
4-1
4
ACL Application for Packet Filtering
When applying an ACL for packet filtering, go to these sections for information you are interested in:
z
z
z
You can apply an ACL to the inbound or direction of an Ethernet interface or VLAN interface to filter
packets:
z
Applied to an Ethernet interface, an ACL can filter all IPv4 packets and IPv6 packets that are
received on the interface.
z
Applied to a VLAN interface, an ACL filters only Layer 3 packets that are needed to be forwarded
through the VLAN interface.
You can edit the rules in an applied ACL, such as add, remove, and modify rules, and the edited rules
take effect immediately.
You can configure an interval for collecting and outputting packet filtering logs. The log information
includes the number of matching packets and the ACL rules used.
The system only logs traffic filtered by basic and advanced ACL rules with the logging keyword
configured.
Filtering IPv4 Packets
Follow these steps to apply an IPv4 ACL to an interface to filter IPv4 packets:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter Ethernet
interface view
interface interface-type
interface-number
Enter
interface
view
Enter VLAN
interface view
interface vlan-interface
vlan-id
Use either command
Apply a basic or advanced IPv4
ACL to the interface to filter
IPv4 packets
packet-filter
{
acl-number
|
name
acl-name
}
inbound
Required
By default, an interface does
not filter IPv4 packets.
Summary of Contents for S5120-EI Series
Page 139: ...ii...
Page 578: ...1 21 C...
Page 739: ...1 12 Enable ARP detection based on 802 1X security entries SwitchB arp detection mode dot1x...
Page 926: ...2 8...
Page 942: ...ii Single Device Upgrade 3 4 IRF System Upgrade 3 5...
Page 985: ...1 1...
Page 1018: ...1 6...