396 Configuration example5510-48T(config)# ssh download-auth-key address10.20.20.20 key-name sac_key.1.pub5510-48T(config)# sshConfiguring the Nortel SNAS pVIP subnet5510-48T(config)# nsna nsnas 10.40.40.0/24Creating port-based VLANs5510-48T(config)# vlan create 210 type port5510-48T(config)# vlan create 220 type port5510-48T(config)# vlan create 230 type port5510-48T(config)# vlan create 240 type portConfiguring the VoIP VLANs5510-48T(config)# nsna vlan 240 color voipConfiguring the Red, Yellow, and Green VLANs5510-48T(config)# nsna vlan 210 color red filter red5510-48T(config)# nsna vlan 220 color yellow filter yellowyellow-subnet 10.120.120.0/245510-48T(config)# nsna vlan 230 color green filter greenConfiguring the login domain controller filtersATTENTIONThis step is optional.The PC client must be able to access the login domain controller you configure(that is, clients using the login domain controller must be able to ping thatcontroller).5510-48T(config)# qos nsna classifier name RED dst-ip10.200.2.12/32 ethertype 0x0800 drop-action disable blockwins-prim-sec eval-order 705510-48T(config)# qos nsna classifier name RED dst-ip10.200.224.184/32 ethertype 0x0800 drop-action disableblock wins-prim-sec eval-order 71Configuring the NSNA portsAdd the uplink port:5510-48T(config)# interface fastEthernet 205510-48T(config-if)# nsna uplink vlans 210,220,230,2405510-48T(config-if)# exitNortel Secure Network Access SwitchUsing the Command Line InterfaceNN47230-100 03.01 Standard28 July 2008Copyright © 2007, 2008 Nortel Networks.