Network Router User Manual
Table Of Contents
- Notices
- Contents
- About This Manual
- Introduction
- Hot Swapping Line Cards and Control Modules
- Bridging Configuration Guide
- Bridging Overview
- VLAN Overview
- Configuring SSR Bridging Functions
- Monitoring Bridging
- Configuration Examples
- SmartTRUNK Configuration Guide
- ATM Configuration Guide
- Packet-over-SONET Configuration Guide
- DHCP Configuration Guide
- IP Routing Configuration Guide
- IP Routing Protocols
- Configuring IP Interfaces and Parameters
- Configuring IP Interfaces to Ports
- Configuring IP Interfaces for a VLAN
- Specifying Ethernet Encapsulation Method
- Configuring Jumbo Frames
- Configuring Address Resolution Protocol (ARP)
- Configuring Reverse Address Resolution Protocol (RARP)
- Configuring DNS Parameters
- Configuring IP Services (ICMP)
- Configuring IP Helper
- Configuring Direct Broadcast
- Configuring Denial of Service (DOS)
- Monitoring IP Parameters
- Configuring Router Discovery
- Configuration Examples
- VRRP Configuration Guide
- RIP Configuration Guide
- OSPF Configuration Guide
- BGP Configuration Guide
- Routing Policy Configuration Guide
- Route Import and Export Policy Overview
- Configuring Simple Routing Policies
- Configuring Advanced Routing Policies
- Multicast Routing Configuration Guide
- IP Policy-Based Forwarding Configuration Guide
- Network Address Translation Configuration Guide
- Web Hosting Configuration Guide
- Overview
- Load Balancing
- Web Caching
- IPX Routing Configuration Guide
- Access Control List Configuration Guide
- Security Configuration Guide
- QoS Configuration Guide
- Performance Monitoring Guide
- RMON Configuration Guide
- LFAP Configuration Guide
- WAN Configuration Guide
- WAN Overview
- Frame Relay Overview
- Configuring Frame Relay Interfaces for the SSR
- Monitoring Frame Relay WAN Ports
- Frame Relay Port Configuration
- Point-to-Point Protocol (PPP) Overview
- Configuring PPP Interfaces
- Monitoring PPP WAN Ports
- PPP Port Configuration
- WAN Configuration Examples
- New Features Supported on Line Cards

Chapter 20: Security Configuration Guide
284 SmartSwitch Router User Reference Manual
Destination filter: No one from the engineering group (port et.1.1) should be allowed to
access the finance server. All traffic destined to the finance server's MAC will be dropped.
Flow filter: Only the consultant is restricted access to one of the finance file servers. Note
that port et.1.1 should be operating in flow-bridging mode for this filter to work.
Static Entries Example
Source static entry: The consultant is only allowed to access the engineering file servers
on port et.1.2.
Destination static entry: Restrict "login multicasts" originating from the engineering
segment (port et.1.1) from reaching the finance servers.
or
Flow static entry: Restrict "login multicasts" originating from the consultant from
reaching the finance servers.
Port-to-Address Lock Examples
You have configured some filters for the consultant on port et.1.1 If the consultant plugs
his laptop into a different port, he will bypass the filters. To lock him to port et.1.1, use the
following command:
filters add address-filter name finance dest-mac AABBCC:DDEEFF vlan 1
in-port-list et.1.1
filters add address-filter name consult-to-finance source-mac
001122:334455 dest-mac AABBCC:DDEEFF vlan 1 in-port-list et.1.1
filters add static-entry name consultant source-mac 001122:334455 vlan 1
in-port-list et.1.1 out-port-list et.1.2 restriction allow
filters add static-entry name login-mcasts dest-mac 010000:334455 vlan 1
in-port-list et.1.1 out-port-list et.1.3 restriction disallow
filters add static-entry name login-mcasts dest-mac 010000:334455 vlan 1
in-port-list et.1.1 out-port-list et.1.2 restriction allow
filters add static-entry name consult-to-mcasts source-mac
001122:334455 dest-mac 010000:334455 vlan 1 in-port-list et.1.1
out-port-list et.1.3 restriction disallow
filters add port-address-lock name consultant source-mac 001122:334455
vlan 1 in-port-list et.1.1