Virus Throttling
Configuring and Applying Connection-Rate ACLs
Configuring a Connection-Rate ACL Using UDP/TCP
Criteria
(To configure a connection-rate ACL using source IP address criteria, turn to
page 3-22.)
Syntax:
ip access-list connection-rate-filter <
crf-list-name
>
Creates a connection-rate-filter ACL and puts the CLI
into the access control entry (ACE) context:
ProCurve(config-crf-nacl)#
If the ACL already exists, this command simply puts
the CLI into the ACE context.
Syntax:
< filter | ignore > < udp | tcp > < any >
< filter | ignore > < udp | tcp > < host <
ip-addr
> > [
udp/tcp
-
options
]
< filter | ignore > < udp | tcp > <
ip-addr
<
mask-length
> [
udp/tcp
-
options
]
Used in the ACE context (above) to specify the action
of the connection-rate ACE (filter or ignore), and the
UDP/TCP criteria and SA of the IP traffic that the ACE
affects.
< filter | ignore >
filter:
This option assigns a policy of filtering (drop-
ping) IP traffic having an SA that matches the source
address criteria in the ACE.
ignore:
This option specifies a policy of allowing IP
traffic having an SA that matches the source address
criteria in the ACE.
< udp | tcp > < any | host <
ip-addr
> |
ip-addr
<
mask-length
>>
Applies the filter or ignore action to either TCP pack
ets or UDP packets having the specified SA.
any:
Applies the ACEs action (
filter
or
ignore
) to IP
traffic having any SA
.
host <
ip-addr
>
:
Applies the ACEs action (
filter
or
ignore
) to IP traffic having the specified host SA
.
3-23
Содержание J8697A
Страница 1: ...6200yl Access Security Guide 5400zl 3500yl ProCurve Switches K 11 XX www procurve com ...
Страница 2: ......
Страница 22: ...Product Documentation Feature Index xx ...
Страница 55: ...Configuring Username and Password Security Front Panel Security 2 21 ...
Страница 56: ...Configuring Username and Password Security Front Panel Security 2 22 ...
Страница 58: ...Virus Throttling Contents Operating Notes 3 30 Connection Rate Log and Trap Messages 3 31 3 2 ...
Страница 88: ...Virus Throttling Connection Rate Log and Trap Messages This page is intentionally unused 3 32 ...
Страница 118: ...Web and MAC Authentication Client Status This page intentionally unused 4 30 ...
Страница 230: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup This page is intentionally unused 8 22 ...
Страница 356: ...Configuring and Monitoring Port Security Operating Notes for Port Security 11 44 ...
Страница 370: ...Using Authorized IP Managers Operating Notes This page is intentionally unused 12 14 ...
Страница 388: ...10 Index ...
Страница 389: ......