392
C
HAPTER
19: C
ONFIGURING
AND
M
ANAGING
S
ECURITY
ACL
S
Mapping Security
ACLs to Ports, VLANs,
Virtual Ports, or
Distributed MAPs
Security ACLs can be mapped to ports, VLANs, virtual ports, and
Distributed MAPs. Use the following command:
set security acl map
acl-name
{
vlan
vlan-id
|
port
port-list
[
tag
tag-value
] |
ap
apnumber
} {
in
|
out
}
Specify the name of the ACL, the port, VLAN, tag value(s) of the virtual
port, or the number of the Distributed MAP to which the ACL is to be
mapped, and the direction for packet filtering. For virtual ports or
Distributed MAPs, you can specify a single value, a comma-separated list
of values, a hyphen-separated range, or any combination, with no
spaces. For example, to map security ACL
acl-222
to virtual ports 1
through 3 and 5 on port 2 to filter incoming packets, type the following
command:
WX1200#
set security acl map acl-222 port 2 tag 1-3,5 in
success: change accepted.
Plan your security ACL maps to ports, VLANs, virtual ports, and
Distributed MAPs so that only one security ACL filters a flow of packets. If
more than one security ACL filters the same traffic, you cannot guarantee
the order in which the ACE rules are applied.
Displaying ACL Maps to Ports, VLANs, and Virtual Ports
Two commands display the port, VLAN, virtual port, and Distributed MAP
mapping of a specific security ACL. For example, to show the ports,
VLANs, virtual ports, and Distributed MAPs mapped to
acl-999
, type one
of the following commands:
WX1200#
display security acl map acl-999
ACL acl-999 is mapped to:
Port 9 In
Port 9 Out
WX1200#
display security acl
ACL table
ACL
Type Class
Mapping
-------------------------------- ---- ------ -------
acl-orange
IP
Static
acl-999
IP
Static Port 6 In
Port 6 Out
acl-blue
IP
Static Port 1 In
acl-violet
IP
Static VLAN 1 Out
Summary of Contents for 3CRWX120695A
Page 138: ...138 CHAPTER 6 CONFIGURING AND MANAGING IP INTERFACES AND SERVICES ...
Page 272: ...272 CHAPTER 11 CONFIGURING RF LOAD BALANCING FOR MAPS ...
Page 310: ...310 CHAPTER 13 CONFIGURING USER ENCRYPTION ...
Page 322: ...322 CHAPTER 14 CONFIGURING RF AUTO TUNING ...
Page 350: ...350 CHAPTER 16 CONFIGURING QUALITY OF SERVICE ...
Page 368: ...368 CHAPTER 17 CONFIGURING AND MANAGING SPANNING TREE PROTOCOL ...
Page 412: ...412 CHAPTER 19 CONFIGURING AND MANAGING SECURITY ACLS ...
Page 518: ...518 CHAPTER 21 CONFIGURING AAA FOR NETWORK USERS ...
Page 530: ...530 CHAPTER 22 CONFIGURING COMMUNICATION WITH RADIUS ...
Page 542: ...542 CHAPTER 23 MANAGING 802 1X ON THE WX SWITCH ...
Page 598: ...598 CHAPTER 26 ROGUE DETECTION AND COUNTERMEASURES ...
Page 706: ...706 GLOSSARY ...