Specifications

VLAN Configuration Summary
7-2 802.1Q VLAN Configuration
IftheSecureStackC3deviceistobeconfiguredformultipleVLANs,itmaybedesirableto
configureamanagementonlyVLAN.ThisallowsastationconnectedtothemanagementVLAN
tomanagethedevice.Italsomakesmanagementsecurebypreventingconfigurationviaports
assignedtootherVLANs.
Tocreate
asecuremanagementVLAN,youmust:
ThecommandsusedtocreateasecuremanagementVLANarelistedinTable 71.Thisexample
assumesthemanagementstationisattachedtofe.1.1andwantsuntaggedframes.
Theprocessdescribedherewouldberepeatedoneverydevicethatisconnectedinthenetworkto
ensurethateachdevicehasasecuremanagementVLAN.
Step Task Refer to page...
1. Create a new VLAN. 7-5
2. Set the PVID for the desired switch port to the VLAN created in Step 1. 7-9
3. Add the desired switch port to the egress list for the VLAN created in
Step 1.
7-16
4. Assign host status to the VLAN. 7-21
5. Set a private community name and access policy. 5-14
Table 7-1 Command Set for Creating a Secure Management VLAN
To do this... Use these commands...
Create a new VLAN and confirm settings. set vlan create 2 (“set vlan” on page 7-5)
(Optional) show vlan 2 (“show vlan” on page 7-3)
Set the PVID to the new VLAN. set port vlan fe.1.1 2 (“set port vlan” on page 7-9)
Add the port to the new VLAN’s egress list. set vlan egress 2 fe.1.1 untagged (“set vlan egress” on
page 7-16)
Remove the port from the default VLAN’s
egress list.
clear vlan egress 1 fe.1.1 (“clear vlan egress” on
page 7-17)
Assign host status to the VLAN. set host vlan 2 (“set host vlan” on page 7-21)
Set a private community name and access
policy and confirm settings.
set snmp community private (set snmp community”
on page 5-14)
(Optional) show snmp community (“show snmp
community” on page 5-13)