Ip Filter Policy Enforcement; Implicit Ip Filter Rules; Default Ip Policy Rules - HP A7533A - Brocade 4Gb SAN Switch Base Administrator's Manual

Hp storageworks fabric os 6.x administrator guide (5697-0015, may 2009)
Hide thumbs Also See for A7533A - Brocade 4Gb SAN Switch Base:
Table of Contents

Advertisement

Table 30
Supported services (continued)
Service name
telnet
www
TCP and UDP protocols are valid selections. Fabric OS 5.3.0 and later does not support configuration to
filter other protocols. Implicitly, ICMP type 0 and type 8 packets are always allowed to support ICMP echo
request and reply on commands like ping and traceroute. For the action, only "permit" and "deny" are
valid.
For every IP Filter policy, the following two rules are always assumed to be appended implicitly to the end
of the policy. This is to ensure TCP and UDP traffics to dynamic port ranges is allowed, that way
management IP traffic initiated from a switch, such as syslog, radius and ftp, will not be affected.
Table 31

Implicit IP Filter rules

Source address
Any
Any
A switch with Fabric OS 5.3.0 or later will have a default IP Filter policy for IPv4 and IPv6. The default IP
Filter policy cannot be deleted or changed. When an alternative IP Filter policy is activated, the default IP
Filter policy becomes deactivated.
Table 32

Default IP policy rules

Rule number
1
2
3
4
5
6
7
9
10
1 1
12

IP Filter policy enforcement

An active IP Filter policy is a filter applied to the IP packets through the management interface. IPv4
management traffic will pass through the active IPv4 filter policy, and IPv6 management traffic will pass
through the active IPv6 filter policy. The IP Filter policy applies to the incoming (ingress) management traffic
only. When a packet arrives, it is compared against each rule, starting from the first rule. If a match is
found for the source address, destination port, and protocol, the corresponding action for this rule is taken,
and the subsequent rules in this policy will be ignored. If there is no match, then it is compared to the next
rule in the policy. This process continues until the incoming packet is compared to all rules in the active
policy.
Port number
23
80
Destination port
Protocol
1024-65535
TCP
1024-65535
UDP
Table 32
Source address Destination
port
Any
22
Any
23
Any
897
Any
898
Any
1 1 1
Any
80
Any
443
Any
161
Any
1 1 1
Any
123
Any
600- 1 023
Action
Permit
Permit
lists the rules of the default IP Filter policy.
Protocol
Action
TCP
Permit
TCP
Permit
TCP
Permit
TCP
Permit
TCP
Permit
TCP
Permit
TCP
Permit
UDP
Permit
UDP
Permit
UDP
Permit
UDP
Permit
Fabric OS 6.x administrator guide 119

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ae370a - brocade 4gb san switch 4/12

Table of Contents