ProCurve 6200yl User's Guide Page 302

  • Download
  • Add to my manuals
  • Print
  • Page
    / 596
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 301
10-16
Access Control Lists (ACLs)
Overview
outbound traffic generated by the switch itself.
VLAN ACL (VACL): on a VLAN configured with a VACL, any inbound
IP traffic, regardless of whether it is switched or routed. On a multi-
netted VLAN, this includes all inbound IP traffic from any subnet.
Static port ACL: any inbound IP traffic on that port.
Dynamic port ACL: on a port having an ACL assigned by a RADIUS
server to filter an authenticated client’s IP traffic, any inbound IP
traffic from that client
(For information on RADIUS-assigned ACLs, refer to chapter 7,
“Configuring RADIUS Server Support for Switch Services”.)
ACL Mirroring: applies an ACL to a port or VLAN to mirror selected
IP traffic to a mirror destination. In this context, a permit ACE means
to mirror the specified IP traffic; a deny ACE means to avoid mirroring.
(A log keyword in a deny ACE is ignored when the associated ACL is
used for mirroring.) Refer to “Local and Remote Traffic Mirroring” in
the appendix titled “Monitoring and Analyzing Switch Operation” in
the Management and Configuration Guide for your switch.
Connection-Rate ACL: An optional feature used with Connection-
Rate filtering based on virus-throttling technology. Refer to the
chapter 3, “Virus Throttling”.
RACL Applications
RACLs filter routed IP traffic entering or leaving the switch on VLANs config-
ured with the “in” and/or “out” ACL option
vlan < vid > ip access-group < identifier > < in | out >
For example, in figure 10-1:
You would assign either an inbound ACL on VLAN 1 or an outbound
ACL on VLAN 2 to filter a packet routed between subnets on different
VLANs; that is, from the workstation 10.28.10.5 on VLAN 1 to the
server at 10.28.20.99 on VLAN 2. (An outbound ACL on VLAN 1 or an
inbound ACL on VLAN 2 would not filter the packet.)
Where multiple subnets are configured on the same VLAN, then you
can use either inbound or outbound ACLs to filter routed IP traffic
between the subnets on the VLAN if the traffic source and destination
IP addresses are on devices external to the switch.
Page view 301
1 2 ... 297 298 299 300 301 302 303 304 305 306 307 ... 595 596

Comments to this Manuals

No comments