3-27
Virus Throttling (Connection-Rate Filtering)
Configuring and Applying Connection-Rate ACLs
configure a connection-rate ACL that causes the switch to ignore (circumvent)
connection-rate filtering for inbound traffic from the server, while maintaining
the filtering for all other inbound traffic on port D2.
The configuration steps include:
1.
Create the connection-rate ACL with a single entry:
•
Use the IP address of the desired server.
•
Include a CIDR notation of “32” for the ACL mask. (Which means the
mask will allow only traffic whose source IP address (SA) exactly
matches the specified IP address.)
•
The ACL will automatically include the implicit
filter
ACE as the last
entry, which means that any traffic that is not from the desired server
will be subject to filtering by the connection-rate policy configured
on port D2.
2.
Assigning the ACL to the VLAN through which traffic from the server
enters the switch.
Figure 3-11. Creating and Assigning a Connection Rate ACL
HP Switch(config)# ip access-list connection-rate-filter 17-server
HP Switch(config-crf-nacl)# ignore ip host 15.45.50.17
HP Switch(config-crf-nacl)# exit
HP Switch(config)# vlan 15
HP Switch(vlan-15)# ip access-group 17-server connection-rate-filter
HP Switch(vlan-15)# exit
HP Switch(config)# write mem
Enters the connection-
rate ACL context and
names the ACL.
Configures the action to allow traffic from the server at
15.45.50.17 without filtering through the per-port connection-
rate policy configured on port D2.
Assigns the new
ACL to VLAN 15,
where traffic
from the desired
server enters the
switch.
Содержание HP ProCurve Series 6600
Страница 2: ......
Страница 6: ...iv ...
Страница 26: ...xxiv ...
Страница 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Страница 204: ...4 72 Web and MAC Authentication Client Status ...
Страница 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Страница 756: ...16 8 Key Management System Configuring Key Chain Management ...
Страница 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Страница 777: ......