Setting The Packet Filtering Default Action; Enabling Hardware-Count For The Packet Filtering Default Action; Enabling Acl Acceleration - HP FlexNetwork MSR Series Configuration Manuals

Comware 7 acl and qos
Hide thumbs Also See for FlexNetwork MSR Series:
Table of Contents

Advertisement

Step
2.
Set the interval for outputting
packet
notifications.

Setting the packet filtering default action

Step
1.
Enter system view.
2.
Set
the
default action to deny.
NOTE:
The packet filtering default action does not take effect on zone pair packet filtering. The default
action for zone pair packet filtering is deny.
Enabling hardware-count for the packet filtering default
action
When you enable hardware-count for the packet filtering default action on an interface, the interface
counts how many times the packet filtering default action is performed.
To enable the hardware-count feature for the packet filtering default action on an interface, make
sure you have applied ACLs to the interface for packet filtering.
To enable hardware-count for the packet filtering default action:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Enable hardware-count for
the packet filtering default
action on the interface.

Enabling ACL acceleration

ACL acceleration speeds up ACL rule lookup. The acceleration effect increases with the number of
ACL rules. For example, when a large ACL is used for a session-based service, such as NAT or
ASPF, ACL acceleration can avoid session timeouts caused by ACL processing delays.
To enable ACL acceleration:
Step
1.
Enter system view.
Command
acl { logging | trap } interval
filtering
logs
or
interval
Command
system-view
packet
filtering
packet-filter default deny
Command
system-view
interface
interface-number
packet-filter default { inbound |
outbound } hardware-count
Command
system-view
interface-type
16
Remarks
The default setting is 0 minutes.
By default, the device does not
generate log entries or SNMP
notifications for packet filtering.
Remarks
N/A
By
default,
the
packet
permits packets that do not match
any ACL rule to pass.
Remarks
N/A
N/A
By default, hardware-count is
disabled for the packet filtering
default action.
Remarks
N/A
filter

Advertisement

Table of Contents
loading

Table of Contents