10-40
IPv4 Access Control Lists (ACLs)
Configuring and Assigning an IPv4 ACL
CIDR Notation.
For information on using CIDR notation to specify ACL
masks, refer to “Using CIDR Notation To Enter the IPv4 ACL Mask” on page
10-49.
Configuring and Assigning an IPv4 ACL
Overview
General Steps for Implementing ACLs
1.
Configure one or more ACLs. This creates and stores the ACL(s) in the
switch configuration.
2.
Assign an ACL. This step uses one of the following applications to assign
the ACL to an interface:
•
RACL (routed IPv4 traffic entering or leaving the switch on a given
VLAN)
•
VACL (any IPv4 traffic entering the switch on a given VLAN)
•
Static Port ACL (any IPv4 traffic entering the switch on a given port,
port list, or static trunk)
3.
If the ACL is applied as an RACL, enable IPv4 routing. Except for instances
where the switch is the traffic source or destination, assigned RACLs filter
IPv4 traffic only when routing is enabled on the switch.
Caution Regarding
the Use of IPv4
Source Routing
IPv4 source routing is enabled by default on the switch and can be used to
override ACLs. For this reason, if you are using ACLs to enhance network
security, the recommended action is to disable source routing on the switch.
To do so, execute
no ip source-route
.
ACL Feature
Page
Configuring and Assigning a Standard ACL
Configuring and Assigning an Extended ACL
Enabling or Disabling ACL Filtering
Содержание HP ProCurve Series 6600
Страница 2: ......
Страница 6: ...iv ...
Страница 26: ...xxiv ...
Страница 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Страница 204: ...4 72 Web and MAC Authentication Client Status ...
Страница 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Страница 756: ...16 8 Key Management System Configuring Key Chain Management ...
Страница 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Страница 777: ......