ProCurve 6200yl User's Guide Page 81

  • Download
  • Add to my manuals
  • Print
  • Page
    / 596
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 80
3-21
Virus Throttling
Configuring and Applying Connection-Rate ACLs
Figure 3-8. Connection-Rate ACL Applied to Traffic Received Through a Given Port
Configuring a Connection-Rate ACL Using
Source IP Address Criteria
(To configure a connection-rate ACL using UDP/TCP criteria, go to page 3-23.)
Syntax: ip access-list connection-rate-filter < crf-list-name >
Creates a connection-rate-filter ACL and puts the CLI
into the access control entry (ACE) context:
ProCurve(config-crf-nacl)#
If the ACL already exists, this command simply puts the
CLI into the ACE context.
Syntax: < filter | ignore > ip < any | host < ip-addr > | ip-addr < mask-length > >
Used in the ACE context (above) to specify the action of
the connection-rate ACE and the source IP address of the
traffic that the ACE affects.
Inbound IP traffic from Host “A”
with relatively high number of IP
connection-rate attempts
Source Match
on any ACE in
the ACL?
Ignore
or
Filter?
Apply per-port connection-rate
policy to Host “A” traffic:
–Notify-Only
Throttle
–Block
Apply Implicit ACE
(filter)
Filter
Allow traffic from Host
“A” without filtering
through per-port
connection-rate policy
No
Yes
Ignore
Page view 80
1 2 ... 76 77 78 79 80 81 82 83 84 85 86 ... 595 596

Comments to this Manuals

No comments