![Intel 480T User Manual Download Page 270](http://html1.mh-extra.com/html/intel/480t/480t_user-manual_2073446270.webp)
268
C H A P T E R 1 4
Access Policies
In addition, suppose the administrator wants to preclude users on
the VLAN
Engsvrs
from seeing any multicast streams that are
generated by the VLAN
Sales
across the backbone. The additional
configuration of the switch labeled Engsvrs is as follows:
create access-profile nosales ipaddress
config access-profile nosales mode deny
config access-profile nosales add 10.2.1.0/24
config dvmrp vlan backbone import-filter nosales
Routing Access Policies for PIM-DM
Because PIM-DM leverages the unicast routing capability that is
already present in the switch, the access policy capabilities are, by
nature, different. If the PIM-DM protocol is used for routing IP
multicast traffic, the switch can be configured to use an access
profile to determine any of the following:
•
Trusted Neighbor
— Use an access profile to determine trusted
PIM-DM router neighbors for the VLAN on the switch running
PIM-DM. To configure a trusted neighbor policy, use the
following command:
config pim vlan [<name> | all] trusted-gateway
[<access_profile> | none]
Example
Using PIM-DM, the unicast access policies can be used to restrict
multicast traffic. In this example, a network similar to the example
used in the previous RIP example is also running PIM-DM. The
network administrator wants to disallow Internet access for
multicast traffic to users on the VLAN
Engsvrs
. This is
accomplished by preventing the learning of routes that originate
from the switch labeled Internet by way of PIM-DM on the switch
labeled Engsvrs.
To configure the switch labeled Engsvrs, the commands would be
as follows:
create access-profile nointernet ipaddress
config access-profile nointernet mode deny
config access-profile nointernet add 10.0.0.10/32
config pim vlan backbone trusted-gateway nointernet
Summary of Contents for 480T
Page 16: ...14 P R E F A C E...
Page 88: ...86 C H A P T E R 4 Configuring Switch Ports...
Page 112: ...110 C H A P T E R 5 Virtual LANs VLANs...
Page 152: ...150 C H A P T E R 8 Quality of Service QoS...
Page 166: ...164 C H A P T E R 9 Enterprise Standby Router Protocol...
Page 198: ...196 C H A P T E R 1 0 IP Unicast Routing...
Page 228: ...226 C H A P T E R 1 1 RIP and OSPF...
Page 254: ...252 C H A P T E R 1 3 IPX Routing...
Page 274: ...272 C H A P T E R 1 4 Access Policies...
Page 296: ...294 C H A P T E R 1 6 Using Web Device Manager...
Page 320: ...318 A P P E N D I X A...
Page 328: ...326 A P P E N D I X B...
Page 346: ...344 A P P E N D I X C...
Page 358: ...356 I N D E X...
Page 366: ...364 I N D E X...