
V6100 and V7122 User Guide
347
Figure 124
Example of an Access List Definition via
ini
File
[ ACCESSLIST ]
FORMAT AccessList_Index = AccessList_Source_IP, AccessList_Net_Mask,
AccessList_Start_Port, AccessList_End_Port, AccessList_Protocol,
AccessList_Packet_Size, AccessList_Byte_Rate, AccessList_Byte_Burst,
AccessList_Allow_Type;
AccessList 10 = mgmt.customer.com, 255.255.255.255, 0, 80, tcp, 0, 0, 0, allow
;
AccessList 15 = 192.0.0.0, 255.0.0.0, 0, 65535, any, 0, 40000, 50000, block ;
AccessList 20 = 10.31.4.0, 255.255.255.0, 4000, 9000, any, 0, 0, 0, block ;
AccessList 22 = 10.4.0.0, 255.255.0.0, 4000, 9000, any, 0, 0, 0, block ;
[ \ACCESSLIST ]
Explanation of the example access list:
Rule #10: traffic from the host ‘mgmt.customer.com’ destined to TCP ports 0 to 80, is
always allowed.
Rule #15: traffic from the 192.xxx.yyy.zzz subnet, is limited to a rate of 40 Kbytes per
second (with an allowed burst of 50 Kbytes). Note that the rate is specified in bytes, not
bits, per second; a rate of 40000 bytes per second, nominally corresponds to 320 kbps.
Rule #20: traffic from the subnet 10.31.4.xxx destined to ports 4000 to 9000 is always
blocked, regardless of protocol.
Rule #22: traffic from the subnet 10.4.xxx.yyy destined to ports 4000 to 9000 is always
blocked, regardless of protocol.
All other traffic is allowed.
More complex rules may be defined, relying on the ‘single-match’ process described above:
Figure 125
shows an advanced example of an access list definition via
ini
file:
Figure 125
Advanced Example of an Access List Definition via
ini
File
[ ACCESSLIST ]
FORMAT AccessList_Index = AccessList_Source_IP, AccessList_Net_Mask,
AccessList_Start_Port, AccessList_End_Port, AccessList_Protocol,
AccessList_Packet_Size, AccessList_Byte_Rate, AccessList_Byte_Burst,
AccessList_Allow_Type;
AccessList 10 = 10.0.0.0, 255.0.0.0, 0, 65535, any, 0, 40000, 50000, allow ;
AccessList 15 = 10.31.4.0, 255.255.255.0, 4000, 9000, any, 0, 0, 0, allow ;
AccessList 20 = 0.0.0.0, 0.0.0.0, 0, 65535, any, 0, 0, 0, block;
[ \ACCESSLIST ]
Summary of Contents for TP-1610
Page 28: ...28 V6100 and V7122 User Guide Reader s Notes ...
Page 48: ...48 V6100 and V7122 User Guide Reader s Notes ...
Page 72: ...72 V6100 and V7122 User Guide Reader s Notes ...
Page 80: ...80 V6100 and V7122 User Guide Reader s Notes ...
Page 152: ...152 V6100 and V7122 User Guide Reader s Notes ...
Page 262: ...262 V6100 and V7122 User Guide Reader s Notes ...
Page 284: ...284 V6100 and V7122 User Guide Reader s Notes ...
Page 291: ...V6100 and V7122 User Guide 291 Figure 95 V7122 Startup Process ...
Page 324: ...324 V6100 and V7122 User Guide Reader s Notes ...
Page 354: ...354 V6100 and V7122 User Guide Reader s Notes ...
Page 374: ...374 V6100 and V7122 User Guide Reader s Notes ...
Page 382: ...382 V6100 and V7122 User Guide Figure 130 Example of a User Information File Reader s Notes ...
Page 392: ...392 V6100 and V7122 User Guide Reader s Notes ...
Page 409: ...V6100 and V7122 User Guide 409 Reader s Notes ...
Page 413: ...V6100 and V7122 User Guide 413 Reader s Notes ...
Page 425: ...V6100 and V7122 User Guide 425 Figure 145 UDP2File Utility Reader s Notes ...
Page 431: ...V6100 and V7122 User Guide 431 Reader s Notes ...
Page 447: ...V6100 and V7122 User Guide 447 Reader s Notes ...
Page 483: ...V6100 and V7122 User Guide 483 Reader s Notes ...