R3102-R3103-HP 6600/HSR6600 Routers OAA Configuration Guide
11
Configure the ACFP client to analyze traffic arriving at interface GigabitEthernet 3/0/2, and control the
traffic as follows:
• Permit all packets whose source IP address is 192.168.1.1/24.
• Deny all packets whose source IP address is 192.168.1.2/24.
Figure 2 Network diagram
Configuration procedure
1. Configure Router:
# Enable the ACFP server and ACSEI server.
<Router> system-view
[Router] acfp server enable
[Router] acsei server enable
2. Use a MIB browser to configure a collaboration policy to redirect traffic arriving at interface
GigabitEthernet 3/0/2 to the ACFP client:
a. Set the value of the node hh3cAcfpClientRowStatus to 4 to create an ACFP client with the index
1, and set the value of the node hh3cAcfpClientMode to 1 to enable working mode redirect for
the client.
b. Set the node hh3cAcfpPolicyRowStatus to 4 to create an ACFP policy and assign index 1.1 to
the policy, where the first "1" represents the index of the ACFP client you just created. Search
the ifTable node for the indexes of interfaces GigabitEthernet 3/0/2 and GigabitEthernet
3/0/3, and set the value of the node hh3cAcfpPolicyInIfIndex to the index of GigabitEthernet
3/0/2 and set the value of the node hh3cAcfpPolicyDestIfIndex to the index of
GigabitEthernet 3/0/3 to specify the interfaces as the inbound interface and outbound
interface of the policy respectively.
c. Set the value of the node hh3cAcfpRuleRowStatus to 4 to create an ACFP rule, and assign
index 1.1.1 to the rule, where the first "1" is the client index and the second "1" is the policy
index. Set the value of the node hh3cAcfpRuleAction to 3 to specify the redirect action.
3. Use the MIB browser to configure a collaboration policy to permit packets from 192.168.1.1/24
and drop packets from 192.168.1.2/24:
a. Set the node hh3cAcfpPolicyRowStatus to 4 to create an ACFP policy and assign index 1.2 to
the policy, and set the value of the node hh3cAcfpPolicyInIfIndex to the index of
GigabitEthernet 3/0/2 to specify the interface as the inbound interface of the policy.
b. Set the value of the node hh3cAcfpRuleRowStatus to 4 to create an ACFP rule, and assign
index 1.2.1 to the rule. Set the value of the node hh3cAcfpRuleAction to 1 to specify the permit
GE3/0/3
GE3/0/2 GE3/0/1
Router
ACFP client
ACFP server
Host A
192.168.1.1/24
Host B
192.168.1.2/24
Host C
192.168.2.1/24
Host D
192.168.2.2/24










