Virus Throttling
Configuring and Applying Connection-Rate ACLs
Configuring a Connection-Rate ACL Using
Source IP Address Criteria
(To configure a connection-rate ACL using UDP/TCP criteria, go to page 3-23.)
Syntax:
ip access-list connection-rate-filter <
crf-list-name
>
Creates a connection-rate-filter ACL and puts the CLI
into the access control entry (ACE) context:
ProCurve(config-crf-nacl)#
If the ACL already exists, this command simply puts the
CLI into the ACE context.
Syntax:
< filter | ignore > ip < any | host <
ip-addr
> |
ip-addr
<
mask-length
> >
Used in the ACE context (above) to specify the action of
the connection-rate ACE and the source IP address (SA)
of the traffic that the ACE affects.
< filter | ignore >
The
filter
option assigns policy filtering to traffic with an
SA matching the source address in the ACE. The
ignore
option specifies bypassing policy filtering for traffic with
an SA that matches the source address in the ACE.
ip < any | host <
ip-addr
> |
ip-addr
<
mask-length
>
Specifies the SA criteria for traffic addressed by the ACE.
any:
Applies the ACEs action (
filter
or
ignore
) to traffic
having any SA
.
host <
ip-addr
>
:
Applies the ACEs action (
filter
or
ignore
)
to traffic having the specified host SA
.
ip-addr
<
mask-length
>:
Applies the ACEs action (
filter
or
ignore
) to traffic having an SA
within the range defined
by either:
< src-ip-addr/cidr-mask-bits>
or
< src-ip-addr < mask >>
Use this criterion for traffic received from either a subnet
or a group of IP addresses. The mask can be in either
dotted-decimal format or CIDR format with the number
of significant bits. Refer to “Using CIDR Notation To
Enter the ACE Mask” on page 3-26.
3-22
Содержание J8697A
Страница 1: ...6200yl Access Security Guide 5400zl 3500yl ProCurve Switches K 11 XX www procurve com ...
Страница 2: ......
Страница 22: ...Product Documentation Feature Index xx ...
Страница 55: ...Configuring Username and Password Security Front Panel Security 2 21 ...
Страница 56: ...Configuring Username and Password Security Front Panel Security 2 22 ...
Страница 58: ...Virus Throttling Contents Operating Notes 3 30 Connection Rate Log and Trap Messages 3 31 3 2 ...
Страница 88: ...Virus Throttling Connection Rate Log and Trap Messages This page is intentionally unused 3 32 ...
Страница 118: ...Web and MAC Authentication Client Status This page intentionally unused 4 30 ...
Страница 230: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup This page is intentionally unused 8 22 ...
Страница 356: ...Configuring and Monitoring Port Security Operating Notes for Port Security 11 44 ...
Страница 370: ...Using Authorized IP Managers Operating Notes This page is intentionally unused 12 14 ...
Страница 388: ...10 Index ...
Страница 389: ......