184
Rockwell Automation Publication 1783-UM007F-EN-P - September 2016
Chapter 7
Configure Switch Features
This chapter describes software features that you can configure via
Device Manager, the Studio 5000 Logix Designer® application, or both. More
software features are available. You can configure some features with the global
macro or Smartports feature.
For information about how to configure features not available in Device
Manager or the Logix Designer application, see the documentation available at
Some features are available only on select switch models and firmware types.
See
Lite Versus Full Firmware Features (Stratix 5700 Switches) on page 20
and
Access Control Lists (ACLs)
ACLs, also called access lists, filter traffic as it passes through the switch. ACLs
permit or deny packets as they cross specified interfaces or VLANs. You
configure ACLs on switches with Layer 2 or Layer 3 firmware to provide basic
security for your network. If you do not configure ACLs, all packets that pass
through the switch can be allowed onto all parts of the network. You can use
ACLs to control which hosts can access different parts of a network or to
decide which types of traffic are forwarded or blocked at router interfaces.
An ACL contains an ordered list of access control entries (ACEs). Each ACE
specifies whether to permit or deny packets. An ACE also specifies a set of
conditions a packet must satisfy to match the ACE. The meaning of permit or
deny depends on the context in which the ACL is used.
When a packet is received on a port, the switch compares the fields in the
packet against any ACLs applied to the port. Based on the criteria in the ACL,
the switch determines whether the packet has the required conditions to be
forwarded. One by one, it tests packets against the conditions in an ACL. The
first match decides whether the switch accepts or rejects the packets. Because
the switch stops testing after the first match, the order of conditions in the list
is critical. If no conditions match, the switch rejects the packet. If there are no
restrictions, the switch forwards the packet. Otherwise, the switch drops the
packet.
Summary of Contents for ArmorStratix 5700 series
Page 12: ...12 Rockwell Automation Publication 1783 UM007F EN P September 2016 Table of Contents Notes...
Page 14: ...14 Rockwell Automation Publication 1783 UM007F EN P September 2016 Preface Notes...
Page 16: ...16 Rockwell Automation Publication 1783 UM007F EN P September 2016 Summary of Changes Notes...
Page 486: ...486 Rockwell Automation Publication 1783 UM007F EN P September 2016 Appendix A DataTypes Notes...
Page 547: ......