![Dell PowerConnect 8024 Скачать руководство пользователя страница 517](http://html.mh-extra.com/html/dell/powerconnect-8024/powerconnect-8024_user-configuration-manual_84530517.webp)
Configuring Access Control Lists
517
A named time range can contain up to 10 configured time ranges. Only one
absolute time range can be configured per time range. During the ACL
configuration, you can associate a configured time range with the ACL to
provide additional control over permitting or denying a user access to network
resources.
Benefits of using time-based ACLs include:
• Providing more control over permitting or denying a user access to
resources, such as an application (identified by an IP address/mask pair and
a port number).
• Providing control of logging messages. Individual ACL rules defined within
an ACL can be set to log traffic only at certain times of the day so you can
simply deny access without needing to analyze many logs generated during
peak hours.
What Are the ACL Limitations?
The following limitations apply to ingress and egress ACLs.
• Maximum of 100 ACLs.
• Maximum rules per ACL is a maximum of 1023 rules, with 1023 ingress
and 511 egress IPv4 rules or 509 ingress and 253 egress IPv6 rules.
• You can configure mirror or redirect attributes for a given ACL rule, but
not both.
• The PowerConnect 8000/8100-series switches support a limited number
of counter resources, so it may not be possible to log every ACL rule. You
can define an ACL with any number of logging rules, but the number of
rules that are actually logged cannot be determined until the ACL is
applied to an interface. Furthermore, hardware counters that become
available after an ACL is applied are not retroactively assigned to rules that
were unable to be logged (the ACL must be un-applied then re-applied).
Rules that are unable to be logged are still active in the ACL for purposes
of permitting or denying a matching packet. If console logging is enabled
and the severity is set to Info (6) or a lower severity, a log entry may appear
on the screen.
• The order of the rules is important: when a packet matches multiple rules,
the first rule takes precedence. Also, once you define an ACL for a given
port, all traffic not specifically permitted by the ACL is denied access.
Содержание PowerConnect 8024
Страница 48: ...48 Contents ...
Страница 52: ...52 Introduction ...
Страница 86: ...86 Switch Features ...
Страница 140: ...140 Setting Basic Network Information ...
Страница 178: ...178 Managing a Switch Stack ...
Страница 204: ...204 Configuring Authentication Authorization and Accounting ...
Страница 272: ...272 Managing General System Settings ...
Страница 308: ...308 Configuring SNMP ...
Страница 336: ...336 Managing Images and Files ...
Страница 354: ...354 Auto Image and Configuration Update ...
Страница 385: ...Monitoring Switch Traffic 385 Figure 16 26 Configure Additional Port Mirroring Settings 9 Click Apply ...
Страница 468: ...468 Configuring Port Characteristics ...
Страница 509: ...Configuring Port and System Security 509 Figure 20 12 Configure Port Security Settings 5 Click Apply ...
Страница 512: ...512 Configuring Port and System Security ...
Страница 550: ...550 Configuring Access Control Lists ...
Страница 571: ...Configuring VLANs 571 Figure 22 6 Add Ports to VLAN 4 Click Apply 5 Verify that the ports have been added to the VLAN ...
Страница 580: ...580 Configuring VLANs Figure 22 17 GVRP Port Parameters Table ...
Страница 586: ...586 Configuring VLANs Figure 22 24 Double VLAN Port Parameter Table ...
Страница 618: ...618 Configuring VLANs ...
Страница 631: ...Configuring the Spanning Tree Protocol 631 Figure 23 5 Spanning Tree Global Settings ...
Страница 637: ...Configuring the Spanning Tree Protocol 637 Figure 23 11 RSTP LAG Settings ...
Страница 685: ...Configuring Port Based Traffic Control 685 Figure 25 3 Storm Control 5 Click Apply ...
Страница 776: ...776 Snooping and Inspecting Traffic Figure 27 17 DAI Interface Configuration Summary ...
Страница 790: ...790 Snooping and Inspecting Traffic ...
Страница 797: ...Configuring Link Aggregation 797 To view or edit settings for multiple LAGs click Show All ...
Страница 894: ...894 Configuring DHCP Server Settings ...
Страница 928: ...928 Configuring L2 and L3 Relay Features Figure 34 3 DHCP Relay Interface Summary ...
Страница 955: ...Configuring OSPF and OSPFv3 955 Figure 35 1 OSPF Configuration ...
Страница 1030: ...1030 Configuring OSPF and OSPFv3 ...
Страница 1068: ...1068 Configuring VRRP ...
Страница 1092: ...1092 Configuring IPv6 Routing ...
Страница 1112: ...1112 Configuring DHCPv6 Server and Relay Settings Relay Interface Number Vl100 Relay Remote ID Option Flags ...
Страница 1119: ...Configuring Differentiated Services 1119 Figure 40 5 DiffServ Class Criteria ...
Страница 1126: ...1126 Configuring Differentiated Services Figure 40 14 DiffServ Service Summary ...
Страница 1142: ...1142 Configuring Differentiated Services ...
Страница 1148: ...1148 Configuring Class of Service Figure 41 1 Mapping Table Configuration CoS 802 1P ...
Страница 1160: ...1160 Configuring Class of Service ...
Страница 1164: ...1164 Configuring Auto VoIP Figure 42 2 Auto VoIP Interface Configuration ...
Страница 1230: ...1230 Managing IPv4 and IPv6 Multicast Figure 43 51 DVMRP Next Hop Summary ...
Страница 1256: ...1256 Managing IPv4 and IPv6 Multicast ...
Страница 1266: ...1266 Feature Limitations and Platform Constants ...
Страница 1274: ...1274 System Process Definitions ...
Страница 1294: ...Index 1294 ...