494
C
HAPTER
17: Q
O
S
AND
RSVP
Specifying TCP Drop
Control
The TCP drop control option lets you create a control for packets used to
establish TCP connections. This control affects QoS Flow Classifiers that
have TCP traffic going from “source” IP addresses to “destination” IP
addresses.
TCP drop control does not function with nonflow classifiers or UDP. It is
only available for flow classifiers that include TCP.
Figure 83 illustrates how TCP handshaking works between the source
and destination to establish a connection. By dropping only the
initial
TCP
packet used to establish TCP connections (those packets containing a
signature of SYN=1, ACK=0), you can establish one-way TCP flow
filtering.
Figure 83
3-way TCP Handshake
Figure 84 shows an example with TCP drop control disabled.
Figure 84
QoS Control Action (Drop Control Disabled)
With the QoS Classifier and QoS Control definition shown in Figure 84
(TCP control is not enabled), any attempt by a client on the End-user
network to establish a TCP connection to a server on the Admin network
fails.
SYN=1, ACK=0
SYN=1, ACK=1
SYN=0, ACK=1
Destination
Source
QoS Classifier:
Source IP:
0.0.0.0
Destination IP:
10.1.1.0
QoS Control Action:
Drop all
10.1.1.254 10.1.2.254
Admin
End-user
network
Содержание CoreBuilder 3500
Страница 44: ...44 CHAPTER 2 MANAGEMENT ACCESS ...
Страница 58: ...58 CHAPTER 3 SYSTEM PARAMETERS ...
Страница 86: ...86 CHAPTER 5 ETHERNET ...
Страница 112: ...112 CHAPTER 6 FIBER DISTRIBUTED DATA INTERFACE FDDI ...
Страница 208: ...208 CHAPTER 9 VIRTUAL LANS ...
Страница 256: ...256 CHAPTER 10 PACKET FILTERING ...
Страница 330: ...330 CHAPTER 12 VIRTUAL ROUTER REDUNDANCY PROTOCOL VRRP ...
Страница 356: ...356 CHAPTER 13 IP MULTICAST ROUTING ...
Страница 418: ...418 CHAPTER 14 OPEN SHORTEST PATH FIRST OSPF ...
Страница 519: ...RSVP 519 Figure 94 Sample RSVP Configuration Source station End stations Routers ...
Страница 566: ...566 CHAPTER 18 DEVICE MONITORING ...
Страница 572: ...572 APPENDIX A TECHNICAL SUPPORT ...
Страница 592: ...592 INDEX ...