6 - 16 WiNG 4.4 Switch System Reference Guide
•
Precedence Order
6.4.1.1 Router ACLs
Router ACLs are applied to Layer 3 or VLAN interfaces. If an ACL is already applied in a particular direction on an interface,
applying a new one will replace the existing ACL. Router ACLs are applicable only if the switch acts as a gateway, and
traffic is inbound only.
The switch supports two types of Router ACLs:
•
Standard IP ACL
—Uses the source IP address as matching criteria.
•
Extended IP ACL
—Uses the source IP address, destination IP address and IP protocol type as basic matching criteria.
It can also include other parameters specific to a protocol type (like source and destination port for TCP/UDP protocols).
Router ACLs are stateful and are not applied on every packet routed through the switch. Whenever a packet is received
from a Layer 3 interface, it is examined against existing sessions to determine if it belongs to an established session. ACLs
are applied on the packet in the following manner.
1. If the packet matches an existing session, it is not matched against ACL rules and the session decides where to send
the packet.
2. If no existing sessions match the packet, it is matched against ACL rules to determine whether to accept or reject it. If
ACL rules accept the packet, a new session is created and all further packets belonging to that session are allowed. If
ACL rules reject the packet, no session is established.
A session is computed based on:
• Source IP address
• Destination IP address
• Source Port
• Destination Port
• ICMP identifier
• Incoming interface index
•
IP Protocol
Each session has a default idle time-out interval. If no packets are received within this interval, the session is terminated
and a new session must be initiated. These intervals are fixed and cannot be configured by the user.
The default idle time-out intervals for different sessions are:
•
ICMP and UDP sessions
— 30 seconds
•
TCP sessions
— 2 hours
6.4.1.2 Port ACLs
The switch supports Port ACLs on physical interfaces and inbound traffic only. The following Port ACLs are supported:
•
Standard IP ACL
— Uses a source IP address as matching criteria.
•
Extended IP ACL
— Uses a source IP address, destination IP address and IP protocol type as basic matching criteria. It
can also include other parameters specific to a protocol type, like the source and destination ports for TCP/UDP
protocols.
NOTE:
Port and router ACLs can be applied only in an inbound direction. WLAN ACLs
support applying ACLs in the inbound and outbound direction.
Summary of Contents for WiNG 4.4
Page 1: ...Motorola Solutions WiNG 4 4 SYSTEM REFERENCE GUIDE ...
Page 2: ......
Page 3: ...MOTOROLA SOLUTIONS WING 4 4 SYSTEM REFERENCE GUIDE 72E 157062 01 Revision A January 2012 ...
Page 6: ...iv WiNG 4 4 Switch System Reference Guide ...
Page 14: ...xii WiNG 4 4 Switch System Reference Guide ...
Page 48: ...1 32 WiNG 4 4 Switch System Reference Guide ...
Page 58: ...2 10 WiNG 4 4 Switch System Reference Guide ...
Page 280: ...4 176 WiNG 4 4 Switch System Reference Guide ...
Page 352: ...5 72 WiNG 4 4 Switch System Reference Guide ...
Page 476: ...6 124 WiNG 4 4 Switch System Reference Guide ...
Page 506: ...7 30 WiNG 4 4 Switch System Reference Guide ...
Page 532: ...8 26 WiNG 4 4 Switch System Reference Guide ...
Page 536: ...A 4 WiNG 4 4 Switch System Reference Guide ...
Page 544: ...B 12 WiNG 4 4 Switch System Reference Guide ...
Page 558: ...B 26 WiNG 4 4 Switch System Reference Guide ...
Page 574: ...C 16 WiNG 4 4 Switch System Reference Guide ...
Page 596: ...E 4 WiNG 4 4 Switch System Reference Guide ...
Page 597: ......