![Thinklogical TXL24 Скачать руководство пользователя страница 38](http://html1.mh-extra.com/html/thinklogical/txl24/txl24_product-manual_1107271038.webp)
Page 32
TLX24 Matrix Switch Product Manual
thinklogical
Rev. C, August, 2016
Restricted Switching
Restricted Switching provides multiple levels of security classification domains on the same
Matrix Switch.
Each destination must ensure that no unauthorized content is displayed or accessed,
therefore, every input and output must be prioritized. Priorities can range from 1 to the total number of
ports in the Matrix Switch. An output can connect to an input with a priority greater than, or equal to, its
own. Thus, a priority level of 1 on an output can connect to any input (priority 1, 2,
3…).
The user must provide a table defining the priorities for each input and output of the switch matrix. This
table is in the form of a comma separated value (csv) file. This file contains the values in three columns:
Port Direction
(i=input, o=output),
Port Number
and
Port Priority
. For example:
I/O
Number
Priority
"i", 1, 1
"i", 2, 2
"i", 3, 3
"i", 4, 1
"i", 5, 3
"o", 1, 1
"o", 2, 3
"o", 3, 2
"o" 4, 4
"o", 5, 1
Output 1 can connect to ports 1-5.
Output 2 can connect to ports 3 and 5.
Output 3 can connect to ports 2, 3, and 5.
Output 4 cannot connect to any ports.
Output 5 can connect to ports 1-5.
Note that Port Direction (i or o) is in quotes and that the table must use only the following ASCII printable
characters:
Double quotes
character code = 34
(")
Lower case i
character code = 105
(i)
Lower case o
character code = 111
(o)
Comma
character code = 44
(,)
Carriage Return
character code = 13
(CR)
Line Feed
character code = 10
(LF)
The Restricted Switching Table files for the TLX24 Switch are stored in the on-board Controller at:
var/local/router/restrict/upstream.csv
The on-board Controller will evaluate its Restricted Switching Table (upstream.csv file) only once at
boot-up.
Any errors that occur during the Restricted Switching Table evaluation process will be logged in the
daemon.log file
at the following location:
var/log/daemon.log
To verify the
system restrict policy
, Thinklogical recommends the following:
1) Review the
daemon.log
file and correct any errors in the Restricted Switching Table before
implementing multiple levels of security classification domains on the same Matrix Switch
.
2) Fully test
Restricted Switching
before implementing multiple levels of security classification
domains on the same Matrix Switch.
There are cases where updates to the Restricted Switching Table must be made in an active
system.
When an update is made to the table, the Controller will not evaluate the new table until it is
rebooted.
Restricted switching is disabled when Restricted Switching Table files are removed.
By default,
when there are no Restricted Switching Table files, all input and output ports will have a priority of 1. All
Switches are shipped without Restricted Switching Tables and therefore do not restrict any connections.
Содержание TXL24
Страница 1: ......
Страница 10: ...Page 4 TLX24 Matrix Switch Product Manual thinklogical Rev C August 2016...