

UM Config EAGLE 223


Release 3.4 03/2020
Setting up the configuration environment
A.1 Preparing access via SSH

A Setting up the configuration environment

A.1 Preparing access via SSH

To access the device using SSH, perform the following steps:


 Generate a key in the device.
or
 Transfer your own key onto the device.
 Prepare access to the device in the SSH client program.

Note: In the default setting, the key is already existing and access using SSH is enabled.

A.1.1 Generating a key in the device

The device lets you generate the key directly in the device.

Perform the following steps:

 Open the Device Security > Management Access > Server dialog, SSH tab.
 To disable the SSH server, select the Off radio button in the Operation frame.
 To save the changes temporarily, click the button.
 To create a RSA key, in the Signature frame, click the Create button.
 To enable the SSH server, select the On radio button in the Operation frame.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
ssh key rsa generate Generate a new RSA key.

224 UM Config EAGLE


Release 3.4 03/2020
Setting up the configuration environment
A.1 Preparing access via SSH

A.1.2 Loading your own key onto the device

OpenSSH gives experienced network administrators the option of generating an own key. To
generate the key, enter the following commands on your PC:
ssh-keygen(.exe) -q -t rsa -f [Link] -C '' -N ''
rsaparam -out [Link] 2048

The device lets you transfer your own SSH key onto the device.

Perform the following steps:

 Open the Device Security > Management Access > Server dialog, SSH tab.
 To disable the SSH server, select the Off radio button in the Operation frame.
 To save the changes temporarily, click the button.
 When the host key is located on your PC or on a network drive, drag and drop the file that
contains the key in the area. Alternatively click in the area to select the file.
 Click the Start button in the Key import frame to load the key onto the device.
 To enable the SSH server, select the On radio button in the Operation frame.
 To save the changes temporarily, click the button.

 Copy the self-generated key from your PC to the external memory.


 Copy the key from the external memory into the device.

enable Change to the Privileged EXEC mode.


copy sshkey envm <file name> Load your own key onto the device from the
external memory.

A.1.3 Preparing the SSH client program

The PuTTY program lets you access the device using SSH. This program is provided on the product
CD.

Perform the following steps:


 Start the program by double-clicking on it.

UM Config EAGLE 225


Release 3.4 03/2020
Setting up the configuration environment
A.1 Preparing access via SSH

Figure 59: PuTTY input screen

 In the Host Name (or IP address) field you enter the IP address of your device.
The IP address (a.b.c.d) consists of 4 decimal numbers with values from 0 to 255. The 4 decimal
numbers are separated by points.
 To select the connection type, select the SSH radio button in the Connection type option list.
 Click the Open button to set up the data connection to your device.

Before the connection is established, the PuTTY program displays a security alarm message and
lets you check the key fingerprint.

Figure 60: Security alert prompt for the fingerprint

 Check the fingerprint of the key to help ensure that you have actually connected to the desired
device.
 When the fingerprint matches your key, click the Yes button.

For experienced network administrators, another way of accessing your device through an SSH is
by using the OpenSSH Suite. To set up the data connection, enter the following command:

ssh admin@[Link]

admin is the user name.

[Link] is the IP address of your device.

226 UM Config EAGLE


Release 3.4 03/2020
Setting up the configuration environment
A.2 HTTPS certificate

A.2 HTTPS certificate

Your web browser establishes the connection to the device using the HTTPS protocol. The
prerequisite is that you enable the HTTPS server function in theDevice Security > Management Access >
Server dialog, HTTPS tab.

Note: Third-party software such as web browsers validate certificates based on criteria such as
their expiration date and current cryptographic parameter recommendations. Old certificates can
cause errors for example, an expired certificate or cryptographic recommendations change. To
solve validation conflicts with third-party software, transfer your own up-to-date certificate onto the
device or regenerate the certificate with the latest firmware.

UM Config EAGLE 227


Release 3.4 03/2020
Setting up the configuration environment
A.2 HTTPS certificate

A.2.1 HTTPS certificate management

A standard certificate according to X.509/PEM (Public Key Infrastructure) is required for encryption.
In the default setting, a self-generated certificate is already present in the device.

