8-4
C
HAPTER
8: LAN
PLEX
® B
RIDGING
E
XTENSIONS
Enhanced
Network Security
In addition to allowing you to design and use packet filters to improve
network security (as described in Chapter 7), the LANplex 2500 system
allows you to use statically configured addresses as a form of network
security.
From the Administration Console or an SNMP manager, you can manually
assign an address to an Ethernet port. You have permanently tied this
address to the specified port unless you manually remove it. The address is
never aged and can never be learned on a different Ethernet port. If a
packet with a statically configured source address is received on a port that
differs from the address’s assigned port, the packet is discarded and a
management event is generated. The event can be used to expose the
imposter station.
You can also convert dynamic addresses to static addresses. It is often more
convenient to let the bridge first learn all of the addresses on your network
and then to convert these learned, or dynamic, addresses to static addresses
to improve your network security.
For information, see the section on bridging in the
LANplex® 2500
Administration Console User Guide
.
Summary of Contents for LANPLEX 2500
Page 1: ...LANPLEX 2500 OPERATION GUIDE Part No 801 00344 000 Published November 1996 Revision 03...
Page 14: ......
Page 18: ...1 4 CHAPTER 1 LANPLEX MANAGEMENT AND ADMINISTRATION OVERVIEW...
Page 78: ...III Chapter 9 FDDI Overview and Implementation Chapter 10 FDDI Networks FDDI TECHNOLOGY...
Page 97: ...IV Chapter 11 ATM Networks ATM TECHNOLOGY...
Page 116: ...V Appendix A SNMP MIB Support Appendix B Technical Support APPENDIXES...