UANTA COMPUTER INC.
Layer 2,3,IPv6+QoS Switch
_____________________________________________________________________________
Layer 2,3,IPv6+QoS Network Switch User Manual Version 0.1
Page: 907/970
11.2.6.1.3.
Configuring IP Access Control List Rule Configuration Page
Use these screens to configure the rules for the IP Access Control Lists created using the IP
Access Control List Configuration screen. What is shown on this screen varies depending on
the current step in the rule configuration process. A Standard/Extended IP ACL must first be
selected to configure rules for. The rule identification, and the 'Action' and 'Match Every'
parameters must be specified next. If 'Match Every' is set to false a new screen will then be
presented from which the match criteria can be configured.
Selection Criteria
IP ACL ID - Use the pulldown menu to select the IP ACL for which to create or update a
rule.
Rule - Select an existing rule from the pulldown menu, or select 'Create New Rule.' ACL
as well as an option to add a new Rule. New rules cannot be created if the maximum
number of rules has been reached. For each rule, a packet must match all the specified
criteria in order to be true against that rule and for the specified rule action (Permit/Deny)
to take place.
Configurable Data
Rule ID - Enter a whole number in the range of 1 to 8 that will be used to identify the rule.
An IP ACL may have up to 8 rules.
Action - Specify what action should be taken if a packet matches the rule's criteria. The
choices are permit or deny.
Logging - When set to 'True', logging is enabled for this ACL rule (subject to resource
availability in the device). If the Access List Trap Flag is also enabled, this will cause
periodic traps to be generated indicating the number of times this rule was 'hit' during the
current report interval. A fixed 5 minute report interval is used for the entire system. A trap
is not issued if the ACL rule hit count is zero for the current interval. This field is visible for
a 'Deny' Action.
Assign Queue ID - Specifies the hardware egress queue identifier used to handle all
packets matching this IP ACL rule. Valid range of Queue Ids is (0 to 6). This field is visible
when 'Permit' is chosen as 'Action'.
Mirror Interface - Specifies the specific egress interface where the matching traffic
stream is copied in addition to being forwarded normally by the device. This field cannot
be set if a Redirect Interface is already configured for the ACL rule. This field is visible for
a 'Permit' Action.
Redirect Interface - Specifies the specific egress interface where the matching traffic
stream is forced, bypassing any forwarding decision normally performed by the device.
This field is visible when 'Permit' is chosen as 'Action'.
Match Every - Select true or false from the pulldown menu. True signifies that all packets
will match the selected IP ACL and Rule and will be either permitted or denied. In this
case, since all packets match the rule, the option of configuring other match criteria will