Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell EMC SmartFabric OS10 User Guide Release 10.5.0

PDF

基于流的监控

基于流的监控通过仅检查指定的流量而不是所有接口流量来节省带宽。使用基于流的监控,您只能监控在入口访问列表 (ACL) 中与条件相匹配的源端口接收的流量。IPv4 ACL、IPv6 ACL 和 MAC ACL 支持基于流的监控。

  1. 在 MONITOR-SESSION 模式下启用监控会话的基于流的监控。
    flow-based enable
  2. 返回 CONFIGURATION 模式。
    exit
  3. 在 CONFIGURATION 模式下创建访问列表。
    ip access-list access-list-name
  4. 在 CONFIG-ACL 模式中使用 seqpermitdeny 语句定义访问列表规则。ACL 规则描述了要监控的流量。
    seq sequence-number {deny | permit} {source [mask] | any | host ip-address} [count [byte]] [fragments] [threshold-in-msgs count] [capture session session-id]
  5. 返回 CONFIGURATION 模式。
    exit
  6. 在 CONFIGURATION 模式下将基于流的监控 ACL 应用到受监控的源端口。访问列表名称的最大长度为 140 个字符。
    ip access-group access-list-name {in | out}

启用基于流的监控

OS10(config)# monitor session 1
OS10(conf-mon-local-1)# flow-based enable
OS10(conf-mon-local-1)# exit
OS10(config)# ip access-list ipacl1
OS10(conf-ipv4-acl)# deny ip host 1.1.1.23 any capture session 1 count
OS10(conf-ipv4-acl)# exit
OS10(config)# mac access-list mac1
OS10(conf-mac-acl)# deny any any capture session 1
OS10(conf-mac-acl)# exit 
OS10(config)# interface ethernet 1/1/9
OS10(conf-if-eth1/1/9)# mac access-group mac1 in
OS10(conf-if-eth1/1/9)# end
OS10# show mac access-lists in
Ingress MAC access-list mac1
 Active on interfaces :
  ethernet1/1/9
 seq 10 deny any any capture session 1 count (0 packets)

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\