![Intel 480T Скачать руководство пользователя страница 270](http://html1.mh-extra.com/html/intel/480t/480t_user-manual_2073446270.webp)
268
C H A P T E R 1 4
Access Policies
In addition, suppose the administrator wants to preclude users on
the VLAN
Engsvrs
from seeing any multicast streams that are
generated by the VLAN
Sales
across the backbone. The additional
configuration of the switch labeled Engsvrs is as follows:
create access-profile nosales ipaddress
config access-profile nosales mode deny
config access-profile nosales add 10.2.1.0/24
config dvmrp vlan backbone import-filter nosales
Routing Access Policies for PIM-DM
Because PIM-DM leverages the unicast routing capability that is
already present in the switch, the access policy capabilities are, by
nature, different. If the PIM-DM protocol is used for routing IP
multicast traffic, the switch can be configured to use an access
profile to determine any of the following:
•
Trusted Neighbor
— Use an access profile to determine trusted
PIM-DM router neighbors for the VLAN on the switch running
PIM-DM. To configure a trusted neighbor policy, use the
following command:
config pim vlan [<name> | all] trusted-gateway
[<access_profile> | none]
Example
Using PIM-DM, the unicast access policies can be used to restrict
multicast traffic. In this example, a network similar to the example
used in the previous RIP example is also running PIM-DM. The
network administrator wants to disallow Internet access for
multicast traffic to users on the VLAN
Engsvrs
. This is
accomplished by preventing the learning of routes that originate
from the switch labeled Internet by way of PIM-DM on the switch
labeled Engsvrs.
To configure the switch labeled Engsvrs, the commands would be
as follows:
create access-profile nointernet ipaddress
config access-profile nointernet mode deny
config access-profile nointernet add 10.0.0.10/32
config pim vlan backbone trusted-gateway nointernet
Содержание 480T
Страница 16: ...14 P R E F A C E...
Страница 88: ...86 C H A P T E R 4 Configuring Switch Ports...
Страница 112: ...110 C H A P T E R 5 Virtual LANs VLANs...
Страница 152: ...150 C H A P T E R 8 Quality of Service QoS...
Страница 166: ...164 C H A P T E R 9 Enterprise Standby Router Protocol...
Страница 198: ...196 C H A P T E R 1 0 IP Unicast Routing...
Страница 228: ...226 C H A P T E R 1 1 RIP and OSPF...
Страница 254: ...252 C H A P T E R 1 3 IPX Routing...
Страница 274: ...272 C H A P T E R 1 4 Access Policies...
Страница 296: ...294 C H A P T E R 1 6 Using Web Device Manager...
Страница 320: ...318 A P P E N D I X A...
Страница 328: ...326 A P P E N D I X B...
Страница 346: ...344 A P P E N D I X C...
Страница 358: ...356 I N D E X...
Страница 366: ...364 I N D E X...