![Dell PowerConnect 8024 User Configuration Manual Download Page 518](http://html.mh-extra.com/html/dell/powerconnect-8024/powerconnect-8024_user-configuration-manual_84530518.webp)
518
Configuring Access Control Lists
How Are ACLs Configured?
To configure ACLs, follow these steps:
1
Create a MAC ACL by specifying a name.
2
Create an IP ACL by specifying a number.
3
Add new rules to the ACL.
4
Configure the match criteria for the rules.
5
Apply the ACL to one or more interfaces.
Preventing False ACL Matches
Be sure to specify ACL access-list, permit, and deny rule criteria as fully as
possible to avoid false matches. This is especially important in networks with
protocols such as FCoE that have newly-introduced EtherType values. For
example, rules that specify a TCP or UDP port value should also specify the
TCP or UDP protocol and the IPv4 or IPv6 EtherType. Rules that specify an
IP protocol should also specify the EtherType value for the frame.
In general, any rule that specifies matching on an upper-layer protocol field
should also include matching constraints for each of the lower-layer protocols.
For example, a rule to match packets directed to the well-known UDP port
number 22 (SSH) should also include matching constraints on the IP
protocol field (protocol=0x11 or UDP) and the EtherType field (EtherType=
0x0800 or IPv4). Figure 21-1 lists commonly-used EtherTypes numbers:
NOTE:
The actual number of ACLs and rules supported depends on the
resources consumed by other processes and configured features running on the
switch.
Table 21-1. Common EtherType Numbers
EtherType
Protocol
0x0800
Internet Protocol version 4 (IPv4)
0x0806
Address Resolution Protocol (ARP)
0x0842
Wake-on LAN Packet
0x8035
Reverse Address Resolution Protocol (RARP)
0x8100
VLAN tagged frame (IEEE 802.1Q)
Summary of Contents for PowerConnect 8024
Page 48: ...48 Contents ...
Page 52: ...52 Introduction ...
Page 86: ...86 Switch Features ...
Page 140: ...140 Setting Basic Network Information ...
Page 178: ...178 Managing a Switch Stack ...
Page 204: ...204 Configuring Authentication Authorization and Accounting ...
Page 272: ...272 Managing General System Settings ...
Page 308: ...308 Configuring SNMP ...
Page 336: ...336 Managing Images and Files ...
Page 354: ...354 Auto Image and Configuration Update ...
Page 468: ...468 Configuring Port Characteristics ...
Page 512: ...512 Configuring Port and System Security ...
Page 550: ...550 Configuring Access Control Lists ...
Page 580: ...580 Configuring VLANs Figure 22 17 GVRP Port Parameters Table ...
Page 586: ...586 Configuring VLANs Figure 22 24 Double VLAN Port Parameter Table ...
Page 618: ...618 Configuring VLANs ...
Page 631: ...Configuring the Spanning Tree Protocol 631 Figure 23 5 Spanning Tree Global Settings ...
Page 637: ...Configuring the Spanning Tree Protocol 637 Figure 23 11 RSTP LAG Settings ...
Page 685: ...Configuring Port Based Traffic Control 685 Figure 25 3 Storm Control 5 Click Apply ...
Page 776: ...776 Snooping and Inspecting Traffic Figure 27 17 DAI Interface Configuration Summary ...
Page 790: ...790 Snooping and Inspecting Traffic ...
Page 797: ...Configuring Link Aggregation 797 To view or edit settings for multiple LAGs click Show All ...
Page 894: ...894 Configuring DHCP Server Settings ...
Page 928: ...928 Configuring L2 and L3 Relay Features Figure 34 3 DHCP Relay Interface Summary ...
Page 955: ...Configuring OSPF and OSPFv3 955 Figure 35 1 OSPF Configuration ...
Page 1030: ...1030 Configuring OSPF and OSPFv3 ...
Page 1068: ...1068 Configuring VRRP ...
Page 1092: ...1092 Configuring IPv6 Routing ...
Page 1119: ...Configuring Differentiated Services 1119 Figure 40 5 DiffServ Class Criteria ...
Page 1126: ...1126 Configuring Differentiated Services Figure 40 14 DiffServ Service Summary ...
Page 1142: ...1142 Configuring Differentiated Services ...
Page 1148: ...1148 Configuring Class of Service Figure 41 1 Mapping Table Configuration CoS 802 1P ...
Page 1160: ...1160 Configuring Class of Service ...
Page 1164: ...1164 Configuring Auto VoIP Figure 42 2 Auto VoIP Interface Configuration ...
Page 1230: ...1230 Managing IPv4 and IPv6 Multicast Figure 43 51 DVMRP Next Hop Summary ...
Page 1256: ...1256 Managing IPv4 and IPv6 Multicast ...
Page 1266: ...1266 Feature Limitations and Platform Constants ...
Page 1274: ...1274 System Process Definitions ...
Page 1294: ...Index 1294 ...