Created on: March 21, 2003
Last Update: May 24, 2005
VLANs infrastructure in the National Laboratory
of Frascati
With the new
network infrastructure we have established two environments:
- The
internal VLANs
of the National Laboratory of Frascati, protected from internet
through
firewall.
On these VLANs is
possible to request:
- An
IP address on the internal
network , by compiling the form
- The
abilitation to use
DHCP
, by filling in a Trouble
Ticket. This service automatically supplies
all the network setting . For security reasons, on the
Laboratory's
VLANs the DHCP supplies the network information only to hosts who know
the IP address and MAC address
- LAN
external
connection,
called VLAN 131, is set outside the firewall. This one permits the
guest to connect to the global internet by using:
- Wireless
- Network
Cable,
in the
bulding where the VMPS services is set
On this VLAN 131
is active
a DHCP services that supplies all the network information to the guests
without the computing service knowing the MAC address.
When the guest
uses
the external LAN, he can connect to the internal VLANs in this way:
- By SSH axcalc.lnf.infn.it or
dxcalc.lnf.infn.it,
so it is
possible to check your E-Mail account through PINE;
- Print on the internal printer in LPR mode;
- Use an AFS Client when you want to transfer
files.
VMPS VLAN Management Policy Server
This feature is
typical
for users that connect to the network by Ethernet Cable. The VMPS
service
authenticates the hosts by directing them on VLAN through the MAC
address
or Physical address. When the guest hosts connect to the network by
cable
and don't trasmit the MAC Address or Physical Address to the computing
service they will be directed on the LAN external connection or VLAN
131.
If the guest hosts
want to use this feauture, they must follow these conditions:
- Set
DHCP
on the network property;
- The
connection
to the
network by cable straight through the socket without using HUB.
Author: Angelo Veloce
[
LNF |
Computing
|
Networking ]