ProCurve 6200yl User's Guide Page 308

  • Download
  • Add to my manuals
  • Print
  • Page
    / 596
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 307
10-22
Access Control Lists (ACLs)
Overview
An RACL that denies inbound IP traffic having a destination on the
10.28.10.0 subnet
In this case, no IP traffic received on the switch from clients on the 10.28.20.0
subnet will reach the 10.28.10.0 subnet, even though the VACL allows such
traffic. This is because the deny in the RACL causes the switch to drop the
traffic regardless of whether any other VACLs permit the traffic.
Figure 10-4. Example of Order of Application for Multiple ACLs on an Interface
Exception for Mirrored IP Traffic. If ACL mirroring is configured along
with one or more of the above ACL applications on the same interface, the
mirroring action occurs regardless of the effect of other ACLs on the packets
that match the mirror criteria. This means, for example, that if a dynamic port
ACL denies a packet that also meets the mirror ACL criteria for forwarding to
the configured mirror destination, the packet will be mirrored even though it
will not be forwarded to its intended destination.
Exception for Connection-Rate Filtering. Connection-rate filtering can
be configured along with one or more other ACL applications on the same
interface. In this case, a connection-rate match for a filter action is carried out
according to the configured policy, regardless of whether any other ACLs on
the interface have a match for a deny action. Also, if a connection-rate filter
permits (ignore action) a packet, it can still be denied by another ACL on the
interface.
Features Common to All ACL Applications
Any ACL can have multiple entries (ACEs).
VLAN 1
10.28.10.1
(One Subnet)
VLAN 2 with a VACL and
an RACL
10.28.20.1
VLAN 3
(Multiple Subnets)
10 .28 .40.1 10. 28. 30. 1
Switch with IP Routing Enabled
10.28.10.5
10.28.20.99
10.28.30.33
Subnet Mask: 255.255.255.0.
RACL on VLAN2 denies IP
traffic having a destination on
the 10.28.10.0 subnet.
VACL on VLAN2 permits IP
traffic having a destination on
the 10.28.10.0 subnet.
Because the RACL on VLAN 2
denies traffic entering the
switch for the 10,28.10.0
subnet destination, no IP
traffic received inbound from
clients on the 10.28.20.0 subnet
will reach the 10.28.10.0
subnet, even though the VACL
permits this traffic.
10.28.40.22
A
D
C
E
10.28.20.88
B
Page view 307
1 2 ... 303 304 305 306 307 308 309 310 311 312 313 ... 595 596

Comments to this Manuals

No comments