EKI-9500 Series User Manual
288
4.7.1.4
VLANs
Use the Access Control List VLAN Summary page to associate one or more ACLs
with one or more VLANs on the device.
To access this page, click
QoS
>
Access Control Lists
>
VLANs
.
Figure 4.314 QoS > Access Control Lists > VLANs
The following table describes the items in the previous figure.
ACL Identifier
The name or number that identifies the ACL. When applying an ACL to
an interface, the ACL Identifier menu includes only the ACLs within the
selected ACL Type.
Submit
Click
Submit
to save the values.
Cancel
Click
Cancel
to close the window.
Item
Description
Item
Description
VLAN ID
The ID of the VLAN associated with the rest of the data in the row.
When associating a VLAN with an ACL, use this field to select the
desired VLAN.
Direction
Indicates whether the packet is checked against the rules in an ACL
when it is received on a VLAN (Inbound) or after it has been received,
routed, and is ready to exit a VLAN (Outbound).
Sequence Number
The order the ACL is applied to traffic on the VLAN relative to other
ACLs associated with the VLAN in the same direction. When multiple
ACLs are applied to the same VLAN in the same direction, the ACL
with the lowest sequence number is applied first, and the other ACLs
are applied in ascending numerical order.
ACL Type
The type of ACL. The ACL type determines the criteria that can be
used to match packets. The type also determines which attributes can
be applied to matching traffic. IPv4 ACLs classify Layer 3 and Layer 4
IPv4 traffic, IPv6 ACLs classify Layer 3 and Layer 4 IPv6 traffic, and
MAC ACLs classify Layer 2 traffic. The ACL types are as follows:
IPv4 Standard: Match criteria is based on the source address of
IPv4 packets.
IPv4 Extended: Match criteria can be based on the source and
destination addresses, source and destination Layer 4 ports, and
protocol type of IPv4 packets.
IPv4 Named: Match criteria is the same as IPv4 Extended ACLs,
but the ACL ID can be an alphanumeric name instead of a num-
ber.
IPv6 Named: Match criteria can be based on information includ-
ing the source and destination IPv6 addresses, source and desti-
nation Layer 4 ports, and protocol type within IPv6 packets.
Extended MAC: Match criteria can be based on the source and
destination MAC addresses, 802.1p user priority, VLAN ID, and
EtherType value within Ethernet frames.
ACL Identifier
The name or number that identifies the ACL. The permitted identifier
depends on the ACL type. Standard and Extended IPv4 ACLs use
numbers within a set range, and Named IPv4, IPV6, and MAC ACLs
use alphanumeric characters.