
588
C
HAPTER
22: Q
O
S
AND
RSVP
Figure 68 shows an example with TCP drop control disabled.
Figure 68
QoS Control Action (Drop Control Disabled)
With the QoS Classifier and QoS Control definition shown in Figure 68
(TCP control is not enabled), any attempt by a client on the End-user
network to establish a TCP connection to a server on the Admin network
fails.
This next example illustrates how TCP one-way-filtering can be effective.
Figure 69 shows the same situation, but with TCP drop control enabled to
filter only those packets with the SYN=1 and ACK=0 signature.
Figure 69
QoS Control Action (Drop Control Enabled)
QoS Classifier:
Source IP:
0.0.0.0
Destination IP:
10.1.1.0
QoS Control Action:
Drop all
10.1.1.254 10.1.2.254
Admin
End-user
network
QoS Classifier:
Source IP:
0.0.0.0
Destination IP:
10.1.1.0
QoS Control Action:
Drop only
(SYN=1, ACK=0)
10.1.1.254 10.1.2.254
Admin
End-user
network
Summary of Contents for 4007
Page 36: ...36 ABOUT THIS GUIDE ...
Page 37: ...I UNDERSTANDING YOUR SWITCH 4007 SYSTEM Chapter 1 Configuration Overview ...
Page 38: ......
Page 50: ...50 CHAPTER 1 CONFIGURATION OVERVIEW ...
Page 52: ......
Page 70: ...70 CHAPTER 3 INSTALLING MANAGEMENT MODULES ...
Page 110: ...110 CHAPTER 4 CONFIGURING AND USING EME OPTIONS ...
Page 130: ...130 CHAPTER 5 MANAGING THE CHASSIS POWER AND TEMPERATURE ...
Page 222: ...222 CHAPTER 11 IP MULTICAST FILTERING WITH IGMP ...
Page 240: ...240 CHAPTER 13 RESILIENT LINKS ...
Page 304: ...304 CHAPTER 14 VIRTUAL LANS VLANS ...
Page 350: ...350 CHAPTER 15 PACKET FILTERING ...
Page 506: ...506 CHAPTER 19 OPEN SHORTEST PATH FIRST OSPF ROUTING ...
Page 534: ...534 CHAPTER 20 IPX ROUTING ...
Page 612: ...612 CHAPTER 22 QOS AND RSVP ...
Page 656: ...656 CHAPTER 23 DEVICE MONITORING ...
Page 657: ...IV REFERENCE Appendix A Technical Support Index ...
Page 658: ......
Page 664: ......