![Intel 480T Скачать руководство пользователя страница 265](http://html1.mh-extra.com/html/intel/480t/480t_user-manual_2073446265.webp)
C H A P T E R 1 4
Access Policies
263
Applying Access Profiles
Once the access profile is defined, apply it to one or more routing
protocols or VLANs. When an access profile is applied to a protocol
function (for example, the export of RIP routes) or a VLAN, this
forms an access policy. A profile can be used by multiple routing
protocol functions or VLANs, but a protocol function or VLAN can
use only one access profile.
Routing Access Policies for RIP
If the RIP protocol is being used, the switch can be configured to
use an access profile to determine any of the following:
•
Trusted Neighbor
— Use an access profile to determine trusted
RIP router neighbors for the VLAN on the switch running RIP. To
configure a trusted neighbor policy, use the following command:
config rip vlan [<name> | all] trusted-gateway
[<access_profile> | none]
•
Import Filter
— Use an access profile to determine which RIP
routes are accepted as valid routes. This policy can be combined
with the trusted neighbor policy to accept selected routes only
from a set of trusted neighbors. To configure an import filter
policy, use the following command:
config rip vlan [<name> | all] import-filter
[<access_profile> | none]
•
Export Filter
— Use an access profile to determine which RIP
routes are advertised into a particular VLAN, using the following
command:
config rip vlan [<name> | all] export-filter
[<access_profile> | none]
Examples
In the example shown in Figure 29, a switch is configured with two
VLANs,
Engsvrs
and
Backbone
. The RIP protocol is used to
communicate with other routers on the network. The administrator
wants to allow all internal access to the VLANs on the switch, but
no access to the router that connects to the Internet. The remote
router that connects to the Internet has a local interface connected to
the corporate backbone. The IP address of the local interface
connected to the corporate backbone is 10.0.0.10/24.
Содержание 480T
Страница 16: ...14 P R E F A C E...
Страница 88: ...86 C H A P T E R 4 Configuring Switch Ports...
Страница 112: ...110 C H A P T E R 5 Virtual LANs VLANs...
Страница 152: ...150 C H A P T E R 8 Quality of Service QoS...
Страница 166: ...164 C H A P T E R 9 Enterprise Standby Router Protocol...
Страница 198: ...196 C H A P T E R 1 0 IP Unicast Routing...
Страница 228: ...226 C H A P T E R 1 1 RIP and OSPF...
Страница 254: ...252 C H A P T E R 1 3 IPX Routing...
Страница 274: ...272 C H A P T E R 1 4 Access Policies...
Страница 296: ...294 C H A P T E R 1 6 Using Web Device Manager...
Страница 320: ...318 A P P E N D I X A...
Страница 328: ...326 A P P E N D I X B...
Страница 346: ...344 A P P E N D I X C...
Страница 358: ...356 I N D E X...
Страница 366: ...364 I N D E X...