
Static Virtual LANs (VLANs)
Special VLAN Types
N o t e
The Secure Management VLAN must be a static, port-based VLAN with a
manually configured IP address and subnet mask. (The switch does not allow
the Management VLAN to acquire IP addressing through DHCP/Bootp.)
Links with Ports Belonging to the Management VLAN and other VLANs
Links Between Ports on a Hub and Ports belonging to the Management
VLAN
Links
Not
Belonging to the Management VLAN
Links to Other Devices
Hub Y
Switch A
Hub X
Switch B
Server
Switch C
Management Workstations
• Switches “A”, “B”, and
“C” are connected by
ports belonging to the
management VLAN.
• Hub “X” is connected
to a switch port that
belongs to the
management VLAN. As
a result, the devices
connected to Hub X are
included in the
management VLAN.
• Other devices
connected to the
switches through ports
that are not in the
management VLAN are
excluded from
management traffic.
Figure 2-27. Example of Potential Security Breaches
In figure 2-28, Workstation 1 has management access to all three switches
through the Management VLAN, while the PCs do not. This is because config
uring a switch to recognize a Management VLAN automatically excludes
attempts to send management traffic from any other VLAN.
2-45
Summary of Contents for 6400cl
Page 2: ......
Page 84: ...Static Virtual LANs VLANs VLAN Restrictions This page is intentionally unused 2 54 ...
Page 104: ...GVRP GVRP Operating Notes This page intentionally unused 3 20 ...
Page 274: ...Switch Meshing Operating Notes for Switch Meshing This page is intentionally unused 7 28 ...
Page 662: ... This page is intentionally unused 20 Index ...
Page 663: ......