background image

 

6

 

 

Out-interface—Interface through which the packet is forwarded normally. 

 

Dest-interface—ACFP server interface connected with ACFP client. 

 

Context ID—Used when the packet is mirrored or redirected to an ACFP client. After the interface 
connected to the ACFP client is specified in the policy sent, the ACFP server assigns it a global serial 

number (the Context ID) with each Context ID corresponding to an ACFP collaboration policy. 

 

Admin-Status—Indicates whether to enable the policy. 

 

Effect-Status—Indicates the expiration time of the policy and is used to control the expiration time of 
all the rules under the policy. 

 

Start-Time—Indicates starting from what time (second/minute/hour) the policy takes effect and is 
used to control starting from what time all the rules under the policy take effect. 

 

End-time—Indicates starting from what time (second/minute/hour) the policy turns invalid and is 
used to control starting from what time all the rules under the policy turn invalid. 

 

DestIfFailAction—If the policy dest-interface is down, the actions to all rules under the policy will be 
as follows: for forwarding first devices, select the delete action to keep the redirected and mirrored 

packets being forwarded; for security first devices, select the reserve action to discard the redirected 

and mirrored packets. 

 

Priority—Indicates the priority of a policy, number notation, in the range of 1 to 8. The bigger the 
number, the higher the priority. 

ACFP collaboration rules 

ACFP collaboration rules refer to the collaboration rules that the ACFP client sends to the ACFP server for 

application. Collaboration rules fall in the following types: 

 

Monitoring rules—Monitors, analyzes, and processes the packets to be sent to the ACFP client. The 
action types corresponding to monitoring rules are 

redirect

 and 

mirror

 

Filtering rules—Determines which packets to deny and which packets to permit. The action types 
corresponding to filtering rules are 

deny

 and 

permit

 

Restricting rules—Determines the rate of which packets is to be restricted. The action type 
corresponding to restricting rules is 

rate

Rule information is described as follows: 

 

ClientID—ACFP client identifier. 

 

Policy index 

 

Rule index—Rule identifier. 

 

Status—Indicates whether the rule is applied successfully. 

 

Action—Can be mirror, redirect, deny, permit, or rate. 

 

Match all packets—Indicates whether to match all the packets. If yes, the following matching needs 
not be performed. 

 

Source MAC address 

 

Destination MAC address 

 

Starting VLAN ID 

 

Ending VLAN ID 

 

Protocol number in IP 

 

Source IP address 

 

Wildcard mask of source IP address 

Summary of Contents for s5800 series

Page 1: ...H3C S5820X S5800 Switch Series OAA Configuration Guide Hangzhou H3C Technologies Co Ltd http www h3c com Software version Release 1211 Document version 6W100 20110415...

Page 2: ...re Secware Storware NQA VVG V2 G Vn G PSPT XGbus N Bus TiGem InnoVision and HUASAN are trademarks of Hangzhou H3C Technologies Co Ltd All other trademarks that may be mentioned in this manual are the...

Page 3: ...the operating system of the OAP card and configure the ACFP and ACSEI protocols to exchange information between your switch and the OAP card This preface includes Audience Added and modified features...

Page 4: ...ment combination before the ampersand sign can be entered 1 to n times A line that starts with a pound sign is comments GUI conventions Convention Description Boldface Window names button names field...

Page 5: ...ances features specifications installation and removal of the pluggable 300W power modules available for the products PSR750 A PSR750 D Power Modules User Manual Describes the appearances features spe...

Page 6: ...lp you quickly set up and use your device with the minimum configuration S5800 Series Ethernet Switches Installation Manual S5820X Series Ethernet Switches Installation Manual Provides a complete guid...

Page 7: ...al Documents Provides hardware installation software upgrading and software feature configuration and maintenance documentation Products Solutions Provides information about products and technologies...

Page 8: ...the ACFP server switch 8 Enabling the ACFP server 8 Enabling the ACFP trap function 8 Displaying and maintaining ACFP 9 Configuring the ACFP client OAP card 9 ACSEI configuration 10 Introduction to AC...

Page 9: ...way the terminal display interface is switched from the command line interface CLI on the switch to the operating interface of the software system on the OAP card and you can manage the system and app...

Page 10: ...rd with the following command Follow the step below to restart an OAP card To do Use the command Remarks Restart the OAP card oap reboot slot slot number system system name Required Available in user...

Page 11: ...networking devices for cooperating to handle these services This gives full play to the advantages of respective manufacturers for better support of new services while reducing user investments The op...

Page 12: ...FP collaboration policy that contains information including inbound interface and outbound interface of the packet and collaboration rules When the packet received by the ACFP server is redirected or...

Page 13: ...irroring and redirect modes only The S5800 S5820X switches support carrying the preamble HGPlus as the context ID the HGPlus context only The above mentioned information indicates the collaboration ca...

Page 14: ...ckets being forwarded for security first devices select the reserve action to discard the redirected and mirrored packets Priority Indicates the priority of a policy number notation in the range of 1...

Page 15: ...d IP fragment Indicates whether the packet is an IP packet fragment Rate limit Row state You can use the collaboration policy to manage the collaboration rules that belong to it Using ACFP The S5800 a...

Page 16: ...CFP server acfp server enable Required Disabled by default Enabling the ACFP trap function To make ACFP work normally you must enable the device to send traps of the ACFP module After the trap functio...

Page 17: ...server display acfp server info begin exclude include regular expression Display the configuration information of an ACFP client display acfp client info client id begin exclude include regular expre...

Page 18: ...as the ACFP clients which run applications of other vendors and support the IPS Intrusion Prevention System IDS services For more information about ACFP see ACFP configuration in the OAA Configuratio...

Page 19: ...rts up and runs in the following procedures 1 Run the ACSEI client application to enable ACSEI client 2 Start up the device and enable the ACSEI server function on it 3 The ACSEI client multicasts reg...

Page 20: ...server enable Required Enter ACSEI server view acsei server Configure the monitoring timer for ACSEI server to monitor ACSEI client acsei timer monitor seconds Optional Five seconds by default Closing...

Page 21: ...client information display acsei client info client id begin exclude include regular expression Available in any view ACSEI client configuring OAP card As a function supported by the OAP card an ACSEI...

Page 22: ...ACSEI client configuring OAP card 13 ACSEI server configuration switch 1 1 C Configuring an OAP card 1 Configuring the ACFP client OAP card 9 Configuring the ACFP server switch 8 I Introduction to ACF...

Reviews: