User’s Manual of NS3550-24T/4S
187
access rights.
ACL implementations can be quite complex, for example, when the ACEs are prioritized for the various situations. In networking,
the ACL refers to a list of service ports or network services that are available on a host or server; each with a list of hosts or
servers permitted or denied to use the service. ACL can generally be configured to control inbound traffic, and in this context, they
are similar to firewalls.
ACE is an acronym for Access Control Entry. It describes access permission associated with a particular ACE ID.
There are three ACE frame types (Ethernet Type, ARP, and IPv4) and two ACE actions (permit and deny). The ACE also contains
many detailed, different parameter options that are available for individual application.
4.10.1 Access Control List Status
This page shows the ACL status by different ACL users. Each row describes the ACE that is defined. It is a conflict if a specific
ACE is not applied to the hardware due to hardware limitations. The Voice VLAN OUI Table screen is shown in
Figure 4-10-1
.
Figure 4-10-1
Voice VLAN OUI Table Page Screenshot
The page includes the following fields:
Object
Description
User
Indicates the ACL user.
Ingress Port
Indicates the ingress port of the ACE. Possible values are:
Any
: The ACE will match any ingress port.
Policy
: The ACE will match ingress ports with a specific policy.
Port
: The ACE will match a specific ingress port.
Frame Type
Indicates the frame type of the ACE. Possible values are:
Any
: The ACE will match any frame type.
EType
: The ACE will match Ethernet Type frames. Note that an Ethernet Type
based ACE will not get matched by IP and ARP frames.
ARP
: The ACE will match ARP/RARP frames.
IPv4
: The ACE will match all IPv4 frames.
IPv4/ICMP
: The ACE will match IPv4 frames with ICMP protocol.
IPv4/UDP
: The ACE will match IPv4 frames with UDP protocol.
IPv4/TCP
: The ACE will match IPv4 frames with TCP protocol.
IPv4/Other
: The ACE will match IPv4 frames, which are not ICMP/UDP/TCP.
Action
Indicates the forwarding action of the ACE.
Permit
: Frames matching the ACE may be forwarded and learned.
Deny
: Frames matching the ACE are dropped.
Rate Limiter
Indicates the rate limiter number of the ACE. The allowed range is 1 to 15. When
Disabled is displayed, the rate limiter operation is disabled.
Port Copy
Indicates the port copy operation of the ACE. Frames matching the ACE are
copied to the port number. The allowed values are Disabled or a specific port
number. When the Disabled is displayed, the port copy operation is disabled.
CPU
Forward packet that matched the specific ACE to CPU.
Summary of Contents for IFS NS3550-24T/4S
Page 1: ...P N 1072569 REV 00 05 ISS 11OCT12 IFS NS3550 24T 4S User Manual ...
Page 37: ...User s Manual of NS3550 24T 4S 37 ...
Page 96: ...96 Figure 4 4 6 Port Mirror Configuration Page Screenshot ...
Page 127: ...User s Manual of NS3550 24T 4S 127 Figure 4 6 10 Port 1 Port 6 VLAN Configuration ...
Page 184: ...184 Figure 4 9 14 Voice VLAN Configuration Page Screenshot ...
Page 204: ...204 Figure 4 11 4 Network Access Server Configuration Page Screenshot ...
Page 234: ...234 Figure 4 12 1 Port Limit Control Configuration Overview Page Screenshot ...
Page 250: ...250 Click to undo any changes made locally and revert to previously saved values ...
Page 297: ...User s Manual of NS3550 24T 4S 297 ...
Page 388: ...388 Example Show RADIUS statistics SWITCH security aaa statistics ...
Page 410: ...410 Parameters vid VLAN ID 1 4095 Default Setting disable ...