Access Security Guide K/KA/KB.15.15

configure a traffic filter to either forward or drop all network traffic moving to outbound (destination)
ports and trunks (if any) on the switch
Applicable switch models
As of June 2010, Traffic/Security filers are available on these current HP switch models:
Table 49 Switch model filter availability
Multicast FiltersProtocol FiltersSource-Port FiltersModel
YesYesYes8200zl Switches
YesYesYes6600 Switches
NoNoYes8400cl Switches
YesYesYes5400zl Switches
NoNoYes4200vl Switches
YesYesYes3800 Switches
YesYesYes3500/3500yl Swtiches
NoNoYes3400cl Switches
NoNoYes2800 Switches
YesYesYes2510 Switches
YesYesYes2500 Switches
YesYesYes4000m and 8000m
Switches
Filter Limits
The switch accepts up to 101 static filters. These limitations apply:
Source-port filters: up to 78
Multicast filters: up to 16 with 1024 or fewer VLANs configured. Up to 8 with more than
1024 VLANs configured.
Protocol filters: up to 7
Using port trunks with filter
The switch manages a port trunk as a single source or destination for sourceport filtering. If you
configure a port for filtering before adding it to a port trunk, the port retains the filter configuration,
but suspends the filtering action while a member of the trunk. If you want a trunk to perform filtering,
first configure the trunk, then configure the trunk for filtering. See “Configuring a filter on a port
trunk” (page 432).
Filter types and operation
The following table represents the types of static filters and their selection criteria:
450 Traffic/Security Features and Monitors