ACL Commands
243
5
ACL Commands
Access to a switch or router can be made more secure through the use of
Access Control Lists (ACLs) to control the type of traffic allowed into or out
of specific ports. An ACL consists of a series of rules, each of which describes
the type of traffic to be processed and the actions to take for packets that
meet the classification criteria. Rules within an ACL are evaluated
sequentially until a match is found, if any. Every ACL is terminated by an
implicit
deny all
rule, which covers any packet not matching a preceding
explicit rule. ACLs can help to ensure that only authorized users have access
to specific resources while blocking out any unwarranted attempts to reach
network resources.
ACLs may be used to restrict contents of routing updates, decide which types
of traffic are forwarded or blocked and, above all, provide security for the
network. ACLs are normally used in firewall routers that are positioned
between the internal network and an external network, such as the Internet.
They can also be used on a router positioned between two parts of the
network to control the traffic entering or exiting a specific part of the internal
network.
The PowerConnect ACL feature allows classification of packets based upon
Layer 2 through Layer 4 header information. An Ethernet IPv6 packet is
distinguished from an IPv4 packet by its unique Ethertype value; thus, all
IPv4 and IPv6 classifiers include the Ethertype field.
Multiple ACLs per interface are supported. The ACLs can be a combination
of Layer 2 and/or Layer 3/4 ACLs. ACL assignment is appropriate for both
physical ports and LAGs. ACLs can also be time based.
ACL Logging
Access list rules are monitored in hardware to either permit or deny traffic
matching a particular classification pattern, but the network administrator
currently has no insight as to which rules are being
hit
. Some hardware
platforms have the ability to count the number of hits for a particular
2CSPC4.XModular-SWUM200.book Page 243 Thursday, March 10, 2011 11:18 AM
Содержание PowerEdge M420
Страница 161: ...Command Groups 161 ...
Страница 162: ...162 Command Groups ...
Страница 216: ...216 Layer 2 Commands ...
Страница 290: ...290 Auto VoIP Commands ...
Страница 310: ...310 Data Center Bridging Commands ...
Страница 316: ...316 DHCP Layer 2 Relay Commands Example console config dhcp l2relay vlan 10 340 345 ...
Страница 324: ...324 DHCP Management Interface Commands ...
Страница 340: ...340 DHCP Snooping Commands ...
Страница 354: ...354 Dynamic ARP Inspection Commands ...
Страница 405: ...Ethernet Configuration Commands 405 Name test ...
Страница 406: ...406 Ethernet Configuration Commands ...
Страница 426: ...426 Ethernet CFM Commands ...
Страница 486: ...486 IPv6 Access List Commands ...
Страница 497: ...IPv6 MLD Snooping Commands 497 Vlan Ipv6 Address Ports ...
Страница 498: ...498 IPv6 MLD Snooping Commands ...
Страница 512: ...512 IP Source Guard Commands ...
Страница 524: ...524 iSCSI Optimization Commands ...
Страница 532: ...532 Link Dependency Commands ...
Страница 572: ...572 Port Aggregator Commands ...
Страница 596: ...596 Port Monitor Commands Session ID Admin Mode Probe Port Mirrored Port Type 1 Enable 1 0 10 1 0 8 Rx Tx ...
Страница 756: ...756 VLAN Commands ...
Страница 762: ...762 Voice VLAN Commands ...
Страница 796: ...796 802 1x Commands ...
Страница 798: ...798 Layer 3 Commands ...
Страница 842: ...842 DHCP Server and Relay Agent Commands ...
Страница 868: ...868 DVMRP Commands ...
Страница 888: ...888 IGMP Commands ...
Страница 896: ...896 IGMP Proxy Commands ...
Страница 938: ...938 IP Routing Commands ...
Страница 1012: ...1012 IPv6 Routing Commands ...
Страница 1016: ...1016 Loopback Interface Commands ...
Страница 1048: ...1048 Multicast Commands ...
Страница 1064: ...1064 IPv6 Multicast Commands RP Address 3001 1 origin BSR ...
Страница 1142: ...1142 OSPF Commands ...
Страница 1202: ...1202 OSPFv3 Commands ...
Страница 1212: ...1212 Router Discovery Protocol Commands ...
Страница 1228: ...1228 Routing Information Protocol Commands ...
Страница 1234: ...1234 Tunnel Interface Commands console config interface tunnel 1 console config if tunnel1 tunnel source vlan 11 ...
Страница 1260: ...1260 Virtual Router Redundancy Protocol Commands ...
Страница 1262: ...1260 Utility Commands ...
Страница 1272: ...1270 Auto Install Commands ...
Страница 1306: ...1304 Captive Portal Commands ...
Страница 1316: ...1314 CLI Macro Commands ...
Страница 1334: ...1332 Clock Commands ...
Страница 1340: ...1338 Command Line Configuration Scripting Commands ...
Страница 1362: ...1360 Configuration and Image File Commands ...
Страница 1363: ...Configuration and Image File Commands 1361 ...
Страница 1364: ...1362 Configuration and Image File Commands ...
Страница 1412: ...1408 Password Management Commands ...
Страница 1436: ...1432 RMON Commands ...
Страница 1476: ...1472 Sflow Commands ...
Страница 1536: ...1532 Syslog Commands ...
Страница 1602: ...1598 Telnet Server Commands ...
Страница 1604: ...1600 Terminal Length Commands ...
Страница 1618: ...1614 User Interface Commands ...
Страница 1638: ...1634 Web Server Commands ...
Страница 1680: ...1676 Appendix A List of Commands ...
Страница 1681: ......
Страница 1682: ...www dell com support dell com Printed in the U S A ...