IP Access Lists (ACLs)
ExtremeWare 7.2e Installation and User Guide
145
forwarded. A permit access list can also apply a QoS profile to the packet and modify the packet’s
802.1p value and the DiffServ code point.
Access Mask Precedence Numbers
The access mask precedence number determines the order in which each rule is examined by the switch
and is optional. Access control list entries are evaluated from highest precedence to lowest precedence.
Precedence numbers range from 1 to 25,600, with the number 1 having the highest precedence, but an access
mask without a precedence specified has a higher precedence than any access mask with a precedence
specified. The first access mask defined without a specified precedence has the highest precedence.
Subsequent masks without a specified precedence have a lower precedence, and so on.
Specifying a Default Rule
You can specify a default access control list to define the default access to the switch. You should use an
access mask with a low precedence for the default rule access control list. If no other access control list
entry is satisfied, the default rule is used to determine whether the packet is forwarded or dropped. If
no default rule is specified, the default behavior is to forward the packet.
NOTE
If your default rule denies traffic, you should not apply this rule to the Summit 400-48t port used as a
management port.
Once the default behavior of the access control list is established, you can create additional entries using
precedence numbers.
The
permit-established
Keyword
The
permit-established
keyword is used to directionally control attempts to open a TCP session.
Session initiation can be explicitly blocked using this keyword.
The permit-established keyword denies the access control list. Having a permit-established access
control list blocks all traffic that matches the TCP source/destination, and has the SYN=1 and ACK=0
flags set.
Adding Access Mask, Access List, and Rate Limit Entries
Entries can be added to the access masks, access lists, and rate limits. To add an entry, you must supply
a unique name using the
create
command, and supply a number of optional parameters. For access
lists and rate limits, you must specify an access mask to use. To modify an existing entry, you must
delete the entry and retype it, or create a new entry with a new unique name.
To add an access mask entry, use the following command:
create access-mask <name> ...
To add an access list entry, use the following command:
create access-list <name> ...
To add a rate limit entry, use the following command:
create rate-limit <name> ...
Содержание ExtremeWare 7.2e
Страница 14: ...14 ExtremeWare 7 2 0 Software User Guide Contents...
Страница 18: ...18 ExtremeWare 7 2e Installation and User Guide Preface...
Страница 46: ...46 ExtremeWare 7 2e Installation and User Guide Summit 400 48t Switch Overview and Installation...
Страница 80: ...80 ExtremeWare 7 2e Installation and User Guide Accessing the Switch...
Страница 102: ...102 ExtremeWare 7 2e Installation and User Guide Virtual LANs VLANs...
Страница 108: ...108 ExtremeWare 7 2e Installation and User Guide Forwarding Database FDB...
Страница 180: ...180 ExtremeWare 7 2e Installation and User Guide Security...
Страница 194: ...194 ExtremeWare 7 2e Installation and User Guide Ethernet Automatic Protection Switching...
Страница 218: ...218 ExtremeWare 7 2e Installation and User Guide Spanning Tree Protocol STP...
Страница 248: ...248 ExtremeWare 7 2e Installation and User Guide Interior Gateway Protocols...
Страница 256: ...256 ExtremeWare 7 2e Installation and User Guide IP Multicast Routing...
Страница 308: ...308 ExtremeWare 7 2e Installation and User Guide Using ExtremeWare Vista on the Summit 400...
Страница 316: ...316 ExtremeWare 7 2e Installation and User Guide Technical Specifications...
Страница 324: ...324 ExtremeWare 7 2e Installation and User Guide Software Upgrade and Boot Options...