Alteon Application Switch Operating System Application Guide
Filtering and Traffic Manipulation
Document ID: RDWR-ALOS-V2900_AG1302
373
2. Configure Filter 10 to enable the Redirect to Proxy option.
MAC-Based Filters for Layer 2 Traffic
Filters can be configured based on MAC addresses to capture non-IP frames. The benefits of a MAC-
based filtering solution is that filters can be applied to allow or deny non-IP traffic such as ARP or
AppleTalk. In early Alteon versions, filtering allowed for MAC address criteria, but only IP traffic was
supported.
•
To configure a filter for non-IP traffic, specify only the source MAC (smac) and destination MAC
(dmac) addresses. Do not enter source or destination IP addresses on a MAC-based filter. MAC-
based filtering of non-IP frames is supported for non-cached filters only. Even if caching is
enabled on this type of filter, it does not create a session entry.
•
To configure a MAC-based filter, specify only smac and dmac criteria without any IP-related
parameters. The only filtering actions supported for MAC-based filters are allow and deny.
MAC-based filters are supported for VLAN-based filters (see
VLAN-Based Filtering, page 373
Filtering on 802.1p Priority Bit in a VLAN Header, page 376
Example
MAC-Based Filters for Layer 2 Traffic
VLAN-Based Filtering
Filters are applied per Alteon, per port, or per VLAN. VLAN-based filtering allows a single Alteon to
provide differentiated services for multiple customers, groups, or departments. For example, you
can define separate filters for Customers A and B on the same Alteon on two different VLANs. If
VLANs are assigned based on data traffic, for example, ingress traffic on VLAN 1, egress traffic on
VLAN 2, and management traffic on VLAN 3, filters can be applied accordingly to the different
VLANs.
Example
VLAN-Based Filtering
In the example in
Figure 58 - Example VLAN-Based Filtering Configuration, page 374
, Filter 2 is
configured to allow local clients on VLAN 20 to browse the Web, and Filter 3 is configured to allow
local clients on VLAN 30 to Telnet anywhere outside the local intranet. Filter 2048 is configured to
deny ingress traffic from VLAN 70.
>> # /cfg/slb/filt 10/adv
(Select the Advanced menu for Filter 10)
>> Filter 10 Advanced# redir
(Select the Redirection Advanced menu
for Filter 10)
>> Filter 10 Advanced# rtproxy ena
(Enable redirect to proxy server)
>> # /cfg/slb/filt 23
(Select the menu for Filter 23)
Filter 23# smac any
(From any source MAC address)
>> Filter 23# dmac 00:60:cf:40:56:00
(To this MAC destination address)
>> Filter 23# action deny
(Deny matching traffic)
>> Filter 23# ena
(Enable this filter)
Содержание Alteon
Страница 2: ...Alteon Application Switch Operating System Application Guide 2 Document ID RDWR ALOS V2900_AG1302 ...
Страница 42: ...Alteon Application Switch Operating System Application Guide Preface 42 Document ID RDWR ALOS V2900_AG1302 ...
Страница 582: ...Alteon Application Switch Operating System Application Guide High Availability 582 Document ID RDWR ALOS V2900_AG1302 ...