![HP HP ProCurve Series 6600 Access Security Manual Download Page 440](http://html.mh-extra.com/html/hp/hp-procurve-series-6600/hp-procurve-series-6600_access-security-manual_163101440.webp)
10-20
IPv4 Access Control Lists (ACLs)
Overview
N o t e
In cases where an RACL and any type of port or VLAN ACL are filtering traffic
entering the switch, the
switched
traffic explicitly permitted by the port or
VLAN ACL is not filtered by the RACL (except where the traffic has a
destination on the switch itself). However,
routed
traffic explicitly permitted
by the port or VLAN ACL (and any switched traffic having a destination on the
switch itself) must also be explicitly permitted by the RACL, or it will be
dropped.
Also, a switched packet is not affected by an outbound RACL assigned to the
VLAN on which the packet exits from the switch.
Beginning with software release K.14.01, static ACL mirroring and static ACL
rate-limiting are deprecated in favor of classifier-based mirroring and rate-
limiting features that do not use ACLs. If ACL mirroring or ACL rate-limiting
are already configured in a switch running software version K.13.
xx
, then
downloading and booting from release K.14.01 or greater automatically mod-
ifies the deprecated configuration to conform to the classifier-based mirroring
and rate-limiting supported in release K.14.01 or greater. For more information
on this topic, refer to the chapter titled “Classifier-Based Software Configura-
tion” in the latest
Advanced Traffic Management Guide
for your switch.
For information on traffic mirroring refer to the appendix titled “Monitoring
and Analyzing Switch Operation” in the
Management and Configuration
Guide
for your switch.
For a Packet To Be Permitted, It Must Have a Match with a “Permit”
ACE in All Applicable ACLs Assigned to an Interface.
On a given inter-
face where multiple ACLs apply to the same traffic, a packet having a match
with a
deny
ACE in any applicable ACL on the interface (including an implicit
deny any
) will be dropped.
For example, suppose the following is true:
■
Port A10 belongs to VLAN 100.
■
A static port ACL is configured on port A10.
■
A VACL is configured on VLAN 100.
■
An RACL is also configured for inbound, routed traffic on VLAN 100.
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......