Allied Telesis Layer 3 Switches manual Protecting the user, Using private VLANs

Models: Layer 3 Switches

1 31
Download 31 pages 47.42 Kb
Page 18
Image 18
Products AT-8600 Series AT-8700XL Series Rapier i Series Rapier Series AT-8800 Series AT-8948
x900-48 Series
AT-9900 Series AT-9924Ts
x900-24 Series
Software Versions All

Protecting the user

Protecting the user

This section describes the following methods of protecting users from other users on the network:

z“Using private VLANs” on page 18. This feature isolates switch ports in a VLAN from other switch ports in the same VLAN.

z“Using local proxy ARP and MAC-forced forwarding” on page 19. These features force all traffic in a network to go via an access router.

z“Using IPsec to make VPNs” on page 24. This feature creates secure tunnels through an insecure network.

z“Protecting against worms” on page 25. These methods reduce the damage worms do to users of the network.

Using private VLANs

Private VLANs are an excellent way of preventing hosts on a subnet from attacking each other. Essentially, each switch port is isolated from other ports in the VLAN, but can access another network through an uplink port or uplink trunk group. All traffic between private ports is blocked, not just Layer 2 traffic.

 

uplink port

switch

 

hacker

legitimate

 

customer

Private VLANs are reasonably flexible. A private port can be a member of multiple private VLANs. However, a port cannot be a private port in some VLANs and a non-private port in others.

On AT-8600, AT-8700XL, Rapier i and AT-8800 Series switches running 2.9.1 or later, each private VLAN can have multiple uplink ports. This allows you to use private VLANs on

switches that are connected in a ring topology. Also, you can group private ports together on these switches, which allows the ports in a group to communicate with each other but not with other ports in the VLAN.

Note that ports are only isolated from ports on the same physical switch, not from ports on other switches reached through an uplink port.

Configuration 1. Create the VLAN, specifying that it is private.

2.Add the uplink port, or the ports in the uplink trunk group, to the VLAN. For a trunk group, the ports must already be trunked together, and you must specify all the ports in the trunk group. Note that on Rapier 48i and AT-8748XL switches, the uplink and private ports must be in the same switch instance. See the Switching chapter of the Software Reference for more information about switch instances.

3.Add the private ports to the VLAN.

Create A Secure Network With Allied Telesis Managed Layer 3 Switches

18

Page 18
Image 18
Allied Telesis Layer 3 Switches manual Protecting the user, Using private VLANs