HP 6125G HP 6125G & 6125G/XG Blade Switches ACL and QoS Configuration - Page 17

Displaying and maintaining ACLs, Configuration example of using ACL for device management

Page 17 highlights

Step 1. Enter system view. Command system-view 2. Enter interface view. interface interface-type interface-number 3. Apply an IPv6 basic or IPv6 packet-filter ipv6 { acl6-number | advanced ACL to the interface name acl6-name } { inbound | to filter IPv6 packets. outbound } Remarks N/A N/A By default, no IPv6 ACL is applied to the interface. Displaying and maintaining ACLs Task Command Remarks Display configuration and match statistics for one or all IPv4 ACLs. display acl { acl-number | all | name acl-name } [ slot slot-number ] [ | { begin | exclude | include } regular-expression ] Available in any view Display configuration and match statistics for one or all IPv6 ACLs. display acl ipv6 { acl6-number | all | name acl6-name } [ slot slot-number ] [ | { begin | exclude | include } regular-expression ] Available in any view Display the usage of ACL rules. display acl resource [ slot slot-number ] [ | { begin | exclude | include } regular-expression ] Available in any view Display the application status of packet filtering ACLs on interfaces. display packet-filter { { all | interface interface-type interface-number } [ inbound | outbound ] | interface vlan-interface vlan-interface-number [ inbound | outbound ] [ slot slot-number ] } [ | { begin | exclude | include } regular-expression ] Available in any view Display the configuration and status of one or all time ranges. display time-range { time-range-name | all } [ | { begin | exclude | include } regular-expression ] Available in any view Clear statistics for one or all IPv4 reset acl counter { acl-number | all | name ACLs. acl-name } Available in user view Clear statistics for one or all IPv6 reset acl ipv6 counter { acl6-number | all | basic and advanced ACLs. name acl6-name } Available in user view Configuration example of using ACL for device management Network requirements As shown in Figure 1, configure ACLs so that: • Host A can telnet to the switch only during the working time (8:30 to 18:00 of every working day). • As a TFTP client, the switch can get files from only the server 11.1.1.100. This makes sure that the switch saves only authorized files. 11

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84

11
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type
interface-number
N/A
3.
Apply an IPv6 basic or IPv6
advanced ACL to the interface
to filter IPv6 packets.
packet-filter ipv6
{
acl6-number
|
name
acl6-name
} {
inbound
|
outbound
}
By default, no IPv6 ACL is applied
to the interface.
Displaying and maintaining ACLs
Task
Command
Remarks
Display configuration and match
statistics for one or all IPv4 ACLs.
display
acl
{
acl-number
|
all
|
name
acl-name
} [
slot
slot-number
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display configuration and match
statistics for one or all IPv6 ACLs.
display
acl
ipv6
{
acl6-number
|
all
|
name
acl6-name
} [
slot
slot-number
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display the usage of ACL rules.
display acl resource
[
slot
slot-number
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display the application status of
packet filtering ACLs on interfaces.
display
packet-filter
{ {
all
|
interface
interface-type
interface-number
} [
inbound
|
outbound
] |
interface
vlan-interface
vlan-interface-number
[
inbound
|
outbound
]
[
slot
slot-number
] } [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display the configuration and
status of one or all time ranges.
display time-range
{
time-range-name
|
all
}
[
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Clear statistics for one or all IPv4
ACLs.
reset
acl
counter
{
acl-number
|
all
|
name
acl-name
}
Available in user view
Clear statistics for one or all IPv6
basic and advanced ACLs.
reset
acl
ipv6
counter
{
acl6-number
|
all
|
name
acl6-name
}
Available in user view
Configuration example of using ACL for device
management
Network requirements
As shown in
Figure 1
, configure ACLs so that:
Host A can telnet to the switch only during the working time (8:30 to 18:00 of every working day).
As a TFTP client, the switch can get files from only the server 11.1.1.100. This makes sure that the
switch saves only authorized files.