Figure 3-3 Example 6, Securing Traffic to One Subnet
3.3.1
Solving the Problem
In this example, Switch 1 (S1) has already been configured and is operating.
To isolate the Finance Department traffic, Subnet 28 will be isolated from the Engineering
Department Subnet 50 and other users on the company's network (123.123.xx.xx).
The following covers only those steps needed to configure the switch to solve the problem.
Switch 1
To isolate the network traffic of the Finance Department users on the Finance VLAN (20), which
are on Subnet 28, S1 will be configured as follows using the VLAN Classification Configuration
screen:
•
VID: 20
•
Classification: Bil IP Address
•
IP Address: 123.123.28.0
•
Data Mask: 255.255.255.0
As a result of this setting, any frame with a source or destination IP address of 123.123.28.0-255
will be classified to the Finance VLAN (20) and will remain within Subnet 28. Any frame from
another network or subnet will not be allowed access to Subnet 28 because of the datamask
255.255.255.0.
Example 6, Securing Sensitive Information According to Subnet
Configuration Examples
3-7