Chapter 20: Security Configuration Guide

Layer-4 Bridging and Filtering

Layer-4 bridging is the SSR’s ability to use layer-3/4 information to perform filtering or QoS during bridging. As described in “Layer-2 Security Filters” above, you can configure ports to filter traffic using MAC addresses. Layer-4 bridging adds the ability to use IP addresses, layer-4 protocol type, and port number to filter traffic in a bridged network. Layer-4 bridging allows you to apply security filters on a “flat” network, where the client and server may reside on the same subnet.

Note: Ports that are included in a layer-4 bridging VLAN must reside on updated SSR hardware. Please refer to Appendix A for details.

To illustrate this, the following diagram shows an SSR serving as a bridge for a consultant host, file server, and an engineering host, all of which reside on a single subnet.

 

 

 

SSR

 

 

 

 

et.1.1

et.1.2

et.1.3

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Consultant

File Server

Engineer

1.1.1.1/24

1.1.1.2/24

1.1.1.3/24

Figure 25. Sample VLAN for Layer-4 bridging

You may want to allow the consultant access to the file server for e-mail (SMTP) traffic, but not for Web (HTTP) traffic and allow e-mail, Web, and FTP traffic between the engineer and the file server. You can use Layer-4 bridging to set this up.

Setting up Layer-4 bridging consists of the following steps:

Creating a port-based VLAN

Placing the ports on the same VLAN

Enabling Layer-4 Bridging on the VLAN

Creating an ACL that specifies the selection criteria

Applying an ACL to a port

286

SmartSwitch Router User Reference Manual

Page 312
Image 312
Cabletron Systems 9032578-05 manual Layer-4 Bridging and Filtering, Sample Vlan for Layer-4 bridging