![HP HP ProCurve Series 6600 Access Security Manual Download Page 436](http://html.mh-extra.com/html/hp/hp-procurve-series-6600/hp-procurve-series-6600_access-security-manual_163101436.webp)
10-16
IPv4 Access Control Lists (ACLs)
Overview
VACL Applications
VACLs filter any IPv4 traffic entering the switch on a VLAN configured with
the “VLAN” ACL option.
vlan <
vid
> ip access-group <
identifier
> vlan
For example, in figure 10-2, you would assign a VACL to VLAN 2 to filter all
inbound switched or routed IPv4 traffic received from clients on the 10.28.20.0
network. In this instance, routed traffic received on VLAN 2 from VLANs 1 or
3 would not be filtered by the VACL on VLAN 2.
Figure 10-2. Example of VACL Filter Application to IPv4 Traffic Entering the Switch
N o t e
The switch allows one VACL assignment configured per VLAN. This is in
addition to any other ACL applications assigned to the VLAN or to ports in the
VLAN.
Static Port ACL and RADIUS-Assigned ACL Applications
An IPv4 static port ACL filters any IPv4 traffic inbound on the designated port,
regardless of whether the traffic is switched or routed.
VLAN 1
10.28.10.1
(One Subnet)
VLAN 2 with VACL
(One Subnet)
10.28.20.1
VLAN 3
(Multiple Subnets)
10.28.40.1 10.28.30.1
Switch with IPv4 Routing
Enabled
10.28.10.5
10
.2
8.
20
.9
9
10.28.30.3
3
The subnet mask for this
example is 255.255.255.0.
Configuring a VACL on VLAN
2 filters the inbound IPv4
traffic from clients B and, C
for all switched and routed
destinations on all VLANs on
the switch. Traffic routed
from VLANs 1 and 3 to VLAN
2 is not filtered by the VACL
on VLAN 2 because the
configured VACL applies
only to IPv4 traffic entering
the switch on VLAN 2 (and
not from traffic routed from
other VLANs configured on
the switch.)
10.28.40.22
A
D
C
E
10.28.20.88
B
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......