02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Enabling and Disabling <strong>the</strong> Telnet Daemon<br />

<strong>Force10</strong>(conf)#ip ssh server enable<br />

<strong>Force10</strong>(conf)#no ip ssh server enable<br />

By default, <strong>the</strong> Telnet daemon is enabled. To disable <strong>the</strong> Telnet daemon, you must use <strong>the</strong> command shown<br />

below or disable it in <strong>the</strong> startup config.<br />

Use <strong>the</strong> no ip telnet server enable command to enable or disable <strong>the</strong> Telnet daemon.<br />

<strong>Force10</strong>(conf)#ip telnet server enable<br />

<strong>Force10</strong>(conf)#no ip telnet server enable<br />

Trace List<br />

Trace List is supported on plat<strong>for</strong>m e<br />

You can log packet activity on a port to confirm <strong>the</strong> source of traffic attacking a system. Once <strong>the</strong> Trace list<br />

is enabled on <strong>the</strong> system, you view its traffic log to confirm <strong>the</strong> source address of <strong>the</strong> attacking traffic. In<br />

<strong>FTOS</strong>, Trace lists are similar to extended IP ACLs, except that Trace lists are not applied to an interface.<br />

Instead, Trace lists are enabled <strong>for</strong> all switched traffic entering <strong>the</strong> system.<br />

The number of entries allowed per trace list is 1K.<br />

In <strong>the</strong> E-<strong>Series</strong>, you can create a trace filter based on any of <strong>the</strong> following criteria:<br />

• Source IP address<br />

• Destination IP address<br />

• Source TCP port number<br />

• Destination TCP port number<br />

• Source UDP port number<br />

• Destination UDP port number<br />

For trace lists, you can match criteria on specific or ranges of TCP or UDP ports or established TCP<br />

sessions.<br />

Note: If <strong>the</strong>re are unresolved next-hops and a trace-list is enabled, <strong>the</strong>re is a possibility that <strong>the</strong> traffic<br />

hitting <strong>the</strong> CPU will not be rate-limited.<br />

<strong>FTOS</strong> <strong>Configuration</strong> <strong>Guide</strong>, version 7.7.1.0 167

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!