Commissioning an industrial switch on site comes down to three checks: can you reach the console, did you set a management IP, and did you save the running config. Most on-site failures are not hardware faults — they are a mis-set management subnet or a change that was never saved or backed up. Follow the checklist below in the order field engineers actually work, and you will avoid the ten common mistakes that turn a rollout into a truck roll.
Reach the console first: match the RJ45 console pinout and baud rate (9600 or 115200) before you blame the cable.
Change the default management IP and password, then put management on its own VLAN so the Web UI stays reachable from the uplink.
Save after every change (running-config to startup-config) and export a backup before any firmware upgrade.
A managed network switch ships ready to configure, but only if you arrive prepared. Three items decide whether the first five minutes go smoothly.
1. Console port type. Industrial switches mostly use an RJ45-shaped console port, but the pinout follows the vendor's own wiring. Read the pinout first, then find the matching cable — a wrong cable simply will not translate.
2. Laptop serial port. Modern laptops have no native serial port, so bring a USB-to-serial adapter and install its driver in advance. Hunting for a driver on site wastes the most productive hour of the day.
3. Factory management address and account. Most models ship on 192.168.1.x or a 10.x segment with the account admin. Confirm the exact values before you configure, not after you are standing in the cabinet.
Note: Some models use a baud rate of 9600, others 115200. If you connect and see garbled text, do not suspect the cable first — switch the baud rate and try again.
When the console will not behave, the cause is almost always one of four things. Match the symptom to the fix before you swap hardware.
| Symptom | Likely cause | Fix |
|---|---|---|
| Serial tool cannot open the port | Driver missing / port occupied | Reinstall the driver; close software holding the port |
| All text is garbled | Wrong baud rate | Switch between 9600 and 115200 |
| Connected but keys get no response | Flow control enabled | Disable RTS/CTS hardware flow control |
| Limited rights after login | Stuck in user view | Use enable / system-view to elevate |
Tip: After you enter system view, change the default management address and password first. A default 192.168.1.1 that collides with the site network means the Web UI will never log in, no matter what you try next.The console is used once; daily operations run through the Web UI. Before you open the browser, set the management VLAN and address on the command line: keep the management address on a separate VLAN, never mixed with the business VLAN. If the uplink is a Trunk, add the management VLAN to the allowed tag list — otherwise the Web UI from the upper segment simply cannot reach this switch.
Note: On a layer 2 switch the management address is globally unique — you cannot assign an IP per port. Only a layer 3 model gives each VLAN interface its own IP. Field engineers often configure a layer 2 box like a layer 3 and only realize the mistake when pings fail. Vendors such as Rayin ship preset configuration templates and a Web interface that make commissioning faster.
A switch runs two configurations: running-config lives in memory and is active now; startup-config lives in flash and loads on the next power-up. Many engineers change settings without saving — on a power loss the running config vanishes and the old startup loads, which is the same as configuring nothing. Saving after each segment is the baseline habit.
But saving only protects against power loss, not against a mistyped command or a failed unit. The real safety net is export: pull startup-config out through TFTP or HTTP to a PC or network management server. When a config breaks, push the backup file back instead of retyping from memory on site.
| Step | Action | Done |
|---|---|---|
| 1 | Confirm console pinout / baud rate; reach system view | ☐ |
| 2 | Change default management IP and password to avoid subnet clash | ☐ |
| 3 | Keep management VLAN separate; allow its tag on the uplink Trunk | ☐ |
| 4 | Negotiate port speed/duplex to the peer; reserve uplink aggregation | ☐ |
| 5 | Save after every change segment | ☐ |
| 6 | Export the backup file locally, named with date and location | ☐ |
| 7 | Back up before firmware upgrade; grayscale one unit first | ☐ |
Warning: Never skip the pre-upgrade backup. A failed firmware push with no rollback file means a site visit. Grayscale one unit to confirm Web, port negotiation, and ring stability, then push the rest.
Console shows all garbled characters — what should I do? Confirm the serial tool and driver are working, then switch the baud rate between 9600 and 115200. Industrial switches use both rates, and garbled text is almost always the wrong baud rate, not a bad cable.
Why did my configuration disappear after a reboot? You edited running-config in memory but never ran save to write startup-config in flash. After a power loss or reboot the old startup loads, so every change is gone. Make it a habit to save after every change.
Can a layer 2 switch assign a management IP to each port? No. On a layer 2 switch the management address is globally unique and lives on one VLAN interface. To manage several subnets separately you need a layer 3 model that gives each VLAN interface its own IP.
Why keep the management VLAN separate from the business VLAN? A separate management VLAN keeps control traffic off the user plane and stops a busy business VLAN from starving Web or SSH access. If the uplink is a Trunk, remember to add the management VLAN to the allowed tag list, or the Web UI stays unreachable from above.
Do I really need a backup before a firmware upgrade? Yes. The pre-upgrade backup is your only rollback path. Grayscale one unit first to confirm Web, port negotiation, and ring stability, then push the rest. Without that file a failed push means a truck roll.
A clean industrial switch rollout follows an order, not luck: console login, change the management address and password, set the management VLAN, negotiate ports to the peer, save after every change, and finally export the backup. The backup you take before a firmware upgrade is often the only way back when something breaks.
About the author: Sara — Sara is a Customer Manager at Rayin with over 10 years of experience in the communications field. In her free time, she enjoys badminton and swimming.
About Rayin: Shenzhen Rayin Technology Co., Ltd. — Company Profile