
Security Measures
157
Instruction Manual - NXA-ENET8-POE+
Perform these steps to show information on TCAM utilization:
1.
Click
Security
>
ACL
.
2.
Select
Configure ACL
from the Step list.
3.
Select
Show TCAM
from the Action list.
Setting the ACL Name and Type
Use the Security > ACL (Configure ACL - Add) page to create an ACL.
The following table lists the options on this page:
Used
The number of policy control entries used by the operating system.
Free
The number of policy control entries available for use.
Capability
The processes assigned to each pool.
FIG. 185
Showing TCAM Utilization
Security - ACL Options
ACL Name
Name of the ACL. (Maximum length: 32 characters)
Type
The following filter modes are supported:
• IP Standard: IPv4 ACL mode filters packets based on the source IPv4 address.
• IP Extended: IPv4 ACL mode filters packets based on the source or destination IPv4 address, as
well as the protocol type and protocol port number. If the TCP protocol is specified, then you
can also filter packets based on the TCP control code.
• IPv6 Standard: IPv6 ACL mode filters packets based on the source IPv6 address.
• IPv6 Extended: IPv6 ACL mode filters packets based on the source or destination IP address, as
well as DSCP, and the next header type.
• MAC - MAC ACL mode filters packets based on the source or destination MAC address and the
Ethernet frame type (RFC 1060).
• ARP - ARP ACL specifies static IP-to-MAC address bindings used for ARP inspection (see the
section on page 167 for more information.)
Security - ACL Options