Cabletron Systems EMM-E6 manual Configuring Security

Page 92

Security

Configurable violation response

You can still choose to allow ports to remain enabled even after an unsecured address has attempted to access a locked port. If you choose not to disable a port which has experienced a violation, however, the port’s only response to an intruder will be to issue a trap after the first violation; all packets, regardless of source address, will be allowed to pass.

Forced non-secure status

With the enhanced version of LANVIEWSECURE, even ports on non-

LANVIEWSECURE MIMS can be forced to an unsecurable status (as long as they are currently unlocked).

Learned addresses reset

You can still use the Reset Learned Addresses option in the repeater-, board-, or port-level Security window to clear all learned and secured addresses out of the selected port(s) address table, and allow that port to begin learning (and securing) new addresses. Note that you cannot reset learned addresses on a locked port or on a port which is designated unsecurable.

Eavesdrop protection (scrambling), trunk port locking, continuous lock mode, and the floating address cache are not available for non-LANVIEWSECUREMIMs (A-channel MIMs and non-LANVIEWSECURERIC MIMs) or for any LANVIEWSECURE TPXMIM ports configured to operate on Channel A.

Configuring Security

Most Security parameters are set via the port-level Security window; these will apply to the configured port regardless of the level at which security is enabled.

To access the Port Security window:

1.In the Repeater Security window, click to select the interface for which you would like to configure port-level security.

2.Click mouse button 1 on ; the Channel X Port Security window, Figure 7-2, will appear.

7-6

Configuring Security

Image 92
Contents EMM-E6 Page Virus Disclaimer Restricted Rights Notice Contents Chapter Source Addressing Chapter SecurityChapter Front Panel Redundancy Appendix a EMM-E6 MIB StructureContents Using the EMM-E6 User’s Guide IntroductionUsing the EMM-E6 User’s Guide What’s not in the EMM-E6 User’s Guide UPSConventions Screen Displays Window ConventionsUsing the Mouse ButtonGetting Help EMM-E6 Firmware Year 2000 ComplianceUsing the EMM-E6 Hub View Using the Hub ViewNavigating Through the Hub View Hub View Front PanelUptime Date and TimeDevice Name Device LocationUsing the EMM-E6 Hub View EMM-E6 Ports Display Using the Mouse in a Hub View Module Brim PortsHub View Port Color Codes Port Display FormMonitoring Hub Performance Port Display Form Errors LoadTraffic CollisionsPort Type ProtocolsFrame Sizes Using the EMM-E6 Hub View Contact Checking Device Status and Updating Front Panel InfoName and Location Checking Network Status Chassis TypeName Active UsersChecking Module Status Module TypeChecking Port Status Link StatusStatus Media TypeViewing the IP Address Table Topology TypeLaunching the Global Find MAC Address Tool Checking StatisticsUsing the EMM-E6 Hub View Received Bytes Total PacketsAvg Packet Size Broadcast PacketsTotal Errors Alignment ErrorsCRC Errors OOW CollisionsRunt Frames Giant FramesViewing the Port Source Address List Protocols/Frames StatisticsUsing the EMM-E6 Hub View Setting the Polling Intervals Managing the HubContact Status Device General StatusConfiguring FNB Connections Device ConfigurationPort Operational State StatisticsConfiguring RIC MIM Connections To configure FNB connectivity for an individual port Setting a Port’s Trunk Type 15. Tpxmim Channel Selection WindowTo change a port’s topology status Enabling/Disabling MIM Ports Alarm Configuration Using Alarm Configuration From the command line stand-alone modeFrom the icon From the Hub ViewConfiguring Alarms CRCSetting Repeater Alarms BroadcastSetting and Changing Alarms Set Repeater Alarms WindowSetting Module and Port Alarms Setting Module AlarmsSet Module Alarms Window Set the Status to EnabledSetting Port Alarms Set Port Alarms WindowSet the Status to Enabled Alarm Configuration Setting Module and Port Alarms What is a Segmentation Trap? Link/Seg TrapsWhat is a Link Trap? Enabling and Disabling Link/Seg TrapsSpmarun r4hwtr IP address community name Configuring Link/Seg Traps for the Repeater Viewing and Configuring Link/Seg Traps for Hub ModulesModule Traps Window Viewing and Configuring Link/Seg Traps for Ports Port Traps WindowLink/Seg Traps Link/Seg Traps Enabling and Disabling Link/Seg Traps Setting Network Circuit Redundancy Repeater RedundancyConfiguring a Redundant Circuit Spmarun r4red IP address community nameChannel X Redundancy Window Add Circuit Address Window Repeater Redundancy Monitoring Redundancy To set the Poll IntervalSource Addressing Displaying the Source Address ListDisplaying the Source Address List Source Addressing Setting the Hash Type Setting the Aging TimeLocking Source Addresses Source Address Locking on Older Devices Configuring Source Address Traps Repeater-level Traps Module- and Port-level Traps Source Addressing Finding a Source Address Port Source Address Traps WindowClick on to exit the window Security What is LANVIEWSECURE? Spmarun r4sec IP address SU community nameTrunk port security New definitions for station and trunk portsSecure address assignment Newest Lanviewsecure Features Continuous learning modeConfigurable violation response Full or partial security against eavesdroppingForced non-secure status Learned addresses resetSecurity on Non-LANVIEWSECUREMIMs Configuring Security Security To assign secure addresses to a port Addresses Window Boards with Multiple Caches Add MAC Address WindowResetting Learned Addresses Tips for Successfully Implementing Eavesdropper ProtectionEnabling Security and Traps Security Repeater-level Security and Traps Channel X Security WindowModule-level Security and Traps Channel X Module Security Window Port-level Security and Traps Channel X Port Security WindowSecurity Setting Front Panel Redundancy Front Panel RedundancySetting Front Panel Redundancy Add Circuit Address Window Front Panel Redundancy Setting Front Panel Redundancy Ietf MIB Support EMM-E6 MIB StructureMIB Components Chassis MGRHost Services IP ServicesRepeater One, Repeater Two, and Repeater Three Ctron Use OnlyRmon Default Distributed LAN MonitorMIB Navigator Rmon HostBrief Word About MIB Components and Community Names EMM-E6 MIB Structure Index Index-2 Index-3 Index Index-4
Related manuals
Manual 64 pages 974 b