Vlans And Traffic Isolation; Dhcp Snooping - Avaya 8800 Planning And Engineering, Network Design

Ethernet routing switch
Hide thumbs Also See for 8800:
Table of Contents

Advertisement

Network security
802.1x and the LAN Enforcer or VPN TunnelGuard
The Sygate LAN Enforcer or the Avaya VPN TunnelGuard enables the Avaya Ethernet Routing
Switch 8800/8600 to use the 802.1x standard to ensure that a user connecting from inside a
corporate network is legitimate. The LAN Enforcer/TunnelGuard also checks the endpoint security
posture, including anti-virus, firewall definitions, Windows registry content, and specific file content
(plus date and size). Noncompliant systems that attempt to obtain switch authentication can be
placed in a remediation VLAN, where updates can be pushed to the internal user's station, and
users can subsequently attempt to join the network again.

VLANs and traffic isolation

You can use the Avaya Ethernet Routing Switch 8800/8600 to build secure VLANs. When you
configure port-based VLANs, each VLAN is completely separated from the others.
The Avaya Ethernet Routing Switch 8800/8600 analyzes each packet independently of preceding
packets. This mode, as opposed to the cache mode that some competitors use, allows complete
traffic isolation.
For more information about VLANs, see Avaya Ethernet Routing Switch 8800/8600 Configuration —
VLANs and Spanning Tree, NN46205-517.

DHCP snooping

Dynamic Host Configuration Protocol (DHCP) snooping provides security to the network by
preventing DHCP spoofing. DHCP spoofing refers to an attacker's ability to respond to DHCP
requests with false IP information. DHCP snooping acts like a firewall between untrusted hosts and
the DHCP servers so that DHCP spoofing cannot occur.
The following figure shows a simplified DHCP snooping topology.
Figure 140: DHCP snooping
DHCP snooping classifies ports into two types:
• Untrusted: ports that are configured to receive messages from outside the network or firewall.
Only DHCP requests are allowed.
June 2016
Planning and Engineering — Network Design
Comments on this document? infodev@avaya.com
274

Advertisement

Table of Contents
loading

This manual is also suitable for:

8600

Table of Contents