beautypg.com

Configuring the secblade ns card – H3C Technologies H3C SecBlade NetStream Cards User Manual

Page 174

background image

159

To do…

Use the command…

Remarks

Exit QoS policy view and enter
system view

quit

Required

Enter service port view

interface interface-type
interface-number.subnumber

Required

Enable the ACSEI server function

acsei server enable

Required

Apply the QoS policy to the
inbound direction of the port

qos apply policy QoS-policy-name
inbound

Required
You can also apply a QoS policy
configured with traffic mirroring in

the outbound direction of the port

as needed.

Exit interface view and enter
system view

quit

Required

Configuring the SecBlade NS card

Configure the SecBlade NS card as follows:

Configure the operating mode of the ten-GigabitEthernet port of the SecBlade NS card as trunk,
and assign the port to all VLANs.

Add the ten-GigabitEthernet port to the blackhole-type inline forwarding entry so that the collected
mirrored packets are dropped.

Enable NetStream to collect statistics on the incoming traffic on the ten-GigabitEthernet port.

Configure a management port to connect to the NSC and use it as the output port for traffic
statistics.

For more information about NetStream, see the chapter "NetStream configuration."

Follow these steps to configure the SecBlade NS card:

To do…

Use the command…

Remarks

Enter system view

system-view

Create an blackhole-type
inline forwarding entry

inline-interfaces id blackhole Required

Enter the Ethernet
interface view of the

ten-Gigabit Ethernet port

interface ten-gigabitethernet 0/0

Add the
ten-GigabitEthernet port
to the blackhole-type

inline forwarding entry

port inline-interfaces id

Required
A port does not belong to
any inline forwarding entry

by default.

Configure the link type of
the ten-GigabitEthernet
port as trunk

port link-type trunk

Required

Assign the trunk port to all
VLANs

port trunk permit vlan all

Required