Motorola Solutions AP-6511 Access Point System Reference Guide
7-32
For example, say several computers are used into conference room X and some into conference Y. The
systems in conference room X can communicate with one another, but not with the systems in conference
room Y. The creation of a VLAN enables the systems in conference rooms X and Y to communicate with one
another even though they are on separate physical subnets. The systems in conference rooms X and Y are
managed by the same single device, but ignore the systems that aren't using same VLAN ID.
Administrators often need to route traffic to interoperate between different VLANs. Bridging VLANs are only
for non-routable traffic, like tagged VLAN frames destined to some other device which will untag it. When a
data frame is received on a port, the VLAN bridge determines the associated VLAN based on the port of
reception. Using forwarding database information, the Bridge VLAN forwards the data frame on the
appropriate port(s). VLAN's are useful to set separate networks to isolate some computers from others,
without actually having to have separate cabling and Ethernet switches. Another common use is to put
specialized devices like VoIP Phones on a separate network for easier configuration, administration, security,
or quality of service.
To define a bridge VLAN configuration:
1. Select
Configuration
>
Profiles
>
Network
.
2. Expand the Network menu to display its submenu options.
3. Select
Bridge VLAN
.
4. Review the following VLAN configuration parameters:
5. Select
Add
to define a new Bridge VLAN configuration,
Edit
to modify the configuration of an existing
Bridge VLAN configuration or
Delete
to remove a VLAN configuration.
VLAN
Lists the numerical identifier defined for the Bridge VLAN when it was
initially created. The available range is from 1 - 4095. This value cannot be
modified during the edit process.
Description
Lists a description of the VLAN assigned when it was created or modified.
The description should be unique to the VLAN’s specific configuration and
help differentiate it from other VLANs with similar configurations.
Edge VLAN Mode
Defines whether the VLAN is currently in edge VLAN mode. An edge VLAN
is the VLAN where hosts are connected. For example, if VLAN 10 is defined
with wireless clients and VLAN 20 is where the default gateway resides,
VLAN 10 should be marked as an edge VLAN and VLAN 20 shouldn’t be
marked as an edge VLAN. When defining a VLAN as edge VLAN, the firewall
enforces additional checks on hosts in that VLAN. For example, a host cannot
move from an edge VLAN to another VLAN and still keep firewall flows
active.
Trust ARP Response
When ARP trust is enabled, a green checkmark displays. When disabled, a
red “X” displays. Trusted ARP packets are used to update the IP-MAC Table
to prevent IP spoof and arp-cache poisoning attacks.
Trust DHCP Responses
When DHCP trust is enabled, a green checkmark displays. When disabled, a
red “X” displays. When enabled, DHCP packets from a DHCP server are
considered trusted and permissible within the network. DHCP packets are
used to update the DHCP Snoop Table to prevent IP spoof attacks.
Summary of Contents for AP-6511
Page 1: ...Motorola Solutions AP 6511 Access Point System Reference Guide ...
Page 2: ...Motorola Solutions AP 6511 Access Point System Reference Guide 1 2 ...
Page 24: ...Motorola Solutions AP 6511 Access Point System Reference Guide 2 12 ...
Page 318: ...Motorola Solutions AP 6511 Access Point System Reference Guide 10 16 ...
Page 409: ...Statistics 13 49 Figure 13 31 Access Point Firewall Packet Flow screen ...
Page 433: ......