10-123
IPv4 Access Control Lists (ACLs)
Enable ACL “Deny” Logging
Figure 10-51. Application to Filter Traffic Inbound on Port B2
Using the topology in figure 10-51, a workstation at FE80::20:117 on port B2
attempting to ping and Telnet to the workstation at FE80::20:2 is filtered
through the PACL instance of the “V6-01” ACL assigned to port B2, resulting
in the following:
Figure 10-52. Ping and Telnet from FE80::20:117 to FE80::20:2 Filtered by the
Assignment of “V6-01” as a PACL on Port B2
Figure 10-53. Resulting ACE Hits on ACL “V6-01”
FE80::20:2
ACL “V6-01” assigned as
a PACL on port B2.
VLAN 20
FE80::20:1
5400zl Switch
FE80::20:117
Port
B2
HP Switch# ping6 fe80::20:2%vlan20
fe80:0000:0000:0000:0000:0000:0020:0002 is alive, time = 5 ms
HP Switch# telnet fe80::20:2%vlan20
Telnet failed: Connection timed out.
HP Switch#
HP Switch# show statistics aclv6 IP-01 port b2
Hit Counts for ACL IPV6-ACL
Total
( 1) 10 permit icmp fe80::20:3/128 fe80::20:2/128 128
( 5) 20 deny tcp ::/0 fe80::20:2/128 eq 23 log
( 4) 30 permit ipv6 ::/0 ::/0
HP Switch#
Indicates denied attempts to Telnet to FE80::20:2 via the instance of the “V6-
01” PACL assignment on port B2.
Shows the succesful ping permitted by ACE 10.
Indicates permitted attempts to reach any accessible destination via the
instance of the “V6-01” PACL assignment on port B2.
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......