10-122
IPv4 Access Control Lists (ACLs)
Enable ACL “Deny” Logging
IPv6 Counter Operation with Multiple Interface Assignments
N o t e
The examples of counters in this section use small values to help illustrate
counter operation. The counters in real-time network applications are gener-
ally much more active and show higher values.
Where the same IPv6 ACL is assigned to multiple interfaces, the switch
maintains a separate instance of each ACE counter in the ACL. When there is
a match with traffic on one of the ACL’s assigned interfaces, only the affected
ACE counters for that interface are incremented. Other instances of the same
ACL applied to other interfaces are not affected.
For example, suppose that:
■
An ACL named “V6-01” is configured as shown in figure 10-50 to block
Telnet access to a workstation at FE80::20:2, which is connected to a
port belonging to VLAN 20.
■
The ACL is assigned as a PACL (port ACL) on port B2, which is also
a member of VLAN 20:
Figure 10-50. ACL “V6-01” and Command for PACL Assignment on Port 2
Figure 10-51. Application to Filter Traffic Inbound on Port B2
HP Switch(config)# show access-list config
ipv6 access-list "V6-01"
10 permit icmp ::/0 fe80::20:2/128 128
20 deny tcp ::/0 fe80::20:2/128 eq 23 log
30 permit ipv6 ::/0 ::/0
exit
HP Switch(config)# int b2 ipv access-group V6-01 in
Assigns the ACL to port 2.
FE80::20:2
ACL “V6-01” assigned as
a PACL on port B2.
VLAN 20
FE80::20:1
5400zl Switch
FE80::20:117
Port
B2
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......