Overview
91
15
Access Control Lists (ACLs)
This section describes the Access Control Lists (ACLs) feature.
Overview
Access Control Lists (ACLs) are a collection of permit and deny conditions, called rules, that
provide security by blocking unauthorized users and allowing authorized users to access
specific resources. Normally ACLs reside in a firewall router or in a router connecting two
internal networks.
ACL Logging provides a means for counting the number of “hits” against an ACL rule. When
you configure ACL Logging, you augment the ACL deny rule specification with a ‘log’
parameter that enables hardware hit count collection and reporting. The D-Link DWS-3000
switch uses a fixed five minute logging interval, at which time trap log entries are written for
each ACL logging rule that accumulated a non-zero hit count during that interval. You cannot
configure the logging interval.
You can set up ACLs to control traffic at Layer 2, Layer 3, or Layer 4. MAC ACLs operate on
Layer 2. IP ACLs operate on Layers 3 and 4.
Limitations
The following limitations apply to ACLs.
•
Maximum of 100 ACLs.
•
Maximum rules per ACL is 10.
•
The system supports ACLs set up for inbound traffic only.
•
The system does not support MAC ACLs and IP ACLs on the same interface.
•
It may not be possible to log every ACL rule due to limited hardware counter resources.
You can define an ACL with any number of logging rules, but the number of rules that are
actually logged cannot be determined until the ACL is applied to an interface. Further-
more, hardware counters that become available after an ACL is applied are not retroac-
tively assigned to rules that were unable to be logged (the ACL must be un-applied then
re-applied). Rules that are unable to be logged are still active in the ACL for purposes of
permitting or denying a matching packet.
Содержание UNIFIED WIRED & WIRELESS ACCESS SYSTEM...
Страница 2: ...2 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 12: ...12 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 14: ...14 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 32: ...32 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 40: ...40 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 44: ...44 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 55: ...Web Examples 55 6 IGMP Snooping Figure 19 IGMP Snooping Multicast Router VLAN Configuration Page ...
Страница 56: ...56 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 66: ...66 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 84: ...84 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 90: ...90 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 103: ...Web Examples 103 15 Access Control Lists ACLs Figure 57 Attach IP ACL to an Interface ...
Страница 110: ...110 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 123: ...Web Examples 123 18 Port Security Figure 70 Port Security Violation Status ...
Страница 124: ...124 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 129: ...RADIUS Configuration Examples 129 19 RADIUS Figure 73 Configuring the RADIUS Server ...
Страница 137: ...TACACS Configuration Example 137 20 TACACS Figure 82 Set the User Login TACACS ...
Страница 138: ...138 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 146: ...146 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 166: ...166 2001 2011 D Link Corporation All Rights Reserved Configuration Guide Figure 109 DHCP Filter Binding Information ...
Страница 176: ...176 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 183: ...Web Interface Examples 183 28 Simple Network Time Protocol SNTP Figure 115 Summer Time Configuration Page ...
Страница 184: ...184 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...