Chapter 9: Security Configuration Guide
9 - 8
SSR User Reference Manual
Destination static entry: Restrict "login multicasts" originating from the engineering
segment (port et.1.1) from reaching the finance servers.
filters add static-entry name login-mcasts dest-mac
010000:334455 vlan 1 in-port-list et.1.1 out-port-list et.1.3
restriction disallow
or
filters add static-entry name login-mcasts dest-mac
010000:334455 vlan 1 in-port-list et.1.1 out-port-list et.1.2
restriction allow
Flow static entry: Restrict "login multicasts" originating from the consultant from
reaching the finance servers.
filters add static-entry name consult-to-mcasts source-mac
001122:334455 dest-mac 010000:334455 vlan 1 in-port-list et.1.1
out-port-list et.1.3 restriction disallow
Port-to-address Lock Examples:
You have configured some filters for the consultant on port et.1.1 If the consultant
plugs his laptop into a different port, he will bypass the filters. To lock him to port
et.1.1, use the following command:
filters add port-address-lock name consultant source-mac
001122:334455 vlan 1 in-port-list et.1.1
Note: If the consultant’s MAC is detected on a different port, all of its traffic will be
blocked.
Example 2 : Secure Ports
Source secure port: To block all engineers on port 1 from accessing all other ports,
enter the following command:
filters add secure-port name engineers direction source vlan 1
in-port-list et.1.1
To allow ONLY the engineering manager access to the engineering servers, you must
"punch" a hole through the secure-port wall. A "source static-entry" overrides a
"source secure port".
filters add static-entry name eng-mgr source-mac 080060:123456
vlan 1 in-port-list et.1.1 out-port-list et.1.2 restriction allow
Destination secure port: To block access to all file servers on all ports from port et.1.1
use the following command:
Summary of Contents for SmartSwitch 8-slot
Page 1: ...SmartSwitch Router User Reference Manual 9032578...
Page 2: ......
Page 6: ...Notice vi...
Page 10: ...About This Manual x SSR User Reference Manual...
Page 36: ...Chapter 1 SmartSwitch Router Product Overview 1 18 SSR User Reference Manual...
Page 60: ...Chapter 4 RIP Configuration Guide 4 6 SSR User Reference Manual...
Page 115: ...Chapter 7 Multicast Routing Configuration Guide SSR User Reference Manual 7 9...
Page 116: ...Chapter 7 Multicast Routing Configuration Guide 7 10 SSR User Reference Manual...
Page 142: ...Chapter 9 Security Configuration Guide 9 18 SSR User Reference Manual...