Virus Throttling
Configuring and Applying Connection-Rate ACLs
For more on ACE masks, refer to “How an ACE Uses a Mask To Screen Packets
for Matches” in the chapter titled “Access Control Lists” in the
Advanced
Traffic Management Guide
for your switch.
Example of Using an ACL in a Connection-Rate
Configuration
This example adds connection-rate ACLs to the basic example on page 3-14.
Server
Company
Intranet
VLAN 1
15.45.100.1
VLAN 10
15.45.200.1
5400zl Switch
Server
VLAN 15
15.45.300.1
Switch
Server
Server
Switch
Switch
A
B
C
D
E
H
F
G
B1
B2
B3
B9
B4
D1
D2
IP Address:
15.45.100.7
IP Address: 15.45.50.17
Figure 3-10. Sample Network
In the basic example on page 3-14, the administrator configured connection-
rate blocking on port D2. However:
■
The administrator has elevated the connection-rate sensitivity to
high.
■
The server at IP address 15.45.50.17 frequently transmits a relatively
high rate of legitimate connection requests, which now triggers
connection-rate blocking of the server’s IP address on port D2. This
causes periodic, unnecessary blocking of access to the server.
3-27
Содержание J8697A
Страница 1: ...6200yl Access Security Guide 5400zl 3500yl ProCurve Switches K 11 XX www procurve com ...
Страница 2: ......
Страница 22: ...Product Documentation Feature Index xx ...
Страница 55: ...Configuring Username and Password Security Front Panel Security 2 21 ...
Страница 56: ...Configuring Username and Password Security Front Panel Security 2 22 ...
Страница 58: ...Virus Throttling Contents Operating Notes 3 30 Connection Rate Log and Trap Messages 3 31 3 2 ...
Страница 88: ...Virus Throttling Connection Rate Log and Trap Messages This page is intentionally unused 3 32 ...
Страница 118: ...Web and MAC Authentication Client Status This page intentionally unused 4 30 ...
Страница 230: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup This page is intentionally unused 8 22 ...
Страница 356: ...Configuring and Monitoring Port Security Operating Notes for Port Security 11 44 ...
Страница 370: ...Using Authorized IP Managers Operating Notes This page is intentionally unused 12 14 ...
Страница 388: ...10 Index ...
Страница 389: ......