Cabletron Systems SmartSwitch manual Port-to-Address Lock Examples, Example 2 Secure Ports

Models: SmartSwitch

1 338
Download 338 pages 45.77 Kb
Page 280
Image 280

Chapter 18: Security Configuration Guide

Destination static entry: Restrict "login multicasts" originating from the engineering segment (port et.1.1) from reaching the finance servers.

filters add static-entry name login-mcasts dest-mac 010000:334455 vlan 1 in-port-list et.1.1 out-port-list et.1.3 restriction disallow

or

filters add static-entry name login-mcasts dest-mac 010000:334455 vlan 1 in-port-list et.1.1 out-port-list et.1.2 restriction allow

Flow static entry: Restrict "login multicasts" originating from the consultant from reaching the finance servers.

filters add static-entry name consult-to-mcasts source-mac 001122:334455 dest-mac 010000:334455 vlan 1 in-port-list et.1.1 out-port-list et.1.3 restriction disallow

Port-to-Address Lock Examples

You have configured some filters for the consultant on port et.1.1 If the consultant plugs his laptop into a different port, he will bypass the filters. To lock him to port et.1.1, use the following command:

filters add port-address-lock name consultant source-mac 001122:334455 vlan 1 in-port-list et.1.1

Note: If the consultant’s MAC is detected on a different port, all of its traffic will be blocked.

Example 2 : Secure Ports

Source secure port: To block all engineers on port 1 from accessing all other ports, enter the following command:

filters add secure-port name engineers direction source vlan 1 in-port-list et.1.1

To allow ONLY the engineering manager access to the engineering servers, you must "punch" a hole through the secure-port wall. A "source static-entry" overrides a "source secure port".

filters add static-entry name eng-mgr source-mac 080060:123456 vlan 1 in-port-list et.1.1 out-port-list et.1.2 restriction allow

280

SmartSwitch Router User Reference Manual

Page 280
Image 280
Cabletron Systems SmartSwitch manual Port-to-Address Lock Examples, Example 2 Secure Ports