Example 6, Locking a MAC Address to a Port Using Classification Rules
VLAN Operation and Network Applications 12-37
The objective here is to configure S1 so that when it receives a frame on Port 1 from MAC address
00.00.00.00.00.0A, the frame is classified into the Red VLAN. When S1 receives a frame on Port
1 from a MAC address other than 00.00.00.00.00.0A, the frame is associated with the Default
VLAN. To accomplish this, S1 is configured so that the frames originating from the Red VLAN
are eligible to be forwarded out the desired ports. The frames associated with the Default VLAN
are not forwarded to any ports and are discarded by S1. Frames received on Port 2 will be handled
in the same way except that S1 will only allow frames with the MAC address 00.00.00.00.00.0B
frames to be forwarded out the desired ports and discard all other frames received on Port 2 that
are not MAC address 00.00.00.00.00.0B frames.
This is accomplished using the screens as follows:
The Static VLAN Configuration screen to create one VLAN, which will be named Red VLAN
in this example.
The Static VLAN Egress Configuration screen to set Ports 1 and 2 to transmit only untagged
frames and add them to the VLAN Egress list of the switch.
The Static VLAN Egress Configuration screen to remove all ports from the Default VLAN List.
The VLAN Port Configuration screen to associate Ports 1 and 2 with Red VLAN and enable the
port to receive all frames.
The VLAN Classification Configuration screen to create two src MAC address classification
rules and assign them to the appropriate new VLAN.
The Protocol Ports Configuration screen to assign the new classification rules to Ports 1 and 2
and add the new VLANs to their port VLAN forwarding list.
Switch 1
To secure Port 1, you would configure Switch 1 as follows:
1. Create the static Red VLAN and add it to the module VLAN list by entering the following
settings using the Static VLAN Configuration screen:
VLAN ID: 2
VLAN NAME: Red