10-20
IPv4 Access Control Lists (ACLs)
Overview
N o t e
In cases where an RACL and any type of port or VLAN ACL are filtering traffic
entering the switch, the
switched
traffic explicitly permitted by the port or
VLAN ACL is not filtered by the RACL (except where the traffic has a
destination on the switch itself). However,
routed
traffic explicitly permitted
by the port or VLAN ACL (and any switched traffic having a destination on the
switch itself) must also be explicitly permitted by the RACL, or it will be
dropped.
Also, a switched packet is not affected by an outbound RACL assigned to the
VLAN on which the packet exits from the switch.
For a Packet To Be Permitted, It Must Have a Match with a “Permit”
ACE in All Applicable ACLs Assigned to an Interface.
On a given inter-
face where multiple ACLs apply to the same traffic, a packet having a match
with a
deny
ACE in any applicable ACL on the interface (including an implicit
deny any
) will be dropped.
For example, suppose the following is true:
■
Port A10 belongs to VLAN 100.
■
A static port ACL is configured on port A10.
■
A VACL is configured on VLAN 100.
■
An RACL is also configured for inbound, routed traffic on VLAN 100.
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......