ProCurve 6200yl User's Guide Page 67

  • Download
  • Add to my manuals
  • Print
  • Page
    / 596
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 66
3-7
Virus Throttling
Overview of Connection-Rate Filtering
Operating Rules
Connection-rate filtering is triggered by inbound IP traffic exhibiting
high rates of IP connections to new hosts. After connection-rate
filtering has been triggered on a port, all traffic from the suspect host
is subject to the configured connection-rate policy (notify-only, throttle,
or block).
When connection-rate filtering is configured on a port, the port cannot
be added to, or removed from, a port trunk group. Before this can be
done, connection-rate filtering must be disabled on the port.
Where the switch is throttling or blocking inbound IP traffic from a
host, any outbound traffic destined for that host is still permitted.
Once a throttle has been triggered on a port—temporarily blocking
inbound IP traffic—it cannot be undone during operation: the penalty
period must expire before traffic will be allowed from the host.
Unblocking a Currently Blocked Host
A host blocked by connection-rate filtering remains blocked until explicitly
unblocked by one of the following methods:
Using the connection-rate-filter unblock command (page 3-17).
Rebooting the switch.
Disabling connection-rate filtering using the no connection-rate-filter
command.
Deleting a VLAN removes blocks on any hosts on that VLAN.
Note Changing a port setting from block to throttle, notify-only, or to no filter connec-
tion-rate, does not unblock a currently blocked host. Similarly, applying a
connection-rate ACL will not unblock a currently blocked host. Refer to the
above list for the correct methods to use to unblock a host.
Page view 66
1 2 ... 62 63 64 65 66 67 68 69 70 71 72 ... 595 596

Comments to this Manuals

No comments