ZXR105250SeriesCongurationGuide
lCongurationProcedure
àCongureaVLANfortheports:
zte(cfg)#setvlan400addport1/1,1/2,1/4untag
zte(cfg)#setport1/1,1/2,1/4pvid400
àConguretheMFFattributesfortheportsandVLAN:
zte(cfg)#setmffvlan400addport1/1userport
zte(cfg)#setmffvlan400addport1/2userport
zte(cfg)#setmffvlan400addport1/4network
àCongureanintra-VLANgateway:
zte(cfg)#setmffvlan400gatewayip197.1.23.15
lCongurationVerication
WhenanARPrequestisreceivedonauserport,theswitchsearchestheARPtable
rst.IfthegatewayARPentryisnotcontainedintheARPtable,theswitchreplaces
theusertosendanARPrequesttothegateway,andthenaddsanMFFuserentry.
TheMFFuserentryisasfollows:
zte(cfg)#showmffuser-table
MFFuserentrytotalcount:1
Type:bornwayofMFFuserentry.
'M',manualconfigure;'A',ARPpacket;'D',DHCPsnoopingpacket.
VlanIdIpAddressTypeMacAddressGateway(IpOrMac)
----------------------------------------------------
400197.1.23.3A00.10.94.00.00.03197.1.23.15
5.43SSLConguration
SSLOverview
TheSSLprotocolisanintermediateprotocol.Itislocatedbetweentheapplicationlayer
andtransportlayerinthenetworkmodel.Throughthedataencryption,identication
authentication,andmessageintegrityvalidationmechanisms,SSLensuressecurityfor
connectionsestablishedbasedonreliableapplicationlayerprotocols(forexample,TCP).
TheSSLfunctionalmoduleenablestheZXR105250tooperateasanSSLserverand
completeinteractionwithaclient.TheinteractionprocedureincludesSSLhandshaking,
andpacketmonitoring,receiving,parsingandsending.TheSSLhandshakingprocedure
includesnegotiatinganencryptionalgorithm,verifyingthelocalcerticateontheserver,
exchangingkeys,andverifyingaMACaddress.Theencryptionalgorithm,localcerticate
ontheserver,keys,andMACaddressareusedfordataencryptionanddecryption,
identicationauthentication,andmessageintegrityvalidationinasubsequentsession.
EncryptioncerticatemanagementistheprerequisiteforSSLhandshaking.Certicate
managementincludeskeygenerationmanagement,localcerticategenerationonthe
server,androotcerticategenerationontheclient.
5-148
SJ-20131111172707-002|2013-11-27(R1.0)ZTEProprietaryandCondential