10-126
IPv4 Access Control Lists (ACLs)
Enable ACL “Deny” Logging
Figure 10-57. Resulting ACE Hits on ACL “Test-1”
However, using a device at 10.10.30.11 on VLAN 50 for attempts to ping and
Telnet to 10.10.20.12 requires routing, and filters the attempts through the
RACL instance of the “Test-1” ACL on VLAN 50.
Figure 10-58. Ping and Telnet from 10.10.30.11 to 10.10.20.2 Filtered by the
Assignment of “Test-1” as a RACL on VLAN 30
This action has an identical effect on the counters in all RACL instances of the
“Test-1” ACL configured and assigned to interfaces on the same switch. In this
example, it means that the RACL assignments of “Test-1” on VLANs 50 and 70
will be incremented by the above action occurring on VLAN 50.
HP Switch(config)# show statistics aclv4 Test-1 vlan 20 vlan
Hit Counts for ACL Test-1
Total
( 5) 10 deny tcp 0.0.0.0 255.255.255.255 10.10.20.2 0.0.0.0 eq 23 log
( 2) 20 permit ip 0.0.0.0 255.255.255.255 0.0.0.0 255.255.255.255
HP Switch# show statistics aclv4 Test-1 vlan 50 in
Hit Counts for ACL Test-1
Total
( 0) 10 deny tcp 0.0.0.0 255.255.255.255 10.10.20.2 0.0.0.0 eq 23 log
( 0) 20 permit ip 0.0.0.0 255.255.255.255 0.0.0.0 255.255.255.255
Indicates denied attempts to Telnet to 10.10.20.12 filtered by the instance of the “Test-1” VACL
assignment on VLAN 20.
Indicates permitted attempts to reach any accessible destination via the instance of the “Test-
1” VACL assignment on VLAN 20. In this example, shows the succesful pings permitted by ACE 20.
Shows that the hits on the instance of the “Test-1” VACL assignment on VLAN 20
have no effect on the counters for the RACL assignment of “Test-1” on VLAN 50.
HP Switch# ping 10.10.20.2
10.10.20.2 is alive, time = 25 ms
HP Switch# telnet 10.10.20.2
Telnet failed: Connection timed out.
HP Switch#
Summary of Contents for E3800 Series
Page 2: ......
Page 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Page 30: ...xxviii ...
Page 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Page 186: ...4 72 Web and MAC Authentication Client Status ...
Page 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Page 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 730: ...20 Index ...
Page 731: ......