HP 5200zl, 3500yl manual Appendix G Vrrp, Response options, Sensitivity, Connection-rate ACL

Page 53

Response options

The response behavior of connection-rate filtering can be adjusted by using filtering options. When a worm-like behavior is detected, the connection-rate filter can respond to the threats on the port in the following ways:

Notify only of potential attack: While the apparent attack continues, the switch generates an Event Log notice identifying the offending host source address (SA) and (if a trap receiver is configured on the switch) a similar SNMP trap notice.

Notify and reduce spreading: In this case, the switch temporarily blocks inbound routed traffic from the offending host source address for a “penalty” period and generates an Event Log notice of this action and a similar SNMP trap notice if a trap receiver is configured on the switch. When the penalty period expires, the switch re-evaluates the routed traffic from the host and continues to block this traffic if the apparent attack continues. During the re-evaluation period, routed traffic from the host is allowed.

Block spreading: This option blocks routing of the host’s traffic on the switch. When a block occurs, the switch generates an Event Log notice and a similar SNMP trap notice if a trap receiver is configured on the switch. Note that system personnel must explicitly re-enable a host that has been previously blocked.

Sensitivity

The ability of connection-rate filtering to detect relatively high instances of connection-rate attempts from a given source can be adjusted by changing the global sensitivity settings. The sensitivity can be set to low, medium, high, or aggressive as described below:

Low: sets the connection-rate sensitivity to the lowest possible sensitivity, which allows a mean of 54 routed destinations in less than 0.1 seconds, and a corresponding penalty time for Throttle mode (if configured) of less than 30 seconds

Medium: sets the connection-rate sensitivity to allow a mean of 37 routed destinations in less than 1 second, and a corresponding penalty time for Throttle mode (if configured) between 30 and 60 seconds

High: sets the connection-rate sensitivity to allow a mean of 22 routed destinations in less than 1 second, and a corresponding penalty time for Throttle mode (if configured) between 60 and 90 seconds

Aggressive: sets the connection-rate sensitivity to the highest possible level, which allows a mean of 15 routed destinations in less than 1 second, and a corresponding penalty time for Throttle mode (if configured) between 90 and 120 seconds

Connection-rate ACL

Connection-rate ACLs are used to exclude legitimate high-rate inbound traffic from the connection- rate filtering policy. A connection-rate ACL, consisting of a series of access control entries, creates exceptions to these per-port policies by creating special rules for individual hosts, groups of hosts, or entire subnets. Thus, the system administrator can adjust a connection-rate filtering policy to create and apply an exception to configured filters on the ports in a VLAN.

Appendix G: VRRP

Virtual Router Redundancy Protocol (VRRP) is designed to eliminate the single point of failure inherent in the static default routed environment. In a VRRP environment, two or more “virtual” routers cooperate to provide a high-availability capability on a LAN. VRRP specifies an election protocol that dynamically assigns routing responsibility to one of the virtual routers on a LAN.

A virtual router consists of a set of router interfaces on the same network that share a virtual router identifier (VRID) and a virtual IP address. One router in the group becomes the VRRP Master and the other routers are designated as VRRP Backups. The VRRP Master controls the IP addresses associated with a virtual router.

53

Image 53
Contents HP ProCurve Switch 5400zl, 3500yl, and 6200yl Series Ospf Page Introduction Executive summaryOverview Product positioningProVision Asic architecture HP ProCurve Switch 5400zl and 3500yl SeriesHP ProCurve Switch 6200yl-24G-mGBIC Classification and lookup Inside the ProVision Asic ArchitecturePolicy Enforcement Engine Advanced capabilities of the product family Management subsystemHP ProCurve Switch 5400zl Series 5400zl chassis layout ProCurve Switch 5400zl ChassisHP ProCurve Switch 5406zl chassis layout Power supply types System PoE power Power suppliesFan tray Management module Zl modulesHP ProCurve Switch 5400zl series line interface modules Power supply configurations5406zl 5412zl Specifications Memory ProcessorConsole port Auxiliary portMini-GBICs supported ordered separately DescriptionPorts Open mini-GBIC slots Maximum distance Transceivers supported ordered separatelyHP ProCurve Radio Ports supported ordered separately HP ProCurve ONE Services zl Module J9289A DescriptionHP ProCurve Switch 3500yl Series Page Additional line interface module LED status indicatorsHP ProCurve Switch 6200yl HP ProCurve Switch 6200yl-24G-mGBIC J8992A Performance Overview of features and benefitsSecurity features QoS functions Bandwidth shaping usingConvergence Advanced classifier-based QoSBridging protocols Layer 2 switchingRouting protocols IPv6Management DiagnosticsFuture-proofing Low cost of ownershipDevice management Standards and protocolsGeneral protocols IP MulticastNetwork management MIBsPerformance and capacity Capacity and performance features comparisonQoS/Cos SecurityPer-port buffer sizes Optimizing the 10-GbE port configuration Page Throughput and latency performance data Gbps Gigabit performance traffic patterns Industry-leading warranty HP ProCurve warranty and supportIntelligent Edge and Premium License Appendix a Premium LicenseTask Manual Using Appendix B Policy Enforcement Engine Policy Enforcement Engine benefits Wire-speed performance for ACLsGranular policy enforcement Hardware-based performancePoE device types Appendix C Power over EthernetPoE negotiation Power delivery optionsAdditional PoE power-external supplies Support for pre-802.3af standard powered devices Appendix D PIM Sparse ModeAppendix E LLDP-MED Appendix F Virus Throttle security Page Response options Appendix G VrrpSensitivity Connection-rate ACLXrrp support on 5300xl switch Appendix H Ospf Equal Cost Multipath Vlan ID Appendix I Advanced Classifier-Based QoSLimitations/Restrictions Appendix J Server-to-Switch Distributed TrunkingAn example of upstream traffic forwarding is as follows Appendix K TroubleshootingLED status indicators for 5400zl series EPS LED LED status indicators for 3500yl and 6200yl series Temp On green Blinking orange Fan Status PoE Status Off Part number Component Part numbers and Field Replaceable UnitsPart number Component For more information