![H3C S5120-SI Series Скачать руководство пользователя страница 495](http://html2.mh-extra.com/html/h3c/s5120-si-series/s5120-si-series_operation-manual_3711174495.webp)
1-1
1
ACL Overview
An access control list (ACL) is a set of rules (that is, a set of permit or deny statements) for identifying
traffic based on matching criteria such as source address, destination address, and port number. The
selected traffic will then be permitted or rejected by predefined security policies.
ACLs are widely used in technologies where traffic identification is desired, such as packet filtering and
QoS.
Introduction to ACL
This section covers these topics:
z
ACL Classification
z
ACL Naming
z
ACL Match Order
z
ACL Step
z
Effective Period of an ACL
z
IP Fragments Filtering with ACL
ACL Classification
ACLs, identified by ACL numbers, fall into three categories, as shown in
Table 1-1
.
Table 1-1
ACL categories
Category
ACL number
Matching criteria
Basic ACL
2000 to 2999
Source IP address
Advanced ACL
3000 to 3999
Source IP address, destination
IP address, protocol carried
over IP, and other Layer 3 or
Layer 4 protocol header
information
Ethernet frame header ACL
4000 to 4999
Layer 2 protocol header fields
such as source MAC address,
destination MAC address,
802.1p priority, and link layer
protocol type
ACL Naming
When creating an ACL, you can specify a unique name for it. Afterwards, you can identify the ACL by its
name.
Содержание S5120-SI Series
Страница 61: ...7 8 Sysname ip http acl 2030...
Страница 138: ...2 10 PORT VLAN MODE GigabitEthernet1 0 1 2 MANUAL...
Страница 186: ...1 46 Instance Vlans Mapped 0 1 to 9 11 to 19 21 to 29 31 to 4094 1 10 2 20 3 30...
Страница 218: ...ii Displaying and Maintaining BOOTP Client Configuration 4 2 BOOTP Client Configuration Example 4 3...
Страница 255: ...1 12...
Страница 381: ...ii Troubleshooting RADIUS 1 32...
Страница 577: ...1 8 Return to the upper directory Sysname cd Display the current working directory Sysname pwd flash...