Beruflich Dokumente
Kultur Dokumente
• Provide access between FTE community subnets, by grouping servers into an IP address range that
can be
separated from other level 2 nodes using a subnet mask, as discussed in Section 8.
• Provide a routed interface into level 3. Use of VLANs on the level 3/level 2 interface can cause spanning
tree issues and is hence not allowed. However, DO NOT configure IP Proxy-ARP on the routed interface.
Note that, this is often enabled by default and you must explicitly disable it.
• The use of unicast for DSA keepalive messages is the recommended best practice.
• If you must use multicast, which is not recommended, enable IP multicast routing for the DSA multicast
address of 225.7.4.103, and create an access-list filter to allow only this multicast address to pass to the
FTE
subnets. Redirection Manager can use multicast addresses as described in the “Using Redirection
Manager
(RDM) with Level 3” on page 49.
• Configure each FTE subnet to be in a separate VLAN, which protects the FTE community from
unintended
access by other nodes on the router.
• Connect only switch A (yellow tree) to the router. If multiple connections to level 3 are needed, refer to
“Best practice for multiple connections from level 2 to level 3” on page 49.
• Configure access list filters for the FTE communities that have the following:
– Allow complete access only to the server IP range.
– Allow established access to the remainder of the FTE subnet.
– Deny all other access to the FTE subnet.
• If SFP/GBIC connections are not used, configure the FTE switch’s router interfaces for 100-megabit full
duplex.
Attention
The router must be connected to a switch interface configured as an uplink port, or to a SFP/GBIC based interface.
• Place each FTE community in a separate subnet. If the level 2 interconnecting device (level 3
switch/router)
is a level 3 switch that uses routing functionality, separate VLANs must be configured for each subnet.
5.2.2 Using Redirection Manager (RDM) with Level 3
Honeywell’s Redirection Manager can use the FTE multicast test message multicast from the servers to
keep
track of when the primary OPC server goes off line. Honeywell recommends to only use the multicast
when the
OPC client is in the same FTE community as the servers. When the OPC client resides in level 3, or when
the
client is in another FTE community, a mechanism using ICMP must be selected. In this case, ICMP must
be
allowed between level 3 nodes and subnets.
5 LEVEL 3 NODES
37
6 Level 4 nodes
Related topics
“About level 4 nodes” on page 42
“Level 4 best practices” on page 43
“Implementing Level 4 Best Practices” on page 44
41