Example 4, Securing Sensitive Information According to Subnet

2.The VLAN Classification Configuration screen is used to configure the switch to detect and classify the incoming RIP broadcast frames on Port 25 to the Null VLAN. Since the Null VLAN is not assigned to any port, the frame is dropped (not transmitted out any port). The VLAN Classification Configuration screen is set as follows:

VID: 99

Classification: Dest UDP Port

IP UDP Port: 520

Port 520 is a well known port number used by RIP.

12.15EXAMPLE 4, SECURING SENSITIVE INFORMATION ACCORDING TO SUBNET

The ABC Company wants to confine the sensitive information being transmitted by their Finance Department to its users only.

In this example, illustrated in Figure 12-17, the users in the Finance Department are members of the Finance VLAN and are also on subnet 28 as shown in bold type.

Figure 12-17 Example 4, Securing Traffic to One Subnet

Finance Department

User Subnet Class B Address:

123.123.28.1 123.123.28.2 123.123.28.3 123.123.28.4 123.123.28.5

Engineering Department

User Subnet Class B Address:

123.123.50.1

123.123.50.2

123.123.50.3

123.123.50.4

123.123.50.5

S1

Port 25

Finance

 

Server

 

 

123.123.28.25

 

 

Other Users

 

 

123.123.xx.xx

 

 

30691_74

VLAN Operation and Network Applications 12-33

Page 365
Image 365
Enterasys Networks 2H253, 2E253, 2H252, 2H258 manual Finance Department