7-1
C
HAPTER
7
A
CCESS
C
ONTROL
L
ISTS
Access Control Lists (ACL) provide packet filtering for IPv4 frames (based
on address, protocol, Layer 4 protocol port number or TCP control code),
IPv6 frames (based on address, next header type, or flow label), or any
frames (based on MAC address or Ethernet type). To filter incoming
packets, first create an access list, add the required rules, and then bind the
list to a specific port.
Configuring Access Control Lists
An ACL is a sequential list of permit or deny conditions that apply to IP
addresses, MAC addresses, or other more specific criteria. This switch tests
ingress packets against the conditions in an ACL one by one. A packet will
be accepted as soon as it matches a permit rule, or dropped as soon as it
matches a deny rule. If no rules match, the packet is accepted.
Command Usage
The following restrictions apply to ACLs:
• Each ACL can have up to 32 rules.
• The maximum number of ACLs is also 32.
• The maximum number of rules that can be bound to the ports is 96 for
each of the following list types: MAC ACLs, IP ACLs (including
Standard and Extended ACLs), IPv6 Standard ACLs, and IPv6
Extended ACLs. For the SMC8824M, all ports share this quota. For the
SMC8848M, ports 1-24 share a quota of 96 rules, and ports 25-50 share
another quota of 96 rules (since there are two switch chips in this
system).
Summary of Contents for WPCI-G - annexe 1
Page 2: ......
Page 26: ...TABLE OF CONTENTS xxvi ...
Page 36: ...GETTING STARTED ...
Page 72: ...MANAGING SYSTEM FILES 2 24 ...
Page 74: ...SWITCH MANAGEMENT ...
Page 90: ...CONFIGURING THE SWITCH 3 16 ...
Page 245: ...SHOWING PORT STATISTICS 8 33 Figure 8 12 Port Statistics ...
Page 252: ...ADDRESS TABLE SETTINGS 9 6 ...
Page 318: ...CLASS OF SERVICE 12 16 ...
Page 330: ...QUALITY OF SERVICE 13 12 ...
Page 348: ...DOMAIN NAME SERVICE 15 8 ...
Page 404: ...IP ROUTING 17 44 ...
Page 406: ...COMMAND LINE INTERFACE ...
Page 608: ...MIRROR PORT COMMANDS 26 4 ...
Page 644: ...SPANNING TREE COMMANDS 29 28 ...
Page 668: ...VLAN COMMANDS 30 24 ...
Page 686: ...CLASS OF SERVICE COMMANDS 31 18 ...
Page 700: ...QUALITY OF SERVICE COMMANDS 32 14 ...
Page 792: ...IP INTERFACE COMMANDS 36 50 ...
Page 818: ...APPENDICES ...
Page 824: ...SOFTWARE SPECIFICATIONS A 6 ...
Page 828: ...TROUBLESHOOTING B 4 ...
Page 844: ...INDEX Index 6 ...
Page 845: ......