beautypg.com

Using acfp – H3C Technologies H3C SR8800 User Manual

Page 18

background image

12

Protocol number in IP

Source IP address

Wildcard mask of source IP address

Source port operator—Its type can be equal to, not equal to, greater than, less than, greater than
and less than. The following ending source port number takes effect only when the type is greater

than and less than. The source port number of the packets matched by the identifier must be greater

than the starting source port number and less than the ending source port number.

Starting source port number

Ending source port number

Destination IP address

Wildcard mask of destination IP address

Destination port number operator—Its type can be equal to, not equal to, greater than, less than,
greater than and less than. The following ending destination port number is meaning only when

the type is greater than and less than. The destination port number of the packets matched by the

identifier must be greater than the starting destination port number and less than the ending
destination port number.

Starting destination port number

Ending destination port number

Pro—Protocol type, which can be GRE, ICMP, IGMP, OSPF, TCP, UDP, and IP.

IP precedence—Packet precedence, a number in the range of 0 to 7.

IP ToS—Type of Service (ToS) of IP

IP DSCP—Differentiated Services Code Point (DSCP) of IP

TCP flag—It indicates that some bits in the six flag bits (URG, ACK, PSH, RST, SYN, FIN) are
concerned.

IP fragment—It indicates whether the packet is an IP packet fragment.

Rate limit

You can use the collaboration policy to manage the collaboration rules that belong to it.

Using ACFP

ACFP does not support policy-based routing services or NetStream services.

The handling of the packets redirected by ACFP is mutually exclusive with ordinary ACL rules. No
QoS processing is performed on the packets returned after they are redirected to the ACFP client.

A stream cannot be mirrored or redirected to multiple ACFP clients.

ACFP does not support applying flow redirect policies to an aggregate interface.

SPE cards support applying flow redirect policies only to Layer 3 interfaces.

If a Layer 3 interface is added into an aggregation group, or an aggregate interface leaves an

aggregation group, the configured flow redirect policies on the interface will become ineffective
and you need to first delete the original flow redirect policies and then configure new policies on the

interface.

When the ACFP server is enabled, the internal interface cannot act as the source port for port
mirroring.

This manual is related to the following products: