ProCurve 6200yl User's Guide Page 301

  • Download
  • Add to my manuals
  • Print
  • Page
    / 596
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 300
10-15
Access Control Lists (ACLs)
Overview
Overview
Types of IP ACLs
A permit or deny policy for IP traffic you want to filter can be based on source
IP address alone, or on source IP address plus other IP factors.
Standard ACL: Use a standard ACL when you need to permit or deny IP
traffic based on source IP address only. Standard ACLs are also useful when
you need to quickly control a performance problem by limiting IP traffic from
a subnet, group of devices, or a single device. (This can block all IP traffic
from the configured source, but does not hamper IP traffic from other sources
within the network.) A standard ACL uses an alphanumeric ID string or a
numeric ID of 1 through 99. You can specify a single host, a finite group of
hosts, or any host.
Extended ACL: Use an extended ACL when simple IP source address
restrictions do not provide the sufficient IP traffic selection criteria needed
on an interface. Extended ACLs allow use of the following criteria:
source and destination IP address combinations
IP protocol options
Extended, named ACLs also offer an option to permit or deny IP connections
using TCP for applications such as Telnet, http, ftp, and others.
Connection-Rate ACL. An optional feature used with Connection-Rate fil-
tering based on virus-throttling technology. Refer to the chapter 3, “Virus
Throttling”.
ACL Applications
ACL filtering is applied to IP traffic as follows:
Routed ACL (RACL)— on a VLAN configured with an RACL:
routed IP traffic entering or leaving the switch. (Routing can be
between different VLANs or between different subnets in the same
VLAN. IP routing must be enabled.)
routed IP traffic having a destination address (DA) on the switch
itself. In figure 10-1 on page 10-17, this is any of the IP addresses
shown in VLANs “A”, “B”, and “C”. (IP routing need not be enabled.)
Page view 300
1 2 ... 296 297 298 299 300 301 302 303 304 305 306 ... 595 596

Comments to this Manuals

No comments