Presentation is loading. Please wait.

Presentation is loading. Please wait.

1/117 Switch internals Floor SwitchCore Switch L3 Default NSNA port VLAN L2 Filter NSNA default VLANs access Filter per VLAN DHCP Relay Agent DHCP Relay.

Similar presentations


Presentation on theme: "1/117 Switch internals Floor SwitchCore Switch L3 Default NSNA port VLAN L2 Filter NSNA default VLANs access Filter per VLAN DHCP Relay Agent DHCP Relay."— Presentation transcript:

1 1/117 Switch internals Floor SwitchCore Switch L3 Default NSNA port VLAN L2 Filter NSNA default VLANs access Filter per VLAN DHCP Relay Agent DHCP Relay additional VLANs VoIP drop all except: DHCP, DNS ARP, ICMP, UNISTIM UDP port RTP UPD ports Filter restrict each VLAN down to the minimum of communication Department: devolvement drop all except: DHCP, DNS, ARP, SMB HTTP/HTTPS destined to SNAS restricted drop all except: DHCP, DNS, ARP, SMB HTTP/HTTPS destined to SNAS Guest drop all except: DHCP, DNS, ARP, ICMP HTTP/HTTPS destined to SNAS all traffic to internet Printer drop all except: DHCP, DNS ARP, ICMP, LPR, IPP, TCP/515 & 9100 All from source Print Server Remediation drop all except: DHCP, DNS, ARP, ICMP HTTP/HTTPS destined to SNAS all traffic to Yellow-1 Subnet Department: engineering drop all except: DHCP, DNS, ARP, SMB HTTP/HTTPS destined to SNAS Port assignment either static or 802.1x or NSNA

2 2/117 Enter the network SNASFloor SwitchCore Switch L3 DHCPDNS LDAP Radius request IP start Internet Explorer and open a web page (www.google.com) Login through the captive portal validate user connect PC Tunnel Guard check L2 DHCP provides IP = red VLAN IP DNS = SNAS VIP PC DNS query goes to the SNAS VIP and get the VIP back www.google.com = SNAS VIP

3 3/117 Integrity check fails Floor SwitchCore Switch DHCPDNSRemediation corporate policy compliant L2 reconfigure switch => NO inform Access Controller issue new IP (triggered through TG) TG inform third party application L3 SNAS

4 4/117 Integrity check fails => pass Floor SwitchCore Switch Server Farm DHCPDNS L2L3 corporate policy compliant reconfigure switch inform Access Controller issue new IP (triggered through TG) => OK ready to work SNAS

5 5/117 Integrity check pass Floor SwitchCore Switch Server Farm DHCPDNS L2L3 corporate policy compliant reconfigure switch inform Access Controller issue new IP (triggered through TG) => OK ready to work SNAS

6 6/117 Voice over IP (i200x) Floor SwitchCore Switch central voice services DHCPDNS L2L3 connect IP phone DHCP-SV provide the VLAN ID request IP ready to work SNAS inform Access Controller tagging DHCP offer with VLAN tag ID with IP from white IP range DHCP provide the call SV parameter request IP again with VLAN ID tag


Download ppt "1/117 Switch internals Floor SwitchCore Switch L3 Default NSNA port VLAN L2 Filter NSNA default VLANs access Filter per VLAN DHCP Relay Agent DHCP Relay."

Similar presentations


Ads by Google