
CoreWatch Users Guide
213
Chapter 13: Configuring Security on the SSR
administrator to know ahead of time that a packet should be dropped at the inbound
interface. Nonetheless, for performance reasons, whenever possible, one should create
and apply an ACL to the inbound interface.
When a packet comes into a router at an interface where an inbound ACL is applied, the
router compares the packet with the rules specified by that ACL. If it is permitted, the
packet is allowed into the router. If not, the packet is dropped. If that packet is to be
forwarded to go out of another interface (that is, the packet is to be routed) then a second
ACL check is possible. At the output interface, if an outbound ACL is applied, the packet
will be compared with the rules specified in this outbound ACL. Consequently, it is
possible for a packet to go through two separate checks, once at the inbound interface and
once more at the outbound interface.
Note:
When you apply an ACL to an interface, the SSR appends an
implicit deny rule
to
that ACL. The implicit deny rule denies all traffic. If you intend to allow all traffic
that does not match your specified ACL rules to go through, you must explicitly
define a rule to permit all traffic. To do so, make sure the last rule of the ACL
permits all traffic.
You can apply previously defined IP ACLs only to IP interfaces and previously defined
IPX, IPX RIP, or IPX SAP ACLs only to IPX interfaces.
Caution
: You can apply up to two IP ACLs to an IP interface, and you can apply two of
each of the different IPX ACLs (IPX, IPX RIP, and IPX SAP) to an IPX interface. When
applying multiple ACLs to an IP interface, one ACL must govern inbound traffic and the
other ACL must govern outbound traffic. When applying multiple ACLs of the same type
to an IPX interface, one ACL must govern inbound traffic and the other must govern
outbound traffic.
You may apply an ACL to an interface either when you create the interface or afterwards.
For details on applying an IP ACL while creating an IP interface, see
“Creating IP
Interfaces” on page 103
. For details on applying an IPX, IPX RIP, or IPX SAP ACL while
creating an IPX interface, see
“Creating IPX Interfaces” on page 149
.
You apply an IP or IPX, IPX RIP, or IPX SAP ACL to an interface after the interface is
created by either copying the ACL or by editing the interface’s definition. Separate
discussions on each task follow.
Copying an ACL to Apply It to an Interface
You can copy an ACL to apply it to an interface by either dragging it or using the Copy
and Paste buttons. To apply an ACL by copying it to an interface:
1.
Start Configuration Expert if you have not already done so.
2.
Open the configuration file you want to modify and then double-click that file’s
Routing Configuration object.
3.
Expand the configuration tree until you locate the interface to which you want to
apply the ACL. Double-click that interface’s object.
Содержание SSR-ATM29-02
Страница 1: ...CoreWatch User s Guide 9032564...
Страница 2: ......
Страница 6: ...Notice vi...
Страница 14: ...Contents 14 CoreWatch User s Guide...
Страница 18: ...Preface 18 CoreWatch User s Guide...
Страница 134: ...Chapter 9 Configuring Unicast Routing on the SSR 134 CoreWatch User s Guide...
Страница 194: ...Chapter 12 Configuring QoS on the SSR 194 CoreWatch User s Guide...
Страница 234: ...Chapter 13 Configuring Security on the SSR 234 CoreWatch User s Guide...
Страница 258: ...Chapter 15 Checking System Status 258 CoreWatch User s Guide...
Страница 278: ...Chapter 16 Monitoring Real Time Performance 278 CoreWatch User s Guide...
Страница 316: ...Chapter 18 Checking the Status of Routing Tables 316 CoreWatch User s Guide...
Страница 326: ...Chapter 20 Monitoring Faults 326 CoreWatch User s Guide...
Страница 330: ...Chapter 21 Obtaining Reports 330 CoreWatch User s Guide...
Страница 344: ...Appendix B CoreWatch Menus 344 CoreWatch User s Guide...