© Copyright Lenovo 2018
Chapter 7: Access Control Lists
127
ACL Port Mirroring
For
regular
ACLs
and
VMaps,
packets
that
match
an
ACL
on
a
specific
port
can
be
mirrored
to
another
switch
port
for
network
diagnosis
and
monitoring.
The
source
port
for
the
mirrored
packets
cannot
be
a
portchannel,
but
may
be
a
member
of
a
portchannel.
The
destination
port
to
which
packets
are
mirrored
must
be
a
physical
port.
If
the
ACL
has
an
action
(permit,
drop
etc.)
assigned,
it
cannot
be
used
to
mirror
packets
for
that
ACL.
Use
the
following
commands
to
add
mirroring
to
an
ACL:
For
regular
ACLs:
The
ACL
must
be
also
assigned
to
it
target
ports
as
usual
(see
,
or
Viewing ACL Statistics
ACL
statistics
display
how
many
packets
have
“hit”
(matched)
each
ACL.
Use
ACL
statistics
to
check
filter
performance
or
to
debug
the
ACL
filter
configuration.
You
must
enable
statistics
for
each
ACL
that
you
wish
to
monitor:
ACL Logging
ACLs
are
generally
used
to
enhance
port
security.
Traffic
that
matches
the
characteristics
(source
addresses,
destination
addresses,
packet
type,
etc.)
specified
by
the
ACLs
on
specific
ports
is
subject
to
the
actions
(chiefly
permit
or
deny)
defined
by
those
ACLs.
Although
switch
statistics
show
the
number
of
times
particular
ACLs
are
matched,
the
ACL
logging
feature
can
provide
additional
insight
into
actual
traffic
patterns
on
the
switch,
providing
packet
details
in
the
system
log
for
network
debugging
or
security
purposes.
Enabling ACL Logging
By
default,
ACL
logging
is
disabled.
Enable
or
disable
ACL
logging
on
a
per
‐
ACL
basis
as
follows:
NE2552E(config)#
access-control list
<ACL
number>
mirror port
<destination
port>
NE2552E(config)#
access-control list
<ACL
number>
statistics
NE2552E(config)# [
no
]
access-control list
<IPv4
ACL
number>
log
NE2552E(config)# [
no
]
access-control list6
<IPv6
ACL
number>
log
Summary of Contents for ThinkSystem NE2552E
Page 27: ... Copyright Lenovo 2018 27 Part 1 Getting Started ...
Page 28: ...28 NE2552E Application Guide for ENOS 8 4 ...
Page 70: ...70 NE2552E Application Guide for ENOS 8 4 ...
Page 85: ... Copyright Lenovo 2018 85 Part 2 Securing the Switch ...
Page 86: ...86 NE2552E Application Guide for ENOS 8 4 ...
Page 112: ...112 NE2552E Application Guide for ENOS 8 4 ...
Page 134: ...134 NE2552E Application Guide for ENOS 8 4 ...
Page 154: ...154 NE2552E Application Guide for ENOS 8 4 ...
Page 194: ...194 NE2552E Application Guide for ENOS 8 4 ...
Page 218: ...218 NE2552E Application Guide for ENOS 8 4 ...
Page 234: ...234 NE2552E Application Guide for ENOS 8 4 ...
Page 238: ...238 NE2552E Application Guide for ENOS 8 4 ...
Page 239: ... Copyright Lenovo 2018 239 Part 4 Advanced Switching Features ...
Page 240: ...240 NE2552E Application Guide for ENOS 8 4 ...
Page 242: ...242 NE2552E Application Guide for ENOS 8 4 ...
Page 278: ...278 NE2552E Application Guide for ENOS 8 4 ...
Page 284: ...284 NE2552E Application Guide for ENOS 8 4 ...
Page 314: ...314 NE2552E Application Guide for ENOS 8 4 ...
Page 338: ...338 NE2552E Application Guide for ENOS 8 4 ...
Page 374: ...374 NE2552E Application Guide for ENOS 8 4 ...
Page 388: ...388 NE2552E Application Guide for ENOS 8 4 ...
Page 418: ...418 NE2552E Application Guide for ENOS 8 4 ...
Page 430: ...430 NE2552E Application Guide for ENOS 8 4 ...
Page 432: ...432 NE2552E Application Guide for ENOS 8 4 ...
Page 436: ...436 NE2552E Application Guide for ENOS 8 4 ...
Page 460: ...460 NE2552E Application Guide for ENOS 8 4 ...
Page 461: ... Copyright Lenovo 2018 461 Part 7 Network Management ...
Page 462: ...462 NE2552E Application Guide for ENOS 8 4 ...
Page 476: ...476 NE2552E Application Guide for ENOS 8 4 ...
Page 498: ...498 NE2552E Application Guide for ENOS 8 4 ...
Page 520: ...520 NE2552E Application Guide for ENOS 8 4 ...
Page 534: ...534 NE2552E Application Guide for ENOS 8 4 ...
Page 536: ...536 NE2552E Application Guide for ENOS 8 4 ...
Page 544: ...544 NE2552E Application Guide for ENOS 8 4 ...
Page 549: ... Copyright Lenovo 2018 549 Part 9 Appendices ...
Page 550: ...550 NE2552E Application Guide for ENOS 8 4 ...
Page 566: ...566 NE2552E Application Guide for ENOS 8 4 ...
Page 572: ...572 NE2552E Application Guide for ENOS 8 4 ...
Page 573: ......
Page 574: ...Part Number 01KN246 Printed in USA IP P N 01KN246 ...