SNR S2989G-48TX-RPS — настройка функций безопасности и перенаправления трафика [385/553]

Превью страниц Страница 385 / 553
SNR S2989G-48TX-DC [385/553] Flow based redirection troubleshooting help
S2989G-24TX Operation Manual
Chapter 6 Security Function Configuration
6-112
Command
Explanation
Global Mode
vlan-port-redirect vlan maximum <1-1000>
no vlan-port-redirect vlan maximum
Configure the maximum
number of vlan of redirect on
each port.
6.13.3
Flow-based Redirection Examples
Example:
User’s request of configuration is listed as follows: redirecting the frames whose
source IP is 192.168.1.111 received from port 1 to port 6, that is sending the frames
whose source IP is 192.168.1.111 received from port 1 through port6.
Modification of configuration:
1: Set an ACL, the condition to be matched is: source IP is 192.168.1.111;
2: Apply the redirection based on this flow to port 1.
The following is the configuration procedure:
Switch(config)#access-list 1 permit host 192.168.1.111
Switch(config)#interface ethernet 1/0/1
Switch(Config-If-Ethernet1/0/1)# access-group 1 redirect to interface ethernet 1/0/6
6.13.4
Flow-based Redirection Troubleshooting Help
When the configuration of flow-based redirection fails, please check that whether it
is the following reasons causing the problem:
The type of flow (ACL) can only be digital standard IP ACL, digital extensive IP ACL,
nomenclature standard IP ACL, nomenclature extensive IP ACL, digital standard
IPv6 ACL, and nomenclature standard IPv6 ACL;
Parameters of Timerange and Portrange can not be set in ACL, the type of ACL
should be Permit.
The redirection port must be 1000Mb port in the flow-based redirection function.
Do not implement the forward across VLAN for flow-based redirection.

Содержание

666

Изучите, как настроить функции безопасности и перенаправление трафика на портах. Узнайте о примерах конфигурации и устранении неполадок.