Brief Introduction to ACL
353
Table 362
Set the Absolute Time Range
When the start-time and end-time are not configured, it will be all the time for one
day. The end time shall be later than the start time.
When
end-time end-date
is not configured, it will be all the time from now to the
date which can be displayed by the system. The end time shall be later than the start
time.
Defining ACL
The Switch 5500 supports several types of ACL. This section introduces how to define
these ACLs.
Defining ACL by following the steps below:
1
Enter the corresponding ACL view.
2
Add a rule to the ACL.
You can add multiple rules to one ACL.
■
If a specific time range is not defined, the ACL will always function after activated.
■
During the process of defining the ACL, you can use the rule command several
times to define multiple rules for an ACL.
■
If ACL is used to filter or classify the data transmitted by the hardware of the
Switch, the match order defined in the acl command will not be effective. If ACL is
used to filter or classify the data treated by the software of the Switch, the match
order of ACL’s sub-rules will be effective. Once the user specifies the match-order
of an ACL rule, he cannot modify it later.
■
The default matching-order of ACL is config, that is following the order as that
configured by the user.
Define Basic ACL
The rules of the basic ACL are defined on the basis of the Layer-3 source IP address to
analyze the data packets.
You can use the following command to define basic ACL.
Perform the following configuration in the corresponding view.
Operation
Command
Set the time range
time-range
time-name
{
start_time
to
end_time
days_of_the_week
[ from
start_time start_date
] [ to
end_time end_date
] | from
start_time start_date
[ to
end_time end_date
] | to
end_time end_date
}
Delete the time range
undo time-range
time-name
[
start_time
to
end_time
days_of_the_week
[ from
start_time start_date
] [ to
end_time end_date
] | from
start_time start_date
[
to
end_time end_date
] | to
end_time end_date
]
Содержание 5500 SI - Switch - Stackable
Страница 24: ...24 ABOUT THIS GUIDE...
Страница 30: ...30 CHAPTER 1 GETTING STARTED Figure 3 Setting up a New Connection Figure 4 Configuring the Port for Connection...
Страница 50: ...50 CHAPTER 1 GETTING STARTED...
Страница 54: ...54 CHAPTER 2 ADDRESS MANAGEMENT CONFIGURATION...
Страница 78: ...78 CHAPTER 3 PORT OPERATION...
Страница 88: ...88 CHAPTER 4 XRN CONFIGURATION...
Страница 122: ...122 CHAPTER 8 VLAN VPN CONFIGURATION...
Страница 216: ...216 CHAPTER 15 SSH TERMINAL SERVICES...
Страница 268: ...268 CHAPTER 16 IP ROUTING PROTOCOL OPERATION...
Страница 308: ...308 CHAPTER 17 NETWORK PROTOCOL OPERATION...
Страница 349: ...349...
Страница 350: ...350 CHAPTER 18 MULTICAST PROTOCOL...
Страница 522: ...522 CHAPTER 22 FILE SYSTEM MANAGEMENT...
Страница 584: ...584 CHAPTER 30 PASSWORD CONTROL CONFIGURATION OPERATIONS...
Страница 600: ...600 CHAPTER 31 MSDP CONFIGURATION...
Страница 614: ...614 CHAPTER 32 CLUSTERING...
Страница 670: ...670 CHAPTER C AUTHENTICATING THE SWITCH 5500 WITH CISCO SECURE ACS...