Configuring Packet Filtering With Acls; Applying An Acl To An Interface For Packet Filtering; Applying An Acl To A Zone Pair For Packet Filtering; Configuring Logging And Snmp Notifications For Packet Filtering - HP FlexNetwork MSR Series Configuration Manuals

Comware 7 acl and qos
Hide thumbs Also See for FlexNetwork MSR Series:
Table of Contents

Advertisement

Configuring packet filtering with ACLs

This section describes procedures for applying an ACL to filter incoming or outgoing IPv4 or IPv6
packets on the specified interface.

Applying an ACL to an interface for packet filtering

Step
1.
Enter system view.
2.
Enter interface view.
3.
Apply an ACL to the interface
to filter packets.

Applying an ACL to a zone pair for packet filtering

Step
1.
Enter system view.
2.
Enter zone pair view.
3.
Apply an ACL to the zone
pair to filter packets.
Configuring logging and SNMP notifications for packet
filtering
You can configure the ACL module to generate log entries or SNMP notifications for packet filtering
and output them to the information center or SNMP module at the output interval. The log entry or
notification records the number of matching packets and the matched ACL rules. If an ACL is
matched for the first time, the device immediately outputs a log entry or notification to record the
matching packet.
For more information about the information center and SNMP, see Network Management and
Monitoring Configuration Guide.
To configure logging and SNMP notifications for packet filtering:
Step
1.
Enter system view.
Command
system-view
interface
interface-type
interface-number
packet-filter [ ipv6 | mac ]
{ acl-number | name acl-name }
{ inbound | outbound }
Command
system-view
zone-pair
security
source-zone-name
destination
destination-zone-name
packet-filter [ ipv6 ] { acl-number
| name acl-name }
Command
system-view
15
Remarks
N/A
Layer
2
interfaces
supported.
By default, an interface does not
filter packets.
You can apply up to 32 ACLs to
the same direction of an interface.
Remarks
N/A
source
N/A
By default, a zone pair does not
filter packets.
You can apply up to 32 ACLs to
the same zone pair.
For more information about zone
pair,
see
Configuration Guide.
Remarks
N/A
are
not
Fundamentals

Advertisement

Table of Contents
loading

Table of Contents