10-2
IPv4 Access Control Lists (ACLs)
Introduction
IPv4 filtering with ACLs can help improve network performance and restrict
network use by creating policies for:
■
Switch Management Access:
Permits or denies in-band manage-
ment access. This includes limiting and/or preventing the use of
designated protocols that run on top of IPv4, such as TCP, UDP, IGMP,
ICMP, and others. Also included are the use of precedence and ToS
criteria, and control for application transactions based on source and
destination IPv4 addresses and transport layer port numbers.
■
Application Access Security:
Eliminates unwanted traffic in a path
by filtering IPv4 packets where they enter or leave the switch on
specific VLAN interfaces.
IPv4 ACLs can filter traffic to or from a host, a group of hosts, or entire subnets.
N o t e s
IPv4 ACLs can enhance network security by blocking selected traffic, and can
serve as part of your network security program.
However, because ACLs do
not provide user or device authentication, or protection from malicious
manipulation of data carried in IPv4 packet transmissions, they should not
be relied upon for a complete security solution
.
IPv4 ACLs on the switches covered by this manual do not filter non-IPv4 traffic
such as IPv6, AppleTalk, and IPX packets.
Configure an ACL from a TFTP Server
n/a
Enable ACL Logging
n/a
Feature
Default
CLI
Summary of Contents for E3800 Series
Page 2: ......
Page 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Page 30: ...xxviii ...
Page 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Page 186: ...4 72 Web and MAC Authentication Client Status ...
Page 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Page 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 730: ...20 Index ...
Page 731: ......