docs.na.id.au

Purpose

09 — Siemens Scalance XR326-2C PoE Switch Configuration

Last updated: 2026-09-05 | Status: ✅ Analyzed and documented
Model: Siemens Scalance XR326-2C (Scalance X Series)
Hostname: Siemens PoE Switch
Location: Study (per config comment)
Config source: RunningCLI(1).txt

Purpose

Documentation of the Siemens Scalance XR326-2C edge switch that provides access layer connectivity for LAN, IoT, and guest devices. This switch works in combination with the Aruba JL253A (documented in 02-switch-configuration.md) to provide comprehensive network coverage.

Switch Identity

PropertyValue
ModelSiemens Scalance XR326-2C
FamilyScalance X Series (managed edge switch)
HostnameSiemens PoE Switch
Contact PersonAdrian
LocationStudy (per system config)
Management IP192.168.28.241/24 (VLAN 28)

VLAN Configuration

VLAN IDNameNative PortsTrunked on UplinksPurpose
1DEFAULT_VLANPort 6 onlyEdge VLAN, DHCP client on router
27GuestPorts 2-4, 13-180/25, 0/26Guest WiFi clients
29HASS (Home Automation)Ports 2-4, 7, 13-18, 23-240/25, 0/26IoT devices, smart home
30LAN (User Traffic)Ports 2-5, 7-240/13, 0/23, 0/25, 0/26Main user network
31DMZPort 13 only0/13 (only)External services, AdGuard
101Edge VLANPorts 6Management loopback interface
28ManagementPorts 1-5, 7, 13-19, 23-240/25, 0/26Switch/firewall management

Port-to-VLAN Mapping (per-port configuration)

Port-by-Port VLAN Membership

PortAliasPVID (Native)Allowed VLANsNotes
ge 0/1Omada OC20028All + port-specific tagsAP management, tagged in DMZ/VLAN 31
ge 0/2–530VLANs 27, 29, 30User access ports
ge 0/6101 (self)VLANs 28, 101 onlyEdge VLAN interface for management
ge 0/13Clacks30All VLANs + taggedUplink to Clarks router - primary uplink
ge 0/14Errol (Passage)30VLANs 29, 30Passage lighting control
ge 0/15Laolith (Music Room)30VLANs 29, 30, taggedMusic room - LIFX devices
ge 0/16Asphalt (Family Room AP)30All VLANsAdditional AP connection
ge 0/17Ninereeds (Media Room)30VLANs 29, 30, taggedMedia room devices
ge 0/18Death30VLANs 27, 29, 30User device or spare
ge 0/19–2230All VLANsAvailable for expansion
ge 0/23Leonard30All VLANs + taggedRouter uplink port 2 - secondary connection
ge 0/24Ruby30VLANs 27, 29, 30Ruby device (AdGuard?)
ext-e 0/2528All VLANs + trunkedUplink 1 (SFP+), redundancy link to router/firewall
ext-e 0/26Aruba Switch28All VLANs + trunkedConnected to Aruba JL253A switch - ring redundancy uplink

The Siemens switch uses a redundant uplink configuration:

PortPurposeSpeedNotes
ge 0/13 (Clacks)Primary LAN uplink1GbpsVLAN-aware trunk to all zones
ge 0/23 (Leonard)Secondary/router port 21GbpsAlternative uplink, redundant path
PortPurposeSpeedNotes
ext-e 0/25SFP+ Redundant uplink10GbpsRing redundancy link 1
ext-e 0/26 (Aruba Switch)Uplink to Aruba JL253A10GbpsRing redundancy link 2, VLAN trunk

Ring Redundancy (Ring topology for resilience)

The switch is configured for MRP (Media Redundancy Protocol) ring redundancy:

ring ports extreme-ethernet 0/25 extreme-ethernet 0/26
standby wait-for-partner
no standby force-master

This creates a resilient ring topology where if one uplink fails, traffic automatically reroutes through the other path. The SFP+ links (0/25, 0/26) provide high-speed failover to the Aruba switch.

NTP/Time Configuration

SettingValueNotes
System timezoneUTC +08:00 (Australia Perth)Matches router timezone
NTP Server192.168.28.1Internal management server
SNTP ClientBroadcast modeListening on VLAN interface
Sinec offset+00:00Additional timezone adjustment

Security Configuration

SSH & Web Access

ServiceStatusPortNotes
SSH ServerEnabled22Disabled and re-enabled (password protected)
HTTPS ServerEnabled443TLS v1.2 minimum required
HTTP ServerEnabled80Unencrypted web access for config mgmt
TelnetDisabledLegacy protocol disabled
TFTP ServerEnabled (IPv4)69Config/package backup/restore
SFTP ServerEnabled (IPv4)22Secure config transfer

