HP 5500 Ei 5500 Si Switch Series Configuration Guide
Here you can view all the pages of manual HP 5500 Ei 5500 Si Switch Series Configuration Guide. The HP manuals for Printer are available online for free. You can easily download all the documents as PDF.
Page 1571
ii Configuration procedure ··················\ ··················\ ··················\ ··················\ ··················\ ············· ··················\ ············· 20 Defining a traffic behavior ··················\ ··················\ ··················\ ··················\ ··················\ ········· ··················\ ··················\ ····· 21 Defining a policy ··················\ ··················\ ··················\ ··················\ ··················\ ··················\...
Page 1572
iii Configuration procedure ··················\ ··················\ ··················\ ··················\ ··················\ ············· ··················\ ············· 48 Configuration example ··················\ ··················\ ··················\ ··················\ ··················\ ··············· ··················\ ·············· 48 Configuring WRR queuing ··················\ ··················\ ··················\ ··················\ ··················\ ·············...
Page 1573
iv Data buffer configuration approaches ··················\ ··················\ ··················\ ··················\ ··················\ ··················\ ············· 73 Using the burst function to configure the data buffer setup ··················\ ··················\ ··················\ ············· ··················\ ·· 74 Manually configuring th e data buffer setup ··················\ ··················\ ··················\ ··················\ ············ ··················\ ··········...
Page 1574
1 Configuring ACLs • Unless otherwise stated, ACLs refer to both IP v4 and IPv6 ACLs throughout this document. • The term interface i n t h e ro u t i n g f e a t u r e s r e f e r s t o V L A N i n t e r f a c e s , b r i d g e m o d e ( L a ye r 2 ) a n d r o u t e mode (Layer 3) Ethernet ports. You can set an Ethernet port to operate in route mode by using the port link-mode route command (see Layer 2—LAN Switching Configuration Guide ). 5500 SI Switch Series does not...
Page 1575
2 Numbering and naming ACLs Each ACL category has a unique range of ACL numbers. When creating an ACL, you must assign it a number. In addition, you can assign the ACL a name for ease of identification. After creating an ACL with a name, you cannot rename it or delete its name. For an Ethernet frame header ACL, the ACL number and name must be globally unique. For an IPv4 basic or advanced ACLs, its ACL number and name must be unique among all IPv4 ACLs, and for an IPv6 basic or advanced ACL, its...
Page 1576
3 ACL category Sequence of tie breakers Ethernet frame header ACL 7. More 1s in the source MAC address mask (more 1s means a smaller MAC address) 8. More 1s in the destination MAC address mask 9. Rule configured earlier A wildcard mask, also called an inverse mask, is a 32-bit binary and represented in dotted decimal notation. In contrast to a network mask, the 0 bits in a wildcard mask represent do care bits, and the 1 bits represent don’t care bits. If the do care bits in an IP address...
Page 1577
4 Whenever the step changes, the rules are renumbered, starting from 0. For example, if there are five rules numbered 5, 10, 13, 15, and 20, changing the step from 5 to 2 causes the rules to be renumbered 0, 2, 4, 6, and 8. Fragments filtering with ACLs Traditional packet filtering matches only first fragments of packets, and allows all subsequent non-first fragments to pass through. Attackers can fabricate non-first fragments to attack networks. To avoids the risks, the HP ACL implementation:...
Page 1578
5 Step Command Remarks 2. Configure a time range. time-range time-range-name { start-time to end-time days [ from time1 date1 ] [ to time2 date2 ] | from time1 date1 [ to time2 date2 ] | to time2 date2 } By default, no time range exists. Repeat this command with the same time range name to create multiple statements for a time range. Configuring a basic ACL Configuring an IPv4 basic ACL IPv4 basic ACLs match packets based only on source IP addresses. To configure an...
Page 1579
6 Configuring an IPv6 basic ACL To configure an IPv6 basic ACL: Step Command Remarks 1. Enter system view. system-view N/A 2. Create an IPv6 basic ACL view and enter its view. acl ipv6 number acl6-number [ name acl6-name ] [ match-order { auto | config } ] By default, no ACL exists. IPv6 basic ACLs are numbered in the range of 2000 to 2999. You can use the acl ipv6 name acl6-name command to enter the view of a named IPv6 ACL. 3. Configure a description for the IPv6...
Page 1580
7 Step Command Remarks 1. Enter system view. system-view N/A 2. Create an IPv4 advanced ACL and enter its view. acl number acl-number [ name acl-name ] [ match-order { auto | config } ] By default, no ACL exists. IPv4 advanced ACLs are numbered in the range of 3000 to 3999. You can use the acl name acl-name command to enter the view of a named IPv4 ACL. 3. Configure a description for the IPv4 advanced ACL. description text Optional. By default, an IPv4 ad vanced...