HP 7102dl - ProCurve Secure Router Configuration Manual page 114

Procurve secure router 7000dl series - advanced management and configuration guide
Hide thumbs Also See for 7102dl - ProCurve Secure Router:
Table of Contents

Advertisement

Configuring Backup WAN Connections
Configuring Demand Routing for Backup Connections
3-26
ACP to control access to an already-active backup connection. However, the
connection will only be triggered by traffic that matches the ACL that you
specify in the match-interesting list command.
Because you can configure one ACL to trigger the dial-up connection and
another ACL to control access to the dial-up connection, you can allow certain
types of traffic to use a connection only when it is already established. For
example, if you apply an ACL for outbound traffic to the demand interface,
the router will match traffic destined out the demand interface against this list
first. If the router determines that a packet is allowed, it will then check the
ACL specified with the match-interesting list command to determine if the
packet should trigger the backup connection. If the packet is not defined as
interesting traffic, the ProCurve Secure Router will not attempt to establish
the connection. However, if the connection is already established, the router
will transmit packets that are permitted by the ACL, but not selected as
interesting traffic, over the ISDN link. These packets will not reset the idle
timer for the demand interface. (The idle timer determines how long the dial-
up connection will remain connected in the absence of interesting traffic.
When the router receives interesting traffic, it resets the idle timer. For more
information about timers, see "Configuring the idle-timeout Option" on page
3-36 and "Configuring the fast-idle Option" on page 3-36.)
For example, suppose two nodes at a remote site need to communicate with
a server at a local site. One node is specified in the ACL that triggers the
connection, but the other node is not. The first node's communication will
keep the link active until it has completed its transfer of data and the idle timer
has expired. If the idle timer expires when the second node is communicating
with the server, the connection will be terminated because the second node's
traffic does not match the ACL specified in the match-interesting list
command.
In addition to applying an ACL to control outbound traffic, you can apply an
ACL for inbound traffic or an ACP to the demand interface. In this case, the
ACL or the ACP will filter inbound traffic to your network over the backup
connection. If the router determines that a packet is allowed, it will forward
the packet. However, the router will reset the dial-up connection's idle timer
only if the packet also matches the ACL specified with the match-interesting
reverse list command.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve secure router 7203dl j8753a j8753a

Table of Contents