176
1.877.877.2269
BLACKBOX.COM
NEED HELP?
LEAVE THE TECH TO US
LIVE 24/7
TECHNICAL
SUPPORT
1.877.877.2269
CHAPTER 11: ACCESS CONTROL
6. When editing an entry on the ACE Configuration page, note that the Items displayed depend on various selections, such as Frame
Type and IP Protocol Type. Specify the relevant criteria to be matched for this rule, and set the actions to take when a rule is
matched (such as Rate Limiter, Port Copy, Logging, and Shutdown).
FIGURE 11-3. ACCESS CONTROL LIST CONFIGURATION
PARAMETER DESCRIPTION
ACE: Indicates the ACE ID.
Ingress Port: Indicates the ingress port of the ACE. Possible values are:
- Any: The ACE will match any ingress port.
- Policy: The ACE will match ingress ports with a specific policy.
- Port: The ACE will match a specific ingress port.
Policy / Bitmask: Indicates the policy number and bitmask of the ACE.
Frame Type: Indicates the frame type of the ACE. Possible values are:
Any: The ACE will match any frame type.
EType: The ACE will match Ethernet Type frames. Note that an Ethernet Type based ACE will not get matched by IP and ARP frames.
ARP: The ACE will match ARP/RARP frames.
IPv4: The ACE will match all IPv4 frames.
IPv4/ICMP: The ACE will match IPv4 frames with ICMP protocol.
IPv4/UDP: The ACE will match IPv4 frames with UDP protocol
IPv4/TCP: The ACE will match IPv4 frames with TCP protocol.
IPv4/Other: The ACE will match IPv4 frames, which are not ICMP/UDP/TCP.
IPv6: The ACE will match all IPv6 standard frames.
Action: Indicates the forwarding action of the ACE
Permit: Frames matching the ACE may be forwarded and learned.
Deny: Frames matching the ACE are dropped.