© Copyright IBM Corp. 2011
79
Chapter 7. Access Control Lists
Access Control Lists (ACLs) are filters that permit or deny traffic for security
purposes. They can also be used with QoS to classify and segment traffic to provide
different levels of service to different traffic types. Each filter defines the conditions
that must match for inclusion in the filter, and also the actions that are performed
when a match is made.
IBM Networking OS 6.8 supports the following ACLs:
•
IPv4 ACLs
Up to 512 ACLs are supported for networks that use IPv4 addressing. IPv4 ACLs
are configured using the following ISCLI command path:
•
IPv6 ACLs
Up to 128 ACLs are supported for networks that use IPv6 addressing. IPv6 ACLs
are configured using the following ISCLI command path:
•
VLAN Maps (VMaps)
Up to 128 VLAN Maps are supported for attaching filters to VLANs rather than
ports. See
for details.
Summary of Packet Classifiers
ACLs allow you to classify packets according to a variety of content in the packet
header (such as the source address, destination address, source port number,
destination port number, and others). Once classified, packet flows can be identified
for more processing.
IPv4 ACLs, IPv6 ACLs, and VMaps allow you to classify packets based on the
following packet attributes:
•
Ethernet header options (for IPv4 ACLs and VMaps only)
– Source MAC address
– Destination MAC address
– VLAN number and mask
– Ethernet type (ARP, IP, IPv6, MPLS, RARP, etc.)
– Ethernet Priority (the IEEE 802.1p Priority)
RS G8000(config)#
access-control list
<IPv4 ACL number>
?
RS G8000(config)#
access-control list6
<IPv6 ACL number>
?
Summary of Contents for RackSwitch G8000
Page 1: ...RackSwitch G8000 Application Guide...
Page 2: ......
Page 3: ...RackSwitch G8000 Application Guide...
Page 16: ...16 RackSwitch G8000 Application Guide...
Page 22: ...20 RackSwitch G8000 Application Guide...
Page 23: ...Copyright IBM Corp 2011 21 Part 1 Getting Started...
Page 24: ...22 RackSwitch G8000 Application Guide...
Page 54: ...52 RackSwitch G8000 Application Guide...
Page 55: ...Copyright IBM Corp 2011 53 Part 2 Securing the Switch...
Page 56: ...54 RackSwitch G8000 Application Guide...
Page 92: ...90 RackSwitch G8000 Application Guide...
Page 94: ...92 RackSwitch G8000 Application Guide...
Page 144: ...142 RackSwitch G8000 Application Guide...
Page 145: ...Copyright IBM Corp 2011 143 Part 4 Advanced Switch ing Features...
Page 146: ...144 RackSwitch G8000 Application Guide...
Page 148: ...146 RackSwitch G8000 Application Guide...
Page 182: ...180 RackSwitch G8000 Application Guide...
Page 184: ...182 RackSwitch G8000 Application Guide...
Page 212: ...210 RackSwitch G8000 Application Guide...
Page 258: ...256 RackSwitch G8000 Application Guide...
Page 286: ...284 RackSwitch G8000 Application Guide...
Page 294: ...292 RackSwitch G8000 Application Guide...
Page 298: ...296 RackSwitch G8000 Application Guide...
Page 310: ...308 RackSwitch G8000 Application Guide...
Page 311: ...Copyright IBM Corp 2011 309 Part 7 Network Management...
Page 312: ...310 RackSwitch G8000 Application Guide...
Page 320: ...318 RackSwitch G8000 Application Guide...
Page 332: ...330 RackSwitch G8000 Application Guide...
Page 334: ...332 RackSwitch G8000 Application Guide...
Page 345: ...Copyright IBM Corp 2011 343 Part 9 Appendices...
Page 346: ...344 RackSwitch G8000 Application Guide...
Page 357: ...Copyright IBM Corp 2011 Appendix C Notices 355 Taiwan Class A compliance statement...