 Open the Device Security > Management Access > Server dialog, HTTPS tab.
 To create a X509/PEM certificate, in the Certificate frame, click the Create button.
 To save the changes temporarily, click the button.
 Restart the HTTPS server to activate the key. Restart the server using the Command Line
Interface.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
https certificate generate Generate a https X.509/PEM Certificate.
no https server Disable the HTTPS function.
https server Enable the HTTPS function.

 The device also enables you to transfer an externally generated X.509/PEM certificate onto the
device:

 Open the Device Security > Management Access > Server dialog, HTTPS tab.
 When the certificate is located on your PC or on a network drive, drag and drop the
certificate in the area. Alternatively click in the area to select the certificate.
 Click on the Start button to copy the certificate to the device.
 To save the changes temporarily, click the button.

enable Change to the Privileged EXEC mode.


copy httpscert envm <file name> Copy HTTPS certificate from external non-volatile
memory device.
configure Change to the Configuration mode.
no https server Disable the HTTPS function.
https server Enable the HTTPS function.

Note: To activate the certificate after you created or transfered it, reboot the device or restart the
HTTPS server. Restart the HTTPS server using the Command Line Interface.

228 UM Config EAGLE


Release 3.4 03/2020
Setting up the configuration environment
A.2 HTTPS certificate

A.2.2 Access through HTTPS

The default setting for HTTPS data connection is TCP port 443. If you change the number of the
HTTPS port, then reboot the device or the HTTPS server. Thus the change becomes effective.

Perform the following steps:

 Open the Device Security > Management Access > Server dialog, HTTPS tab.
 To enable the function, select the On radio button in the Operation frame.
 To access the device by HTTPS, enter HTTPS instead of HTTP in your browser, followed
by the IP address of the device.

enable Change to the Privileged EXEC mode.


configure Change to the Configuration mode.
https port 443 Specifies the number of the TCP port on which the
web server receives HTTPS requests from clients.
https server Enable the HTTPS function.
show https Displays the status of the HTTPS server and the
port number.

When you make changes to the HTTPS port number, disable the HTTPS server and enable it again
in order to make the changes effective.

The device uses HTTPS protocol and establishes a new data connection. When the user logs out
at the end of the session, the device terminates the data connection.

UM Config EAGLE 229


Release 3.4 03/2020
Appendix
B.1 Literature references

B Appendix

B.1 Literature references

 Optische Übertragungstechnik in industrieller Praxis


Christoph Wrobel (ed.)
Hüthig Buch Verlag Heidelberg
ISBN 3-7785-2262-0
 Hirschmann Manual
Basics of Industrial ETHERNET and TCP/IP
280 710-834
 TCP/IP Illustrated, vol. 1
W.R. Stevens
Addison Wesley 1994
ISBN 0-201-63346-9

230 UM Config EAGLE


Release 3.4 03/2020
Appendix
B.2 Maintenance

B.2 Maintenance

Hirschmann is continually working on improving and developing their software. Check regularly
whether there is an updated version of the software that provides you with additional benefits. You
find information and software downloads on the Hirschmann product pages on the Internet at
[Link].

UM Config EAGLE 231


Release 3.4 03/2020
Appendix
B.3 Management Information Base (MIB)

B.3 Management Information Base (MIB)

The Management Information Base (MIB) is designed in the form of an abstract tree structure.

The branching points are the object classes. The "leaves" of the MIB are called generic object
classes.

When this is required for unique identification, the generic object classes are instantiated, that
means the abstract structure is mapped onto reality, by specifying the port or the source address.

Values (integers, time ticks, counters or octet strings) are assigned to these instances; these values
can be read and, in some cases, modified. The object description or object ID (OID) identifies the
object class. The subidentifier (SID) is used to instantiate them.

232 UM Config EAGLE


Release 3.4 03/2020
Appendix
B.3 Management Information Base (MIB)

Example:

The generic object class hm2PSState (OID = [Link].[Link].[Link].1.2) is the


description of the abstract information power supply status. However, it is not possible to read
any value from this, as the system does not know which power supply is meant.

Specifying the subidentifier 2 maps this abstract information onto reality (instantiates it), thus
identifying it as the operating status of power supply 2. A value is assigned to this instance and can
be read. The instance get [Link].[Link].[Link].1.2.1 returns the response 1, which
means that the power supply is ready for operation.

