![Dell PowerConnect 8024 Скачать руководство пользователя страница 518](http://html.mh-extra.com/html/dell/powerconnect-8024/powerconnect-8024_user-configuration-manual_84530518.webp)
518
Configuring Access Control Lists
How Are ACLs Configured?
To configure ACLs, follow these steps:
1
Create a MAC ACL by specifying a name.
2
Create an IP ACL by specifying a number.
3
Add new rules to the ACL.
4
Configure the match criteria for the rules.
5
Apply the ACL to one or more interfaces.
Preventing False ACL Matches
Be sure to specify ACL access-list, permit, and deny rule criteria as fully as
possible to avoid false matches. This is especially important in networks with
protocols such as FCoE that have newly-introduced EtherType values. For
example, rules that specify a TCP or UDP port value should also specify the
TCP or UDP protocol and the IPv4 or IPv6 EtherType. Rules that specify an
IP protocol should also specify the EtherType value for the frame.
In general, any rule that specifies matching on an upper-layer protocol field
should also include matching constraints for each of the lower-layer protocols.
For example, a rule to match packets directed to the well-known UDP port
number 22 (SSH) should also include matching constraints on the IP
protocol field (protocol=0x11 or UDP) and the EtherType field (EtherType=
0x0800 or IPv4). Figure 21-1 lists commonly-used EtherTypes numbers:
NOTE:
The actual number of ACLs and rules supported depends on the
resources consumed by other processes and configured features running on the
switch.
Table 21-1. Common EtherType Numbers
EtherType
Protocol
0x0800
Internet Protocol version 4 (IPv4)
0x0806
Address Resolution Protocol (ARP)
0x0842
Wake-on LAN Packet
0x8035
Reverse Address Resolution Protocol (RARP)
0x8100
VLAN tagged frame (IEEE 802.1Q)
Содержание PowerConnect 8024
Страница 48: ...48 Contents ...
Страница 52: ...52 Introduction ...
Страница 86: ...86 Switch Features ...
Страница 140: ...140 Setting Basic Network Information ...
Страница 178: ...178 Managing a Switch Stack ...
Страница 204: ...204 Configuring Authentication Authorization and Accounting ...
Страница 272: ...272 Managing General System Settings ...
Страница 308: ...308 Configuring SNMP ...
Страница 336: ...336 Managing Images and Files ...
Страница 354: ...354 Auto Image and Configuration Update ...
Страница 385: ...Monitoring Switch Traffic 385 Figure 16 26 Configure Additional Port Mirroring Settings 9 Click Apply ...
Страница 468: ...468 Configuring Port Characteristics ...
Страница 509: ...Configuring Port and System Security 509 Figure 20 12 Configure Port Security Settings 5 Click Apply ...
Страница 512: ...512 Configuring Port and System Security ...
Страница 550: ...550 Configuring Access Control Lists ...
Страница 571: ...Configuring VLANs 571 Figure 22 6 Add Ports to VLAN 4 Click Apply 5 Verify that the ports have been added to the VLAN ...
Страница 580: ...580 Configuring VLANs Figure 22 17 GVRP Port Parameters Table ...
Страница 586: ...586 Configuring VLANs Figure 22 24 Double VLAN Port Parameter Table ...
Страница 618: ...618 Configuring VLANs ...
Страница 631: ...Configuring the Spanning Tree Protocol 631 Figure 23 5 Spanning Tree Global Settings ...
Страница 637: ...Configuring the Spanning Tree Protocol 637 Figure 23 11 RSTP LAG Settings ...
Страница 685: ...Configuring Port Based Traffic Control 685 Figure 25 3 Storm Control 5 Click Apply ...
Страница 776: ...776 Snooping and Inspecting Traffic Figure 27 17 DAI Interface Configuration Summary ...
Страница 790: ...790 Snooping and Inspecting Traffic ...
Страница 797: ...Configuring Link Aggregation 797 To view or edit settings for multiple LAGs click Show All ...
Страница 894: ...894 Configuring DHCP Server Settings ...
Страница 928: ...928 Configuring L2 and L3 Relay Features Figure 34 3 DHCP Relay Interface Summary ...
Страница 955: ...Configuring OSPF and OSPFv3 955 Figure 35 1 OSPF Configuration ...
Страница 1030: ...1030 Configuring OSPF and OSPFv3 ...
Страница 1068: ...1068 Configuring VRRP ...
Страница 1092: ...1092 Configuring IPv6 Routing ...
Страница 1112: ...1112 Configuring DHCPv6 Server and Relay Settings Relay Interface Number Vl100 Relay Remote ID Option Flags ...
Страница 1119: ...Configuring Differentiated Services 1119 Figure 40 5 DiffServ Class Criteria ...
Страница 1126: ...1126 Configuring Differentiated Services Figure 40 14 DiffServ Service Summary ...
Страница 1142: ...1142 Configuring Differentiated Services ...
Страница 1148: ...1148 Configuring Class of Service Figure 41 1 Mapping Table Configuration CoS 802 1P ...
Страница 1160: ...1160 Configuring Class of Service ...
Страница 1164: ...1164 Configuring Auto VoIP Figure 42 2 Auto VoIP Interface Configuration ...
Страница 1230: ...1230 Managing IPv4 and IPv6 Multicast Figure 43 51 DVMRP Next Hop Summary ...
Страница 1256: ...1256 Managing IPv4 and IPv6 Multicast ...
Страница 1266: ...1266 Feature Limitations and Platform Constants ...
Страница 1274: ...1274 System Process Definitions ...
Страница 1294: ...Index 1294 ...