商城 设为首页注册本站  论坛  繁體中文

慧民电脑芯片级维修-电脑技巧
手机 | MP3 | MP4 | 显卡 | 主板 | 显示器 | 光存储 | 笔记本 | 网络设备 | 移动存储 | 数码相机
键鼠 | CPU | 音箱 | GPS | 电视 | 服务器 | 投影机 | 机箱电源 | 品牌电脑 | 办公打印 |
| 网站首页 | Cisco | Windows | Linux | Java | Dotnet | Oracle | 网页设计 | 平面设计 | 安全 | 软件应用 | 电脑维修 | 办公维修 |
您现在的位置: 电脑技巧 >> Cisco >> 安全技术 >> vpn >> Cisco正文

动态VLAN详细配置实例

文章来源:中国IT实验室收集整理 作者:佚名 更新时间:2007-8-3 【 】 【加入收藏

  To use VMPS, you first must create a VMPS database and store it on a TFTP server. The VMPS parser is line based. Start each entry in the file on a new line. The example at the end of this section corresponds to the information described below.

  The VMPS database can have up to five sections:

  Section 1, Global settings, lists the settings for the VMPS domain name, security mode, fallback VLAN, and the policy for VMPS and VTP domain name mismatches.

  Begin the configuration file with the Word "VMPS," to prevent other types of configuration files from incorrectly being read by the VMPS server.

  Define the VMPS domain. The VMPS domain should correspond to the VTP domain name configured on the switch.

  Define the security mode. VMPS can operate in open or secure mode. If you set it to open mode, VMPS returns an Access denied response for an unauthorized MAC address and returns the fallback VLAN for a MAC address not listed in the VMPS database. In secure mode, VMPS shuts down the port for a MAC address that is unauthorized or that is not listed in the VMPS database.

  (Optional) Define a fallback VLAN. Assign the fallback VLAN is assigned if the MAC addresses of the connected host is not defined in the database.

  In the example at the end of this section, the VMPS domain name is WBU, the VMPS mode is set to open, the fallback VLAN is set to the VLAN default, and if the VTP domain name does match the VMPS domain name, then VMPS sends an access denied response message.

  Section 2, MAC addresses, lists MAC addresses and authorized VLAN names for each MAC address.

  Enter the MAC address of each host and the VLAN name to which each should belong.

  Use the ——NONE—— keyword as the VLAN name to deny the specified host network connectivity.

  You can enter up to 21,051 MAC addresses in a VMPS database file for the Catalyst 2948G switch.

  In the example at the end of this section, MAC addresses are listed in the MAC table. Notice that the MAC address fedc.ba98.7654 is set to ——NONE——。 This setting eXPlicitly denies this MAC address from accessing the network.

  Section 3, Port groups, lists groups of ports on various switches in your network that you want grouped together. You use these port groups when defining VLAN port policies.

  Define a port group name for each port group; then list all ports you want included in the port group.

  A port is identified by the IP address of the switch and the module/port number of the port in the form mod_num/port_num. Ranges are not allowed for the port numbers.

  Use the all-ports keyword to specify all the ports in the specified switch.

  The example at the end of this section has two port groups:

  WiringCloset1 consists of the two ports: port 3/2 on the VMPS client 198.92.30.32 and port 2/8 on the VMPS client 172.20.26.141

  Executive Row consists of three ports: port 1/2 and 1/3 on the VMPS client 198.4.254.222, and all ports on the VMPS client 198.4.254.223

  Section 4, VLAN groups, lists groups of VLANs you want to associate together. You use these VLAN groups when defining VLAN port policies.

  Define the VLAN group name; then list each VLAN name you want to include in the VLAN group.

  You can enter a maximum of 256 VLANS in a VMPS database file for the Catalyst 2948G switch.

  The example at the end of this section has the VLAN group Engineering, which consists of the VLANs hardware and software.

  Section 5, VLAN port policies, lists the VLAN port policies, which use the port groups and VLAN groups to further restrict access to the network.

  You can configure a restricted access using MAC addresses and the port groups or VLAN groups.

  The example at the end of this section has three VLAN port policies specified.

  In the first VLAN port policy, the VLAN hardware or software is restricted to port 3/2 on the VMPS client 198.92.30.32 and port 2/8 on the VMPS client 172.20.23.141.

  In the second VLAN port policy, the devices specified in VLAN Green can connect only to port 4/8 on the VMPS client 198.92.30.32.

  In the third VLAN port policy, the devices specified in VLAN Purple can connect to only port 1/2 on the VMPS client 198.4.254.22 and the ports specified in the port group Executive Row.

  The following example shows a sample VMPS database configuration file.

  • 上一篇Cisco:

  • 下一篇Cisco:
  • 最 新 热 门
     CDMA无线网络优化流程与方法
     Wi-Fi探查连接工具帮无线网络管理连接
     无线路由器天线扫描无线信号
     从技术角度看11n走向无线前端的难度
     2008年盘点:从企业应用解析802.11n
     企业网络遭受ARP攻击 需提升网络安全
     与时俱进 分钟级别WEP破解全功略
     不可不知的路由交换安全七宗罪
     无线大讲堂 你的企业无线网络安全吗?
     网管支招:小技巧让企业无线安全上一台阶
    最 新 推 荐
     企业信息化与南凌IP-VPN
     专家谈:采用UTM实现立体安全的VPN体系
     案例剖析:新东方外语培训学校VPN应用
     你用SSL VPN要小心 它仍有安全漏洞
     国产SSL VPN产品技术概述
     SSL VPN可能不如大家想象得那么安全
     防护小型网络 SSL-VPN 200防火墙评测
     第三代VPN技术演绎长尾理论
     配置预共享密钥的Site-to-site IPSEC VPN服…
     巧改交换模式,让VLAN不跟随端口变化
    相 关 文 章

    动态和静态IP地址引起的VPN问题
    简要介绍如何检测VLAN交换机及其端口
    多个VLAN通信&华为cisco路由协议优先级
    解决DHCP动态更改IP地址问题
    以太网交换技术:静态交换和动态交换介绍
    巧改交换模式,让VLAN不跟随端口变化
    教你交换机建立VLAN出错的解决办法
    VLAN中的路由器与交换机角色的改变
    保障企业信息安全 VLAN交换机选购分析
    实例:路由器接交换机划分VLAN

    | 设为首页 | 加入收藏 | 联系站长 | 友情链接 | 版权申明 | 网站公告

      Copyright 2006-2008 pcjx.com All Rights Reserved
    电脑技巧 版权所有 粤ICP备06059145号 地图
    门市地址:广东省佛山市南海区黄岐黄海路133号
    本网站所有内容未经许可不得转载或做其他使用
    电话:0757-81139980 QQ:83306923