C
ONFIGURING
A
CCESS
C
ONTROL
L
ISTs
An Access Control List (ACL) is a sequential list of permit or deny
conditions that apply to IP addresses, MAC addresses, or other more
specific criteria. This switch tests ingress packets against the conditions
in an ACL one by one. A packet will be accepted as soon as it matches
a permit rule, or dropped as soon as it matches a deny rule. If no rules
match, the frame is accepted. Other actions can also be invoked when
a matching packet is found, including rate limiting, copying matching
packets to another port or to the system log, or shutting down a port.
The ACLs are divided into EtherTypes. IPv4, ARP protocol, MAC and
VLAN parameters etc. Here we will just go over the standard and
extended access lists for TCP/IP. As you create ACEs for ingress
classification, you can assign a policy for each port, the policy number
is 1-8, however, each policy can be applied to any port. This makes it
very easy to determine what type of ACL policy you will be working with.
The switch ACL function support up to 128 Access Control Entries
(ACEs), using the shared 128 ACEs for ingress classification. You can
create an ACE and assign this ACE for each port with <Any> or assign
this ACE for a policy or assign this ACE for a port. There are 8 policies,
each port can select one of policy, then decides which of the following
actions would take according to the packet‘s IPv4, EtherType, ARP
Protocol, MAC Parameters and VLAN parameters:
Packet Deny or Permit
Rate Limiter (Unit: pps)
Port Copy (1 – 24)
W
EB
I
NTERFACE
To configure ACL policies and responses for a port
:
1.
Click ACL, Ports.
2
.
Assign an ACL policy configured on the ACE Configuration page,
specify the responses to invoke when a matching frame is seen,
including the filter mode, copying matching frames to another
port, or shutting down the port. Note that the setting for rate
limiting is implemented regardless of whether or not a
matching packet is seen.
ACL Ports
C
ONFIGRATION
The ACL Port Configuration page can be used to define a port to
which matching frames are copied, enable logging, or shut down a
port when a matching frame is seen. Note that rate limiting is
implemented regardless of whether or not a matching packet is
seen. You can create an ACE and assign this ACE for each port with
<
Any
> or assign this ACE for a policy or assign this ACE for a port.
There are 8 policies, each port can select one of policy, then
decides which of the following actions would take according to the
packet‘s IPv4, EtherType, ARP Protocol, MAC Parameters and VLAN
parameters
.
Summary of Contents for LGS-2816C-RPS
Page 4: ...Revision History Release Date Revision 5 17 01 10 2010 B1...
Page 5: ...CONTENTS...
Page 56: ...74 CHAPTER 4 Configuring the Switch Configuring Power Saving the manufacturer...
Page 69: ......
Page 117: ...Figure 4 50 Access Control List Configuration...
Page 154: ...172 CHAPTER 4 Configuring the Switch Configure SNMP designated port of the root bridge...
Page 162: ...180 CHAPTER 4 Configuring the Switch Configure SNMP...
Page 196: ...346 CHAPTER 8 Commands of CLI Alarm Commandsof CLI...
Page 199: ...346 CHAPTER 8 Commands of CLI Alarm Commandsof CLI...
Page 207: ...3 Click Upload Figure 110 Display Firmware Upgrade Screen...
Page 241: ...349 Interfaces Evolution MIB RFC 2863 IP MIB RFC 2011...