Example 6, Locking a MAC Address to a Port Using Classification Rules
VLAN Operation and Network Applications 13-37
The frames received on Port 2 will be handled in the same way except that S1 will only allow
frames with the MAC address 00.00.00.00.00.0B frames to be forwarded out the desired ports and
discard all other frames received on Port 2 that are not MAC address 00.00.00.00.00.0B frames.
This is accomplished using the screens as follows:
The Static VLAN Configuration screen to create one VLAN, which will be named Red VLAN
in this example.
The Static VLAN Egress Configuration screen to set Ports 1 and 2 to transmit only untagged
frames and add them to the VLAN Egress list of the switch.
The Static VLAN Egress Configuration screen to remove all ports from the Default VLAN List.
The VLAN Port Configuration screen to associate Ports 1 and 2 with Red VLAN and enable the
port to receive all frames.
The VLAN Classification Configuration screen to create two src MAC address classification
rules and assign them to the appropriate new VLAN, and
The Protocol Ports Configuration screen to assign the new classification rules to Ports 1 and 2
and add the new VLANs to their port VLAN forwarding list.
Switch 1
To secure Port 1, you would configure Switch 1 as follows:
1. Create the static Red VLAN and add it to the module VLAN list by entering the following
settings using the Static VLAN Configuration screen:
VLAN ID: 2
VLAN NAME: Red
2. Assign Port 1 and 2 to the Red VLAN and set the ports to handle untagged frames as follows:
The Red VLAN is selected from the Static VLAN Configuration screen to display the Static
VLAN Egress Configuration screen.
The following are set using the Static VLAN Egress Configuration screen:
– Port 1, Egress: UNTAGGED
– Port 2, Egress: UNTAGGED
No other ports are assigned to the Red VLAN and the exiting ports are left in the default
setting of NO.