IPv4 Access Control Lists (ACLs)
Introduction
Introduction
An Access Control List (ACL) is a list of one or more Access Control Entries
(ACEs) specifying the criteria the switch uses to either permit (forward) or
deny (drop) IP packets traversing the switch’s interfaces. This chapter
describes how to configure, apply, and edit IPv4 ACLs in a network populated
with the switches covered by this guide, and how to monitor IPv4 ACL actions.
N o t e
This chapter describes ACLs for IPv4 configuration and operation. In this
chapter, unless otherwise noted:
■
The term “ACL” refers to IPv4 ACLs.
■
Descriptions of ACL operation apply only to IPv4 ACLs.
For information on dynamic (RADIUS-assigned) ACLs, refer to “Dynamic Port
ACLs” on page 9-6.
.
Feature
Default
CLI
Standard ACLs
None
Extended ACLs
None
Enable or Disable an ACL
n/a
Display ACL Data
n/a
Delete an ACL
n/a
Configure an ACL from a TFTP Server
n/a
Enable ACL Logging
n/a
IPv4 filtering with ACLs can help improve network performance and restrict
network use by creating policies for:
■
Switch Management Access:
Permits or denies in-band manage
ment access. This includes limiting and/or preventing the use of
designated protocols that run on top of IPv4, such as TCP, UDP, IGMP,
ICMP, and others. Also included are the use of precedence and ToS
criteria, and control for application transactions based on source and
destination IPv4 addresses and transport layer port numbers.
■
Application Access Security:
Eliminates unwanted traffic in a path
by filtering IPv4 packets where they enter or leave the switch on
specific interfaces.
IPv4 ACLs can filter traffic to or from a host, a group of hosts, or entire subnets.
9-4
Содержание PROCURVE 2910AL
Страница 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Страница 2: ......
Страница 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Страница 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Страница 156: ...TACACS Authentication Operating Notes 4 30 ...
Страница 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Страница 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Страница 516: ...Configuring Port Based and User Based Access Control 802 1X Messages Related to 802 1X Operation 12 76 ...
Страница 527: ...Configuring and Monitoring Port Security Port Security Figure 13 4 Examples of Show Mac Address Outputs 13 11 ...
Страница 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Страница 592: ...12 Index ...
Страница 593: ......
Страница 594: ... Copyright 2009 Hewlett Packard Development Company L P February 2009 Manual Part Number 5992 5439 ...