การแปลด้วย AI ของเนื้อหานี้พร้อมใช้งานแล้ว
แปลไปเป็น ไทย
QSS 4.4.2 build 20260511
2026-05-20
Applicable Models
- QSW-M7308R-4X
- QSW-M3224-24T
- QSW-M3212R-8S4T
- QSW-M3216R-8S8T
- QSW-IM3216R-8S8T
Important Notice
Privacy Agreement
- After updating the firmware to QSS (QSS Pro) 4.4.2, a Privacy Agreement window will appear upon first login. Please review and accept the agreement to continue.
DHCP Snooping / DAI with MC-LAG
- DHCP Snooping and Dynamic ARP Inspection (DAI) are not intended to be used simultaneously with MC-LAG. Enabling these features in an MC-LAG environment may result in unexpected traffic forwarding behavior.
Dashboard
- Dashboard default as closed since QSS v4.4.2
New Features
Support for Command Line Interface (CLI)
- This update introduces a Command-Line Interface, allowing users to configure and manage the switch directly through text-based commands. User can access the CLI via SSH port 22 or through the console.
DHCPv4 Snooping
- This update adds DHCPv4 Snooping, a security feature that monitors DHCP traffic to prevent unauthorized DHCP servers from distributing invalid IP addresses. By classifying ports as trusted or untrusted, it protect the network against attacks such as DHCP spoofing.
IP Source Guard (IPSG)
- This update adds IP Source Guard, a security feature that restricts IP traffic on untrusted ports by filtering packets based on the DHCP Snooping binding table. Only traffic with a matching source IP and MAC address is permitted, preventing IP spoofing attacks on the network.
Dynamic ARP Inspection (DAI)
- This update adds Dynamic ARP Inspection, a security feature that validates ARP packets against the DHCP Snooping binding table. It intercepts and discards ARP packets with invalid IP-to-MAC address bindings, protecting the network against ARP spoofing and man-in-the-middle attacks.
Support for Secure Shell (SSH)
- This update adds SSH access support, allowing administrators to securely manage the switch remotely via encrypted command-line sessions. User can SSH in via the standard port 22.
DHCP Auto Configuration
- This update adds DHCP Auto Configuration, allowing the switch to automatically download and apply its configuration file from a DHCP server during startup. This simplifies large-scale deployments by enabling centralized, zero-touch provisioning of switch settings.
IEEE 802.1X Port-Based Network Access Control
- This update adds 802.1X authentication, enabling port-based access control that requires users to authenticate before gaining network access. Working with a RADIUS server, it ensures only authorized devices can connect to the switch, enhancing network security.
Enhancement
Enhanced ADRA NDR Support
- Enhanced ADRA NDR integration with dedicated VLAN support for improved network detection and response functionality.
UI Enhancement
- Optimized the user interface with navigation style updates for improved clarity and consistency.
Fixed Issues
- Fixed an issue where opening the MC-LAG page could cause continuous loading and subsequent device reboot.
- Resolved intermittent ping loss in MC-LAG environments.
- Fixed an issue where changing the port speed could prevent the port from linking up.
- Fixed an issue where ACL rules could be configured beyond the supported limit of 255.
- Improved MC-LAG stability during prolonged operation.
- Fixed dashboard display issues for breakout port icons and VLAN status layout.
- Fixed an issue where a password change could succeed but the new password could not be used to log in.
รุ่นที่ใช้งานได้
- QSW-M7308R-4X
- QSW-M3224-24T
- QSW-M3212R-8S4T
