1. BitStorm 2400 Overview
1-16
December 2002
2400-A2-GB20-10
MAC Layer Filtering
MAC layer filtering provides network security in the absence of VLANs. The MAC
address-based privacy filter feature of the StormPort modem can provide strict
privacy to segregate each end user’s traffic, but does not provide an effective
means of forming work groups that can share traffic.
In the privacy filter system, each modem is programmed with a list of MAC
addresses that represent valid gateways for backhaul. The BitStorm 2400 units will
only forward traffic downstream that has a source MAC address from this list. The
CPE modems will only forward traffic upstream that has a destination MAC
address from this list.
Because this system is MAC-address based, it is not practical to maintain a list of
end-user MAC addresses on the CPE modem side that are part of a work group
(allowed to communicate to end-user MAC addresses on the CPE modem side of
another port). This privacy prevents peer-to-peer communication, eliminating, for
example, Microsoft Network Neighborhood browsing.
Multiple gateways are possible and each modem contains its own privacy filter
table. This allows the access service provider to provision each customer to a
choice of gateways. This is one method of providing a choice of ISP or ASP to
consumers on the same access network.
Summary of Contents for BitStorm 2400
Page 1: ...BitStorm 2400 User s Guide Document No 2400 A2 GB20 10 December 2002...
Page 10: ...About This Guide viii December 2002 2400 A2 GB20 10...
Page 42: ...3 Using the Asynchronous Terminal Interface 3 14 December 2002 2400 A2 GB20 10...
Page 70: ...4 Using the Web Interface 4 28 December 2002 2400 A2 GB20 10...
Page 86: ...C MIB Support C 12 December 2002 2400 A2 GB20 10...