Definition of the
syntax terms
used:
Integer An integer in the range -231 - 231-1
IP address [Link]
(xxx = integer in the range 0..255)
MAC address 12-digit hexadecimal number in accordance with ISO/IEC 8802-3
Object x.x.x.x… (for example [Link].[Link]...)
Identifier
Octet String ASCII character string
PSID Power supply identifier (number of the power supply unit)
TimeTicks Stopwatch, Elapsed time = numerical value / 100 (in seconds)
numerical value = integer in the range 0-232-1
Timeout Time value in hundredths of a second
time value = integer in the range 0-232-1
Type field 4-digit hexadecimal number in accordance with ISO/IEC 8802-3
Counter Integer (0-232-1), when certain events occur, the value increases by 1.

UM Config EAGLE 233


Release 3.4 03/2020
Appendix
B.3 Management Information Base (MIB)

1 iso

3 org

6 dod

1 internet

2 mgmt 4 private 6 snmp V2

1 mib-2 1 enterprises 3 modules

1 system 248 hirschmann 10 Framework

2 interfaces 11 hm2Configuration 11 mpd

3 at 12 hm2Platform5 12 Target

4 ip 13 Notification

5 icmp 15 usm

6 tcp 16 vacm

7 udp

11 snmp

16 rmon

17 dot1dBridge

26 snmpDot3MauMGT
Figure 61: Tree structure of the Hirschmann MIB

A description of the MIB can be found on the product CD provided with the device.

234 UM Config EAGLE


Release 3.4 03/2020
Appendix
B.4 List of RFCs

B.4 List of RFCs

RFC 768 UDP


RFC 791 IP
RFC 792 ICMP
RFC 793 TCP
RFC 826 ARP
RFC 1157 SNMPv1
RFC 1155 SMIv1
RFC 1191 Path MTU Discovery
RFC 1212 Concise MIB Definitions
RFC 1213 MIB2
RFC 1493 Dot1d
RFC 1643 Ethernet-like -MIB
RFC 1757 RMON
RFC 1812 Requirements for IP Version 4 Routers
RFC 1867 Form-Based File Upload in HTML
RFC 1901 Community based SNMP v2
RFC 1905 Protocol Operations for SNMP v2
RFC 1906 Transport Mappings for SNMP v2
RFC 1945 HTTP/1.0
RFC 2068 HTTP/1.1 protocol as updated by draft-ietf-http-v11-spec-rev-03
RFC 2233 The Interfaces Group MIB using SMI v2
RFC 2246 The TLS Protocol, Version 1.0
RFC 2328 OSPF v2
RFC 2346 AES Ciphersuites for Transport Layer Security
RFC 2365 Administratively Scoped IP Multicast
RFC 2578 SMIv2
RFC 2579 Textual Conventions for SMI v2
RFC 2580 Conformance statements for SMI v2
RFC 2618 RADIUS Authentication Client MIB
RFC 2620 RADIUS Accounting MIB
RFC 2663 IP Network Address Translator (NAT) Terminology and Considerations
RFC 2674 Dot1p/Q
RFC 2818 HTTP over TLS
RFC 2851 Internet Addresses MIB
RFC 2863 The Interfaces Group MIB
RFC 2865 RADIUS Client
RFC 3022 Traditional IP Network Address Translator
RFC 3164 The BSD Syslog Protocol
RFC 3410 Introduction and Applicability Statements for Internet Standard Management
Framework
RFC 3411 An Architecture for Describing Simple Network Management Protocol (SNMP)
Management Frameworks
RFC 3412 Message Processing and Dispatching for the Simple Network Management
Protocol (SNMP)

