10-2
IPv4 Access Control Lists (ACLs)
Introduction
IPv4 filtering with ACLs can help improve network performance and restrict
network use by creating policies for:
■
Switch Management Access:
Permits or denies in-band manage-
ment access. This includes limiting and/or preventing the use of
designated protocols that run on top of IPv4, such as TCP, UDP, IGMP,
ICMP, and others. Also included are the use of precedence and ToS
criteria, and control for application transactions based on source and
destination IPv4 addresses and transport layer port numbers.
■
Application Access Security:
Eliminates unwanted traffic in a path
by filtering IPv4 packets where they enter or leave the switch on
specific VLAN interfaces.
IPv4 ACLs can filter traffic to or from a host, a group of hosts, or entire subnets.
N o t e s
IPv4 ACLs can enhance network security by blocking selected traffic, and can
serve as part of your network security program.
However, because ACLs do
not provide user or device authentication, or protection from malicious
manipulation of data carried in IPv4 packet transmissions, they should not
be relied upon for a complete security solution
.
IPv4 ACLs on the switches covered by this manual do not filter non-IPv4 traffic
such as IPv6, AppleTalk, and IPX packets.
Configure an ACL from a TFTP Server
n/a
Enable ACL Logging
n/a
Feature
Default
CLI
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......