Chapter 9: Security Configuration Guide
SSR User Reference Manual
9 - 9
filters add secure-port name engineers direction dest vlan 1 in-
port-list et.1.1
To allow all engineers access to the engineering servers, you must "punch" a hole
through the secure-port wall. A "dest static-entry" overrides a "dest secure port".
filters add static-entry name eng-server dest-mac 080060:abcdef
vlan 1 in-port-list et.1.1 out-port-list et.1.2 restriction allow
L3 Access Control Lists (ACLs)
Traffic Filters at Layer-3 and 4 (Access Control List)
Access Control Lists (ACLs) allow you to restrict Layer-3/4 traffic going through the
router. Each ACL or each list consists of one or more rules describing a particular type
of IP or IPX traffic. An ACL can be simple, consisting of only one rule, or complicated
with many rules. Each rule tells the router to either permit or deny the packet that
matches the rule's packet description.
The Anatomy of an ACL rule
Each ACL is identified by a name. The name can be a meaningful string, such as
denyftp or noweb or it can be a number such as 100 or 101.
Each rule has an action, that is, to permit or to deny the packet if a packet satisfies the
criterion defined by the rule.
A criterion describes one or more characteristics about a packet. In an ACL rule, these
characteristics are described as fields of a rule. Not all characteristics (fields) of a
packet (rule) need to be specified. If a particular field is not specified, it is treated as a
wildcard or "don't care" condition. However, if a field is specified, that particular field
will be matched against the packet. Each protocol can have a number of different fields
to match. For example, TCP can use socket port numbers while IPX can use a network
node address to define a rule. For IP, TCP and UDP ACLs, the following fields can be
specified:
• Source IP address
• Destination IP address
• Source port number
• Destination port number
• Type of Service (TOS)
Содержание SmartSwitch 8-slot
Страница 1: ...SmartSwitch Router User Reference Manual 9032578...
Страница 2: ......
Страница 6: ...Notice vi...
Страница 10: ...About This Manual x SSR User Reference Manual...
Страница 36: ...Chapter 1 SmartSwitch Router Product Overview 1 18 SSR User Reference Manual...
Страница 60: ...Chapter 4 RIP Configuration Guide 4 6 SSR User Reference Manual...
Страница 115: ...Chapter 7 Multicast Routing Configuration Guide SSR User Reference Manual 7 9...
Страница 116: ...Chapter 7 Multicast Routing Configuration Guide 7 10 SSR User Reference Manual...
Страница 142: ...Chapter 9 Security Configuration Guide 9 18 SSR User Reference Manual...