[ etype-value { <0x600-0x7ff,0x801-0x805,0x807-0x86dc,0x86de-0xffff> | any } ] |
ipv4 | ipv4-icmp | ipv4-tcp | ipv4-udp | ipv6 | ipv6-icmp | ipv6-tcp | ipv6-udp }
- DMAC Filter :
(config)# access-list ace [ update ] <1-256> dmac-type { unicast | multicast |
broadcast | any }
- VLAN ID Filter :
(config)# access-list ace [ update ] <1-256> vid { <1-4095> | any }
- Tag Priority :
(config)# access-list ace [ update ] <1-256> tag-priority { <0-7> | any }
- Action if matched :
(config)# access-list ace [ update ] <1-256> action { permit | deny }
- Rate Limiter if matched :
(config)# access-list ace [ update ] <1-256> rate-limiter { <1-16> | disable }
- Logging if matched :
(config)# access-list ace [ update ] <1-256> logging
- Shutdown if matched :
(config)# access-list ace [ update ] <1-256> shutdown
Disable shutdown :
(config)# access-list ace [ update ] <1-256> disable
- Redirect frame to specific port if matched :
(config)# access-list ace [ update ] <1-256> redirect { disable | interface
{ <port_type_id> | <port_type_list> } }
- Insert the current ACE before the next ACE ID :
(config)# access-list ace [ update ] <1-256> { last | <1-256> }
Status by Web
:
[Monitor] -> [Security] -> [Network] -> [ACL Status]
Click “
?
” at this web page to get details of the settings.
Status by Command
:
# clear access-list ace statistics
# show access-list ace statistics [ <1~256> ] [ interface { <port_type_id> |
<port_type_list> } ] [ rate-limiter ]
# show access-list ace-status [ static ] [ link-oam ] [ loop-protect ] [ dhcp ] [ ptp ]
[ upnp ] [ arp-inspection ] [ mep ] [ ipmc ] [ ip-source-guard ] [ ip-mgmt ]
[ conflicts ]
4.
IP Source Guard
IP Source Guard is a secure feature used to restrict IP traffic on DHCP snooping
untrusted ports by filtering traffic based on the DHCP Snooping Table or
manually configured IP Source Bindings. It helps prevent IP spoofing attacks
when a host tries to spoof and use the IP address of another host.
Configuration by Web
:
Enable/Disable, Dynamic Client Number :
[Configuration] -> [Security] -> [Network] -> [IP Source Guard] -> [Configuration]
52
Содержание GSW-3420FM
Страница 64: ...Status by Command show tacacs server 61 ...
Страница 79: ...76 ...
Страница 144: ......
Страница 145: ......