![Cisco Catalyst Blade 3032 Скачать руководство пользователя страница 803](http://html.mh-extra.com/html/cisco/catalyst-blade-3032/catalyst-blade-3032_software-configuration-manual_67665803.webp)
35-37
Cisco Catalyst Blade Switch 3130 and 3032 for Dell Software Configuration Guide
OL-13270-06
Chapter 35 Configuring Network Security with ACLs
Configuring VLAN Maps
Beginning in privileged EXEC mode:
Use the
no vlan access-map
command with a sequence number to delete a map sequence. Use the
no
version of the command without a sequence number to delete the map.
This example shows how to configure a VLAN access map to drop and log IP packets. Here IP traffic
matching the permit entries in net_10 is dropped and logged.
DomainMember(config)#
vlan access-map ganymede 10
DomainMember(config-access-map)#
match ip address net_10
DomainMember(config-access-map)#
action drop log
DomainMember(config-access-map)#
exit
This example shows how to configure global VACL logging parameters:
DomainMember(config)#
vlan access-log maxflow 800
DomainMember(config)#
vlan access-log threshold 4000
Command
Purpose
Step 1
configure terminal
Enter the global configuration mode.
Step 2
vlan access-map name
[
number
]
Create a VLAN map. Give it a name and optionally a number. The number is the
sequence number of the entry within the map.
The sequence number range is from 0 to 65535.
When you create VLAN maps with the same name, numbers are assigned
sequentially in increments of 10. When modifying or deleting maps, you can
enter the number of the map entry that you want to modify or delete.
Specifying the map name and optionally a number enters the access-map
configuration mode.
Step 3
action drop log
Set the VLAN access map to drop and log IP packets.
Step 4
exit
Exit the VLAN access map configuration mode and return to the global
configuration mode.
Step 5
vlan access-log
{
maxflow
max_number
|
threshold
pkt_count
}
Configure the VACL logging parameters.
•
maxflow
max_number
—Set the log table size. The content of the log table
can be deleted by setting the
maxflow
to 0. When the log table is full, the
sofware drops logged packets from new flows.
The range is from 0 to 2048. The default is 500.
•
threshold
pkt_count
—Set the logging threshold. A logging message is
generated if the threshold for a flow is reached before the 5-minute interval.
The threshold range is from 0 to 2147483647. The default threshold is 0,
which means that a syslog message is generated every 5 minutes.
Step 6
exit
Return to privileged EXEC mode.
Step 7
show vlan access-map
Verify your entries.
Step 8
copy running-config
startup-config
(Optional) Save your entries in the configuration file.
Содержание Catalyst Blade 3032
Страница 46: ...Contents xlvi Cisco Catalyst Blade Switch 3130 and 3032 for Dell Software Configuration Guide OL 13270 06 ...
Страница 50: ...lii Cisco Catalyst Blade Switch 3130 and 3032 for Dell Software Configuration Guide OL 13270 06 Preface ...
Страница 1380: ...Index IN 54 Cisco Catalyst Switch Module 3110 and 3012 for IBM BladeCenter Software Configuration Guide OL 12189 06 ...