10-125
IPv4 Access Control Lists (ACLs)
Enable ACL “Deny” Logging
Figure 10-55. Example of Using the Same ACL for VACL and RACL Applications
In the above case:
■
Matches with ACEs 10 or 20 that originate on VLAN 20 will increment
only the counters for the instances of these two ACEs in the Test-1
VACL assignment on VLAN 20. The same counters in the instances of
ACL Test-1 assigned to VLANs 50 and 70 will not be incremented.
■
Any Telnet requests to 10.10.20.12 that originate on VLANs 50 or 70
will be filtered by instances of Test-1 assigned as RACLs, and will
increment the counters for ACE 10 on both RACL instances of the
Test-1 ACL.
Using the network in figure 10-55, a device at 10.10.20.4 on VLAN 20 attempting
to ping and Telnet to 10.10.20.12 is filtered through the VACL instance of the
“Test-1” ACL on VLAN 20 and results in the following:
Figure 10-56. Ping and Telnet from 10.10.20.4 to 10.10.20.2 Filtered by the
Assignment of “Test-1” as a VACL on VLAN 20
VLAN 20
10.10.20.1
VLAN 50
10.10.55.1
5400zl Switch
10.10.2
0.0
10.10.3
0.0
10.10.20.12
ACL “Test-1” assigned as an RACL
to both VLAN 50 and VLAN 70.
VLAN 70
10.10.70.1
10.10.7
0.0
ACL “Test-1” assigned as a VACL
to VLAN 20.
HP Switch(config)# ping 10.10.20.2
10.10.20.2 is alive, time = 5 ms
HP Switch(config)# telnet 10.10.20.2
Telnet failed: Connection timed out.
HP Switch(config)#
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......