Virus Throttling
Configuring and Applying Connection-Rate ACLs
N o t e
Connection-Rate ACLs are a special case of the switch’s ACL feature. If you
need information on other applications of ACLs or more detailed information
on how ACLs operate, refer to the chapter titled “Access Control Lists (ACLs)”
in the Advanced Traffic Management Guide for your switch.
Connection-Rate ACL Operation
A connection-rate ACL applies to inbound traffic on all ports configured for
connection-rate filtering in the assigned VLAN, and creates an exception to
the connection-rate filter policy configured on each port. A connection-rate
ACL has no effect on ports in the VLAN that are not configured for connection-
rate filtering.
A connection-rate ACL accepts inbound, legitimate traffic from trusted
sources without filtering the traffic for the configured connection-rate policy.
You can configure an ACL to assign policy filtering (
filter
) for traffic from some
sources and no policy filtering (
ignore
) for traffic from other sources. How-
ever, the implicit
filter
invoked as the last entry in any connection-rate ACL
ensures that any traffic not specifically excluded from policy filtering (by the
ignore
command) will be filtered by the configured policy for the port on which
that traffic entered the switch.
Inbound Routed Traffic from
Host “A” with Relatively High
Number of IP Connection-Rate
Attempts
Source Match
on any ACE in
the ACL?
Ignore
or
Filter
?
Apply Per-Port Connection-Rate
Policy to Host “A” Traffic:
– Notify-Only
– Throttle
– Block
Apply Implicit ACE
(filter)
Filter
Allow Traffic from Host
“A” without Filtering
Through Per-Port
Connection-Rate Policy
No
Yes
Ignore
Figure 3-8. Connection-Rate ACL Applied to Traffic Received Through a Given Port
3-21
Содержание J8697A
Страница 1: ...6200yl Access Security Guide 5400zl 3500yl ProCurve Switches K 11 XX www procurve com ...
Страница 2: ......
Страница 22: ...Product Documentation Feature Index xx ...
Страница 55: ...Configuring Username and Password Security Front Panel Security 2 21 ...
Страница 56: ...Configuring Username and Password Security Front Panel Security 2 22 ...
Страница 58: ...Virus Throttling Contents Operating Notes 3 30 Connection Rate Log and Trap Messages 3 31 3 2 ...
Страница 88: ...Virus Throttling Connection Rate Log and Trap Messages This page is intentionally unused 3 32 ...
Страница 118: ...Web and MAC Authentication Client Status This page intentionally unused 4 30 ...
Страница 230: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup This page is intentionally unused 8 22 ...
Страница 356: ...Configuring and Monitoring Port Security Operating Notes for Port Security 11 44 ...
Страница 370: ...Using Authorized IP Managers Operating Notes This page is intentionally unused 12 14 ...
Страница 388: ...10 Index ...
Страница 389: ......