12-7
Traffic/Security Filters and Monitors
Filter Types and Operation
A named source-port filter must first be defined and configured before it can
be applied. In the following example two named source-port filters are
defined,
web-only
and
accounting
.
HP Switch(config)# filter source-port named-filter
web-only
HP Switch(config)# filter source-port named-filter
accounting
By default, these two named source-port filters forward traffic to all ports and
port trunks.
To configure a named source-port filter to prevent inbound traffic from being
forwarded to specific destination switch ports or port trunks, the
drop
option
is used. For example, on a 26-port switch, to configure the named source-port
filter
web-only
to drop any traffic except that for destination ports 1 and 2, the
following command would be used:
HP Switch(config)# filter source-port named-filter
web-only drop 3-26
A named source-port filter can be defined and configured in a single command
by adding the
drop
option, followed by the required
destination-port-list.
Syntax
:
filter source-port named-filter <
filter-name
> drop <
destination-port-list
>
Configures the named source-port filter to drop traffic having
a destination on the ports and/or port trunks in the <
destination-port-list >. Can be followed by the
forward
option
if you have other destination ports or port trunks previously
set to
drop
that you want to change to
forward
. For example:
filter source-port named-filter <filter-name
> drop < destina-
tion-port-list > forward < destination-port-list>
The
destination-port-list
may contain ports, port trunks, and
ranges (for example 3-7 or trk4-trk9) separated by commas.
Syntax:
filter source-port named-filter <
filter-name
> forward
<
destination-port-list
>
Configures the named source-port filter to forward traffic
having a destination on the ports and/or port trunks in the
<
destination-port-list
>. Since “forward” is the default state for
destinations in a filter, this command is useful when
destinations in an existing filter are configured for “drop”
and you want to change them to ”forward”. Can be followed
by the
drop
option if you have other destination ports set to
forward
that you want to change to
drop
. For example:
filter source-port named-filter
<
filter-name
>
forward
<
destination-port-list
>
drop
<
destination-port-list
>
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......