H3C S5800 Configuration Manual page 14

Hide thumbs Also See for S5800:
Table of Contents

Advertisement

Out-interface—Interface through which the packet is forwarded normally.
Dest-interface—ACFP server interface connected with ACFP client.
Context ID—Used when the packet is mirrored or redirected to an ACFP client. After the interface
connected to the ACFP client is specified in the policy sent, the ACFP server assigns it a global serial
number (the Context ID) with each Context ID corresponding to an ACFP collaboration policy.
Admin-Status—Indicates whether to enable the policy.
Effect-Status—Indicates the expiration time of the policy and is used to control the expiration time of
all the rules under the policy.
Start-Time—Indicates starting from what time (second/minute/hour) the policy takes effect and is
used to control starting from what time all the rules under the policy take effect.
End-time—Indicates starting from what time (second/minute/hour) the policy turns invalid and is
used to control starting from what time all the rules under the policy turn invalid.
DestIfFailAction—If the policy dest-interface is down, the actions to all rules under the policy will be
as follows: for forwarding first devices, select the delete action to keep the redirected and mirrored
packets being forwarded; for security first devices, select the reserve action to discard the redirected
and mirrored packets.
Priority—Indicates the priority of a policy, number notation, in the range of 1 to 8. The bigger the
number, the higher the priority.
ACFP collaboration rules
ACFP collaboration rules refer to the collaboration rules that the ACFP client sends to the ACFP server for
application. Collaboration rules fall in the following types:
Monitoring rules—Monitors, analyzes, and processes the packets to be sent to the ACFP client. The
action types corresponding to monitoring rules are redirect and mirror.
Filtering rules—Determines which packets to deny and which packets to permit. The action types
corresponding to filtering rules are deny and permit.
Restricting rules—Determines the rate of which packets is to be restricted. The action type
corresponding to restricting rules is rate.
Rule information is described as follows:
ClientID—ACFP client identifier.
Policy index
Rule index—Rule identifier.
Status—Indicates whether the rule is applied successfully.
Action—Can be mirror, redirect, deny, permit, or rate.
Match all packets—Indicates whether to match all the packets. If yes, the following matching needs
not be performed.
Source MAC address
Destination MAC address
Starting VLAN ID
Ending VLAN ID
Protocol number in IP
Source IP address
Wildcard mask of source IP address
6

Advertisement

Table of Contents
loading

This manual is also suitable for:

S5820xS5800 seriesS5820x series

Table of Contents