- QSW-M3216R-8S8T
- QSW-IM3216R-8S8T
ประกาศสำคัญ
ข้อตกลงความเป็นส่วนตัว
- หลังจากอัปเดตเฟิร์มแวร์เป็น QSS (QSS Pro) เวอร์ชัน 4.4.2 แล้ว หน้าต่างข้อตกลงความเป็นส่วนตัวจะปรากฏขึ้นเมื่อเข้าสู่ระบบครั้งแรก โปรดตรวจสอบและยอมรับข้อตกลงเพื่อดำเนินการต่อ
DHCP Snooping / DAI ร่วมกับ MC-LAG
- ฟังก์ชัน DHCP Snooping และ Dynamic ARP Inspection (DAI) ไม่ได้ออกแบบมาให้ใช้งานพร้อมกันกับ MC-LAG การเปิดใช้งานฟังก์ชันเหล่านี้ในสภาพแวดล้อม MC-LAG อาจส่งผลให้พฤติกรรมการส่งต่อทราฟฟิกเปลี่ยนแปลงไปอย่างไม่คาดคิด
แดชบอร์ด
- แดชบอร์ดถูกตั้งค่าเริ่มต้นเป็นปิดตั้งแต่ QSS เวอร์ชัน 4.4.2
คุณสมบัติใหม่
รองรับการใช้งานผ่านอินเทอร์เฟซบรรทัดคำสั่ง (CLI)
- การอัปเดตนี้ได้เพิ่มส่วนต่อประสานบรรทัดคำสั่ง (Command-Line Interface หรือ CLI) ซึ่งช่วยให้ผู้ใช้สามารถกำหนดค่าและจัดการสวิตช์ได้โดยตรงผ่านคำสั่งแบบข้อความ ผู้ใช้สามารถเข้าถึง CLI ได้ผ่านพอร์ต SSH 22 หรือผ่านทางคอนโซล
การสอดแนม DHCPv4
- การอัปเดตนี้เพิ่มฟีเจอร์ DHCPv4 Snooping ซึ่งเป็นฟีเจอร์ด้านความปลอดภัยที่ตรวจสอบการรับส่งข้อมูล DHCP เพื่อป้องกันไม่ให้เซิร์ฟเวอร์ DHCP ที่ไม่ได้รับอนุญาตแจกจ่ายที่อยู่ IP ที่ไม่ถูกต้อง โดยการจำแนกพอร์ตเป็นพอร์ตที่เชื่อถือได้หรือไม่น่าเชื่อถือ จะช่วยปกป้องเครือข่ายจากการโจมตี เช่น การปลอมแปลง DHCP
IP Source Guard (IPSG)
- การอัปเดตนี้เพิ่ม IP Source Guard ซึ่งเป็นคุณสมบัติด้านความปลอดภัยที่จำกัดการรับส่งข้อมูล IP บนพอร์ตที่ไม่น่าเชื่อถือโดยการกรองแพ็กเก็ตตามตารางการผูกข้อมูล DHCP Snooping เฉพาะการรับส่งข้อมูลที่มีที่อยู่ IP ต้นทางและที่อยู่ MAC ที่ตรงกันเท่านั้นที่จะได้รับอนุญาต ป้องกันการโจมตีปลอมแปลง IP บนเครือข่าย
การตรวจสอบ ARP แบบไดนามิก (DAI)
- การอัปเดตนี้เพิ่ม Dynamic ARP Inspection ซึ่งเป็นคุณสมบัติด้านความปลอดภัยที่ตรวจสอบความถูกต้องของแพ็กเก็ต ARP กับตารางการผูก IP กับ MAC address ของ DHCP Snooping โดยจะดักจับและทิ้งแพ็กเก็ต ARP ที่มีการผูก IP กับ MAC address ที่ไม่ถูกต้อง เพื่อป้องกันเครือข่ายจากการปลอมแปลง ARP และการโจมตีแบบ Man-in-the-Middle
รองรับ Secure Shell (SSH)
- การอัปเดตนี้เพิ่มการรองรับการเข้าถึง SSH ทำให้ผู้ดูแลระบบสามารถจัดการสวิตช์จากระยะไกลได้อย่างปลอดภัยผ่านเซสชันบรรทัดคำสั่งที่เข้ารหัส ผู้ใช้สามารถ SSH เข้ามาได้ผ่านพอร์ตมาตรฐาน 22
การกำหนดค่าอัตโนมัติของ DHCP
- การอัปเดตนี้เพิ่มฟังก์ชันการกำหนดค่า DHCP อัตโนมัติ ทำให้สวิตช์สามารถดาวน์โหลดและใช้ไฟล์การกำหนดค่าจากเซิร์ฟเวอร์ DHCP โดยอัตโนมัติระหว่างการเริ่มต้นระบบ ซึ่งช่วยลดความซับซ้อนในการติดตั้งใช้งานขนาดใหญ่โดยการเปิดใช้งานการกำหนดค่าสวิตช์แบบรวมศูนย์และไม่ต้องทำอะไรเลย
การควบคุมการเข้าถึงเครือข่ายแบบพอร์ตตามมาตรฐาน IEEE 802.1X
- การอัปเดตนี้เพิ่มการตรวจสอบสิทธิ์ 802.1X ซึ่งช่วยให้สามารถควบคุมการเข้าถึงตามพอร์ตได้ โดยกำหนดให้ผู้ใช้ต้องตรวจสอบสิทธิ์ก่อนจึงจะสามารถเข้าถึงเครือข่ายได้ เมื่อทำงานร่วมกับเซิร์ฟเวอร์ RADIUS จะช่วยให้มั่นใจได้ว่าเฉพาะอุปกรณ์ที่ได้รับอนุญาตเท่านั้นที่จะสามารถเชื่อมต่อกับสวิตช์ได้ ซึ่งช่วยเพิ่มความปลอดภัยของเครือข่าย
การปรับปรุง
การสนับสนุน ADRA NDR ที่ได้รับการปรับปรุง
- ปรับปรุงการทำงานร่วมกับ ADRA NDR ให้ดียิ่งขึ้น พร้อมรองรับ VLAN เฉพาะ เพื่อเพิ่มประสิทธิภาพในการตรวจจับและตอบสนองเครือข่าย
การปรับปรุง UI
- ปรับปรุงส่วนติดต่อผู้ใช้ด้วยการอัปเดตรูปแบบการนำทางเพื่อให้มีความชัดเจนและสอดคล้องกันมากขึ้น
แก้ไขปัญหาแล้ว
- แก้ไขปัญหาที่การเปิดหน้า MC-LAG อาจทำให้เกิดการโหลดอย่างต่อเนื่องและส่งผลให้เครื่องรีบูต
- แก้ไขปัญหาการสูญเสียสัญญาณ ping เป็นระยะๆ ในสภาพแวดล้อม MC-LAG
- แก้ไขปัญหาที่การเปลี่ยนความเร็วพอร์ตอาจทำให้พอร์ตเชื่อมต่อไม่ได้
- แก้ไขปัญหาที่สามารถกำหนดค่ากฎ ACL เกินขีดจำกัดที่รองรับไว้ที่ 255 ได้
- ปรับปรุงเสถียรภาพของ MC-LAG ในระหว่างการใช้งานต่อเนื่องเป็นเวลานาน
- แก้ไขปัญหาการแสดงผลบนแดชบอร์ดสำหรับไอคอนพอร์ตเชื่อมต่อและรูปแบบสถานะ VLAN
- แก้ไขปัญหาที่การเปลี่ยนรหัสผ่านสำเร็จ แต่ไม่สามารถใช้รหัสผ่านใหม่ในการเข้าสู่ระบบได้
Thank you for your feedback.