IPv4 Access Control Lists (ACLs)
Monitoring Static ACL Performance
ACE Counter Operation:
For a given ACE in an assigned
ACL, the counter increments by 1 each time the switch detects
a packet that matches the criteria in that ACE, and maintains
a running total of the matches since the last counter reset.
For example, in ACL line 10 below, there has been a total of 37
matches on the ACE since the last time the ACL’s counters were
reset.
Total
(
37)
10 permit icmp 10.10.20.3
Note:
This ACL monitoring feature does not include hits on
the “implicit deny” that is included at the end of all ACLs.
Resetting ACE Hit Counters to Zero:
• Removing an ACL from an interface zeros the ACL’s ACE
counters for that interface only.
• For a given ACL, either of the following actions clear the ACE
counters to zero for all interfaces to which the ACL is
assigned.
– adding or removing a permit or deny ACE in the ACL
– rebooting the switch
9-93
Summary of Contents for PROCURVE 2910AL
Page 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Page 2: ......
Page 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Page 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Page 156: ...TACACS Authentication Operating Notes 4 30 ...
Page 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Page 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Page 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Page 592: ...12 Index ...
Page 593: ......