Defining The Source And Destination Addresses - HP ProCurve Secure Router 7203 dl Advanced Management And Configuration Manual

Secure router
Hide thumbs Also See for ProCurve Secure Router 7203 dl:
Table of Contents

Advertisement

For demand routing, you may want to create an ACL that selects all the traffic
to a particular subnet. In this case, you should specify ip as the protocol.

Defining the Source and Destination Addresses

When you create an extended ACL, you must configure both a source and a
destination address for each entry. You specify first the source address and
then the destination address, using the following syntax for each address:
[any | host <A.B.C.D> | hostname <hostname>] | <A.B.C.D> <wildcard bits>]
Table 3-2 lists the options you have for specifying a source or destination
address.
Table 3-2.
Options for Specifying Source and Destination Addresses
Option
any
host <A.B.C.D>
hostname <hostname>
<A.B.C.D> <wildcard bits>
Using Wildcard Bits. You use wildcard bits to permit or deny a range of IP
addresses. Wildcard bits define which address bits the Secure Router OS
should match and which address bits it should ignore.
When you enter wildcard bits, you use a zero to indicate that the Secure Router
OS should match the corresponding bit in the IP address. You use a one to
indicate that the Secure Router OS can ignore the corresponding bit in the IP
address. In other words, the Secure Router OS does not have to match that bit.
For example, you might enter:
ProCurve(config-ext-nacl)# deny ip any 192.115.1.0 0.0.0.255
If you enter 192.115.1.0 with the wildcard bits 0.0.0.255, the Secure Router
OS will not match any address bits in the fourth octet of the IP address. The
Secure Router OS will match incoming packets to the IP subnet with the
address 192.115.1.0 /24. (For more information about configuring ACLs, see
Chapter 5: Applying Access Control to Router Interfaces.)
Configuring Backup WAN Connections
Configuring Demand Routing for Backup Connections
Meaning
match all hosts
specify a single IP address or a single host
specify a single host, using a hostname rather than an IP
address
specify a range of IP addresses
3-19

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve secure router 7102 dl

Table of Contents