136 Configuring advanced security features
2.
Enter the following command:
ipfilter –-show [<policyname>]
where
<policyname>
is the name of the policy and is optional.
Saving an IP Filter policy
You can save one or all IP Filter policies persistently in the defined configuration. The policy name is
optional for this subcommand. If the policy name is given, the IP Filter policy in the temporary buffer is
saved; if the policy name is not given, all IP Filter policies in the temporary buffer are saved. Only the CLI
session that owns the updated temporary buffer may run this command. Modification to an active policy
cannot be saved without being applied. Hence, the
--
save
subcommand is blocked for the active policies.
Use
--
activate
instead.
1.
Log in to the switch using an account assigned to the admin role.
2.
Enter the following command:
ipfilter –-save [<policyname>]
where
<policyname>
is the name of the policy and is optional.
Activating an IP Filter policy
IP Filter policies are not enforced until they are activated. Only one IP Filter policy per IPv4 and IPv6 type
can be active. If there is a temporary buffer for the policy, the policy is saved to the defined configuration
and activated at the same time. If there is no temporary buffer for the policy, the policy existing in the
defined configuration becomes active. The activated policy remains in the defined configuration. The
policy to be activated replaces the existing active policy of the same type. Activating the default IP Filter
policies returns the IP management interface to its default state. An IP Filter policy without any rule cannot
be activated. This subcommand prompts for a user confirmation before proceeding.
1.
Log in to the switch using an account assigned to the admin role.
2.
Enter the following command:
ipfilter –-activate <policyname>
where
policyname
is the name of the policy.
Deleting an IP Filter policy
You can delete a specified IP Filter policy. Deleting an IP Filter policy removes it from the temporary buffer.
To permanently delete the policy from the persistent database, run
ipfilter
--
save
. An active IP Filter
policy cannot be deleted.
1.
Log in to the switch using an account assigned to the admin role.
2.
Enter the following command:
ipfilter –delete <policyname>
where
policyname
is the name of the policy.
3.
To permanently delete the policy, enter the following command:
ipfilter --save
IP Filter policy rules
An IP Filter policy consists of a set of rules. Each rule has an index number identifying the rule. There can
be a maximum of 256 rules within an IP Filter policy.
Each rule contains the following elements:
•
Source Address: A source IP address or a group prefix.
•
Destination Port: The destination port number or name, such as: Telnet, SSH, HTTP, HTTPS.
•
Protocol: The protocol type. Supported types are TCP or UDP.
•
Action: The filtering action taken by this rule, either Permit or Deny.
Содержание A7533A - Brocade 4Gb SAN Switch Base
Страница 1: ...HP StorageWorks Fabric OS 6 2 administrator guide Part number 5697 0016 Edition May 2009 ...
Страница 24: ...24 ...
Страница 99: ...Fabric OS 6 2 administrator guide 99 ...
Страница 100: ...100 Managing user accounts ...
Страница 118: ...116 Configuring standard security features ...
Страница 164: ...162 Configuring advanced security features ...
Страница 234: ...232 Installing and maintaining firmware ...
Страница 268: ...266 Administering advanced zoning ...
Страница 284: ...282 Configuring Enterprise class platforms ...
Страница 292: ...290 Routing traffic ...
Страница 294: ...292 Interoperability for merged SANs ...
Страница 302: ...300 Configuring the Distributed Management Server ...
Страница 334: ...332 iSCSI gateway service ...
Страница 340: ...338 Administering NPIV ...
Страница 407: ...Fabric OS 6 2 administrator guide 405 ...
Страница 408: ...406 Using the FC FC routing service ...
Страница 438: ...434 Administering extended fabrics ...
Страница 460: ...456 Administering ISL trunking ...
Страница 498: ...494 Configuring and monitoring FCIP extension services 556200 Bps 30s avg 491394 Bps lifetime avg ...
Страница 516: ...512 FICON fabrics ...
Страница 526: ...522 Configuring and monitoring FICON Extension Services ...
Страница 540: ...536 Configuring the PID format ...
Страница 544: ...540 Understanding legacy password behavior ...
Страница 546: ...542 Mixed fabric configurations for non merge SANs ...
Страница 550: ...546 Migrating from an MP Router to a 400 MP Router ...
Страница 558: ...554 Inband Management ...
Страница 572: ...568 ...