Foundry Networks Switch and Router Installation And Configuration Manual page 1013

Switch and router
Table of Contents

Advertisement

IP Access Policies
IP access policies are rules that determine whether the device forwards or drops IP packets. You create an IP
access policy by defining an IP filter, then applying it to an interface. The filter consists of source and destination
IP information and the action to take when a packet matches the values in the filter. You can configure an IP filter
to permit (forward) or deny (drop) the packet.
You also can configure Layer 4 information in an IP filter. If you configure Layer 4 information, you are configuring
a Layer 4 policy. See "TCP/UDP Access Policies" on page C-20.
You can apply an IP filter to inbound or outbound packets. When you apply the filter to an interface, you specify
whether the filter applies to inbound packets or outbound packets. Thus, you can use the same filter on multiple
interfaces and specify the filter direction independently on each interface.
Figure C.1 shows an example of an inbound IP access policy group applied to port 1 on slot 1 of a BigIron Layer 3
Switch. In this example, packets enter the port from left to right. The first three packets have entered the port and
have been permitted or denied. The two packets on the left have not yet entered the port. When they do, they will
be permitted. Since the last policy in the group is a "permit any" policy, all packets that do not match another
policy are permitted. The "permit any" policy changes the default action to permit.
Source:
209.157.22.69/24
Dest:
211.44.29.67/24
Figure C.1
IP access policies in inbound policy group for a port
Actions
IP access policies either forward or drop IP packets based on the IP source and IP destination addresses. You
also can configure the policy to forward or drop a packet based on TCP/UDP port information. In this case, you
are configuring a TCP/UDP access policy. See "TCP/UDP Access Policies" on page C-20.
December 2000
Inbound IP Access Policy Group for Port 1/1
PolicyID Action
--------------------------------------------------------------------------------
3
17
34
1024
Source:
Source:
209.157.22.11/24
209.157.22.26/24
Dest:
Dest:
209.241.12.66/24
201.21.2.7/24
Denied
Bit
Bucket
Source
Destination
Deny
209.157.22.26/32
any
Deny
209.157.22.14/32
any
Deny
209.157.22.69/32
201.21.2.7/32
Permit any
any
Source:
209.157.22.69/24
Dest:
209.211.44.128/24
Permitted
Policies and Filters
Source:
209.157.22.128/24
Dest:
209.184.66.128/24
Permitted
C - 9

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents