Access policy extensions
The access policy feature controls the admittance of the incoming connections though various
applications such as HTTP, SNMPv3, Telnet and SSH. The access is controlled at two levels:
• the source IP address (IPv4 or IPv6)
• the logon access level, that is, read-only (ro), read-write (rw), read-write-all (rwa), and, in
the case of SNMP, extra configuration for groups
The first check, performed at the PDU level, determines if an action is allowed based on the
access configuration.
For SNMP, version 3 provides a group option in the access policy. See
page 51.
Any modifications in the access policy entry can affect the existing application session.
The following modifications result in changes to established TCP-based connections:
• Disallowing connections from the host or network for the entry in the access policy table
• Deleting an entry
• Reducing the access level; that is; ro/rw/rwa.
This results in a session logoff to clear the cached entry and forces the user to log on
again. The new logon information is verified according to the configuration.
• Increasing the access level
Multicast link discovery
IPv6 routers use multicast link discovery (MLD) to discover
• the presence of multicast listeners on directly attached links
• multicast addresses required by neighboring nodes
MLD is an asymmetric protocol. It specifies separate behaviors for multicast address listeners
(that is, hosts or routers that listen to multicast packets) and multicast routers. Each multicast
router learns, for each directly attached link, which multicast addresses and which sources
have listeners on that link. The information that MLD gathers is provided to the multicast routing
protocols that the router uses. This information ensures that multicast packets arrive at all links
where listeners require such packets.
A multicast router can itself be a listener of one or more multicast addresses. That is, the router
performs both the multicast router role and the multicast address listener part of the protocol.
IPv6 routing fundamentals
58 Configuration — IPv6 Routing
November 2010
Содержание ERS 8600 series
Страница 1: ...Configuration IPv6 Routing Avaya Ethernet Routing Switch 8800 8600 7 0 NN46205 504 03 03 November 2010...
Страница 14: ...New in this release 14 Configuration IPv6 Routing November 2010...
Страница 78: ...IPv6 routing configuration 78 Configuration IPv6 Routing November 2010...
Страница 132: ...Basic IPv6 configuration using the ACLI 132 Configuration IPv6 Routing November 2010...
Страница 176: ...IPv6 routing configuration using the CLI 176 Configuration IPv6 Routing November 2010...
Страница 194: ...IPv6 routing configuration using the ACLI 194 Configuration IPv6 Routing November 2010...
Страница 198: ...IPv6 DHCP Relay configuration using Enterprise Device Manager 198 Configuration IPv6 Routing November 2010...
Страница 206: ...IPv6 DHCP Relay configuration using the CLI 206 Configuration IPv6 Routing November 2010...
Страница 224: ...IPv6 VRRP configuration using Enterprise Device Manager 224 Configuration IPv6 Routing November 2010...
Страница 238: ...IPv6 VRRP configuration using the CLI 238 Configuration IPv6 Routing November 2010...
Страница 250: ...IPv6 VRRP configuration using the ACLI 250 Configuration IPv6 Routing November 2010...
Страница 262: ...IPv6 RSMLT configuration using the CLI 262 Configuration IPv6 Routing November 2010...
Страница 268: ...IPv6 RSMLT configuration using the ACLI 268 Configuration IPv6 Routing November 2010...
Страница 292: ...Multicast protocol configuration using Enterprise Device Manager 292 Configuration IPv6 Routing November 2010...
Страница 306: ...Multicast protocol configuration using the ACLI 306 Configuration IPv6 Routing November 2010...
Страница 344: ...IPv6 traffic filter configuration using the ACLI 344 Configuration IPv6 Routing November 2010...
Страница 398: ...CLI show commands 398 Configuration IPv6 Routing November 2010...