ZyXEL ES3500-24HP V4.00(AADE.6)C0 Release Note/Manual Supplement
Date: Nov. 28, 2016
This document describes the features in the ES3500-24HP product for its 4.00(AADE.6)C0 release.
Support Platforms
ZyXEL ES3500-24HP V4.00(AADE.6)C0 supports models: ZyXEL ES3500-24HP
Version
OS Version: V4.00(AADE.6) | 11/28/2016
BootBase Version: V1.00 | 04/12/2012
Default Bootbase Setting
Setting | Value |
---|---|
OS Version | V4.00(AADE.6) | 11/28/2016 15:22:14 |
Bootbase Version | V1.00 | 04/12/2012 17:14:19 |
Serial Number | XXXXXXXXXXXXXXX |
Vendor Name | ZyXEL |
Product Model | ES3500-24HP |
OS Code Model | ES3500 |
OS ROM address | bd0a0000 |
System Type | 8 |
First MAC Address | 0019CB000001 |
Last MAC Address | 0019CB00001D |
MAC Address Quantity | 29 |
Default Country Code | FF |
Boot Module Debug Flag | FF |
RomFile Version | E8 |
RomFile Checksum | 7d15 |
OS Checksum | 54bc |
SNMP MIB level & OID | 060102030405060708091011121314151617181920 |
Main Feature Bits | C0 |
Other Feature Bits | 02 3E 00 00 00 00 00 00-00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00-00 13 00 00 00 00 |
Main Features
- IEEE 802.1ag: Connective Fault Management, CFM
- IEEE 802.1AB: Link Layer Discovery Protocol, LLDP
- IEEE 802.1ax: Link Aggregation Control Protocol, LACP
- IEEE 802.1D: transparent bridging
- IEEE 802.1X: Standard for port-based Network Access Control, PNAC
- IEEE 802.1W: Rapid Spanning Tree Protocol, RSTP
- IEEE 802.1s: Multiple Spanning Tree Protocol, MSTP
- IEEE 802.1Q: tag-based VLAN
- IEEE 802.1Q: VLAN port isolation
- IEEE 802.3/3u: 10BASE5 10 Mbit/s (1.25 MB/s) over thick coax. / 100BASE-TX, 100BASE-T4, 100BASE-FX Fast Ethernet at 100 Mbit/s (12.5 MB/s) w/autonegotiation
- IEEE 802.3AD: 802.1QinQ, Double Tagging for VLAN Stacking
- IEEE 802.3ah: OAM
- IEEE 802.3at: PoE Plus
- IEEE 802.3x: flow control for full duplex
- RFC 1213: MIB II
- RFC 1493: Bridge MIB (Management Information Base)
- RFC 1643: Ethernet MIB
- RFC 1757: Four group of RMON
- RFC 1981: Path MTU Discovery for IPv6
- RFC 2674: VLAN MIB
- RFC 2698: Two Rate Three Color Marker, trTCM
- RFC 3046: DHCP Relay Agent Information Option (DHCP option 82)
- RFC 3176: sFlow
- RFC 4022: MIB for the Transmission Control Protocol
- RFC 4113: MIB for the User Datagram Protocol
- RFC 4293: MIB for IP
- RFC 4292: IP Forwarding Table MIB
- RFC 4541: IGMPv2/IGMPv3 and MLD snooping
- IPv6 Management/Host
- DHCPv6: client and relay
- ICMPv6
- MLD snooping proxy
- IPv6 address stateless auto-configuration: host
- Support IPv6 in classifier
- MAC address learning
- MAC aging time
- MAC filtering
- MAC forward
- MAC freeze
- MAC search
- GVRP (GARP VLAN Registration Protocol)
- Port-based VLAN
- VLAN search
- Selective QinQ
- VLAN Translation (Egress/Ingress)
- Protocol-based VLAN
- IP subnet based VLAN
- Configurable multicast VLAN
- Support MVR up to 5 multicast VLANs
- Guest VLAN
- Private VLAN
- Independent IGMP snooping and MVR setting.
- Support IGMP snooping fast leave
- Support IGMP snooping statistics
- IGMP throttling
- Support display IGMP snooping client
- CLI/MIB for IGMP report-proxy mode
- DHCP relay/snooping
- LACP algorithm of Source-MAC/Source-IP/Destination-MAC/Destination-IP
- Extend to 8 trunk groups (per group with max 8 port number)
- Integrated multicast services.
