Creating A Secure Management Vlan - Enterasys Matrix 2G4072-52 Configuration Manual

Firmware version 5.41.xx
Hide thumbs Also See for Matrix 2G4072-52:
Table of Contents

Advertisement

VLAN Configuration Command Set

Creating a Secure Management VLAN

7.3.5
Creating a Secure Management VLAN
If the Matrix Series device is to be configured for multiple VLAN's, it may be desirable to
configure a management-only VLAN. This allows a station connected to the management VLAN
to manage the device. It also makes management secure by preventing configuration via ports
assigned to other VLANs.
To create a secure management VLAN, you must:
1. Create a new VLAN.
2. Set the PVID for the host port and the desired switch port to the VLAN created in Step 1.
(Section
7.3.3.2)
3. Add the host port and the desired switch port to the egress list for the VLAN created in Step 1.
(Section
7.3.4.2)
4. Set a private community name and access policy.
The commands used to create a secure management VLAN are listed in
the associated sections as shown. This example assumes the management station is attached to
fe.1.1 and wants untagged frames.The process described in this section would be repeated on every
device that is connected in the network to ensure that each device has a secure management VLAN.
.
NOTES: By default at device startup, there is one VLAN configured on the Matrix
Series device. It is VLAN ID 1, the DEFAULT VLAN. The default community name,
which determines remote access for SNMP management, is set to "public" with
read-write access.
Table 7-4 Command Set for Creating a Secure Management VLAN
To do this...
Create a new VLAN and confirm
settings.
Set the PVIDs to the new VLAN.
Add the ports to the new VLAN's egress
list.
Set a private community name and access
policy and confirm settings.
7-36 Matrix DFE-Platinum and Diamond Series Configuration Guide
(Section
7.3.2.1)
(Section
5.3.2.8)
Use these commands...
set vlan create 2
(Section
(Optional) show vlan 2
set port vlan host.0.1; fe.1.1 2
set vlan egress 2 host.0.1; fe.1.1 2 untagged
(Section
7.3.4.2)
set snmp community private
(Optional) show snmp community
(Section
5.3.2.7)
Table 7-4
and described in
7.3.2.1)
(Section
7.3.1.1)
(Section
7.3.3.2)
(Section
5.3.2.8)

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Matrix dfe-platinum seriesMatrix dfe-diamond series

Table of Contents