Connection-Rate Acl Operation - HP ProCurve 6400cl Series Access Security Manual

Hide thumbs Also See for ProCurve 6400cl Series:
Table of Contents

Advertisement

Note
Connection-Rate ACLs are a special case of the switch's ACL feature. If you
need information on other applications of ACLs or more detailed information
on how ACLs operate, refer to the chapter titled "Access Control Lists (ACLs)
for the Series 5300xl Switches" in the Advanced Traffic Management Guide
for your 5300xl switch.

Connection-Rate ACL Operation

A connection-rate ACL applies to inbound traffic on all ports configured for
connection-rate filtering in the assigned VLAN, and creates an exception to
the connection-rate filter policy configured on each port. A connection-rate
ACL has no effect on ports in the VLAN that are not configured for connection-
rate filtering.
A connection-rate ACL accepts inbound, legitimate traffic from trusted
sources without filtering the traffic for the configured connection-rate policy.
You can configure an ACL to assign policy filtering (filter) for traffic from some
sources and no policy filtering (ignore) for traffic from other sources. How­
ever, the implicit filter invoked as the last entry in any connection-rate ACL
ensures that any traffic not specifically excluded from policy filtering (by the
ignore command) will be filtered by the configured policy for the port on which
that traffic entered the switch.
Ignore
Al
low Traffic from Host
"A" without Filtering
Through Per-Port
Connection-Rate Pol
Figure 3-8. Connection-Rate ACL Applied to Traffic Received Through a Given Port
Virus Throttling (5300xl Switches Only)
Configuring and Applying Connection-Rate ACLs
Inbound Routed Traffic from
Host "A" w th Relatively H
i
Number of IP Connection-Rate
Attempts
Yes
Source Match
on any ACE in
the ACL?
Ignore
Filter
or
Filter
?
Apply Per-Port Connection-Rate
Policy to Host "A" Traffic:
– Not fy-On
i
icy
Throttle
– Bl
ock
igh
No
Apply Implicit ACE
(filter)
ly
3-21

Advertisement

Table of Contents
loading

Table of Contents