OmniSwitch 6600 Family Network Configuration Guide April 2006 page 8-1
8 Defining VLAN Rules
VLAN rules are used to classify mobile port traffic for dynamic VLAN port assignment. Rules are defined
by specifying a port, MAC address, protocol, network address, user-defined, binding, or DHCP criteria to
capture certain types of network device traffic. It is also possible to define multiple rules for the same
VLAN. A mobile port is assigned to a VLAN if its traffic matches any one VLAN rule.
There is an additional method for dynamically assigning mobile ports to VLANs that involves enabling
VLAN mobile tagging. This method is similar to defining rules in that the feature is enabled on the VLAN
that is going to receive the mobile port tagged traffic. The difference, however, is that tagged packets
received on mobile ports are classified by their 802.1Q VLAN ID tag and not by whether or not their
source MAC, network address, or protocol type matches VLAN rule criteria.
In This Chapter
This chapter contains information and procedures for defining VLAN rules through the Command Line
Interface (CLI). CLI commands are used in the configuration examples; for more details about the syntax
of commands, see the OmniSwitch CLI Reference Guide. Refer to Chapter 4, “Configuring VLANs,” and
Chapter 7, “Assigning Ports to VLANs,” for information about the VLAN mobile tagging feature.
Configuration procedures described in this chapter include:
Defining DHCP rules on page 8-12.
Defining binding rules to restrict access to specific network devices on page 8-14.
Defining MAC address rules on page 8-17.
Defining IP and IPX network address rules on page 8-18.
Defining protocol rules on page 8-20.
Defining user-defined (custom) rules on page 8-21.
Defining forwarding-only port rules on page 8-21.
Verifying the VLAN rule configuration on page 8-25.
For information about creating and managing VLANs, see Chapter4, “Configuring VLANs.”
For information about enabling port mobility and defining mobile port properties, see Chapter7, “Assign-
ing Ports to VLANs.”