Traffic/Security Filters (ProCurve Series 2600/2600-PWR and 2800 Switches)

Using Source-Port Filters

The same command, using IDX 26, shows how traffic from the Internet is handled.

ProCurve(config)# show filter 26

Traffic/Security Filters

Filter Type : Source Port

Source Port : 1

Dest Port Type

Action

--------- ---------

+ -------

1

10/100TX

Forward

2

10/100TX

Forward

3

10/100TX

Forward

4

10/100TX

Forward

5

10/100TX

Forward

6

10/100TX

Forward

7

10/100TX

Drop

8

10/100TX

Forward

9

10/100TX

Forward

1010/100TX Drop

1110/100TX Drop

1210/100TX Forward

.. .

As the company grows, more resources are required in accounting. Two additional accounting workstations are added and attached to ports 12 and 13. A second server is added attached to port8.

Network Design

1.Accounting Workstations may only send traffic to the Accounting Server.

2.No Internet traffic may be sent to the Accounting Server or Workstations.

3All other switch ports may only send traffic to Port 1.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Accounting Workstation 1

 

 

 

 

 

 

Port 10

Port 1

 

Router to the

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Accounting Workstation 2

 

 

 

 

 

 

 

 

 

 

 

Port 11

 

 

 

Internet

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Accounting Workstation 3

 

 

 

 

 

 

 

 

 

 

Port 12

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Port 13

Port 7

 

Accounting Server 1

Accounting Workstation 4

 

 

 

 

 

 

 

 

Port 8

 

 

Accounting Server 2

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Figure 10-7. Expanded Network Configuration for Named Source-Port FiltersExample

10-16