10-124
IPv4 Access Control Lists (ACLs)
Enable ACL “Deny” Logging
has multiple assignments as an RACL, then a match with an ACE in any RACL
instance of the ACL increments that same counter on all RACL-assigned
instances of that ACL. (The ACE counters for VACL and PACL instances of an
ACL are not affected by counter activity in RACL instances of the same ACL.)
For example, suppose that an IPv4 ACL named “Test-1” is configured as shown
in figure 10-54 to block Telnet access to a server at 10.10.20.12 on VLAN 20,
and that the Test-1 ACL is assigned to VLANs as follows:
■
VLAN 20: VACL
■
VLAN 50: RACL
■
VLAN 70: RACL
Figure 10-54. ACL “Test-1” and Interface Assignment Commands
Figure 10-55. Example of Using the Same ACL for VACL and RACL Applications
HP Switch(config)# show access-list config
ip access-list extended “Test1”
10 deny tcp 0.0.0.0 255.255.255.255 10.10.20.12 0.0.0.0 eq 23 log
20 permit ip 0.0.0.0 255.255.255.255 0.0.0.0 255.255.255.255
exit
HP Switch(config)# vlan 20 ip access-group Test-1 vlan
HP Switch(config)# vlan 50 ip access-group Test-1 in
HP Switch(config)# vlan 70 ip access-group Test-1 in
Assigns the ACL as a VACL to VLAN 20.
Assigns the ACL as
an RACL to VLANs
50 and 70.
VLAN 20
10.10.20.1
VLAN 50
10.10.55.1
5400zl Switch
10.10.2
0.0
10.10.3
0.0
10.10.20.12
ACL “Test-1” assigned as an RACL
to both VLAN 50 and VLAN 70.
VLAN 70
10.10.70.1
10.10.7
0.0
ACL “Test-1” assigned as a VACL
to VLAN 20.
Summary of Contents for E3800 Series
Page 2: ......
Page 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Page 30: ...xxviii ...
Page 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Page 186: ...4 72 Web and MAC Authentication Client Status ...
Page 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Page 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 730: ...20 Index ...
Page 731: ......