LevelOne GTL-5280 Manual - Page 138

MAC-based VLAN, 10.6.1 Configuration

Page 138 highlights

3-10.6 MAC-based VLAN MAC address-based VLAN decides the VLAN for forwarding an untagged frame based on the source MAC address of the frame. A most common way of grouping VLAN members is by port, hence the name port-based VLAN. Typically, the device adds the same VLAN tag to untagged packets that are received through the same port. Later on, these packets can be forwarded in the same VLAN. Portbased VLAN is easy to configure, and applies to networks where the locations of terminal devices are relatively fixed. As mobile office and wireless network access gain more popularity, the ports that terminal devices use to access the networks are very often non-fixed. A device may access a network through Port A this time, but through Port B the next time. If Port A and Port B belong to different VLANs, the device will be assigned to a different VLAN the next time it accesses the network. As a result, it will not be able to use the resources in the old VLAN. On the other hand, if Port A and Port B belong to the same VLAN, after terminal devices access the network through Port B, they will have access to the same resources as those accessing the network through Port A do, which brings security issues. To provide user access and ensure data security in the mean time, the MAC-based VLAN technology is developed. MAC-based VLANs group VLAN members by MAC address. With MAC-based VLAN configured, the device adds a VLAN tag to an untagged frame according to its source MAC address. MAC-based VLANs are mostly used in conjunction with security technologies such as 802.1X to provide secure, flexible network access for terminal devices. 3-10.6.1 Configuration The MAC-based VLAN entries can be configured here. This page allows for adding and deleting MAC-based VLAN entries and assigning the entries to different ports. This page shows only static entries. Web Interface To configure MAC address-based VLAN configuration in the web interface: 1. Click MAC address-based VLAN configuration and add new entry. 2. Specify the MAC address and VLAN ID. 3. Click Apply. Figure 3-10.6.1: The MAC-based VLAN Membership Configuration Parameter description:  Delete : To delete a MAC-based VLAN entry, check this box and press Apply. The entry will be deleted on the selected switch. 130

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264

130
3-10.6 MAC-based VLAN
MAC address-based VLAN decides the VLAN for forwarding an untagged frame based on the
source MAC address of the frame.
A most common way of grouping VLAN members is by port, hence the name port-based
VLAN. Typically, the device adds the same VLAN tag to untagged packets that are received
through the same port. Later on, these packets can be forwarded in the same VLAN. Port-
based VLAN is easy to configure, and applies to networks where the locations of terminal
devices are relatively fixed. As mobile office and wireless network access gain more
popularity, the ports that terminal devices use to access the networks are very often non-fixed.
A device may access a network through Port A this time, but through Port B the next time. If
Port A and Port B belong to different VLANs, the device will be assigned to a different VLAN
the next time it accesses the network. As a result, it will not be able to use the resources in
the old VLAN. On the other hand, if Port A and Port B belong to the same VLAN, after
terminal devices access the network through Port B, they will have access to the same
resources as those accessing the network through Port A do, which brings security issues. To
provide user access and ensure data security in the mean time, the MAC-based VLAN
technology is developed.
MAC-based VLANs group VLAN members by MAC address. With MAC-based VLAN
configured, the device adds a VLAN tag to an untagged frame according to its source MAC
address. MAC-based VLANs are mostly used in conjunction with security technologies such
as 802.1X to provide secure, flexible network access for terminal devices.
3-10.6.1 Configuration
The MAC-based VLAN entries can be configured here. This page allows for adding and
deleting MAC-based VLAN entries and assigning the entries to different ports. This page
shows only static entries.
Web Interface
To configure MAC address-based VLAN configuration in the web interface:
1.
Click MAC address-based VLAN configuration and add new entry.
2.
Specify the MAC address and VLAN ID.
3.
Click Apply.
Figure 3-10.6.1:
The MAC-based VLAN Membership Configuration
Parameter description:
Delete :
To delete a MAC-based VLAN entry, check this box and press Apply. The entry will be
deleted on the selected switch.