Configuring the secblade ns card – H3C Technologies H3C SecBlade NetStream Cards User Manual
Page 174

159
To do…
Use the command…
Remarks
Exit QoS policy view and enter
system view
quit
Required
Enter service port view
interface interface-type
interface-number.subnumber
Required
Enable the ACSEI server function
acsei server enable
Required
Apply the QoS policy to the
inbound direction of the port
qos apply policy QoS-policy-name
inbound
Required
You can also apply a QoS policy
configured with traffic mirroring in
the outbound direction of the port
as needed.
Exit interface view and enter
system view
quit
Required
Configuring the SecBlade NS card
Configure the SecBlade NS card as follows:
•
Configure the operating mode of the ten-GigabitEthernet port of the SecBlade NS card as trunk,
and assign the port to all VLANs.
•
Add the ten-GigabitEthernet port to the blackhole-type inline forwarding entry so that the collected
mirrored packets are dropped.
•
Enable NetStream to collect statistics on the incoming traffic on the ten-GigabitEthernet port.
•
Configure a management port to connect to the NSC and use it as the output port for traffic
statistics.
•
For more information about NetStream, see the chapter "NetStream configuration."
Follow these steps to configure the SecBlade NS card:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Create an blackhole-type
inline forwarding entry
inline-interfaces id blackhole Required
Enter the Ethernet
interface view of the
ten-Gigabit Ethernet port
interface ten-gigabitethernet 0/0
—
Add the
ten-GigabitEthernet port
to the blackhole-type
inline forwarding entry
port inline-interfaces id
Required
A port does not belong to
any inline forwarding entry
by default.
Configure the link type of
the ten-GigabitEthernet
port as trunk
port link-type trunk
Required
Assign the trunk port to all
VLANs
port trunk permit vlan all
Required