UM Config EAGLE 235


Release 3.4 03/2020
Appendix
B.4 List of RFCs

RFC 3413 Simple Network Management Protocol (SNMP) Applications


RFC 3414 User-based Security Model (USM) for version 3 of the Simple Network
Management Protocol (SNMPv3)
RFC 3415 View-based Access Control Model (VACM) for the Simple Network Management
Protocol (SNMP)
RFC 3418 Management Information Base (MIB)
for the Simple Network Management Protocol (SNMP)
RFC 3584 Coexistence between Version 1, Version 2, and Version 3 of the Internet-
standard Network Management Framework
RFC 3768 VRRP
RFC 4022 Management Information Base for the Transmission Control Protocol (TCP)
RFC 4113 Management Information Base for the User Datagram Protocol (UDP)
RFC 4188 Definitions of Managed Objects for Bridges
RFC 4251 SSH protocol architecture
RFC 4252 SSH authentication protocol
RFC 4253 SSH transport layer protocol
RFC 4254 SSH connection protocol
RFC 4293 Management Information Base for the Internet Protocol (IP)
RFC 4318 Definitions of Managed Objects for Bridges with Rapid Spanning Tree Protocol
RFC 4363 Definitions of Managed Objects for Bridges with Traffic Classes, Multicast
Filtering, and Virtual LAN Extensions
RFC 4836 Definitions of Managed Objects for IEEE 802.3 Medium Attachment Units
(MAUs)
RFC 5905 NTPv4

236 UM Config EAGLE


Release 3.4 03/2020
Appendix
B.5 Underlying IEEE Standards

B.5 Underlying IEEE Standards

IEEE 802.1AB Station and Media Access Control Connectivity Discovery


IEEE 802.1D MAC Bridges (switching function)
IEEE 802.1Q Virtual LANs (VLANs, MRP, Spanning Tree)
IEEE 802.3 Ethernet
IEEE 802.3ac VLAN Tagging
IEEE 802.3x Flow Control
IEEE 802.3af Power over Ethernet

UM Config EAGLE 237


Release 3.4 03/2020
Appendix
B.6 Underlying ANSI Norms

B.6 Underlying ANSI Norms

ANSI/TIA-1057 Link Layer Discovery Protocol for Media Endpoint Devices, April 2006

238 UM Config EAGLE


Release 3.4 03/2020
Appendix
B.7 Technical Data

B.7 Technical Data

Switching
MTU (max. length of packets) 1518 Bytes

Routing/Switching
MTU (max. length of over-long 1500
packets) on router interfaces
Number of loopback interfaces 8
Max. number of Secondary IP 1
addresses (Multinetting)
Max. number of static routing entries 256

Firewall
Max. number of L3 firewall rules 2048

NAT
Max. number of 1:1 NAT rules 255
Max. number of Destination NAT rules 255
Max. number of Double NAT rules 255
Max. number of Masquerading NAT 128
rules
Max. number of Connection Tracking 7768
entries

UM Config EAGLE 239


Release 3.4 03/2020
Appendix
B.8 Copyright of integrated Software

B.8 Copyright of integrated Software

The product contains, among other things, Open Source Software files developed by third parties
and licensed under an Open Source Software license.

You can find the license terms in the Graphical User Interface in the Help > Licenses dialog.

240 UM Config EAGLE


Release 3.4 03/2020
Appendix
B.9 Abbreviations used

B.9 Abbreviations used

ACA Name of the external memory


BOOTP Bootstrap Protocol
CLI Command Line Interface
DHCP Dynamic Host Configuration Protocol
GUI Graphical User Interface
HTTP Hypertext Transfer Protocol
HTTPS Hypertext Transfer Protocol Secure
ICMP Internet Control Message Protocol
IEEE Institute of Electrical and Electronics Engineers
IGMP Internet Group Management Protocol
IP Internet Protocol
LED Light Emitting Diode
LLDP Link Layer Discovery Protocol
MAC Media Access Control
MIB Management Information Base
NMS Network Management System
NTP Network Time Protocol
PC Personal Computer
RFC Request For Comment
RM Redundancy Manager
SCP Secure Copy
SFP Small Form-factor Pluggable
SFTP SSH File Transfer Protocol
SNMP Simple Network Management Protocol
TCP Transmission Control Protocol
TP Twisted Pair
UDP User Datagram Protocol
URL Uniform Resource Locator
UTC Coordinated Universal Time

