Nortel Networks 450 series Switch User Manual


 
396 Configuration example
5510-48T(config)# ssh download-auth-key address
10.20.20.20 key-name sac_key.1.pub
5510-48T(config)# ssh
Configuring the Nortel SNAS pVIP subnet
5510-48T(config)# nsna nsnas 10.40.40.0/24
Creating port-based VLANs
5510-48T(config)# vlan create 210 type port
5510-48T(config)# vlan create 220 type port
5510-48T(config)# vlan create 230 type port
5510-48T(config)# vlan create 240 type port
Configuring the VoIP VLANs
5510-48T(config)# nsna vlan 240 color voip
Configuring the Red, Yellow, and Green VLANs
5510-48T(config)# nsna vlan 210 color red filter red
5510-48T(config)# nsna vlan 220 color yellow filter yellow
yellow-subnet 10.120.120.0/24
5510-48T(config)# nsna vlan 230 color green filter green
Configuring the login domain controller filters
ATTENTION
This step is optional.
The PC client must be able to access the login domain controller you configure
(that is, clients using the login domain controller must be able to ping that
controller).
5510-48T(config)# qos nsna classifier name RED dst-ip
10.200.2.12/32 ethertype 0x0800 drop-action disable block
wins-prim-sec eval-order 70
5510-48T(config)# qos nsna classifier name RED dst-ip
10.200.224.184/32 ethertype 0x0800 drop-action disable
block wins-prim-sec eval-order 71
Configuring the NSNA ports
Add the uplink port:
5510-48T(config)# interface fastEthernet 20
5510-48T(config-if)# nsna uplink vlans 210,220,230,240
5510-48T(config-if)# exit
Nortel Secure Network Access Switch
Using the Command Line Interface
NN47230-100 03.01 Standard
28 July 2008
Copyright © 2007, 2008 Nortel Networks
.