![Comnet reliance RL1000GW Скачать руководство пользователя страница 67](http://html1.mh-extra.com/html/comnet/reliance-rl1000gw/reliance-rl1000gw_installation-and-operation-manual_2644386067.webp)
INS_RL1000GW_REV– 15 Jul 2016 PAGE 67
INSTALLATION AND OPERATION MANUAL
RL1000GW
TECH SUPPORT: 1.888.678.9427
ACG
»
For an ACL to take effect on incoming packets, it must be asserted on an interface. The
assignment of the ACL to an interface is referred to as Port Access Group (ACG).
»
An ACG assigns a specific ACL to an interface.
»
Multiple ACGs, assigning the same ACL to the same interface are not allowed.
»
Each ACG is assigned with a priority, integer of value 1-255.
An ACG with priority value 1 will be inspected before ACG with priority value 255. Generally
speaking, priority x will be inspected before y, if x<y.
»
A packet which is assigned multiple ACGs, will be inspected according to the ACG priorities
until first match is found. The packet will then be permitted/ denied, with the ACL option of
‘redirect’. The packet will not be further inspected by lower priority ACGs.
»
If a packet does not meet any of the port assigned ACG conditions, it will be permitted.
Comments
1. An ACL rule which denies ICMP, does not block TCP or UDP traffic, only ICMP
2. An ACL rule which denies TCP, does not block ICMP or UDP traffic, only TCP
3. An ACL rule which denies UDP, does not block ICMP or TCP traffic, only UDP
4. Deleting an ACL will automatically remove corresponding ACGs on the interfaces, if such exists.
5. For an ACL which is already set to a port with an ACG, if a rule is added to the ACL (on the fly) it
takes effect immediately on the ACG without need to reassign it to the interface.
6. To delete a rule, it is needed to delete the entire ACL it is assigned to.