HP ProCurve Secure Router 7203 dl Advanced Management And Configuration Manual page 227

Secure router
Hide thumbs Also See for ProCurve Secure Router 7203 dl:
Table of Contents

Advertisement

N o t e
The ProCurve Secure Router supports "named" ACLs. That is, when you
configure a standard or an extended ACL, you assign it a unique name.
A standard ACL matches only one packet pattern: the source IP address. An
extended ACL matches more complex packet patterns:
source address and destination address
IP protocols
TCP and UDP ports
You should create a standard ACL if you want to select traffic based only on
the source IP address. (See Figure 5-1.) If you want to select traffic based on
other fields in the IP, TCP, or UDP header or if you want the Secure Router OS
to filter traffic based on the both the source and destination IP addresses, you
must create an extended ACL. (See Figure 5-2.)
Server
Server
Core Switch
Edge Switch
LAN
LAN
Figure 5-1. With Standard ACLs, the ProCurve Secure Router Checks Only the
Source Address
Applying Access Control to Router Interfaces
Using ACLs Alone to Configure Access Control
Standard ACL is applied
to the PPP 1 interface
Router
Is this source address
permitted or denied?
Edge Switch
LAN
LAN
Internet
User
5-7

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve secure router 7102 dl

Table of Contents