INS_CNXE2GE2TX8MSPOE 11 Jan 2021 PAGE 143
INSTALLATION AND OPERATION MANUAL
CNXE2GE2TX8MSPOE
TECH SUPPORT: 1.888.678.9427
ACL Control List
Configure ACE (Access Control Entry). An ACE consists of several parameters. These parameters
vary with the frame type you have selected. First select the ingress port for the ACE, and then
the frame type. Different parameter options are displayed according to the frame type you have
selected. A frame matching the ACE can be configured here.
Label
Description
Ingress Port
Indicates the ingress port to which the ACE will apply.
Any: the ACE applies to any port
Port n: the ACE applies to this port number, where n is the number of the switch port.
Policy n: the ACE applies to this policy number, where n can range from 1 to 8.
Frame Type
Indicates the frame type of the ACE. These frame types are mutually exclusive.
Any: any frame can match the ACE.
Ethernet Type: only Ethernet type frames can match the ACE. The IEEE 802.3
descripts the value of length/types should be greater than or equal to 1536 decimal
(equal to 0600 hexadecimal). ARP: only ARP frames can match the ACE. Notice the
ARP frames will not match the ACE with Ethernet type.
IPv4: only IPv4 frames can match the ACE. Notice the IPv4 frames will not match the
ACE with Ethernet type.
Action
Specifies the action to take when a frame matches the ACE.
Permit: takes action when the frame matches the ACE.
Deny: drops the frame matching the ACE.
Rate Limiter
Specifies the rate limiter in number of base units. The allowed range is 1 to 15.
Disabled means the rate limiter operation is disabled.
Port Copy
Frames matching the ACE are copied to the port number specified here. The allowed
range is the same as the switch port number range. Disabled means the port copy
operation is disabled.
Logging
Specifies the logging operation of the ACE. The allowed values are:
Enabled: frames matching the ACE are stored in the system log.
Disabled: frames matching the ACE are not logged.
Please note that system log memory capacity and logging rate is limited.
Shutdown
Specifies the shutdown operation of the ACE. The allowed values are:
Enabled: if a frame matches the ACE, the ingress port will be disabled.
Disabled: port shutdown is disabled for the ACE.
Counter
Indicates the number of times the ACE matched by a frame.