Enhanced Network Security - 3Com LANPLEX 2500 Operation Manual

Hide thumbs Also See for LANPLEX 2500:
Table of Contents

Advertisement

8-4
C
8: LAN
HAPTER
Enhanced
Network Security
® B
E
PLEX
RIDGING
XTENSIONS
In addition to allowing you to design and use packet filters to improve
network security (as described in Chapter 7), the LANplex 2500 system
allows you to use statically configured addresses as a form of network
security.
From the Administration Console or an SNMP manager, you can manually
assign an address to an Ethernet port. You have permanently tied this
address to the specified port unless you manually remove it. The address is
never aged and can never be learned on a different Ethernet port. If a
packet with a statically configured source address is received on a port that
differs from the address's assigned port, the packet is discarded and a
management event is generated. The event can be used to expose the
imposter station.
You can also convert dynamic addresses to static addresses. It is often more
convenient to let the bridge first learn all of the addresses on your network
and then to convert these learned, or dynamic, addresses to static addresses
to improve your network security.
For information, see the section on bridging in the LANplex® 2500
Administration Console User Guide.

Advertisement

Table of Contents
loading

Table of Contents