UM Config EAGLE 241


Release 3.4 03/2020
Index

C Index

0-9
1to1 NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 146

A
ABR . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 172, 175
Access roles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 52
Access security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 90
Address Resolution Protocol . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 127
Adjacency . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 176
Advertisement . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 166
Advertisement interval . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 167
Alarm . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 199
Alarm messages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 197
APNIC . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37
Area Border Router . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 172, 175
ARIN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37
ARP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40, 127, 128
ASBR . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 171, 175
Authentication . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66
Authentication list . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47
Automatic configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 91
Autonomous System Area Border Router . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 175
Autonomous System Boundary Router . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 171

B
Backbone Area . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 173
Backup Designated Router . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 177, 178
Backup router . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 166
BDR . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 177
Broadcast . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 126

C
CA . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66
Certificate . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66
Certification authority (CA) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66
CIDR . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40, 129, 170
Classless inter domain routing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40
Classless Inter-Domain Routing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 129, 170
Closed circuit . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 207
Command Line Interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
Command tree . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
Confidentiality . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64
Configuration modifications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 197

242 UM Config EAGLE


Release 3.4 03/2020
Index

D
Data traffic . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 101
Daylight saving time . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 115
Deep Packet Inspection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 109
Default gateway . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 165, 166
Denial of Service . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 101
Denial of service . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 108
Designated Router . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 177, 178
Destination NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 148
Destination table . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 197
Device status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 201
DHCP server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 114
Distance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 138
DoS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 101, 108
Double NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 151
DPI . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 109
DR . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 177

E
Event log . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 220

F
FAQ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 248
First installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37

G
Gateway . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38, 42
Generic object classes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 232
Global Config mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20, 21

H
Hardware reset . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 197
Hello . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 176
HiDiscovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37
HiView . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 46
Host address . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38

I
IANA . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37
IEEE MAC Adresse . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 215
IKE . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66
Importance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 139
Industrial HiVision . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9
Instantiation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 232
Integrity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64
Interface tracking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 155, 158, 159
Interface tracking object . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 156
Internal router . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 175
Internet Key Exchange . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66
Internet key exchange protocol . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66
Internet Protocol Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64
IP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 127
IP address . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37, 42, 165
IP address owner . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 166
IP Masquerading . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 150
IPsec . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64, 66
ISO/OSI layer model . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40
ISO/OSI reference model . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 126

UM Config EAGLE 243


Release 3.4 03/2020
Index

L
LACNIC . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38
LDAP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47
Link Aggregation interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 155
Link down delay . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 156
Link monitoring . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 201, 207
Link State Advertisement . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 175
Link State Database . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 178
Link up delay . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 156
Load sharing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 138
Logical tracking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 155, 157, 160, 162
Login page . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
LSA . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 175, 178
LSD . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 178

M
MAC address . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 166
MAC address filter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 121
MAC destination address . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40
Masquerading NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 150
Master router . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 166
Memory (RAM) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 73
Message . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 197
Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 91
Multicast . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 126
Multicast address . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 177
Multinetting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 129

N
NAPT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 150
NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 145
NAT (1
1 NAT) 146
NAT (Double NAT) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 151
NAT (Masquerading NAT) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 150
Netmask . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38, 42
Network Address Port Translation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 150
Network Address Translation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 145
Network plan . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 125
Network Time Protocol . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 113
Non-volatile memory (NVM) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 73
Not So Stubby Area . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 173
NSSA . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 173
NTP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 113
NVM (non-volatile memory) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 73

O
Object classes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 232
Object description . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 232
Object ID . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 232
Open Shortest Path First . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 170
OpenSSH-Suite . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14
OpenSSL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66
Operand . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 160, 163
Operation monitoring . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 207
Operators . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 157
OSI reference model . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 126
OSPF . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 125, 170

244 UM Config EAGLE


Release 3.4 03/2020
Index

P
Packet filter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 101, 103
Password . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15, 17
Ping response . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 156
Ping tracking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 139, 155, 156
Polling . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 197
Port forwarding . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 148
Port-based router interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 131
Pre-shared key . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66
Privileged Exec mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
Proxy ARP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 128
PuTTY . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13

R
RADIUS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47
RAM (memory) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 73
Redistributing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 173
Redistribution . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 171
Redundant static route . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 137
Reference clock . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 117
Reference time source . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 114
Relay contact . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 207
Remote diagnostics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 207
Report . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 217
RFC . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 235
RIPE NCC . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38
Route Summarization . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 172
Route tracking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 139
Router . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38
Router ID . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 177
Router priority . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 177
Routing table . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 132, 139

