SmartSwitch Router User Reference Manual
277
Chapter 18: Security Configuration Guide
Configuring Layer-2 Static Entry Filters
Static entry filters allow or force traffic to go to a set of destination ports based on a
frame's source MAC address, destination MAC address, or both source and destination
MAC addresses in flow bridging mode. Static entries are always configured and applied
at the input port. You can set the following static entry filters:
•
Source static entry, which specifies that any frame coming from source MAC address
will be allowed or disallowed to go to a set of ports
•
Destination static entry, which specifies that any frame destined to a specific
destination MAC address will be allowed, disallowed, or forced to go to a set of ports
•
Flow static entry, which specifies that any frame coming from a specific source MAC
address that is destined to specific destination MAC address will be allowed,
disallowed, or forced to go to a set of ports
To configure Layer-2 static entry filters, enter the following commands in Configure
mode:
Configuring Layer-2 Secure Port Filters
Secure port filters block access to a specified port. You can use a secure port filter by itself
to secure unused ports. Secure port filters can be configured as source or destination port
filters. A secure port filter applied to a source port forces all incoming packets to be
dropped on a port. A secure port filter applied to a destination port prevents packets from
going out a certain port.
You can combine secure port filters with static entries in the following ways:
•
Combine a source secure port filter with a source static entry to drop all received traffic
but allow any frame coming from specific source MAC address to go through
•
Combine a source secure port filter with a flow static entry to drop all received traffic
but allow any frame coming from a specific source MAC address that is destined to
specific destination MAC address to go through
•
Combine a destination secure port with a destination static entry to drop all received
traffic but allow any frame destined to specific destination MAC address go through
Configure a source static
entry filter.
filters add static-entry name
<name>
restriction allow|disallow|force source-
mac
<MACaddr>
vlan
<VLAN-num>
in-port-
list
<port-list>
out-port-list
<port-list>
Configure a destination static
entry filter.
filters add static-entry name
<name>
restriction allow|disallow|force dest-
mac
<MACaddr>
vlan
<VLAN-num>
in-port-
list
<port-list>
out-port-list
<port-list>
Summary of Contents for SmartSwitch Router
Page 1: ...SmartSwitch Router User Reference Manual 9032578 04...
Page 12: ...Notice 12 SmartSwitch Router User Reference Manual...
Page 28: ...Preface 28 SmartSwitch Router User Reference Manual...
Page 68: ...Chapter 3 Bridging Configuration Guide 68 SmartSwitch Router User Reference Manual...
Page 74: ...Chapter 4 SmartTRUNK Configuration Guide 74 SmartSwitch Router User Reference Manual...
Page 84: ...Chapter 5 DHCP Configuration Guide 84 SmartSwitch Router User Reference Manual...
Page 108: ...Chapter 7 VRRP Configuration Guide 108 SmartSwitch Router User Reference Manual...
Page 207: ...SmartSwitch Router User Reference Manual 207 Chapter 12 Multicast Routing Configuration Guide...
Page 208: ...Chapter 12 Multicast Routing Configuration Guide 208 SmartSwitch Router User Reference Manual...
Page 254: ...Chapter 16 IPX Routing Configuration Guide 254 SmartSwitch Router User Reference Manual...
Page 282: ...Chapter 18 Security Configuration Guide 282 SmartSwitch Router User Reference Manual...
Page 294: ...Chapter 19 QoS Configuration Guide 294 SmartSwitch Router User Reference Manual...
Page 298: ...Chapter 20 Performance Monitoring Guide 298 SmartSwitch Router User Reference Manual...
Page 338: ...Chapter 22 WAN Configuration Guide 338 SmartSwitch Router User Reference Manual...