Net Optics Director Filter capacity, Inports=n1.1-n1.7 Ipproto=6 Vlan=100 Redirports=m.1-m.5,m.10

Page 43

Director

Be aware of these similar pairs of commands:

filter discard clears the pending filter list, while filter clear clears the CAM

filter list shows the pending filter list, while filter running shows the CAM

filter commit copies the pending filter list to the CAM, while filter sync copies the CAM to the pending filter list

Pending filter list

 

 

CAM

Address

Filter

filter commit

Address

Filter

1

 

1

 

 

 

 

2

 

filter sync

2

 

 

 

 

 

filter discard to clear

 

filter clear to clear

filter list to view contents

 

filter running to view contents

Figure 45: Pairs of similar filter commands

Filter capacity

The capacity of Director's filtering function is roughly 1,000 filter elements per chassis, where a filter element is a port list or a filter parameter. For example, filter add in_ports=n1.1-n1.7 ip_proto=6 vlan=100 action=redir redir_ports=m.1-m.5,m.10has four filter elements:

1.in_ports=n1.1-n1.7

2.ip_proto=6

3.vlan=100

4.redir_ports=m.1-m.5,m.10

Counting filter elements is only a rough gauge of filter utilization, and is not recommended. Instead, examine the pending filter list or CAM contents with filter list and filter running commands. The filter resource utilization is displayed after the filter list.

Warning!______________________________________________________________________________________________

User interactions

When multiple users are logged into Director at the same time, each user has a separate pending filter list in which to create filter configurations. However, there is only one CAM, so any time a user executes a commit or filter commit command, the CAM takes on the filter configuration from that user's pending filter list, and those become the active filters on Director. For this reason, it is a good idea to use a filter sync command to get the current contents of the CAM before adding or modifying filters; that way, the filters that you don't touch remain unaffected after you commit.

________________________________________________________________________________________________________

39

Image 43
Contents Data Monitoring Switch Trademarks and Copyrights Contents Appendix B Chapter Configuring Filters Using the CLIChapter Appendix aChapter Introduction Passive, Secure Technology Key FeaturesEase of Use Monitor port FilteringDescription About this GuideDirector internal architecture Director ArchitectureDirector Management USB portNetwork Links Typical ApplicationMonitoring Tools In-line Monitoring of 10 Gigabit Links 10 Gigabit in-line network connection using a network TapDNM / Network Port LEDs Power LEDsDirector Front Panel Monitor Port LEDsXFP Director Rear PanelChapter Installing Director Unpack and Inspect the Director device Plan the InstallationInstall SFP and XFP Monitor port Modules Install Director Network ModulesRack Mount the Director device Connect the local CLI Interface Connect Power to DirectorTo connect the CLI for remote use over the Management port Connect the remote CLI InterfaceBaud Data bits No parity 1 stop bit No flow control TipTo log into the CLI Log into the CLIChange Director Password Configure Director using the CLITo change the login password Change Port Modes To change the port modeAssign a New Manager IP Address To assign a new Manager IP address to DirectorSet the Current Date and Time Save and Load Director ConfigurationsTo view CLI help information Using the CLI Help CommandShow name show running, factory, default, or file name Using the CLI Command History BufferTo connect a Span port Connect Span Ports to DirectorTo connect an in-line network link Connect Director With In-line Network LinksCheck the Installation Configure a Matrix Switch connection in DirectorConnect Monitoring Tools to Director Syntax Chapter Configuring Filters Using the CLICopy Traffic From Any Network Port to Any Monitor Port Enter filter commit. The switch connection is activatedLter add inports=n1.1 action=redir redirports=m.3-m.5 Regenerate Traffic to Any Set of Monitor PortsTo create a filter that selects IPv4 packets by protocol Create FiltersLogical and filter connection Create Complex FiltersUDP View filtersConfigurable 10 Gigabit XFP ports used as Network ports Work with configurable 10 Gigabit portsXFP Port Protocol = Monitor Port CAM Understand filter interactionsFlow diagram now looks as follows N1.1 ipproto=UDP action=drop N1.1 m.1 Exclusive filtersUnderstand pending and active filters To change the Director filter configurationFilter running command Enter filter list to view the pending filter list Inports=n1.1-n1.7 Ipproto=6 Vlan=100 Redirports=m.1-m.5,m.10 Filter capacityDaisy-chaining Multiple Director Chassis Specifications, chassis Appendix a Director SpecificationsAvailable Models Specifications, DNMEnvironmental CertificationsAppendix B Command Line Interface Commit Command Sub-Command Arguments Example and descriptionFilter discard Image Quit User add name=bob pw=bob-pw priv=3 Filter parameters Vlan=128 Director Filter Parameters Qual Value Example DescriptionNum Keyword Protocol Appendix C Protocol NumbersMobile L2TP Limitations on Warranty and Liability By Net Optics, Inc. All Rights Reserved