10-112
IPv4 Access Control Lists (ACLs)
Enable ACL “Deny” Logging
Enable ACL “Deny” Logging
ACL logging enables the switch to generate a message when IP traffic meets
the criteria for a match with an ACE that results in an explicit “deny” action.
You can use ACL logging to help:
■
Test your network to ensure that your ACL configuration is detecting
and denying the IPv4 traffic you do not want forwarded
■
Receive notification when the switch detects attempts to forward
IPv4 traffic you have designed your ACLs to reject (deny)
The switch sends ACL messages to Syslog and optionally to the current
console, Telnet, or SSH session. You can use
logging <
>
to configure up to six
Syslog server destinations.
Requirements for Using ACL Logging
■
The switch configuration must include an ACL (1) assigned to a port,
trunk, or static VLAN interface and (2) containing an ACE configured
with the
deny
action and the
log
option.
■
If the RACL application is used, then IPv4 routing must be enabled on
the switch.
■
For ACL logging to a Syslog server:
•
The server must be accessible to the switch and identified in the
running configuration.
•
The logging facility must be enabled for Syslog.
•
Debug must be configured to:
–
support ACL messages
–
send debug messages to the desired debug destination
These requirements are described in more detail under “Enabling ACL
Logging on the Switch” on page 10-114.
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......