![SNR S2940-8G-v2 Configuration Manual Download Page 299](http://html1.mh-extra.com/html/snr/s2940-8g-v2/s2940-8g-v2_configuration-manual_1310630299.webp)
SNR S2940-8G-v2 Switch Configuration Guide
Self-defined ACL Configuration
Chapter 44
Self-defined ACL Configuration
44.1
Introduction to Self-defined ACL
ACL (Access Control Lists) is a packet filtering mechanism implemented by switch, providing net-
work access control by granting or denying access the switches, effectively safeguarding the secu-
rity of networks. The user can set a set of rules according to some information specific to packets,
each rule describes the action for a packet with certain information matched: “permit” or “deny”.
The user can apply such rules to the incoming direction of switch ports, so that data streams of
specified ports must comply with the ACL rules assigned..
Self-defined ACL means that users can configure several self-defined windows as the matching
field when users configure ACL. Self-defined windows do not specify which field definitely, but
specify the offset in a packet and ignore the meaning of field. It matches the data at offset position
which begins to fix the byte length according to the value and mask configuration.
44.1.1
Standard Self-defined ACL Template
Standard self-defined ACL can configure 11 windows and each of them can specify a start offset
position: L2 end of tag / start of L3 header / start of L4 header. Each window can specify offset,
its value from 0 to 31, unit is 2Bytes, namely, 0 means 0Bytes offset and 1 means 2Bytes offset.
Besides, offset is according to the start offset position.
A standard self-defined ACL template should be configured for the offset configuration of every
window before configuring the standard self-defined ACL list. This template is global and takes
effect to all standard self-defined ACL list. Standard self-defined ACL template can configure the
start offset position and offset for 11 windows at most. The window which is not configured is
not available, that means it cannot transmit configuration successfully if the standard self-defined
ACL use this window. When a window in the template is configured, it cannot be modified if the
standard self-defined ACL rule is configured with this window. But the standard self-defined ACL
rule is not configured, the window can be reconfigured, modified or deleted.
44.1.2
Extended Self-defined ACL Template
Extended self-defined ACL template can configure 2 swindows and 8 lwindows. Every swindow
can specify a start offset position: Start of L2 header / L2 end of tag / start of L3 header / start of
L4 header; every lwindow can specify a start offset position: L2 end of tag / start of L3 header /
299
Summary of Contents for S2940-8G-v2
Page 11: ...SNR S2940 8G v2 Switch Configuration Guide Part I Basic Management Configuration 11...
Page 46: ...SNR S2940 8G v2 Switch Configuration Guide Part II Port Configuration 46...
Page 123: ...SNR S2940 8G v2 Switch Configuration Guide Part III VLAN and MAC Table Configuration 123...
Page 164: ...SNR S2940 8G v2 Switch Configuration Guide Part IV MSTP Configuration 164...
Page 198: ...SNR S2940 8G v2 Switch Configuration Guide Part VI L3 Forward and ARP Configuration 198...
Page 218: ...SNR S2940 8G v2 Switch Configuration Guide Part VII DHCP Configuration 218...
Page 257: ...SNR S2940 8G v2 Switch Configuration Guide Part VIII Multicast Protocol 257...
Page 278: ...SNR S2940 8G v2 Switch Configuration Guide Part IX Security Function Configuration 278...
Page 376: ...SNR S2940 8G v2 Switch Configuration Guide Part X Reliability Configuration 376...
Page 395: ...SNR S2940 8G v2 Switch Configuration Guide Part XI Flow Monitor Configuration 395...
Page 403: ...SNR S2940 8G v2 Switch Configuration Guide Part XII Network Time Management Configuration 403...
Page 411: ...SNR S2940 8G v2 Switch Configuration Guide Part XIII Debugging and Diagnosis 411...