Setting The Packet Filtering Default Action; Displaying And Maintaining Acls; Acl Configuration Example; Network Requirements - HP FlexFabric 5700 series Configuration Manual

Hide thumbs Also See for FlexFabric 5700 series:
Table of Contents

Advertisement

Setting the packet filtering default action

Step
1.
Enter system view.
2.
Set the packet filtering default
action to deny.

Displaying and maintaining ACLs

Execute display commands in any view and reset commands in user view.
Task
Display ACL configuration and match statistics.
Display whether an ACL has been successfully applied
to an interface for packet filtering.
Display match statistics for packet filtering ACLs.
Display the accumulated statistics for packet filtering
ACLs.
Display detailed ACL packet filtering information.
Display QoS and ACL resource usage.
Clear ACL statistics.
Clear match statistics (including the accumulated
statistics) for packet filtering ACLs.

ACL configuration example

Network requirements

A company interconnects its departments through Device A. Configure an ACL to:
Permit access from the President's office at any time to the financial database server.
Command
system-view
packet-filter default deny
Command
display acl [ ipv6 ] { acl-number | all | name
acl-name }
display packet-filter { interface [ interface-type
interface-number ] [ inbound | outbound ] | interface
vlan-interface vlan-interface-number [ inbound |
outbound ] [ slot slot-number ] }
display packet-filter statistics interface interface-type
interface-number { inbound | outbound } [ [ ipv6 ]
{ acl-number | name acl-name } ] [ brief ]
display packet-filter statistics sum { inbound |
outbound } [ ipv6 ] { acl-number | name acl-name }
[ brief ]
display packet-filter verbose interface interface-type
interface-number { inbound | outbound } [ [ ipv6 ]
{ acl-number | name acl-name } ] [ slot slot-number ]
display qos-acl resource [ slot slot-number ]
reset acl [ ipv6 ] counter { acl-number | all | name
acl-name }
reset packet-filter statistics interface [ interface-type
interface-number ] { inbound | outbound } [ [ ipv6 ]
{ acl-number | name acl-name } ]
12
Remarks
N/A
By default, the packet filter permits
packets that do not match any ACL
rule to pass.

Advertisement

Table of Contents
loading

Table of Contents