90
Table of Contents
Linksys
STEP 3 Click Add
STEP 4 Enter the parameters
•
ACL Name—Displays the name of the ACL
ACE Settings
•
ACE Priority—Enter the priority ACEs with higher priority are processed first
•
Action on Match Packets—Select the action assigned to the packet
matching the ACE The options are as follows:
•
Permit—Forward packets that meet the ACE criteria
•
Deny—Drop packets that meet the ACE criteria
•
Shutdown—Drop packet that meets the ACE criteria and disable the
port to which the packet was addressed Ports are reactivated from
the Port Management page
•
Protocol—Select to create an ACE based on a specific protocol or
protocol ID Select Any IPv6 to accept all IP protocols Otherwise select
one of the following protocols from the drop-down list:
•
ICMP—Internet Control Message Protocol
•
TCP—Transmission Control Protocol
•
UDP—User Datagram Protocol
•
Protocol ID—Instead of selecting the name, enter the protocol ID
•
Source IP Address—Select Any if all source addresses are acceptable or
User Defined to enter a source address or range of source addresses
•
Source IP Address Value—Enter the IP address to which the source MAC
address is to be matched and its mask (if relevant)
•
Source IP Prefix Length—Enter the prefix length of the source IP address
•
Destination IP Address—Select Any if all destination addresses are
acceptable or User Defined to enter a destination address or range of
destination addresses
•
Destination IP Address Value—Enter the IP address to which the
destination IP address is to be matched
•
Destination IP Prefix Length—Enter the prefix length of the destination
IP address
•
Source Port—Select one of the following:
•
Any—Match to all source ports
•
Single Port—Enter a single TCP/UDP source port to which packets
are matched This field is active only if 800/6-TCP or 800/17-UDP is
selected in the Select from List drop-down menu
•
Destination Port—Select one of the available values that are the same as
the Source Port field described above
NOTE:
You must specify the IP protocol for the ACE before you can enter the source
and/or destination port
•
Type of Services—The service type of the IP packet
•
Any—Any service type
•
DSCP to Match—Differentiated Serves Code Point (DSCP) to match
•
IP Precedence—IP precedence is a model of TOS (type of service) that
the network uses to help provide the appropriate QoS commitments
This model uses the 3 most significant bits of the service type byte in
the IP header, as described in RFC 791 and RFC 1349
STEP 5 Click Apply The IPv6-Based ACE is saved to the Running
Configuration file
ACL Binding
When an ACL is bound to an interface (port, LAG or VLAN), its ACE rules are
applied to packets arriving at that interface Packets that do not match any
of the ACEs in the ACL are matched to a default rule, whose action is to drop
unmatched packets
Multiple interfaces can be bound to the same ACL
After an ACL is bound to an interface, it cannot be edited, modified, or deleted
until it is removed from all the ports to which it is bound or in use
To bind an ACL to a port or LAG:
STEP 1 Click Configuration > Access Control List > ACL Binding (Port)
STEP 2 Select an interface type Ports/LAGs (Port or LAG)
STEP 3 Click Search For each type of interface selected, all interfaces of that
type are displayed with a list of their current ACLs:
NOTE To unbind all ACLs from an interface, select the interface, and click Clear