Introduction

Contents

 

Introduction

1

Which products and software version does this Note apply to?

2

Creating hardware ACLs

3

Creating IP hardware ACLs

3

Creating MAC address hardware ACLs

6

The effects of the action keywords in ACLs

6

Making filters by applying hardware ACLs to ports

7

Making filters by using QoS class-maps

8

Creating a class-map

9

Specifying what the class-map will match on

9

Matching on “inner” keywords for nested VLANs

10

Matching on TCP flag

11

Matching on eth-format and protocol

12

Applying the class-maps to a policy-map

12

Applying the policy-map to ports

12

The logic of the operation of the hardware filters

13

Combining interface ACLs and QoS class-maps

13

Examples

14

Blocking all multicast traffic

14

Blocking all multicast traffic except one address

15

Mirroring HTTP and SMTP traffic

15

Mirroring ARP packets

16

Blocking TCP sessions in one direction

17

How many filters can you create?

18

1. The filter rules table

18

2. The profile (mask)

19

Are there enough bytes for your set of filters?

20

Some protocols also use filters, so use some of the length

21

Which products and software version does this Note apply to?

zProducts: SwitchBlade x908, x900-12XT/S, and x900-24 series switches

zSoftware versions: 5.2.1-0.1 and above

Hardware filters are also available on Layer 3 switches running the AlliedWare OS. For AlliedWare OS configurations, see the AlliedWare OS How To Notes:

zHow To Use the Hardware Filters on the AT-8948 and AT-9900 Series Switches

zHow To Configure Filtering Actions on QoS Flow Groups and Traffic Classes

These Notes are available from www.alliedtelesis.com/resources/literature/howto.aspx.

Page 2 AlliedWare Plus™ OS How To Note

Page 2
Image 2
Allied Telesis x908, X900-12XT/S manual Which products and software version does this Note apply to?

X900-12XT/S, x908 specifications

The Allied Telesis x908 and the SwitchBlade x900 series of network switches are cutting-edge solutions designed to address the demands of modern networking environments. These switches are known for their high performance, reliability, and robust feature sets, making them ideal for enterprise and service provider networks.

The Allied Telesis x908 series consists of modular and chassis-based systems that can accommodate a variety of network configurations. One of the main features of the x908 series is its ability to offer high scalability with support for a large number of ports. This makes it suitable for data centers and large enterprise networks where space and bandwidth optimization are critical.

In addition to scalability, the x908 series supports advanced Layer 2 and Layer 3 switching capabilities. This allows for efficient traffic management and routing, ensuring that data is delivered swiftly and reliably. The x908 also incorporates intelligent features such as Quality of Service (QoS), which prioritizes critical network traffic, ensuring that time-sensitive data—like voice and video—maintains its quality during transmission.

The SwitchBlade x900 series takes this functionality further with its innovative modular architecture. This allows organizations to configure their networks to meet specific needs by choosing from a variety of interface cards and service modules. The SwitchBlade x900 also supports advanced security features such as Access Control Lists (ACLs) and VLAN segmentation, which provide enhanced protection against unauthorized access and network threats.

Another hallmark of the x908 and SwitchBlade series is their support for high-speed Ethernet technologies, including 10G and 40G Ethernet. This enables organizations to keep pace with the increasing bandwidth demands of applications and services, particularly in cloud computing and data-intensive workloads.

Both the x908 and the SwitchBlade x900 series are designed with energy efficiency in mind, featuring power-saving technologies that reduce overall operational costs. Coupled with Allied Telesis' management tools, which provide detailed analytics and monitoring, network administrators can optimize performance and energy consumption simultaneously.

In summary, the Allied Telesis x908 and SwitchBlade x900 series offer a comprehensive suite of features, high performance, scalability, and advanced networking technologies. They represent a strategic investment for organizations looking to build resilient, efficient, and future-proof network infrastructures.