Acl Configuration Examples; Interface-Based Packet Filter Configuration Example - HP FlexNetwork MSR Series Configuration Manuals

Comware 7 acl and qos
Hide thumbs Also See for FlexNetwork MSR Series:
Table of Contents

Advertisement

Task
Display detailed ACL packet filtering
information
standalone mode).
Display detailed ACL packet filtering
information
standalone mode/centralized devices in
IRF mode).
Display detailed ACL packet filtering
information (distributed devices in IRF
mode).
Clear ACL statistics.
Clear
match
accumulated statistics) and default action
statistics for packet filtering ACLs.

ACL configuration examples

Interface-based packet filter configuration example

Network requirements
A company interconnects its departments through the device. Configure a packet filter to:
Permit access from the President's office at any time to the financial database server.
Permit access from the Financial department to the database server only during working hours
(from 8:00 to 18:00) on working days.
Deny access from any other department to the database server.
(centralized
devices
(distributed
devices
statistics
(including
Command
display packet-filter verbose { interface interface-type
interface-number { inbound | outbound } [ [ ipv6 | mac ]
{ acl-number | name acl-name } ] | zone-pair security
in
source
destination-zone-name [ [ ipv6 ] { acl-number | name
acl-name } ] }
display packet-filter verbose { interface interface-type
interface-number { inbound | outbound } [ [ ipv6 | mac ]
in
{ acl-number | name acl-name } ] | zone-pair security
source
destination-zone-name [ [ ipv6 ] { acl-number | name
acl-name } ] } [ slot slot-number ]
display packet-filter verbose { interface interface-type
interface-number { inbound | outbound } [ [ ipv6 | mac ]
{ acl-number | name acl-name } ] | zone-pair security
source
destination-zone-name [ [ ipv6 ] { acl-number | name
acl-name } ] } [ chassis chassis-number slot slot-number ]
reset acl [ ipv6 | mac ] counter { acl-number | all | name
acl-name }
reset packet-filter statistics { interface [ interface-type
interface-number ] { inbound | outbound } [ default | [ ipv6 |
the
mac ] { acl-number | name acl-name } ] | zone-pair security
[
source
destination-zone-name ] [ [ ipv6 ] { acl-number | name
acl-name } ] }
18
source-zone-name
source-zone-name
source-zone-name
source-zone-name
destination
destination
destination
destination

Advertisement

Table of Contents
loading

Table of Contents