Allied Telesisメーカーx908の使用説明書/サービス説明書
ページ先へ移動 of 21
C613-16119-00 REV A www .alliedtelesis.com AlliedW ar e Plus TM OS How T o | Intr oduction The SwitchBlade x908 , x900-12XT/S, and x90 0-24 series switches supp or t a pow erful hardwar e based packet-filtering facility .
Page 2 | AlliedW are Plus ™ OS How T o Note Intr oduction Contents Intr oduction .......... .................................................................... .................................... ............................ 1 Which pr oducts and software version does this Note apply to? .
Page 3 | AlliedW are Plus ™ OS How T o Note Creating hardwar e A CLs Cr eating hardwar e A CLs Hardwar e A CLs contain both the match criteria and the action to take on matching traffic. Ther e are two types of har dware A CL: IP ad dress and MA C address.
Page 4 | AlliedW are Plus ™ OS How T o Note Creating hardwar e A CLs IP pack ets Y ou can filter IP packets on the basis of thei r source and/or destination IP addr esses.
Page 5 | AlliedW are Plus ™ OS How T o Note Creating hardwar e A CLs TCP and UDP packets Y ou can filter TCP and UDP packets on the basis of: z sour ce IP address and/or destination IP ad dress (using the same syntax as when filtering IP pack ets) z sour ce and/or destination TCP/UDP por ts.
Page 6 | AlliedW are Plus ™ OS How T o Note The effects of the action k eyw ords in A CL s Cr eating MA C addr ess hardwar e A CLs MA C addr ess hardware A CLs filter pack ets on the basis of their source or destination MA C addr ess.
Page 7 | AlliedW are Plus ™ OS How T o Note Making fi lters by a pplying har dware A CLs to ports Making filters by a pplying har dware A CLs to por ts Y ou can create a filter by simpl y applying one or more ACLs to a port, as long as y ou can select the matching traffic thr ough hard ware A CL ke ywor ds, a s described abov e .
Page 8 | AlliedW are Plus ™ OS How T o Note Making fil ters by using QoS class-maps Making filters by using QoS class-ma ps QoS class-maps allow y ou to match on a m uch wi der range of pack et attributes than A CLs by themselves. The y do this by determining the match criteria fr om an A CL, or from match commands, or fr om both in combination.
Page 9 | AlliedW are Plus ™ OS How T o Note Making fil ters by using QoS class-maps 3. Specify what the class-map will match on (see page 9 ). This inv olves: z attaching the A CL to the class-map z using other match commands to further limi t what the traffic will match the class-map (unless the A CL ’ s se ttings wer e enough) 4.
Page 10 | AlliedW are Plus™ OS How T o Note Making fil ters by using QoS class-maps Matching on “inner” k eyw ords f or nested VLANs The match tpid , ma tch inner -tpid , match inner -vlan , and match inner -cos commands all appl y to nested VLAN configuration.
Page 11 | AlliedW are Plus™ OS How T o Note Making fil ters by using QoS class-maps Matching on TCP flag Unlik e the other match commands, you can match on multiple TCP flags.
Page 12 | AlliedW are Plus™ OS How T o Note Making fil ters by using QoS class-maps Matching on eth-format and pr otocol Ethernet format and pr otocol are specified to ge ther , as a pair .
Page 13 | AlliedW are Plus™ OS How T o Note The logic of the operation of the har dware filters The logic of the operation of the hardwar e filters The operation of the filters follows the standar d A CL log ic: if a pack et matches an A CL on the por t, the comparison pr ocess stops and the action attached to the A CL is performed.
Page 14 | AlliedW are Plus™ OS How T o Note Examples Examples Blocking all multicast traffic This example uses an interface A CL with an action of deny . Consider a situation where m ultiple clients ar e attached to the s witch, with each client attached to a differ ent por t.
Page 15 | AlliedW are Plus™ OS How T o Note Examples Blocking all multicast tr affic except one ad dress This example uses two interface A CLs, one with an action of permit and one with an action of deny . Use this type of configuration when y ou want to discar d a wide range of traffic but want to forwar d a subset of traffic within tha t range.
Page 16 | AlliedW are Plus™ OS How T o Note Examples Mirr oring ARP pack ets This example uses a QoS class-map . Use this type of configuration when y ou want to mirror a subset of the incoming traffic on a port, a nd y ou need to us e QoS match comm ands to select the mirr ored traffic.
Page 17 | AlliedW are Plus™ OS How T o Note Examples Blocking TCP sessions in one dir ection This example uses two QoS class-maps. Administrators often want to block the establis hment of TCP sessions in one direction, but allow TCP sessions to be established in the opposi te dir ection.
Page 18 | AlliedW are Plus™ OS How T o Note Ho w many filters can you cr eate? How man y filters can you cr eate? The total number of filters that can be cr eate d is not an exact number , but depends on w hich fields the various filters are matching on.
Page 19 | AlliedW are Plus™ OS How T o Note Ho w many filters can you cr eate? 2. The pr ofile (mask) The other item is called the pr of ile. Conceptually , this is a 16 -byte mask that decides whic.
Page 20 | AlliedW are Plus™ OS How T o Note Ho w many filters can you cr eate? Ar e there enough bytes f or your set of filters? Of course, the m ask cannot incr ease withou t limit—it has a maximum size of 16 b ytes.
USA Headq u ar ters | 19800 Nor th Cr eek Parkwa y | S u ite 200 | Bothell | WA 98011 | USA | T: +1 800 424 4284 | F: +1 425 481 3895 E u r opea n Headq u ar ters | Via Motta 24 | 6830 Chiasso | Switzerla n d | T: +41 91 69769.
デバイスAllied Telesis x908の購入後に(又は購入する前であっても)重要なポイントは、説明書をよく読むことです。その単純な理由はいくつかあります:
Allied Telesis x908をまだ購入していないなら、この製品の基本情報を理解する良い機会です。まずは上にある説明書の最初のページをご覧ください。そこにはAllied Telesis x908の技術情報の概要が記載されているはずです。デバイスがあなたのニーズを満たすかどうかは、ここで確認しましょう。Allied Telesis x908の取扱説明書の次のページをよく読むことにより、製品の全機能やその取り扱いに関する情報を知ることができます。Allied Telesis x908で得られた情報は、きっとあなたの購入の決断を手助けしてくれることでしょう。
Allied Telesis x908を既にお持ちだが、まだ読んでいない場合は、上記の理由によりそれを行うべきです。そうすることにより機能を適切に使用しているか、又はAllied Telesis x908の不適切な取り扱いによりその寿命を短くする危険を犯していないかどうかを知ることができます。
ですが、ユーザガイドが果たす重要な役割の一つは、Allied Telesis x908に関する問題の解決を支援することです。そこにはほとんどの場合、トラブルシューティング、すなわちAllied Telesis x908デバイスで最もよく起こりうる故障・不良とそれらの対処法についてのアドバイスを見つけることができるはずです。たとえ問題を解決できなかった場合でも、説明書にはカスタマー・サービスセンター又は最寄りのサービスセンターへの問い合わせ先等、次の対処法についての指示があるはずです。