Allied Telesis SwitchBlade x900-24XT User Manual

Browse online or download User Manual for Software Allied Telesis SwitchBlade x900-24XT. How To Configure Hardware Filters on SwitchBlade

  • Download
  • Add to my manuals
  • Print
  • Page
    / 40
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 0
C613-16119-00 REV D
www.alliedtelesis.com
AlliedWare Plus
TM
OS
How To |
Contents
Contents .................................................................................................................................................... 1
Introduction .............................................................................................................................................. 3
Which products and software versions does this Note apply to? ....................................... 4
Benefits of Named Sequential Hardware ACLs ................................................................................ 5
Extended support limit ................................................................................................................... 5
Flexible hardware filter ................................................................................................................... 5
Structure of a Named Sequential Hardware ACL ........................................................................... 6
IP protocol filter entry .................................................................................................................... 6
MAC filter entry ............................................................................................................................... 6
ICMP protocol filter entry ............................................................................................................. 6
TCP/UDP protocol filter entry ..................................................................................................... 6
Creating Named Sequential Hardware ACLs ................................................................................... 7
Configuring a Named Hardware ACL - without sequence numbers ................................. 7
Configuring a Named Sequential Hardware ACL - with sequence numbers ..................... 7
Removing a sequential entry ......................................................................................................... 7
Overwriting an entry in a Named Sequential Hardware ACL .............................................. 8
Creating Numbered IP Hardware ACLs ............................................................................................ 9
IP packets ........................................................................................................................................... 9
ICMP packets .................................................................................................................................... 9
TCP and UDP packets .................................................................................................................. 10
Creating Numbered MAC address Hardware ACLs ..................................................................... 11
The effects of the action keywords in ACLs ................................................................................... 12
Applying Named Sequential Hardware Filters to port interfaces .............................................. 13
Viewing port information ............................................................................................................. 13
Configure Hardware Filters (ACLS) on SwitchBlade
x908, x900-12XT/S, and x900-24 Series Switches
Page view 0
1 2 3 4 5 6 ... 39 40

Summary of Contents

Page 1 - How To

C613-16119-00 REV Dwww.alliedtelesis.comAlliedWare PlusTM OSHow To |ContentsContents ...

Page 2 - Contents

Page 10 | AlliedWare Plus™ OS How To NoteCreating Numbered IP Hardware ACLsTCP and UDP packetsYou can filter TCP and UDP packets on the basis of: sou

Page 3 - Introduction

Page 11 | AlliedWare Plus™ OS How To NoteCreating Numbered MAC address Hardware ACLsCreating Numbered MAC address Hardware ACLsMAC address hardware AC

Page 4

Page 12 | AlliedWare Plus™ OS How To NoteThe effects of the action keywords in ACLsThe effects of the action keywords in ACLsThe following lists the e

Page 5 - Flexible hardware filter

Page 13 | AlliedWare Plus™ OS How To NoteApplying Named Sequential Hardware Filters to port interfacesApplying Named Sequential Hardware Filters to po

Page 6 - TCP/UDP protocol filter entry

Page 14 | AlliedWare Plus™ OS How To NoteApplying Named Sequential Hardware Filters to a channel-groupApplying Named Sequential Hardware Filters to a

Page 7 - Removing a sequential entry

Page 15 | AlliedWare Plus™ OS How To NoteApplying Numbered Hardware Filters to port interfacesApplying Numbered Hardware Filters to port interfaces Yo

Page 8

Page 16 | AlliedWare Plus™ OS How To NoteApplying Numbered Hardware Filters globallyApplying Numbered Hardware Filters globally You can apply Numbered

Page 9 - ICMP packets

Page 17 | AlliedWare Plus™ OS How To NoteChanging Numbered Hardware ACL orderChanging Numbered Hardware ACL orderUnlike Named Sequential Hardware ACLs

Page 10 - TCP and UDP packets

Page 18 | AlliedWare Plus™ OS How To NoteApplying filters by using QoS class-mapsApplying filters by using QoS class-mapsThe addition of QoS class-map

Page 11

Page 19 | AlliedWare Plus™ OS How To NoteApplying filters by using QoS class-maps2. Create the class-map, as shown below.3. Specify what the class-map

Page 12

Page 2 | AlliedWare Plus™ OS How To NoteContentsApplying Named Sequential Hardware Filters to a channel-group ...

