Example Of Using An Acl In A Connection-Rate Configuration - HP ProCurve 6400cl Series Access Security Manual

Hide thumbs Also See for ProCurve 6400cl Series:
Table of Contents

Advertisement

For more on ACE masks, refer to "How an ACE Uses a Mask To Screen Packets
for Matches" in the chapter titled "Access Control Lists (ACLs for the Series
5300xl Switches" in the Advanced Traffic Management Guide for your switch.
Example of Using an ACL in a Connection-Rate
Configuration
This example adds connection-rate ACLs to the basic example on page 3-14.
B1
Server
B2
Server
Server
B3
Company
Intranet
Server
IP Address: 15.45.50.17
Figure 3-10. Sample Network
In the basic example on page 3-14, the administrator configured connection-
rate blocking on port D2. However:
The administrator has elevated the connection-rate sensitivity to high.
The server at IP address 15.45.50.17 frequently transmits a relatively
high rate of legitimate connection requests, which now triggers
connection-rate blocking of the server's IP address on port D2. This
causes periodic, unnecessary blocking of access to the server.
Virus Throttling (5300xl Switches Only)
Configuring and Applying Connection-Rate ACLs
5300xl Switch
VLAN 1
B9
15.45.100.1
VLAN 10
B4
15.45.200.1
VLAN 15
15.45.300.1
D1
D2
IP Address:
A
B
15.45.100.7
Switch
C
D
Switch
Switch
F
G
H
E
3-27

Advertisement

Table of Contents
loading

Table of Contents