Specifications
2. Associate the VLANs with GESW interfaces
Go to Network > Interfaces and VPN > VLAN > Switch Management, enable port based VLAN
and set each numbered GESW interface to be associated with the relevant VLAN to get the
desired configuration.
For this example, the screenshot below shows how this would look in the Web Interface.
This last dialog is only available in the Web Interface for Clavister hardware platforms that
support port based VLANs.
Port Based VLAN Issues
There are some issues which the adminstrator should be aware of when setting up port based
VLANs:
• Port based VLANs cannot be mixed with VLAN trunks.
When the port based VLAN feature is used, all of the GESW interfaces act as access ports and
none can be used for 802.1q VLAN trunks.
• MAC addresses are duplicated.
The MAC addresses of all the GESW interfaces are the same. This means that a switch might
have two connections to the security gateway that have two different IP addresses but the
same MAC address. For some switches this can be a problem and the situation should be
avoided by using separate switches.
Appendix C: Port Based VLAN Setup
79