![Dell PowerConnect M6220 Скачать руководство пользователя страница 527](http://html.mh-extra.com/html/dell/powerconnect-m6220/powerconnect-m6220_user-configuration-manual_84547527.webp)
Configuring Access Control Lists
527
A named time range can contain up to 10 configured time ranges. Only one
absolute time range can be configured per time range. During the ACL
configuration, you can associate a configured time range with the ACL to
provide additional control over permitting or denying a user access to network
resources.
Benefits of using time-based ACLs include:
• Providing more control over permitting or denying a user access to
resources, such as an application (identified by an IP address/mask pair and
a port number).
• Providing control of logging messages. Individual ACL rules defined within
an ACL can be set to log traffic only at certain times of the day so you can
simply deny access without needing to analyze many logs generated during
peak hours.
What Are the ACL Limitations?
The following limitations apply to ingress and egress ACLs.
• Maximum of 100 ACLs.
• Maximum rules per ACL is a maximum of 1023 rules, with 1023 ingress
and 511 egress IPv4 rules or 509 ingress and 253 egress IPv6 rules.
• You can configure mirror or redirect attributes for a given ACL rule, but
not both.
• The PowerConnect M6220, M6348, M8024, and M8024-k switches
support a limited number of counter resources, so it may not be possible to
log every ACL rule. You can define an ACL with any number of logging
rules, but the number of rules that are actually logged cannot be
determined until the ACL is applied to an interface. Furthermore,
hardware counters that become available after an ACL is applied are not
retroactively assigned to rules that were unable to be logged (the ACL
must be un-applied then re-applied). Rules that are unable to be logged are
still active in the ACL for purposes of permitting or denying a matching
packet. If console logging is enabled and the severity is set to Info (6) or a
lower severity, a log entry may appear on the screen.
• The order of the rules is important: when a packet matches multiple rules,
the first rule takes precedence. Also, once you define an ACL for a given
port, all traffic not specifically permitted by the ACL is denied access.
Содержание PowerConnect M6220
Страница 52: ...52 Introduction ...
Страница 86: ...86 Switch Features ...
Страница 100: ...100 Hardware Overview ...
Страница 116: ...116 Using the Command Line Interface ...
Страница 121: ...Default Settings 121 ...
Страница 122: ...122 Default Settings ...
Страница 142: ...142 Setting Basic Network Information ...
Страница 206: ...206 Configuring Authentication Authorization and Accounting ...
Страница 292: ...292 Managing General System Settings Figure 11 31 Verify MOTD ...
Страница 296: ...296 Managing General System Settings ...
Страница 332: ...332 Configuring SNMP ...
Страница 408: ...408 Monitoring Switch Traffic ...
Страница 560: ...560 Configuring Access Control Lists ...
Страница 582: ...582 Configuring VLANs Figure 21 6 Add Ports to VLAN 4 Click Apply 5 Verify that the ports have been added to the VLAN ...
Страница 591: ...Configuring VLANs 591 Figure 21 17 GVRP Port Parameters Table ...
Страница 597: ...Configuring VLANs 597 Figure 21 24 Double VLAN Port Parameter Table ...
Страница 693: ...Configuring Port Based Traffic Control 693 Figure 24 3 Storm Control 5 Click Apply ...
Страница 780: ...780 Configuring Connectivity Fault Management ...
Страница 804: ...804 Snooping and Inspecting Traffic Figure 27 17 DAI Interface Configuration Summary ...
Страница 818: ...818 Snooping and Inspecting Traffic ...
Страница 836: ...836 Configuring Link Aggregation ...
Страница 860: ...860 Configuring Data Center Bridging Features ...
Страница 906: ...906 Configuring DHCP Server Settings ...
Страница 940: ...940 Configuring L2 and L3 Relay Features Figure 34 3 DHCP Relay Interface Summary ...
Страница 1080: ...1080 Configuring VRRP ...
Страница 1104: ...1104 Configuring IPv6 Routing ...
Страница 1124: ...1124 Configuring DHCPv6 Server and Relay Settings Relay Interface Number Vl100 Relay Remote ID Option Flags ...
Страница 1131: ...Configuring Differentiated Services 1131 Figure 40 5 DiffServ Class Criteria ...
Страница 1158: ...1158 Configuring Class of Service Figure 41 1 Mapping Table Configuration CoS 802 1P ...
Страница 1174: ...1174 Configuring Auto VoIP Figure 42 2 Auto VoIP Interface Configuration ...
Страница 1240: ...1240 Managing IPv4 and IPv6 Multicast Figure 43 51 DVMRP Next Hop Summary ...
Страница 1266: ...1266 Managing IPv4 and IPv6 Multicast ...
Страница 1274: ...1274 System Process Definitions ...
Страница 1294: ...1294 Index ...