HP 7102dl - ProCurve Secure Router Configuration Manual page 852

Procurve secure router 7000dl series - advanced management and configuration guide
Hide thumbs Also See for 7102dl - ProCurve Secure Router:
Table of Contents

Advertisement

IP Routing—Configuring RIP, OSPF, BGP, and PBR
Configuring Policy-Based Routing
15-126
For example, a university might allow professors, staff, and administra-
tors to access the Internet directly. However, university policies dictate
that traffic from subnets used by students and guests must be processed
by the IDS before being forwarded to the Internet. This security measure
is to deter students and guests from using the university's Internet con-
nection for unauthorized activities. Although traffic from all users may be
destined to the same networks, the router will forward traffic based on
the host that sends the traffic: either directly to the ISP router or to the IDS.
Reserving a connection for specific traffic
Because some traffic requires special handling, you may want to reserve
a particular WAN connection for this traffic. For example, VoIP traffic
requires low delay. Your organization could establish multiple connec-
tions to a remote site, reserving a high-speed connection or a connection
with fewer hops for VoIP traffic. You would configure a policy that selects
VoIP traffic (or other high-priority) traffic and forwards it across the
reserved connection.
Load balancing
When your router connects to a site through more than link, you can
configure policies to forward some traffic over one link and other traffic
over the other. However, a better practice is to load balance using a routing
protocol. (See, for example, "Load Balancing" on page 15-76.)
Routing traffic for network monitor probes
Network monitor probes test static or DHCP routes. Because a probe
should be tied to a particular route, you must ensure that the ProCurve
Secure Router always forwards a probe's packets the same way no matter
which route is currently in the routing table. See Chapter 9: Network
Monitoring.
You can configure your ProCurve Secure Router to route a packet according
to its:
IP precedence value
DiffServ value
source IP address
source and destination IP addresses
application data (source and destination ports)
payload size
By selecting traffic based on these attributes, you can control the path packets
take through a WAN and enforce basic traffic engineering.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve secure router 7203dl j8753a j8753a

Table of Contents