发明名称 Secure VLANs
摘要 A VLAN is implemented with a logical hub and spoke topology that obviates local switching. Member devices are connected to a hub device such as a router via intermediate devices such as Layer 2 switches that support individual IP subnets within the VLAN. The Layer 2 switch does not allow bridging, so there is no IP subnet broadcast domain. Further, the Layer 2 switch implements only a single logical broadcast uplink port which is connected to the router. The Layer 2 switch also implements only point-to-point downlink ports, i.e., to individual member devices. Consequently, all traffic is forced to flow through the router, e.g., broadcast traffic, multicast traffic and traffic of unknown destination received by the Layer 2 switch from a member device is only flooded to the router, and the router performs intra-subnet routing in addition to routing between subnets and between VLANs. The router subjects all traffic to security measures and provide services including packet inspection, firewall, policing, metering, accounting, anti-virus, marking, filtering and encryption, and thereby reduce or eliminate the drawbacks associated with local switching.
申请公布号 US2008298373(A1) 申请公布日期 2008.12.04
申请号 US20080132680 申请日期 2008.06.04
申请人 NORTEL NETWORKS LIMITED 发明人 LAPUH ROGER;KAMBLE KESHAV;KUC ZENON;ELBAKOURY HESHAM
分类号 H04L12/28 主分类号 H04L12/28
代理机构 代理人
主权项
地址