13.07.2015 Views

configuring ports - Lantech Communications Global Inc

configuring ports - Lantech Communications Global Inc

configuring ports - Lantech Communications Global Inc

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

SECURIY ANDAUTHENTICATIONThis switch provides management access via the console port,Telnet, or a web browser. User names and passwords can beconfigured locally or can be verified via a remote authenticationserver (i.e., RADIUS or TACACS+).Port-based authentication is also supported via the IEEE 802.1Xprotocol. This protocol uses Extensible Authentication Protocol overLANs (EAPOL) to request user credentials from the 802.1X client,and then uses the EAP between the switch and the authenticationserver to verify the client‘s right to access the network via anauthentication server (i.e., RADIUS server).Other authentication options include HTTPS for secure managementaccess via the web, SSH for secure management access over aTelnet-equivalent connection, SNMP Version 3, IP address filteringfor web/SNMP/Telnet/SSH management access, and MAC addressfiltering for port access.NOTE: The SSL only provide the CLI for switch management and SSHdefault enable without UI for management.ACCESS CONTROLLISTSThe ACLs are divided into EtherTypes. IPv4, ARP protocol, MAC andVLAN parameters etc. Here we will just go over the standard andextended access lists for TCP/IP. As you create ACEs for ingressclassification, you can assign a policy for each port, the policynumber is 1-8, however, each policy can be applied to any port.This makes it very easy to determine what type of ACL policy youwill be working with.IGMP SNOOPINGSupport IGMP version 2 (RFC 2236): The function IGMP snooping isused to establish the multicast groups to forward the multicastpacket to the member <strong>ports</strong>, and, in nature, avoid wasting thebandwidth while IP multicast packets are running over the network.IGMP PROXYThe implementation of IP multicast processing. The switch sup<strong>ports</strong> IGMPversion 1 and IGMP version 2, efficient use of network bandwidth, and fastresponse time for channel changing. IGMP version 1 (IGMPv1) is described inRFC1112 ,and IGMP version 2 (IGMPv2) is described in RFC 2236. Hostsinteract with the system through the exchange of IGMP messages. Similarly,when you configure IGMP proxy, the system interacts with the router on itsupstream interface through the exchange of IGMP messages. However, whenacting as the proxy, the system performs the host portion of the IGMP task onthe upstream interface as follows: When queried, sends group membership re<strong>ports</strong> to the group. When one of its hosts joins a multicast address group to whichnone of its other hosts belong, sends unsolicited groupmembership re<strong>ports</strong> to that group. When the last of its hosts in a particular multicast group leaves thegroup, sends an unsolicited leave group membership report to theall-routers group (244.0.0.2).

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!