SNMP Configuration

SettingValueNotes
Agent versionAll (v1, v2c, v3)Legacy and secure access supported
V1/V2c securityRead-only for read communityV2c has no encryption
SNMPv3 userstemplateMD5, templateSHAMD5/SHA auth available
CommunitiesSIMATICNETRD (public/read), public (readonly)Needs rotation!
GroupsSIMATICNETRD, SIMATICNETWRRead/write access groups

Brute Force Prevention

SettingValueNotes
User-specific attempts12Lock after 12 failed logins
IP-specific attempts10Additional IP-based protection
Trigger interval5 secondsMonitor frequency
Auto-reset timer12 minutesUnlock period before relock

PoE Status

PortPoE StatusNotes
All ports (ge 0/1–24)No PoE ActivePassive PoE injector required for some devices
ext-e 0/25No PoESFP+ uplink to router/firewall
ext-e 0/26 (Aruba Switch)No PoEConnects to Aruba JL253A (PoE handled by that switch)

[!note] This switch relies on external PoE injectors or a separate PoE switch for APs and other powered devices. The configuration explicitly disables poem active on all ports.

DHCP Snooping & IGMP

SettingValueNotes
DHCP SnoopingDisabled (no dhcp snooping)May need enabling for security
IGMP SnoopingEnabled v3no ip igmp vlan-snooping removed
IGMP Port Purge300 secondsClear stale multicast entries
IGMP Versionv3Querier disabled (edge switch)
SettingValueNotes
Flap Count15 timesBefore triggering action
Flap Interval60 secondsWindow for counting flaps
ReactionNotify via emailAlert on link flap detection

Unknown Items Requiring Investigation ⚠️

1. Port 26 Alias “Aruba Switch” — Need Physical Verification 🔍

Current config: alias Aruba Switch on ext-e 0/26 Connected to: Aruba JL253A switch (per 02-switch-configuration.md)

Investigation needed:

Risk: Low — just naming confusion unless misconfigured for wrong device.

Current config: alias Omada OC200 VLAN assignment: PVID 28 (Management) + tagged in DMZ/VLAN 31

Possible explanation:

Investigation needed:

Risk: Low — but needs documentation for future reference.

3. Unused Ports 0/19–0/22 — Available but Not Configured 🔍

Current config: All disabled, VLAN 30 native Status: No specific alias or purpose documented

Possible explanations:

Recommendation: Document intended use or consider disabling VLAN membership if truly not needed.

4. DHCP Snooping Disabled ⚠️

no dhcp snooping

Security concern: Without DHCP snooping, rogue DHCP servers could inject addresses on the network.

Recommended actions:

  1. Enable DHCP snooping: ip dhcp snooping
  2. Configure trusted ports (uplinks to router/firewall)
  3. Restrict which ports can serve DHCP leases

Risk: Medium — vulnerable to DHCP spoofing attacks if not enabled.

5. SNMP Community Strings Need Rotation 🔒

Current community strings: public (read-only) Recommended: Replace with strong, unique secrets stored in password manager.

6. Event Notifications Email — Need Valid Addresses 📧

event config cold-warmstart email
event config linkchange email
...

Many event configurations specify “email” but no actual addresses are configured. This may:

Investigation needed: Verify which events should trigger alerts and configure valid SMTP settings if needed.

7. Ring Redundancy Configuration Status 🔁

ring ports extreme-ethernet 0/25 extreme-ethernet 0/26
standby wait-for-partner
no standby force-master

The ring is configured but the config shows no ring-redundancy (disabled) and no mrp-interconnection.

Clarification needed:

8. QoS Configuration — Trust Mode Applied ⚡

All ports configured with qos-trust-mode ... cos-dscp Interpretation: Trusts incoming DSCP markings for QoS treatment. This is appropriate if upstream devices (router, APs) properly mark traffic classes.

Summary of Known vs Unknown Items

ItemStatusInvestigation Priority
Port ge 0/1 (Omada OC200)✅ Known device aliasVerify TP-Link integration
Port ext-e 0/26 (Aruba Switch)✅ Connected to JL253AConfirm ring redundancy state
Ports ge 0/19–22⚠️ Unused sparesLow priority - optional cleanup
DHCP snooping⚠️ DisabledMedium priority - security concern
SNMP communities⚠️ Weak stringsMedium priority - rotate soon
Event email config⚠️ PlaceholdersLow priority - verify/complete

Recommendations Summary

  1. Enable DHCP snooping to prevent rogue DHCP attacks
  2. Rotate SNMP community strings for security hardening
  3. Verify ring redundancy operational state (active vs configured but disabled)
  4. Document device on port ge 0/1 (TP-Link integration?)
  5. Consider enabling PoE if APs need power (currently no PoE active)

Change log


Source Disclaimer