HP ProCurve Secure 7000dl Series Basic Management And Configuration Manual page 419

Secure router procurve 7000dl series
Hide thumbs Also See for ProCurve Secure 7000dl Series:
Table of Contents

Advertisement

N o t e
If you include the in option when you enter the match-interesting command,
the ProCurve Secure Router will check only the traffic received on the demand
interface. If you include the out option, the router will check only the traffic
transmitted from the interface.
For example, suppose that you configured the Branch ACL to select traffic
from the local network destined to a branch office network. If you want both
traffic outbound to the branch office and inbound from the branch office to
trigger the dial-up connection, apply the Branch ACL to demand 1 interface:
ProCurve(config-demand 1)# match-interesting list Branch
When you view the demand interface in the running-config, you will see two
commands, even though you entered only one. (See Figure 8-9.)
interface demand 1
match-interesting list Branch out
match-interesting reverse list Branch in
Figure 8-9. The match-interesting Command as Displayed in the Running-Config
Entering the following two commands would accomplish the same thing:
ProCurve(config-demand 1)# match-interesting list Branch out
ProCurve(config-demand 1)# match-interesting reverse list Branch in
After you configure demand routing, you should monitor usage of the dial-up
connection to determine if you have correctly configured the ACL to select
interesting traffic. To avoid any problems when the bill for the dial-up
connection arrives, ensure that the connection is being triggered only when
you want it to be. To minimize costs, you may need to change the ACL by
further limiting the traffic that triggers the connection.
Applying an ACP or Another ACL to the Demand Interface. In addition
to using an ACL to determine which traffic triggers a dial-up connection, you
can use ACLs to control incoming traffic and outgoing traffic on that connection.
You have two options for controlling traffic:
You can apply ACLs directly to the demand interface. If you choose this
option, you can apply one ACL directly to the interface to control incoming
traffic, and you can apply another ACL directly to the interface to control
outgoing traffic. (For best practices, you typically apply an extended ACL
closest to the source of incoming traffic so that you do not waste the
router's processing time on traffic that will ultimately be discarded.)
Configuring Demand Routing for Primary ISDN Modules
Using Demand Routing for ISDN Connections
8-27

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve 7102dl seriesProcurve 7103dl series

Table of Contents