作者: Joseph J. Ekstrom , Stephen S. Moss , Thomas G. McNeill
DOI:
关键词: Network layer 、 Computer network 、 Data link layer 、 Layer (object-oriented design) 、 Access control 、 Computer science 、 Distributed computing 、 Network administrator 、 Virtual LAN 、 Domain (software engineering) 、 restrict
摘要: A network includes a number of domains ('layer 2 domains') interconnected by routers. Withing each domain, traffic is forwarded based on MAC addresses (or other data link layer addresses). The routes route IP or addresses. To restrict connectivity, administrator specifies connectivity groups which group sub-networks that are allowed to communicate. also entities (MAC addresses, ports, user names) belong the same group. may be in different domains. computer system automatically creates access control lists for routers allow deny as specified administrator. VLANs specified, wherein VLAN part domain whole domain. Connectivity within restricted and between lists.