
VLAN Configuration Summary
10-2
802.1Q VLAN Configuration
Creating a Secure Management VLAN
By
default
at
startup,
there
is
one
VLAN
configured
on
the
SecureStack
C3
device.
It
is
VLAN
ID
1,
the
DEFAULT
VLAN.
The
default
community
name,
which
determines
remote
access
for
SNMP
management,
is
set
to
“public”
with
read
‐
write
access.
If
the
SecureStack
C3
device
is
to
be
configured
for
multiple
VLANs,
it
may
be
desirable
to
configure
a
management
‐
only
VLAN.
This
allows
a
station
connected
to
the
management
VLAN
to
manage
the
device.
It
also
makes
management
secure
by
preventing
configuration
via
ports
assigned
to
other
VLANs.
To
create
a
secure
management
VLAN,
you
must:
The
commands
used
to
create
a
secure
management
VLAN
are
listed
in
Table 10
‐
1
.
This
example
assumes
the
management
station
is
attached
to
ge.1.1
and
wants
untagged
frames.
The
process
described
here
would
be
repeated
on
every
device
that
is
connected
in
the
network
to
ensure
that
each
device
has
a
secure
management
VLAN.
Step
Task
Refer to page...
1.
Create a new VLAN.
10-5
2.
Set the PVID for the desired switch port to the VLAN created in Step 1.
10-9
3.
Add the desired switch port to the egress list for the VLAN created in
Step 1.
10-15
4.
Assign host status to the VLAN.
10-18
5.
Set a private community name and access policy.
8-14
Table 10-1
Command Set for Creating a Secure Management VLAN
To do this...
Use these commands...
Create a new VLAN and confirm settings.
set vlan create 2
(“
set vlan
” on page 10-5)
(Optional)
show vlan 2
(“
show vlan
” on page 10-3)
Set the PVID to the new VLAN.
set port vlan ge.1.1 2
(“
set port vlan
” on page 10-9)
Add the port to the new VLAN’s egress list.
set vlan egress 2 ge.1.1 untagged
(“
set vlan egress
” on
page 10-15)
Remove the port from the default VLAN’s
egress list.
clear vlan egress 1 ge.1.1
(“
clear vlan egress
” on
page 10-15)
Assign host status to the VLAN.
set host vlan 2
(
“set host vlan” on page 10-18
)
Set a private community name and access
policy and confirm settings.
set snmp community private
(“
set snmp community
” on
page 8-14)
(Optional)
show snmp community
(“
show snmp
community
” on page 8-13)
Содержание SECURESTACK C3
Страница 2: ......
Страница 34: ...xxxii...
Страница 40: ...Getting Help xxxviii About This Guide...
Страница 126: ...clear license 4 6 Activating Licensed Features...
Страница 132: ...set port inlinepower 5 6 Configuring System Power and PoE...
Страница 228: ...clear port protected name 7 60 Port Configuration...
Страница 270: ...clear snmp interface 8 42 SNMP Configuration...
Страница 396: ...clear port txq 12 10 Port Priority Configuration...
Страница 414: ...ip igmp robustness 13 18 IGMP Configuration...
Страница 542: ...clear arpinspection statistics 17 32 DHCP Snooping and Dynamic ARP Inspection...
Страница 546: ...Enabling Router Configuration Modes 18 4 Preparing for Router Mode...
Страница 640: ...traceroute ipv6 21 10 IPv6 Management...
Страница 698: ...show ipv6 dhcp binding 24 20 DHCPv6 Configuration...
Страница 746: ...show ipv6 ospf virtual link 25 48 OSPFv3 Configuration...
Страница 834: ...ip access group 26 88 Authentication and Authorization Configuration...
Страница 848: ...TACACS Configuration clear tacacs interface 27 14...
Страница 866: ...sFlow Configuration show sflow agent 28 18...
Страница 872: ...Index 4...