1-2
z
When an ACL is assigned to a piece of hardware and referenced by a QoS policy for traffic
classification, the switch does not take action according to the traffic behavior definition on a packet
that does not match the ACL.
z
When an ACL is referenced by a piece of software to control Telnet, SNMP, and Web login users,
the switch denies all packets that do not match the ACL.
z
For details of ACL application for packet filtering, refer to
ACL Application for Packet Filtering
.
Introduction to IPv4 ACL
This section covers these topics:
z
z
z
z
z
Effective Period of an IPv4 ACL
z
IP Fragments Filtering with IPv4 ACL
IPv4 ACL Classification
IPv4 ACLs, identified by ACL numbers, fall into three categories, as shown in
Table 1-1
IPv4 ACL categories
Category
ACL number
Matching criteria
Basic IPv4 ACL
2000 to 2999
Source IP address
Advanced IPv4 ACL
3000 to 3999
Source IP address, destination IP address,
protocol carried over IP, and other Layer 3 or
Layer 4 protocol header information
Ethernet frame header
ACL
4000 to 4999
Layer 2 protocol header fields such as source
MAC address, destination MAC address, 802.1p
priority, and link layer protocol type
IPv4 ACL Naming
When creating an IPv4 ACL, you can specify a unique name for it. Afterwards, you can identify the ACL
by its name.
An IPv4 ACL can have only one name. Whether to specify a name for an ACL is up to you. After creating
an ACL, you cannot specify a name for it, nor can you change or remove its name.
Summary of Contents for S5500-SI Series
Page 161: ...3 10 GigabitEthernet1 0 1 2 MANUAL...
Page 220: ...1 7 Clearing ARP entries from the ARP table may cause communication failures...
Page 331: ...1 7 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete...
Page 493: ...2 8...
Page 1111: ...1 10 Installing patches Installation completed and patches will continue to run after reboot...