UM Config EAGLE 245


Release 3.4 03/2020
Index

S
Secure shell . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13, 14
Segmentation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 197
Serial interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13, 16
Service . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 217
Service Shell deactivation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33
Setting the time . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 114
SFP module . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 214
Shortest Path First . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 179
Signal contact . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 207
Signal runtime . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 117
Skew time . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 167
SNMP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 197
SNMP trap . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 197, 199
Software version . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 84
SPF . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 179
SSH . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13, 14
Starting the graphical user interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
Static route tracking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 139
Static routes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 125
Static routing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 155
Store-and-forward . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 121
Stub Area . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 173
Subidentifier . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 232
Subnet . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 42
System requirements (Graphical User Interface) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
System time . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 117

T
Tab Completion . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29
Technical questions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 248
Tracking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 139
Tracking (VRRP) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 155
Traffic flow confidentiality . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64
Training courses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 248
Transmission reliability . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 197
Trap . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 197, 199
Trap destination table . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 197
Tunnel mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 65

U
Update . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35
User Exec mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
User name . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15, 17

246 UM Config EAGLE


Release 3.4 03/2020
Index

V
Variable Length Subnet Mask . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 170
virtual link . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 174
Virtual MAC address . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 166
Virtual router . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 166
Virtual router ID . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 166
Virtual router IP address . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 167
Virtual router MAC address . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 167
VLAN router interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 155
VLSM . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 170
VPN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64
VRID . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 166, 167
VRRP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 155, 165
VRRP priority . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 166
VRRP router . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 166
VRRP Tracking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 155
VT100 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17

X
X.509 rsa . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66

UM Config EAGLE 247


Release 3.4 03/2020
Further support

D Further support

Technical questions

For technical questions, please contact any Hirschmann dealer in your area or Hirschmann directly.

You find the addresses of our partners on the Internet at [Link].

A list of local telephone numbers and email addresses for technical support directly from
Hirschmann is available at [Link].

This site also includes a free of charge knowledge base and a software download section.

Technical Documents

The current manuals and operating instructions for Hirschmann products are available at
[Link].

Hirschmann Competence Center

The Hirschmann Competence Center is ahead of its competitors on three counts with its complete
range of innovative services:
 Consulting incorporates comprehensive technical advice, from system evaluation through
network planning to project planning.
 Training offers you an introduction to the basics, product briefing and user training with
certification.
You find the training courses on technology and products currently available at
[Link].
 Support ranges from the first installation through the standby service to maintenance concepts.

With the Hirschmann Competence Center, you decided against making any compromises. Our
client-customized package leaves you free to choose the service components you want to use.

248 UM Config EAGLE


Release 3.4 03/2020
Readers’ Comments

E Readers’ Comments

What is your opinion of this manual? We are constantly striving to provide as comprehensive a
description of our product as possible, as well as important information to assist you in the operation
of this product. Your comments and suggestions help us to further improve the quality of our
documentation.

Your assessment of this manual:

Very Good Good Satisfactory Mediocre Poor


Precise description O O O O O
Readability O O O O O
Understandability O O O O O
Examples O O O O O
Structure O O O O O
Comprehensive O O O O O
Graphics O O O O O
Drawings O O O O O
Tables O O O O O

Did you discover any errors in this manual?


If so, on what page?

Suggestions for improvement and additional information:

UM Config EAGLE 249


Release 3.4 03/2020
Readers’ Comments

General comments:

Sender:

Company / Department:

Name / Telephone number:

Street:

Zip code / City:

E-mail:

Date / Signature:

Dear User,

Please fill out and return this page


 as a fax to the number +49 (0)7127/14-1600 or
 per mail to
Hirschmann Automation and Control GmbH
Department 01RD-NT
Stuttgarter Str. 45-51
72654 Neckartenzlingen
Germany

250 UM Config EAGLE


Release 3.4 03/2020
Readers’ Comments

UM Config EAGLE 251


Release 3.4 03/2020

You might also like