Additional Features
Media Access Control (MAC) Security
5-10
SpectraComm IP T1 Router Card
076R200-000
Installation and Operation Manual
Issue 13
When a SCIP unit has Spanning tree enabled, and when
e0
and
s0
(or
s1
) are not in the
forwarding state, MACL violation traps are suppressed. All violations will still be filtered and
optionally logged to the MACL violation log, but no trap will be sent. Violation traps from
SCIP-B
e0
will be sent since its interfaces are both in the forwarding state. But SCIP-B
e0
will
not receive MACs from the local site because those will be blocked by SCIP-D.
Additionally, if MAC filtering is being used with Spanning Tree as in the above diagram, it is
recommended to have all MACLs defined with the same set of MAC addresses. This is because a
network failure could happen at any point in the diagram, resulting in some filtered interfaces
receiving all MACs. For example, if SCIP-A
e0
becomes unusable (cable problem, external
etherswitch problem, etc.), SCIP-D
e0
will unblock and SCIP-A
s0
will now see both local
MACs and remote MACs.
For ease of use, a single batch script file defining all MAC addresses for the above diagram can be
downloaded and run for all four MACLs shown above. This means each SCIP has its own MAC
address included in the MACL. This takes up an extra entry space in the MACL but is otherwise
harmless. Comments can be added to the script file to help identify the equipment and IP address
associated with the MAC address. Comment syntax in SCIP batch script files are as follows:
# This is a comment line
Note
The
#
sign must be the first character in the line and be followed by at least one space.
Figure 5-6
MAC Filtering and Spanning Tree
T1 (LAN-X)
LOCAL SITE
REMOTE SITE
MACL
FILTER
SCIP
"B"
e0
LOCAL
HOST
LOCAL
HOST
LOCAL
HOST
LOCAL
HOST
LOCAL
HOST
LOCAL
HOST
s0
SCIP
"A"
e0
MACL
FILTER
s0
MACL
FILTER
SCIP
"D"
e0
s0
SCIP
"C"
e0
MACL
FILTER
s0
x
x
BLOCKING
Содержание SpectraComm IP T1
Страница 119: ......
Страница 120: ...The Best Connections in the Business...