- Static multicast forward
- 512 multicasting group
- MRSTP
- Configurable RSTP/MRSTP oper edge
- SNMPv3
- IP source Guard(Static binding, ARP inspection)
- AAA by RADIUS / TACACS+
- Multiple TACACS+ servers
- Multiple RADIUS servers
- PPPoE-IA
- PPPoE-IA option 82
- L2PT (layer 2 protocol tunneling)
- Loop guard
- CPU protection (ARP/IGMP/BPDU, inactive port/inactive reason/rate-limitation)
- Errdisable recovery for err-disabled port/reason
- Smart isolation
- Filtering/Mirroring by L2/L3/L4 rules
- Bandwidth control by L2/L3/L4 rules
- Management through console, telnet, SNMP or web management
- Firmware upgrade by FTP/Web/TFTP
- Configuration download by FTP/Web/TFTP
- Configuration saving and retrieving
- Remote configuration merge by TFTP
- SSHv1/SSHv2/SSL
- Daylight saving time support
- Support concurrent telnet sessions up to 9
- Password encryption
- Syslog
- Synchronize system log and syslog
- SNMP trap group
- Intrusion lock
- User access right
- cluster with dual image & config
- CLI for dump memory usage
- CLI for RMON configuration
- 24 10/100 Base-T interface,
- 4 Gigabyte dual-personality port (10/100/1000BASE-T & Dual speed 100/1000M SFP)
- Cable diagnostics
- Overheat detection (Hardware Monitor)
- Support PoE/Voltage/Temperature /Fan Speed Fault Trap
- Support show PoE per port power consumption information, and classification
- Local console
- Fan-speed monitoring
- 16K layer 2 MAC addresses table
- PWM Fan module
- Support show transceiver DDMI information
- LED indications for link status
- 9K jumbo frame
- Dual RAS
- Egress traffic shaping per port at 64Kbps step
- DHCP Option 82 Profile
- Support ZON
- SSL DHparam length from 512 bits to 2048 bits
Bug Fix
- Fix RomPager CVE-2014-9222
- eITS#150901113: [DHCP] DHCP snooping entries from trust ports should not be learned into DHCP snooping binding table.
- eITS# 160301288: [MGMT] Management loss after perform 9 successful or failed telnet/SSH login attempts.
- eITS# 150601410: [LLDP] When receiving LLDP packet and enter show running configuration continuously, switch will crash. [LLDP] When receiving non-standard LLDP packet, it causes switch crash.
- eITS#151201303: [SNMP] Correct the SNMP GETBULK produces results when max-repetition is more than 55.
- eITS 150500055: [System] Unexpected power loss cause switch reboot then switch cannot boot successfully.
Known Issue
- Storm control has ±1% error ratio. When storm control rate set to 0, the first broadcast packet will pass.
- Port Counter: When packet size over 1520 also count to broadcast/multicast/uni-cast RX packet counter.
- Policy rules will be overwritten by vlan-mapping, trtcm, private-vlan.
- Selective Q-in-Q, VLAN translation, subnet-based VLAN, protocol-based VLAN, mac-based VLAN will not follow VLAN tagged/untagged configuration. Packets always tag out.
- In classification mode, up to five ports that using 802.3at class-4 can be active. (The ES3500-24HP reserve 36W per port (class-4) and the total power budget is 180W). Select consumption mode if you want more ports to be active.
- Switch counts tagged packet that is less or equal to 64 bytes into error packet.
Limitation of Settings
Setting | Limit |
---|---|
VLAN 1Q static entry | 1024 |
Static MAC forwarding entry | 256 |
MAC filtering entry | 256 |
Cluster member | 24 |
IGMP filtering entry | 256 |
IGMP MVR group address entry | 256 |
IGMP MVR VLAN entry | 5 |
Protocol based VLAN entries per port | 7 |
Syslog server entry | 4 |
IP souce guard entry | 128 |
IP subnet based VLAN entry | 16 |
Vlan-stacking Selective QinQ entry | 128 |
Vlan-mapping entry | 128 |
Private-vlan entry | 8 |
TRTCM profile entry | 4 |
Link Aggregation entry | 8 |
Firmware Upgrade
The ES3500-24HP uses FTP to upgrade firmware in run-time through its built-in FTP server. You can use any FTP client (for example, ftp.exe in Windows) to upgrade ES3500-24HP. The upgrade procedure is as follows:
Upgrade ES3500-24HP FW:
C:\> ftp <ES3500-24HP IP address> User : <Enter> Password: 1234 230 Logged in ftp> put 400AADE4C0.bin ras-0 ftp> bye
Where
- User name : just press <Enter>
- Password : the management password, 1234 by default
- 400AADE4C0.BIN : the name of firmware file you want to upgrade
- ras-0 : the internal firmware name in ES3500-24HP. (store at first flash)
- ras-1 : the internal firmware name in ES3500-24HP. (store at second flash)