D-Link DWS-1008 User Manual
To sample the number of hits the security ACLs generate, you must specify the number of seconds
between samples. For example, to sample the hits generated every 180 seconds, type the following
commands:
DWS-1008#
set security acl hit-sample-rate 180
DWS-1008#
show security acl hits
ACL hit-counters
Index
Counter
ACL-name
---------------------------------------------------
1
31986
acl-red
2
0
acl-green
Clearing Security ACLs
The
clear security acl command removes the ACL from the edit buffer only. To clear a security ACL,
enter a specific ACL name, or enter all to delete all security ACLs. To remove the security ACL from the
running configuration and nonvolatile storage, you must also use the
commit security acl command.
For example, the following command deletes
acl-99
from the edit buffer:
DWS-1008#
clear security acl acl-99
To clear
acl-99
from the configuration, type the following command:
DWS-1008#
commit security acl acl-99
success: change accepted
Mapping Security ACLs
An ACL does not take effect until you commit it and map it to a user or an interface.
User-based security ACLs are mapped to an IEEE 802.1X authenticated session during the AAA process.
You can specify that one of the authorization attributes returned during authentication is a named
security ACL. The switch maps the named ACL automatically to the user’s authenticated session.
Security ACLs can also be mapped statically to ports, VLANs, virtual ports, or Distributed APs. User-
based ACLs are processed before these ACLs, because they are more specific and closer to the
network edge.
Содержание DWS-1008
Страница 1: ......