Restricting Layer 2 Traffic Among Clients In A Vlan - 3Com WX4400 Reference Manual

Wireless lan mobility system wireless switch manager
Hide thumbs Also See for WX4400:
Table of Contents

Advertisement

226
C
6: C
HAPTER
ONFIGURING
Restricting Layer 2
Traffic Among Clients
in a VLAN
WX S
P
YSTEM
ARAMETERS
By default, clients within a VLAN are able to communicate with one
another directly at Layer 2. You can enhance network security by
restricting Layer 2 forwarding among clients in the same VLAN. When
you restrict Layer 2 forwarding in a VLAN, MSS allows Layer 2 forwarding
only between a client and a set of MAC addresses, generally the default
routers (gateways) of a VLAN. Clients within the VLAN are not permitted
to communicate among themselves directly. To communicate with
another client, the client must use one of the specified default routers.
You can specify up to four default router MAC addresses. The addresses
must be unicast (not multicast or broadcast).
For networks with IP-only clients, you can restrict client-to-client
forwarding using ACLs. Use the Restrict L3 Traffic option. (See
"Restricting Layer 3 Traffic Among Clients in a VLAN".)
1 Access the VLAN table:
a Select the Configuration tool bar option.
b In the Organizer panel, click the plus sign next to the WX switch.
c Click the plus sign next to System.
d Select VLANs.
2 In the Content panel, select the VLAN.
3 In the Task List panel, select Restrict L2 Traffic.
4 Select Restrict L2 Traffic to enable the feature for the VLAN.
5 Click Create.
6 In a Permitted MAC Address box, edit the address to be the MAC address
of the default router (gateway) of a VLAN.
7 Click Finish.
8 Click OK.

Advertisement

Table of Contents
loading

Table of Contents