Traffic/Security Filters
Filter Types and Operation
Source-Port Filters
This filter type enables the switch to forward or drop traffic from
all
end nodes
on the indicated source-port to specific destination ports.
End
Node
“A”
Server
Switch 5400zl
Configured for
Source-Port
Filtering
Hub
End
Node
“B”
End
Node
“C”
Port
1
Port
2
Configuring a source-port filter to drop traffic received on port 1 with an outbound destination of port
2 means that End Nodes A, B, and C cannot send traffic to the server. To block traffic in the opposite
direction, you would also configure a source-port filter to drop traffic received on port 2 with an
outbound destination of port 1.
Figure 9-1. Example of a Source-Port Filter Application
Operating Rules for Source-Port Filters
■
You can configure one source-port filter for each physical port and
port trunk on the switch. (Refer to the
filter
command on page 9-18.)
■
You can include all destination ports and trunks in the switch on a
single source-port filter.
■
Each source-port filter includes:
•
One source port or port trunk (
trk1
,
trk2
, ...
trk
n
)
•
A set of destination ports and/or port trunks that includes all
untrunked LAN ports and port trunks on the switch
•
An action (forward or drop) for each destination port or port trunk
When you create a source-port filter, the switch automatically sets the
filter to forward traffic from the designated source to all destinations for
which you do not specifically configure a “drop” action. Thus, it is not
necessary to configure a source-port filter for traffic you want the switch
to forward unless the filter was previously configured to drop the desired
traffic.
9-4
Содержание J8697A
Страница 1: ...6200yl Access Security Guide 5400zl 3500yl ProCurve Switches K 11 XX www procurve com ...
Страница 2: ......
Страница 22: ...Product Documentation Feature Index xx ...
Страница 55: ...Configuring Username and Password Security Front Panel Security 2 21 ...
Страница 56: ...Configuring Username and Password Security Front Panel Security 2 22 ...
Страница 58: ...Virus Throttling Contents Operating Notes 3 30 Connection Rate Log and Trap Messages 3 31 3 2 ...
Страница 88: ...Virus Throttling Connection Rate Log and Trap Messages This page is intentionally unused 3 32 ...
Страница 118: ...Web and MAC Authentication Client Status This page intentionally unused 4 30 ...
Страница 230: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup This page is intentionally unused 8 22 ...
Страница 356: ...Configuring and Monitoring Port Security Operating Notes for Port Security 11 44 ...
Страница 370: ...Using Authorized IP Managers Operating Notes This page is intentionally unused 12 14 ...
Страница 388: ...10 Index ...
Страница 389: ......