ETHERNET MANAGEMENT MODULE OVERVIEW
EMME USER’S GUIDE
Page 1-9
Eavesdrop prevention delivers a modified data portion (filled with a
random pattern of binary ones and zeros) of the Ethernet packet to all
ports except the port specified in the original packet’s destination MAC
address field. Effectively all ports, except the actual destination port,
receive meaningless information. There are two learned MAC addresses
per port.
Full security allows the network administrator to configure the ports, so
that “broadcast” and “multicast” packets have the data portion of the
packet modified with a random pattern of ones and zeroes. Therefore, the
ports set to this mode do not see these packet types. The default setting for
“Full security” is disabled. Enabling the “Full security” function modifies
the broadcast and multicast packets.
LANVIEW
SECURE
products support assignment of up to 32 MAC
addresses per LANVIEW
SECURE
chip. The addresses can be assigned to
one or divided among several ports on the chip.
For LANVIEW
SECURE
products, trunk ports are defined as 3 or more
MAC addresses but may not exceed 34 MAC addresses, on that port, in
order to secure it. A port with 35 or more addresses can never be secured.
Ports with 3 - 34 MAC addresses can be secured and will need the
addresses manually entered to secure the port. Non-LANVIEW
SECURE
ports can only be secured with 2 or less MAC addresses associated with
that port. Non-LANVIEW
SECURE
ports with three or more addresses can
never be secured.
LANVIEW
SECURE
is enabled upon locking a channel, module, or port.
When enabled, the first two addresses that are learned become the
expected address associated with that port on any LANVIEW
SECURE
module.