ProCurve 6200yl User's Guide Page 303

  • Download
  • Add to my manuals
  • Print
  • Page
    / 596
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 302
10-17
Access Control Lists (ACLs)
Overview
Figure 10-1. Example of RACL Filter Applications on Routed IP Traffic
Notes The switch allows one inbound RACL assignment and one outbound RACL
assignment configured per VLAN. This is in addition to any other ACL assigned
to the VLAN or to any ports on the VLAN. You can use the same RACL or
different RACLs to filter inbound and outbound routed IP traffic on a VLAN.
RACLs do not filter IP traffic that remains in the same subnet from source to
destination (switched IP traffic) unless the destination IP address (DA) or
source IP address (SA) is on the switch itself.
VLAN 1
10.28.10.1
(One Subnet)
VLAN 3
10.28.40.1 10.28.30.1
(Multiple Subnets)
VLAN 2
10.28.20.1
(One Subnet)
Switch with IP Routing
Enabled
10.28.10.5
10.28.20.99
10.28.30.33
10.28.40.17
Because of multinetting, IP traffic routed from the 10.28.40.0 network to the 10.28.30.0 network, and the
reverse, remains in VLAN 3. This allows you to apply one inbound ACL to screen IP traffic arriving from
either subnet, and one outbound ACL to screen routed IP traffic going to either subnet.
The subnet mask for this
example is 255.255.255.0.
An ACL assigned to screen
routed, inbound IP traffic
on VLAN 1 screens only the
routed IP traffic arriving
from the 10.28.10.0
network. Screening routed
IP traffic inbound from the
10.28.20.0 network requires
assigning another ACL for
inbound IP traffic on VLAN
2.
Page view 302
1 2 ... 298 299 300 301 302 303 304 305 306 307 308 ... 595 596

Comments to this Manuals

No comments