iES26GF
User’s
Manual
UM-iES26GF-1.2.3-EN.docx
Pages 113 of 169
The following table describes the labels for the
ACE Configuration
screen.
Label
Description
Ingress Port
Indicates the ingress port of the ACE. Possible values are:
All
: The ACE will match all ingress port.
Port
: The ACE will match a specific ingress port.
Policy Filter
Specify the policy number filter for this ACE.
Any:
No policy filter is specified. (policy filter status is "don't-care".)
Specific
: If you want to filter a specific policy with this ACE, choose this value.
When
Specific
is chosen, two fields for entering a policy value and bitmask
appear:
Policy Value
and
Policy Bitmask.
Policy
Value
: Enter a range between 0 and 255.
Policy
Bitmask
: Enter a range between 0x0 and 0xff.
Frame Type
Indicates the frame type of the ACE. Choose one of the options provided in the
drop-down list. These frame types are mutually exclusive.
Any
: any frame can match the ACE.
Ethernet Type:
only Ethernet type frames can match the ACE. The IEEE
802.3 descripts the value of length/types should be greater than or equal to 1536
decimal (equal to 0600 hexadecimal).
ARP
: only ARP frames can match the ACE. Notice the ARP frames will not match
the ACE with Ethernet type.
IPv4: The ACE will match all IPv4 frames.
IPv4/ICMP: The ACE will match IPv4 frames with ICMP protocol.
IPv4/UDP: The ACE will match IPv4 frames with UDP protocol.
IPv4/TCP: The ACE will match IPv4 frames with TCP protocol.
IPv4/Other: The ACE will match IPv4 frames, which are not ICMP/UDP/TCP.
IPv6: The ACE will match all IPv6 standard frames.
Action
Specifies the action to take when a frame matches the ACE.
Permit:
takes action when the frame matches the ACE.
Deny:
drops the frame
matching the ACE.
Rate Limiter
Specifies the rate limiter in number of base units. The allowed range is 1 to
16.
Disabled
means that the
Rate Limiter
operation is disabled.
Port Redirect
Indicates the rate limiter number of the ACE. The allowed range is 1 to 16.
When
Disabled
is displayed, the rate limiter operation is disabled.
Mirror
Specify the mirror operation of this port. Frames matching the ACE are mirrored
to the destination mirror port. The allowed values are:
Enabled
: Frames received on the port are mirrored.
Disabled
: Frames received on the port are not mirrored.
The default value is
Disabled
.
Logging
Specifies the logging operation of the ACE. The allowed values are:
Enabled
: frames matching the ACE are stored in the system log.
Disabled
: frames matching the ACE are not logged.
Please note that system log memory capacity and logging rate is limited.
Shutdown
Specifies the shutdown operation of the ACE. The allowed values are:
Enabled
: if a frame matches the ACE, the ingress port will be disabled.
Disabled
: port shutdown is disabled for the ACE.
Counter
Indicates the number of times the ACE is matched by a frame.
ACL Status
This page shows the ACL status of the different ACL users. Each row describes the ACE that is defined.
It is a conflict if a specific ACE is not applied to the hardware due to hardware limitations. The maximum
number of ACEs is 512 on each switch.