[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference netcad::hub_mgnt

Title:DEChub/HUBwatch/PROBEwatch CONFERENCE
Notice:Firmware -2, Doc -3, Power -4, HW kits -5, firm load -6&7
Moderator:NETCAD::COLELLADT
Created:Wed Nov 13 1991
Last Modified:Fri Jun 06 1997
Last Successful Update:Fri Jun 06 1997
Number of topics:4455
Total number of notes:16761

1879.0. "Filtering on Decswitch900EE" by CLPR01::PEYRACHE (Jean-Yves Peyrache Country Support Group France) Thu Jan 12 1995 17:15


  hi,

 following this configuration

              LAN                             LAN
  Decserver90M------ port 1 ---900EE----port 2-----bunch of VAX

 if  put the Mac address of Decserver90M on Port 1 for filtering ,it's work
 as expected,i can't log from my decserver90m to any Vax,
 but if i put the Same Mac address on Port 2 for filtering , all works 
 i can log on any vax hooked on port 2 an my 900EE from the 90M

  Can anybody explain me how to put a filter for Decserver90M on port 2
  (if i want to work from port 1 to another port 3,4,5,6 from my Decserver)

   thanks

   jean-yves
T.RTitleUserPersonal
Name
DateLines
1879.1Like most filters....CGOOA::PITULEYAin't technology wonderful?Thu Jan 12 1995 20:236
    I rather suspect that the filters are only active against incoming
    traffic.......
    
    Brian Pituley
    NPC, Calgary
    
1879.2How filter on Destination addressSOS6::PEYRACHEJean-Yves Peyrache Country Support Group FranceFri Jan 13 1995 15:5212

 thanks,

  more details will be appreciated , i don't understand
  how to filter for destination address, because for me this kind
  of filter is only an source address filter


  any input will be welcomed

   jean-yves
1879.3DECswitch SA/DA FilteringDELNI::PIEPERWed Feb 22 1995 17:1724
    Please understand that address filtering on the DECswitch 900EE and the
    DECswitch 900EF and the PEswitch 900TX works as follows:
    
    	o Source Address (SA) filtering on INBOUND traffic only
    
    	o Destination Address (DA) filtering on OUTBOUND traffic only
    
    Therefore when you specify an SA filter on a specific port, it will
    only check packets coming from a LAN INTO the switch.  It will NOT be
    checking packets coming from the bridge OUT onto a particular LAN.
    
    The DA filters work similarly.  If you specify a DA filter on a
    particular port, all OUTGOING traffic (packets exiting the switch via
    that port) will be checked for that DA address.  NO INCOMING packets
    (coming from the LAN into the switch) will be checked for that DA.
    
    So you can block a specific Source Address from gaining access to the
    switch and you can block a particular destination address from exiting
    a particular LAN port with the address filtering.  This was done to
    keep the throughput performance of the switch high.
    
    I realize that some customers want more flexibility with filtering but
    we hope to address those needs in the future with a flexible VLAN
    capability         
1879.4c'est clair maintenantSZAJBA::PEYRACHEJean-Yves Peyrache Country Support Group FranceThu Feb 23 1995 07:187
thanks karl,

 now it's clear,
 may be the help files need to be updated ..


  jean-yves
1879.5But, if you specify a DA, you have also specified an SA.SLINK::HOODThis is my new personal name for NotesThu Feb 23 1995 12:417
Also remember that you cannot specify an address filter as a DA filter or
as an SA filter.  Each address filter for the DECbridge 900MX, DECswitch
900EE, 900EF, or PEswitch 900TX, or RoamAbout Access Point is used as 
*both* a DA filter *and* an SA filter.

Tom Hood
HUBwatch
1879.6Look at the Bridging/Switching Products on the DECHUB home pageNETCAD::BATTERSBYThu Feb 23 1995 13:107
    There is also a well written description of the filtering
    features of the DECswitch/PEswitch products in the DECHUB
    WEB home page at....
    
    http://www-dechub.lkg.dec.com/internal-info/switches/filtering.html
    
    Bob
1879.7CSC32::MACGREGORColorado: the TRUE mid-westMon Nov 13 1995 13:3423
    
    Below is my attempt at a correction to .3 bearing in mind that there
    are NOT two different filters (Source Address and Destination Address).
    
    o Address Filtering
    
        Configures the bridge so that an address is "not allowed" to
        communicate through the bridge.  Filtering this address will
        result in the following:
    
            o Source Address (SA) filtering on INBOUND traffic only
    
            o Destination Address (DA) filtering on OUTBOUND traffic only
    
        In other words, if the address is seen in the Source Address
        field of the packet, the packet will be filtered on its way
        into the bridge and thus not allowed onto the bridge.  If the
        address is seen in the Destination Address field of the packet,
        the packet will be filtered on its way out of the bridge and thus
        not put on the wire.
    
    Marc (putting modified .3 into STARS)