HP ProCurve 5300xl Series Management Manual page 418

Advanced traffic
Hide thumbs Also See for ProCurve 5300xl Series:
Table of Contents

Advertisement

Access Control Lists (ACLs) for the Series 3400cl and Series 6400cl Switches
Terminology
10-8
Inbound Traffic: For the purpose of defining where the switch applies ACLs
to filter traffic, inbound traffic is any IP packet that:
Enters the switch through a physical port.
Has a destination IP address (DA) that meets either of these criteria:
The packet's DA is for an external device.
The packet's DA is for an IP address configured on the switch
itself. (This increases your options for protecting the switch from
unauthorized management access.)
Because ACLs are assigned to physical ports or port trunks, an ACL that
filters inbound traffic on a particular port or trunk examines packets
meeting the above criteria that enter the switch through that port or trunk.
Outbound Traffic: This is any traffic leaving the switch through a physical
port or trunk. The switch does not apply ACLs to outbound traffic or
internally where routed traffic moves between VLANs. That is, ACL
operation is not affected by enabling or disabling routing on the switch.
(Refer also to "ACL Inbound Application Points" on page 10-9.)
Permit: An ACE configured with this action allows a port or trunk to permit
an inbound packet for which there is a match within an applicable ACL.
Per-Port Mask: An internally applied template for all ACL and IGMP config­
urations. The significance of per-port masks is that a maximum of 8 masks
are available (per-port) for ACL (and IGMP) use.
Figure 10-1. Example of Per-Port Mask Allocation in the Default Configuration
For more information, refer to "Planning an ACL Application on a Series
3400cl or Series 6400cl Switch" on page 10-16. See also "ACL Mask" on
page 10-7.
SA: The acronym for Source IP Address. In an IP packet, this is the source IP
address carried in the IP header, and identifies the packet's sender. In an
extended ACE, this is the first of two IP addresses used by the ACE to
determine whether there is a match between a packet and the ACE. See
also "DA".

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents