HP 7000 dl Router Series Guia do Utilizador Página 254

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 941
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 253
SROS Command Line Interface Reference Guide Global Configuration Mode Command Set
5991-2114 © Copyright 2005 Hewlett-Packard Development Company, L.P. 254
Functional Notes
Access control lists (ACLs) are used as packet selectors by other Secure Router OS systems; by
themselves they do nothing. ACLs are composed of an ordered list of entries with an implicit deny all at
the end of each list. An ACL entry contains two parts: an action (permit or deny) and a packet pattern. A
permit ACL is used to allow packets (meeting the specified pattern) to enter the router system. A deny ACL
advances the Secure Router OS to the next access policy entry. The Secure Router OS provides two types
of ACLs: standard and extended. Standard ACLs allow source IP address packet patterns only. Extended
ACLs may specify patterns using most fields in the IP header and the TCP or UDP header.
ACLs are performed in order from the top of the list down. Generally, the most specific entries should be at
the top and the most general at the bottom.
The following commands are contained in the access-list extended:
remark
Use the remark command to associate a descriptive tag (up to 80 alphanumeric characters encased in
quotation marks) to the access-list. Enter a functional description for the list such as “This list blocks all
outbound web traffic”.
log
Using the log keyword logs a message (if debug access-list is enabled for this access list) when the access
list finds a packet match.
Usage Examples
The following example creates an access list AllowIKE to allow all IKE (UDP Port 500) packets from the
190.72.22.55.0/24 network:
(config)#ip access-list extended AllowIKE
(config-ext-nacl)#permit udp 190.72.22.55.0 0.0.0.255 eq 500 any eq 500
For more details, refer to the ProCurve SROS Documentation CD for technical support notes regarding
access-list configuration.
Technology Review
Creating access policies and lists to regulate traffic through the routed network is a four-step process:
Step 1:
Enable the security features of the
Secure Router OS
using the ip firewall command.
Step 2:
Create an access control list (using the ip access-list command) to permit or deny specified traffic.
Standard access lists provide pattern matching for source IP addresses only. (Use extended access lists
for more flexible pattern matching.) IP addresses can be expressed in one of three ways:
1. Using the keyword any to match any IP address. For example, entering deny any will effectively shut
down the interface that uses the access list because all traffic will match the any keyword.
Vista de página 253
1 2 ... 249 250 251 252 253 254 255 256 257 258 259 ... 940 941

Comentários a estes Manuais

Sem comentários

DeVilbiss COMPACT P2-11 manuály

Uživatelské manuály a uživatelské příručky pro Stříkací barva DeVilbiss COMPACT P2-11.
Poskytujeme 2 manuály pdf DeVilbiss COMPACT P2-11 ke stažení zdarma podle typů dokumentů: Uživatelský manuál, Specifikace






Další produkty a příručky pro Stříkací barva DeVilbiss

Modely Typ Dokumentu
SB-2-001-F Uživatelský manuál   SB-2-259-B JGA-504 CONVENTIONAL SPRAY GUN [en] , 8 stránky
SB-2-001-F Uživatelský manuál   SB-2-362 - Coast Industrial Systems, Inc., 6 stránky
HVLP Gravity Feed Spraygun Uživatelský manuál   BINKS SV100 HVLP GRAVITY FEED SPRAY GUN, 8 stránky
SB-E-2-534 Uživatelský manuál   DEVILBISS COMPACT – Gravity Feed Spraygun, 12 stránky
FAC752-3 Provozní pokyny   DeVilbiss FAC752-3 Operating instructions, 12 stránky
SB-2-546 Uživatelský manuál   parts breakdown, 1 stránky
SB-2-546 Uživatelský manuál   SB-2-199-F, 8 stránky
SB-E-2-534 Uživatelský manuál     CONV-GRAV ENG-FR-GER-534 iss2.pub, 32 stránky
SB-2-001-F Uživatelský manuál   SB-2-246-G JGHV-531 HIGH VOLUME LOW PRESSURE SPRAY, 6 stránky
SB-2-546 Uživatelský manuál   For Waterborne Materials, 34 stránky