Page 146
Configuring Access Control Lists
Access Control List Statistics
Use this page to display the statistical information about the packets forwarded or discarded by the port
that matches the configured rules within an Access Control List (ACL). Each ACL rule is configured to
match one or more aspects of traffic on the network. When a packet matches the conditions in a rule,
the counter associated with the rule gets incremented, until it reaches the rollover value of the counter.
To display the Access Control List Statistics page, click
QoS
>
Access Control Lists
in the navigation
pane, and then click the
Statistics
tab.
Figure 105. Access Control List Statistics Page
Table 79. Access Control List Statistics Fields
Field
Description
ACL Type
The type of ACL. The ACL type determines the criteria that can be used to match packets.
The type also determines which attributes can be applied to matching traffic. IPv4 ACLs
classify Layer 3 and Layer 4 IPv4 traffic, IPv6 ACLs classify Layer 3 and Layer 4 IPv6 traffic,
and MAC ACLs classify Layer 2 traffic.
The ACL types are as follows:
IPv4 Standard – Match criteria is based on the source address of the IPv4 packets.
IPv4 Extended – Match criteria can be based on the source and destination addresses,
source and destination Layer 4 ports, and protocol type of the IPv4 packets.
IPv4 Named – Match criteria is the same as IPv4 Extended ACLs, but the ACL ID can be
an alphanumeric name instead of a number.
Extended MAC – Match criteria can be based on the source and destination MAC
addresses, 802.1p user priority, VLAN ID, and EtherType value within the Ethernet
frames.
ACL Identifier
A list of ACL IDs that exist on the system for a given ACL type. To view the rule(s) within an
ACL, you must select the ID of the ACL from the list. The ACL rules are not displayed when
option All is selected. Option All lets you clear the hit count for an ACL type.
Sequence Number
The number that indicates the position of a rule within the ACL.
Action
The action to take when a packet or frame matches the criteria in the rule:
Permit – The packet or frame is forwarded.
Deny – The packet or frame is dropped.
Match Conditions
The criteria used to determine whether a packet or frame matches the ACL rule.