ExtremeXOS ScreenPlay User Guide
ExtremeXOS ScreenPlay User Guide
27
Dynamic ACL Procedures
Following are common procedures for using Dynamic ACL functions.
Creating ACLs
To create an ACL:
1
Click the Create command button to display a new ACL template in the Create
Dynamic ACL pane.
2 Replace <ACLrulename> with a name.
3 In the template, click in <match-conditions> and then click one of the March
Conditions listed in the Help pane. The selection is inserted into the template.
4 Repeat for the other elements as necessary.
5 Click the Save ACL button. The new ACL is saved and added to the ACLs on
device pane.
Applying ACLs to Interfaces
To apply an ACL to an interface:
1
In the ACLs on device pane, click the ACL to be applied. The Bind ACL
command button is enabled.
2 Click the Bind ACL command button. The Apply <ACL name> on interface pane
is displayed.
3 Click one of the three interface radio buttons (Any, Ports or Vlans). The
appropriate fields for the particular interface are displayed and enabled. (See
Figure 18
below)
Clicking Any disables the other controls in the pane.
Clicking Ports displays a list of all ports on the device. You can choose one or
more ports.
Clicking Vlans displays a text box. Enter a VLAN name in the box.
If there are other ACLs applied to the chosen interface, you can apply the new
ACL as either the “first” or “last” ACL or position it before or after an ACL that
is already applied to the interface. If the ACL is already applied to the chosen
port or VLAN, all controls are disabled.
4 Make the selections and Save. The ACL is applied to the interface(s) and the
details are displayed in the Interfaces applied to pane. Point to the ACL to
display a tooltip showing the interface status.
Removing ACLs
First unbind the ACL from the interface, if appropriate, then remove it from the
device.
1
In the ACLs on device pane, click the ACL to be removed. The interface details
in the Interfaces applied to pane and displayed. Enable the Unbind ACL
command button by clicking the interface details row.
You can choose multiple ports to unbind at the same time but only one VLAN.