Net Optics Director manual Understand pending and active filters

Page 40

Director

Understand pending and active filters

To understand the actions of filter commands such as filter commit, filter discard, and filter delete, it is helpful to visualize the pending filter list and the CAM that holds the active filters.

The previous section explained how the active filters are stored in a CAM, which can be thought of as list of active filters. These filters, which are actively running in the device, may be referred to as active, running, or committed. Pending filters, that is, filters that have been defined using filter add and filter ins commands but not yet committed, are kept in a pending filter list that shadows the CAM. These filters may be referred to as pending or uncommitted. The following table shows which filter commands affect the pending filter list and which affect the CAM.

Commands apply to

Pending filter list

CAM

 

 

filter add

commit

filter del

filter clear

filter discard

filter commit

filter ins

filter running

filter list

 

filter sync

 

As can be seen from the table, most of the time you work with the contents of the pending filter list. When you have the filters set up the way you want them in the pending filter list, a commit or filter commit command transfers the con- tents of the pending filter list to the CAM, activating that filter set-up. (Remeber that commit also changes Director's default configuration, but filter commit does not.)

A common workflow for changing the Director filter configuration might be as follows.

To change the Director filter configuration:

 

 

Pending filter list

 

 

CAM

 

 

 

 

 

 

 

 

 

Address

Filter

 

Address

Filter

 

 

 

 

 

 

 

 

 

 

 

 

1

n1.1 ip_proto=UDP action=drop

 

 

 

 

 

 

 

 

 

 

 

 

2

n1.1 m.1

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Figure 39: Starting state

36

Image 40
Contents Data Monitoring Switch Trademarks and Copyrights Contents Chapter Configuring Filters Using the CLI ChapterAppendix a Appendix BChapter Introduction Key Features Ease of UseMonitor port Filtering Passive, Secure TechnologyAbout this Guide DescriptionDirector Architecture Director internal architectureUSB port Director ManagementTypical Application Network LinksMonitoring Tools 10 Gigabit in-line network connection using a network Tap In-line Monitoring of 10 Gigabit LinksPower LEDs Director Front PanelMonitor Port LEDs DNM / Network Port LEDsDirector Rear Panel XFPChapter Installing Director Plan the Installation Unpack and Inspect the Director deviceInstall SFP and XFP Monitor port Modules Install Director Network ModulesRack Mount the Director device Connect Power to Director Connect the local CLI InterfaceConnect the remote CLI Interface Baud Data bits No parity 1 stop bit No flow controlTip To connect the CLI for remote use over the Management portLog into the CLI To log into the CLIChange Director Password Configure Director using the CLITo change the login password To change the port mode Assign a New Manager IP AddressTo assign a new Manager IP address to Director Change Port ModesSave and Load Director Configurations Set the Current Date and TimeUsing the CLI Help Command To view CLI help informationUsing the CLI Command History Buffer Show name show running, factory, default, or file nameConnect Span Ports to Director To connect a Span portConnect Director With In-line Network Links To connect an in-line network linkCheck the Installation Configure a Matrix Switch connection in DirectorConnect Monitoring Tools to Director Chapter Configuring Filters Using the CLI SyntaxEnter filter commit. The switch connection is activated Copy Traffic From Any Network Port to Any Monitor PortRegenerate Traffic to Any Set of Monitor Ports Lter add inports=n1.1 action=redir redirports=m.3-m.5Create Filters To create a filter that selects IPv4 packets by protocolCreate Complex Filters Logical and filter connectionView filters UDPWork with configurable 10 Gigabit ports Configurable 10 Gigabit XFP ports used as Network portsXFP Port Protocol = Monitor Port Understand filter interactions CAMFlow diagram now looks as follows Exclusive filters N1.1 ipproto=UDP action=drop N1.1 m.1To change the Director filter configuration Understand pending and active filtersFilter running command Enter filter list to view the pending filter list Filter capacity Inports=n1.1-n1.7 Ipproto=6 Vlan=100 Redirports=m.1-m.5,m.10Daisy-chaining Multiple Director Chassis Appendix a Director Specifications Specifications, chassisSpecifications, DNM EnvironmentalCertifications Available ModelsAppendix B Command Line Interface Command Sub-Command Arguments Example and description CommitFilter discard Image Quit User add name=bob pw=bob-pw priv=3 Filter parameters Director Filter Parameters Qual Value Example Description Vlan=128Appendix C Protocol Numbers Num Keyword ProtocolMobile L2TP Limitations on Warranty and Liability By Net Optics, Inc. All Rights Reserved