Page 13 - Viewing port information

Page 20 | AlliedWare Plus™ OS How To NoteApplying filters by using QoS class-mapsMost of these options are self-evident, but the following sections gi

Page 14

Page 21 | AlliedWare Plus™ OS How To NoteApplying filters by using QoS class-mapsMatch on TCP flagUnlike other match commands, you can match on multip

Page 15 - Attaching ACLs

Page 22 | AlliedWare Plus™ OS How To NoteApplying filters by using QoS class-mapsProtocol options are also extremely flexible. You can identify common

Page 16

Page 23 | AlliedWare Plus™ OS How To NoteThe logic of the operation of the hardware filtersThe logic of the operation of the hardware filtersFilter op

Page 17

Page 24 | AlliedWare Plus™ OS How To NoteCombining interface ACLs and QoS class-mapsCombining interface ACLs and QoS class-mapsThe switch compares the

Page 18

Page 25 | AlliedWare Plus™ OS How To NoteExamplesExamplesBlocking all multicast trafficThis example uses an interface ACL with an action of deny.Consi

Page 19 - Create a class-map

Page 26 | AlliedWare Plus™ OS How To NoteExamples3. Attach the ACLs to the port (for example, 1.0.10). You must first attach the permit ACL, then the

Page 20

Page 27 | AlliedWare Plus™ OS How To NoteExamples2. Create ACLs to match and mirror HTTP and SMTP traffic. To do this, return to global configuration

Page 21 - Match on TCP flag

Page 28 | AlliedWare Plus™ OS How To NoteExamples3. Create a class-map that matches on ARP traffic and uses the ACL. To do this, use the commands:awpl

Page 22 - Apply the policy-map to ports

Page 29 | AlliedWare Plus™ OS How To NoteExamples3. Create a second class-map that matches on packets that have only the SYN flag set. Use the ACL to

Page 23

Page 3 | AlliedWare Plus™ OS How To NoteIntroductionIntroductionThe SwitchBlade x908, x900-12XT/S, and x900-24 series switches support a powerful hard

Page 24

Page 30 | AlliedWare Plus™ OS How To NoteExamples7. Attach the Named Sequential Hardware ACLs to the port (for example, 1.0.9). To do this, use the co

Page 25 - Examples

Page 31 | AlliedWare Plus™ OS How To NoteHow many filters can you create?How many filters can you create?The total number of filters that you can crea

Page 26

Page 32 | AlliedWare Plus™ OS How To NoteHow many filters can you create?on them. In this mixed-configuration case, the global ACLs actually consume m

Page 27 - Mirroring ARP packets

Page 33 | AlliedWare Plus™ OS How To NoteHow many filters can you create?Add a local ACL to port 2 (implicitly 'after' the global ACL refere

Page 28

Page 34 | AlliedWare Plus™ OS How To NoteHow many filters can you create?The allocation of silicon filter table entries Conceptually, the allocation o

Page 29 - IP and TCP fields

Page 35 | AlliedWare Plus™ OS How To NoteHow many filters can you create?About port range table entry consumption:A single filter table entry for an L

Page 30

Page 36 | AlliedWare Plus™ OS How To NoteHow many filters can you create?Divide the total number of the ports you want to cover into a sum of powers o

Page 31 - 1. The filter rule tables

Page 37 | AlliedWare Plus™ OS How To NoteHow many filters can you create?field types to filter on. However, more bytes are filled within the mask when

Page 32

Page 38 | AlliedWare Plus™ OS How To NoteHow many filters can you create?if you next make an ACL that matches on destination TCP or UDP port, that use

Page 33

Page 39 | AlliedWare Plus™ OS How To NoteHow many filters can you create?Some other features also use filters, so use some of the lengthThe following

Page 34

Page 4 | AlliedWare Plus™ OS How To NoteIntroductionWhich products and software versions does this Note apply to? Products: SwitchBlade x908, x900-12

Page 35

USA Headquarters | 19800 North Creek Parkway | Suite 100 | Bothell | WA 98011 | USA | T: +1 800 424 4284 | F: +1 425 481 3895European Headquarters | V

Page 36 - 2. The profile (mask)

Page 5 | AlliedWare Plus™ OS How To NoteBenefits of Named Sequential Hardware ACLsBenefits of Named Sequential Hardware ACLsThe recommended ACL type t

Page 37 - Src TCP

Page 6 | AlliedWare Plus™ OS How To NoteStructure of a Named Sequential Hardware ACLStructure of a Named Sequential Hardware ACLA Named Sequential Har

Page 38

Page 7 | AlliedWare Plus™ OS How To NoteCreating Named Sequential Hardware ACLsCreating Named Sequential Hardware ACLsThe first step to configuring a

Page 39

Page 8 | AlliedWare Plus™ OS How To NoteCreating Named Sequential Hardware ACLsThe entry with sequence number 5 is now removed from the ACL:#show acce

Page 40 - Reference section

Page 9 | AlliedWare Plus™ OS How To NoteCreating Numbered IP Hardware ACLsCreating Numbered IP Hardware ACLsIP hardware ACLs filter packets from the f

Comments to this Manuals

No comments