Policies and Filters

Zone Filter to block Marketing from accessing Engineering

FilterID Action Zone

-------------------------------------------

1

Deny

Marketing

1024

Permit

any

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Macintosh

 

Macintosh

computer

 

computer

 

 

 

Macintosh

 

Macintosh

computer

 

computer

 

 

 

Engineering zone does not appear in Marketing’s Choosers.

However, RTMP is not filtered--users in Marketing can still ping devices in Engineering.

Figure D.6 AppleTalk zone filter

Appletalk Zone Filters

AppleTalk zone filters let you secure access to an AppleTalk zone. The filter controls whether the routing switch includes the zone in replies to a MAC chooser’s ZIP GetZoneList request.

Actions

An AppleTalk zone filter permits (advertises) or denies (does not advertise) the specified zone. The zone does not appear in MAC user’s choosers but you can still ping the networks that belong to the zone.

NOTE: Unlike other filters, the default action for AppleTalk filters does not change from permit to deny when you create a filter. To permit only specific zones and deny all others, create permit filters for the zones you want to permit, then use the following command to create a deny filter for all other zones:

appletalk deny zone additional-zones.

Scope

You configure and apply AppleTalk zone filters on individual ports.

Syntax

Use the following CLI commands or Web management interface panels to configure AppleTalk zone filters.

Table C.18: AppleTalk Zone Filters

CLI syntax

Web management links

 

 

HP9300(config-if-1/1)# appletalk permit zone <string>

Configure->AppleTalk->Zone Filter

HP9300(config-if-1/1)# appletalk deny zone <string> additional­

Configure->AppleTalk->Additional

zones rtmp-filtering no-rtmp-filtering

Zone Filter

 

 

C - 21