1.2 LAN

Source: Internet
Author: User

The LAN end is the line that is connected to the enterprise user. Some routers have LAN ports and can be connected to switches. Some network administrators connect the routers to the backbone switches and then to the General switches. Both of the above methods can be used. The latter is suitable for applications with high throughput. For general enterprise applications, the local port of the router can be forwarded based on bandwidth. In hardware configuration, this is relatively simple.
The experience of technical service personnel of xiaonuo points out that IP address management is very important for a good security network configuration. IP address is the IP address of the computer on the Internet. Therefore, you must be able to effectively manage the IP address to prevent attacks or control the problematic calculator. For network management, IP management should pay attention to the following four important items: using a fixed IP address for computers, issuing a fixed IP address for DHCP servers, and preventing unauthorized computer access and group management, the descriptions are as follows:
• The calculator uses a fixed IP Address:
The calculator uses a fixed IP address, which is the strictest configuration method. In this way, you must manually enter IP address-related data in the computer. The advantage of this operation is that the IP address of each machine must be specified in advance. If no IP address is specified in advance, the Internet cannot be accessed. external users or calculators cannot access the Internet easily through the enterprise network. However, for users, you must set a fixed IP address. In other cases, you must reset the IP address. For some users who often need to move, such as business personnel or senior executives, this may cause a lot of trouble.
• The DHCP server issues a fixed IP Address:
The advantage of the DHCP server is that you do not need to make any settings on the computer, which is more convenient for users. However, the disadvantage of DHCP is that, without any control, any user can access the enterprise's network, and it is easy to launch internal attacks, resulting in an impact. Therefore, an enterprise can issue an IP address through DHCP, but at the same time limit the IP address that can be obtained by the calculator for management. The IP/MAC binding function of the Qno xiaonuo router product allows you to identify the MAC address of the calculator through the network management configuration and issue a specific IP address, so that you can manage the IP address. At the same time, the IP/MAC binding function can also prevent users from modifying the IP address to obtain high permissions. The wrong MAC/IP combination will be blocked by the router "blocked wrong MAC address, this function can also prevent ARP attacks.
• Prevent Unauthorized computers from accessing the Internet:
For network administrators, uncontrolled computers often cause security problems. Some users bring their own computer into the computer, and even other users enter the company network through wireless networks. This problem can be solved by preventing unauthorized computers from accessing the Internet. Qno's IP/MAC binding function provides the function of "blocking MAC addresses not in the corresponding list" to achieve unconfigured MAC addresses of the network management and completely disable Internet access.

Figure 1
Figure 1:The IP/MAC binding function of the Qno na router allows the network administrator to type the user's IP address and MAC address so that a fixed IP address can be assigned to the user each time the DHCP service is used. In addition, the "blocked wrong MAC address" and "blocked MAC addresses not in the corresponding list" feature provides more advanced features to provide a layer-1 security protection.
• Group Management:
In addition to binding IP addresses and MAC addresses, You can effectively control the use of the outdoors and use the group function as appropriate to facilitate user management. For example, if the IP Group function provided by Qno is used, different IP users can be set to different groups, for example, the enterprise senior supervisor is set to a group, the business department is set to a group, and the internal administrative staff is set to a group. Users in different groups can apply different control permissions or bandwidth management principles, which can greatly simplify the management work and avoid the leakage of the Internet.
Figure 2
Figure 2:The IP group function allows users of different IP addresses to be classified into different groups and named. The group management function provides comprehensive control functions. You can also avoid security vulnerabilities due to missing configurations.

Related Articles]

  • What is a security router?
  • What aspects should Small and Medium-Sized Enterprises Focus on Security routers?
  • Introduction to the Security Configuration of wireless routers

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.