Viewing Access Policy Sessions - HP ProCurve Secure Router 7203 dl Advanced Management And Configuration Manual

Secure router
Hide thumbs Also See for ProCurve Secure Router 7203 dl:
Table of Contents

Advertisement

Applying Access Control to Router Interfaces
Viewing ACLs and ACPs
ProCurve# show ip policy-sessions
Src IP Address
----------------
Policy class "Inside":
tcp (80)
192.168.20.1
Policy class "Outside":
tcp (20)
192.168.100.99
Policy class "self":
icmp (50)
0.0.0.0
5-52

Viewing Access Policy Sessions

After you enable the firewall and assign an ACP to an interface, the Secure
Router OS firewall checks all the packets entering that interface. When a
packet matches an ACL, the Secure Router OS treats it as specified in the ACP.
If the ACP allows the packet, then the Secure Router OS firewall can establish
a connection (also called a session) between the packet's source and its
destination.
The ProCurve Secure Router records information about that session. To view
this information, move to the enable mode context and enter:
Syntax: show ip policy-sessions
The Secure Router OS lists each ACP, or policy class, by name. Under a specific
policy, you can view the traffic that matched this policy as it arrived on the
interface. You can also view information about the traffic, such as:
source IP address
source port
destination IP address
destination port
If the traffic has been manipulated using NAT, the NAT IP address and port
are also listed.
Figure 5-18 illustrates a sample display of sessions.
Src Port
Dest IP Address
---------
--------------
2001
172.16.1.1
1908
172.16.3.10
10
192.168.100.1
Figure 5-18.
Displaying IP Policy Sessions
Dst Port
NAT IP Address
--------
---------------
80
d 10.10.3.10
80
d 10.10.3.10
10
NAT Port
-------
80
80

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve secure router 7102 dl

Table of Contents