HP 6125XLG R2306-HP 6125XLG Blade Switch ACL and QoS Configuration Guide - Page 16

Configuring packet filtering with ACLs, Applying an ACL to an interface for packet filtering

Page 16 highlights

Configuring packet filtering with ACLs This section describes procedures for applying an ACL to filter incoming or outgoing IPv4 or IPv6 packets on the specified interface. Applying an ACL to an interface for packet filtering Step Command Remarks 1. Enter system view. system-view N/A 2. Enter interface view. interface interface-type interface-number N/A By default, an interface does not 3. Apply an ACL to the interface packet-filter [ ipv6 ] { acl-number | filter packets. to filter packets. name acl-name } { inbound | outbound } [ hardware-count ] You can apply up to one ACL to the same direction of an interface. Setting the interval for generating and outputting packet filtering logs After you set the interval, the device periodically generates and outputs the packet filtering logs, including the number of matching packets and the matched ACL rules. For more information about the information center, see Network Management and Monitoring Configuration Guide. To set the interval for generating and outputting packet filtering logs: Step Command Remarks 1. Enter system view. system-view N/A 2. Set the interval for generating The default setting is 0 minutes, and outputting packet filtering acl [ ipv6 ] logging interval interval which mean that no packet filtering logs. logs are generated. Setting the packet filtering default action Step 1. Enter system view. Command system-view 2. Set the packet filtering default action to deny. packet-filter default deny Remarks N/A By default, the packet filter permits packets that do not match any ACL rule to pass. Displaying and maintaining ACLs Execute display commands in any view and reset commands in user view. 10

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109

10
Configuring packet filtering with ACLs
This section describes procedures for applying an ACL to filter incoming or outgoing IPv4 or IPv6 packets
on the specified interface.
Applying an ACL to an interface for packet filtering
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type
interface-number
N/A
3.
Apply an ACL to the interface
to filter packets.
packet-filter
[
ipv6
] {
acl-number
|
name
acl-name
} {
inbound
|
outbound
} [
hardware-count
]
By default, an interface does not
filter packets.
You can apply up to one ACL to the
same direction of an interface.
Setting the interval for generating and outputting packet
filtering logs
After you set the interval, the device periodically generates and outputs the packet filtering logs,
including the number of matching packets and the matched ACL rules. For more information about the
information center, see
Network Management and Monitoring Configuration Guide
.
To set the interval for generating and outputting packet filtering logs:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Set the interval for generating
and outputting packet filtering
logs.
acl
[
ipv6
]
logging
interval
interval
The default setting is 0 minutes,
which mean that no packet filtering
logs are generated.
Setting the packet filtering default action
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Set the packet filtering default
action to deny.
packet-filter
default
deny
By default, the packet filter permits
packets that do not match any ACL
rule to pass.
Displaying and maintaining ACLs
Execute
display
commands in any view and
reset
commands in user view.