Creating A Secure Management Vlan; Command Set For Creating A Secure Management Vlan - Enterasys SECURESTACK C3 Configuration Manual

Stackable switches
Hide thumbs Also See for SECURESTACK C3:
Table of Contents

Advertisement

VLAN Configuration Summary

Creating a Secure Management VLAN

By default at startup, there is one VLAN configured on the SecureStack C3 device. It is VLAN ID 
1, the DEFAULT VLAN. The default community name, which determines remote access for SNMP 
management, is set to "public" with read‐write access.
If the SecureStack C3 device is to be configured for multiple VLANs, it may be desirable to 
configure a management‐only VLAN. This allows a station connected to the management VLAN 
to manage the device. It also makes management secure by preventing configuration via ports 
assigned to other VLANs.
To create a secure management VLAN, you must:
Step
1.
2.
3.
4.
5.
The commands used to create a secure management VLAN are listed in Table
assumes the management station is attached to ge.1.1 and wants untagged frames.
The process described here would be repeated on every device that is connected in the network to 
ensure that each device has a secure management VLAN. 
Table 10-1 Command Set for Creating a Secure Management VLAN
To do this...
Create a new VLAN and confirm settings.
Set the PVID to the new VLAN.
Add the port to the new VLAN's egress list.
Remove the port from the default VLAN's
egress list.
Assign host status to the VLAN.
Set a private community name and access
policy and confirm settings.
10-2 802.1Q VLAN Configuration
Task
Create a new VLAN.
Set the PVID for the desired switch port to the VLAN created in Step 1.
Add the desired switch port to the egress list for the VLAN created in
Step 1.
Assign host status to the VLAN.
Set a private community name and access policy.
Use these commands...
set vlan create 2
("set
vlan" on page 10-5)
(Optional) show vlan 2
("show
set port vlan ge.1.1 2
("set port
set vlan egress 2 ge.1.1 untagged
page 10-15)
clear vlan egress 1 ge.1.1
page 10-15)
set host vlan 2
("set host vlan" on page
set snmp community private
page 8-14)
(Optional) show snmp community
community" on page 8-13)
Refer to page...
10-5
10-9
10-15
10-18
8-14
10‐1. This example 
vlan" on page 10-3)
vlan" on page 10-9)
("set vlan
egress" on
("clear vlan
egress" on
10-18)
("set snmp
community" on
("show snmp

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents