data:image/s3,"s3://crabby-images/adbbe/adbbe86deb80cea1e536be05b34004c6ceb2d3d0" alt="OmniSwitch os6900 Скачать руководство пользователя страница 673"
Configuring QoS
Using Access Control Lists
OmniSwitch AOS Release 7 Network Configuration Guide
June 2013
page 25-65
Layer 3 ACLs
The QoS software in the switch filters routed and bridged traffic at Layer 3.
For Layer 3 filtering, the QoS software in the switch classifies traffic based on:
•
Source IP address or source network group
•
Destination IP address or destination network group
•
IP protocol
•
ICMP code
•
ICMP type
•
Source TCP/UDP port
•
Destination TCP/UDP port or service or service group
Layer 3 ACL: Example 1
In this example, the default routed disposition is
accept
(the default). Since the default is
accept
, the
qos
default routed disposition
command would only need to be entered if the disposition had previously been
set to
deny
. The command is shown here for completeness.
-> qos default routed disposition accept
-> policy condition addr2 source ip 192.68.82.0 source ip port 23 ip protocol 6
-> policy action Block disposition deny
-> policy rule FilterL31 condition addr2 action Block
Traffic with a source IP address of 192.68.82.0, a source IP port of 23, using protocol 6, matches condi-
tion
addr2
, which is part of
FilterL31
. The action for the filter (
Block
) is set to deny traffic. The flow is
dropped on the switch.
Note that although this example contains only Layer 2 conditions, it is possible to combine Layer 2 and
Layer 3 conditions in the same policy.
Layer 3 ACL: Example 2
This example uses condition groups to combine multiple IP addresses in a single condition. The default
disposition is set to
deny
.
-> qos default routed disposition deny
-> policy network group GroupA 192.60.22.1 192.60.22.2 192.60.22.0
-> policy condition cond7 destination network group GroupA
-> policy action Ok disposition accept
-> policy rule FilterL32 condition cond7 action Ok
In this example, a network group,
GroupA
, is configured with three IP addresses. Condition
cond7
includes
GroupA
as a destination group. Flows coming into the switch destined for any of the specified IP
addresses in the group matches rule
FilterL32
.
FilterL32
is configured with an action (
Ok
) to allow the
traffic on the switch.
Note that although this example contains only Layer 2 conditions, it is possible to combine Layer 2 and
Layer 3 conditions in the same policy.
Содержание os6900
Страница 28: ...Contents xxviii OmniSwitch AOS Release 7 Network Configuration Guide June 2013...
Страница 374: ...VRF Route Leak Configuring IP page 15 40 OmniSwitch AOS Release 7 Network Configuration Guide June 2013...
Страница 692: ...Policy Applications Configuring QoS page 25 84 OmniSwitch AOS Release 7 Network Configuration Guide June 2013...