Configure VLAN tagging | |||
GO |
This topic describes the steps to configure virtual LAN (VLAN) tagging on the Lucent CM server.
By using VLAN tagging, traffic on a single interface is logically separated on to different virtual LANs.
When used together with additional security mechanisms, VLAN tagging increases security.
The following types of traffic can be distinguished on the Lucent CM system:
Traffic type |
Interface |
User client traffic |
Uses the interfaces on eth0. |
Application server control and signalling traffic |
Uses the internal interface on eth1. |
OAM&P traffic |
Uses the internal interface on eth1. |
VLAN tagging can be used to separate OAM&P and application server control and signalling traffic
VLAN tagging by itself does not increase the level of security.
To increase security, VLAN tagging must be deployed together with one of the following additional security mechanisms:
Provision specific routes on the Lucent CM Servers to ensure a specific traffic type only goes through the desired interface. This is required since there can only be one default gateway per server and traffic destined to a network not explicitly defined will egress via the default gateway.
Deploy a firewall to prevent access to a specific interface unless authorized.
Deploy a firewall to prevent access to a specific interface unless on an allowed port.
Deploy Access Control Lists on the network routers to limit access to specific interfaces from specific networks.
Before you begin ensure the following:
The network that connects the Lucent CM servers must support VLAN tagging.
A VLAN schema must have been developed.
The configuration information is available, this includes IP interfaces, subnet masks, and VLAN tag IDs.
The network elements (routers and switches) must have been configured to use the same VLAN tags as the VLAN tags that will be used on the Lucent CM system.
CAUTION
Service-disruption hazard
Restarting services on an operational Lucent CM system results in a service outage for all users. The service outage time is less then one minute, when VLAN tagging is properly configured.
Perform this procedure during low traffic hours.
Perform the following steps to configure VLAN tagging on the Lucent CM system:
Verify the Lucent CM system is fully operational by testing connectivity to and from all new interfaces.
GO | |||
© Lucent Technologies |