10-73
IPv4 Access Control Lists (ACLs)
Configuring Extended ACLs
Example of a Named, Extended ACL.
Suppose that you want to imple-
ment these policies on a switch configured for IPv4 routing and membership
in VLANs 10, 20, and 30:
A.
Permit Telnet traffic from 10.10.10.44 to 10.10.20.78, deny all other IPv4
traffic from network 10.10.10.0 (VLAN 10) to 10.10.20.0 (VLAN 20), and
permit all other IPv4 traffic from any source to any destination. (See “A”
in figure 10-18, below.)
B.
Permit FTP traffic from 10.10.20.100 (on VLAN 20) to 10.10.30.55 (on
VLAN 30). Deny FTP traffic from other hosts on network10.10.20.0 to any
destination, but permit all other IPv4 traffic.
Figure 10-18. Example of an Extended ACL
VLAN 10
10.10.10.1
VLAN 20
10.10.20.1
VLAN 30
10.10.30.1
1
3
2
Switch
10.10.10.0
10.10.20.0
10.10.30.0
A
B
10.10.10.44
10.10.20.100
10.10.20.100
10.10.30.55
Summary of Contents for E3800 Series
Page 2: ......
Page 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Page 30: ...xxviii ...
Page 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Page 186: ...4 72 Web and MAC Authentication Client Status ...
Page 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Page 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 730: ...20 Index ...
Page 731: ......