150
ExtremeWare 7.2e Installation and User Guide
Security
Figure 25: ICMP packets are filtered out
Example 3: Rate-limiting Packets
This example creates a rate limit to limit the incoming traffic from the 10.10.10.x subnet to 10 Mbps on
ingress port 2. Ingress traffic on port 2 below the rate limit is sent to QoS profile qp1 with its DiffServ
code point set to 7. Ingress traffic on port 2 in excess of the rate limit will be dropped.
The commands to create this rate limit is as follows:
create access-mask port2_mask source-ip/24 ports precedence 100
create rate-limit port2_limit port2_mask source-ip 10.10.10.0/24 port 2 permit qp1 set
code-point 7 limit 10 exceed-action drop
Network Login
Network Login is a feature designed to control the admission of user packets into a network by giving
addresses only to users that have been properly authenticated. Network Login is controlled by an
administrator on a per port, per VLAN basis. When Network Login is enabled on a port in a VLAN,
that port will not forward any packets until authentication takes place.
Once Network Login has been enabled on a switch port, that port is placed in a non-forwarding state
until authentication takes place. To authenticate, a user (supplicant) must provide the appropriate
credentials. These credentials are either approved, in which case the port is placed in forwarding mode,
or not approved, and the port remains blocked. The user logout can be initiated by FDB aging or by
submitting a logout request.
There are two types of authentication available to use with Network Login: web-based or 802.1x. There
are also two different modes of operation available to use with Network Login: Campus mode and ISP
mode. The authentication types and modes of operation can be used in any combination. The following
sections describe these choices.
ES4K011
10.10.10.1
10.10.10.100
10.10.20.100
10.10.20.1
NET20 VLAN
NET10 VLAN
ICMP
Summary of Contents for ExtremeWare 7.2e
Page 14: ...14 ExtremeWare 7 2 0 Software User Guide Contents...
Page 18: ...18 ExtremeWare 7 2e Installation and User Guide Preface...
Page 80: ...80 ExtremeWare 7 2e Installation and User Guide Accessing the Switch...
Page 102: ...102 ExtremeWare 7 2e Installation and User Guide Virtual LANs VLANs...
Page 108: ...108 ExtremeWare 7 2e Installation and User Guide Forwarding Database FDB...
Page 180: ...180 ExtremeWare 7 2e Installation and User Guide Security...
Page 194: ...194 ExtremeWare 7 2e Installation and User Guide Ethernet Automatic Protection Switching...
Page 218: ...218 ExtremeWare 7 2e Installation and User Guide Spanning Tree Protocol STP...
Page 248: ...248 ExtremeWare 7 2e Installation and User Guide Interior Gateway Protocols...
Page 256: ...256 ExtremeWare 7 2e Installation and User Guide IP Multicast Routing...
Page 308: ...308 ExtremeWare 7 2e Installation and User Guide Using ExtremeWare Vista on the Summit 400...
Page 316: ...316 ExtremeWare 7 2e Installation and User Guide Technical Specifications...
Page 324: ...324 ExtremeWare 7 2e Installation and User Guide Software Upgrade and Boot Options...