3-19
Virus Throttling (Connection-Rate Filtering)
Configuring and Applying Connection-Rate ACLs
Figure 3-6. Connection-Rate ACL Applied to Traffic Received Through a Given Port
Configuring a Connection-Rate ACL Using
Source IP Address Criteria
(To configure a connection-rate ACL using UDP/TCP criteria, go to page 3-21.)
Syntax:
ip access-list connection-rate-filter <
crf-list-name
>
Creates a connection-rate-filter ACL and puts the CLI
into the access control entry (ACE) context:
HP Switch(config-crf-nacl)#
If the ACL already exists, this command simply puts the
CLI into the ACE context.
Syntax:
< filter | ignore > ip < any | host <
ip-addr
> |
ip-addr
<
mask-length
> >
Used in the ACE context (above) to specify the action of
the connection-rate ACE and the source IP address of the
traffic that the ACE affects.
Inbound IP traffic from Host “A”
with relatively high number of IP
connection-rate attempts
Source Match
on any ACE in
the ACL?
Ignore
or
Filter?
Apply per-port connection-rate
policy to Host “A” traffic:
– Notify-Only
– Throttle
– Block
Apply Implicit ACE
(filter)
Filter
Allow traffic from Host
“A” without filtering
through per-port
connection-rate policy
No
Yes
Ignore
Summary of Contents for E3800 Series
Page 2: ......
Page 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Page 30: ...xxviii ...
Page 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Page 186: ...4 72 Web and MAC Authentication Client Status ...
Page 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Page 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 730: ...20 Index ...
Page 731: ......