Basic Connection-Rate Filtering Configuration; Global And Per-Port Configuration - HP ProCurve 6200yl Series Access Security Manual

Hide thumbs Also See for ProCurve 6200yl Series:
Table of Contents

Advertisement

Note
Note
Basic Connection-Rate Filtering
Configuration
Command

Global and Per-Port Configuration

connection-rate-filter sensitivity < low | medium | high | aggressive >
filter connection-rate < port-list > < notify-only | throttle | block >
show connection-rate-filter < blocked-host >
Unblocking Hosts Per-VLAN
vlan < vid > connection-rate-filter unblock
As mentioned earlier, connection-rate filtering is triggered by inbound, routed
traffic exhibiting a relatively high incidence of IP connection attempts from a
single source. If connection-rate filtering throttles or blocks traffic from a
source, all routed traffic from that source is throttled or blocked. Traffic
switched within the VLAN is not affected.
Using this feature requires that IP routing and multiple VLANs are enabled.

Global and Per-Port Configuration

Use the commands in this section to enable connection-rate filtering on the
switch and to apply the filtering on a per-port basis. (You can use the ACL
commands in the next section to adjust a filter policy on a per-vlan basis to
allow traffic from specific, trusted SAs to be routed without being subjected
to the filtering.)
Immediately after you enable or disable connection-rate filtering, the CLI
prompts you to reboot the switch. ProCurve strongly recommends that you
perform the reboot to help ensure optimal switch performance.

Basic Connection-Rate Filtering Configuration

Virus Throttling
Page
3-12
3-13
3-19
3-11

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents