12.07.2015 Views

BROCADE IP PRIMER

BROCADE IP PRIMER

BROCADE IP PRIMER

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 14: Security, Redundancy and More• Numbered ACLs use a number to define each individual ACL (group ofrules), and the type of ACL— Standard <strong>IP</strong> ACLs use 1-99— Extended <strong>IP</strong> ACLs use 100-199• Named ACLs are labeled with a user-determined name• Named ACLs must be defined manually as either Standard <strong>IP</strong> or Extended<strong>IP</strong>• ACL flow counters and logging may help troubleshoot ACL issues• Rule-Based ACLs incur the lowest CPU utilization (and thus, bestperformance)• Flow-Based ACLs incur a higher CPU penalty— All outbound ACLs are Flow-Based• MAC filters act as a type of Layer 2 ACL, controlling traffic based on MACaddresses and frame types• Policy-Based Routing provides an ability to direct traffic more granularly• PBR uses ACLs to match the type of traffic to process• ACLs may be used to more granularly decide what traffic should be translated(using NAT or PAT)• The keyword “overload” denotes that the router is to use PAT translation• VRRP and VRRP-E may be used to provide a redundant gateway• Quality of Service (QoS) provides a method to prioritize the traffic that isprocessed• QoS bases its decision on the higher of:— 802.1p priority (found in 802.1q-tagged frames)— ToS field (found in the <strong>IP</strong> header)• QoS uses four queues to prioritize traffic (from highest to lowest):— qosp3— qosp2— qosp1— qosp0318 Brocade <strong>IP</strong> Primer

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!