3Com 3CRWX120695A WXR100 manual Configuring Advanced ACL Settings, To change the hit sample rate

Models: 3CRWXR10095A WX4400 3CRWX440095A WX1200 3CRWX120695A WXR100

1 516
Download 516 pages 50.11 Kb
Page 226
Image 226

226CHAPTER 6: CONFIGURING WX SYSTEM PARAMETERS

Configuring

Advanced ACL

Settings

After you configure an ACL, you can configure the following advanced settings:

„Hit counter (enable or disable)

„Hit sample rate (applies if the hit counter is enabled)

„Established option, to apply a new TCP ACE only to established (existing) TCP sessions. By default, TCP ACEs apply to new sessions as well as existing ones.

„ICMP properties, to specify the type and code values for ICMP ports (applies only to ACEs that have ICMP as the protocol)

„Capture option, to redirect matching packets to the CPU (applies to ACEs used for Web Portal access)

To change the hit sample rate

The hit sample rate specifies the time interval, in seconds, at which the packet counter is sampled for each security ACE on which the hit counter is enabled.

By default, the hit sample rate is 0, even when the hit counter is enabled. To use the hit counter, you must enable it and set the hit sample rate. The hit sample rate applies globally to all ACEs on which the hit counter is enabled.

1In the Task List panel, select Edit ACL hit sample rate.

2Select or type the number of seconds between updates in the Hit Sample Rate box.

3Click OK.

To enable the hit counter for an ACE

You can enable the hit counter on an individual ACE basis.

1Select the ACE in the ACL table.

2In the Task List panel, select Enable Hits for this rule.

You also must set the hit sample rate to a value greater than 0, which is the default. (See “To change the hit sample rate”.)

Page 226
Image 226
3Com 3CRWX120695A WXR100, 3CRWXR10095A manual Configuring Advanced ACL Settings, To change the hit sample rate