EasyManuals Logo

HP ProCurve 3500yl Series User Manual

HP ProCurve 3500yl Series
390 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #65 background imageLoading...
Page #65 background image
Virus Throttling
General Configuration Guidelines
General Configuration Guidelines
As stated earlier, connection-rate filtering is triggered only by routed, inbound
traffic generating a relatively high number of new IP connection requests from
the same host. Thus, for the switch to apply connection-rate filters, IP routing
and multiple VLANs with member ports must first be configured.
For a network that is relatively attack-free:
1. Enable notify-only mode on the ports you want to monitor.
2. Set global sensitivity to low.
3. Use clear arp to clear the arp cache.
4. If SNMP trap receivers are available in your network, use the snmp-server
command to configure the switch to send SNMP traps.
5. Monitor the Event Log or (if configured) the available SNMP trap receivers
to identify hosts exhibiting high connection rates.
6. Check any hosts that exhibit relatively high connection rate behavior to
determine whether malicious code or legitimate use is the cause of the
behavior.
7. Hosts demonstrating high, but legitimate connection rates, such as heavily
used servers, may trigger a connection-rate filter. Configure connection
rate ACLs to create policy exceptions for trusted hosts. (Exceptions can
be configured for these criteria:
A single source host or group of source hosts
A source subnet
Either of the above with TCP or UDP criteria
(For more on connection rate ACLs, refer to “Application Options” on
page 3-6.)
8. Increase the sensitivity to Medium and repeat steps 6 and 7.
Note On networks that are relatively infection-free, sensitivity levels above Medium
are not recommended.)
9. (Optional.) Enable throttle or block mode on the monitored ports.
3-9

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HP ProCurve 3500yl Series and is the answer not in the manual?

HP ProCurve 3500yl Series Specifications

General IconGeneral
ModelHP ProCurve 3500yl Series
Switching Capacity176 Gbps
LayerLayer 3
Input Voltage100-240 VAC
PoEAvailable on some models
ManagementWeb, CLI, SNMP
Routing ProtocolRIP, OSPF, BGP
Remote Management ProtocolTelnet
FeaturesVLAN
Power Consumption OperationalVaries by model
Memory256 MB
Power SupplyInternal
Security Features802.1X, RADIUS, TACACS+
Ports24 or 48 x 10/100/1000Base-T ports

Related product manuals