1-3
A wildcard mask is in dotted decimal notation. Its binary value 0 means "match" and binary value 1
means "do not care", which contrast with the meanings of the values of a subnet mask. For example, a
wildcard mask of 0.0.0.255 corresponds to a subnet mask of 255.255.255.0.
Depth-first match for an advanced IPv4 ACL
The following shows how your device performs depth-first match in an advanced IPv4 ACL:
1) Sort rules by the protocol carried over IP. A rule with no limit to the protocol type (that is, configured
with the
ip
keyword) has the lowest precedence. Rules each of which has a single specified
protocol type are of the same precedence level.
2) If the protocol types have the same precedence, look at the source IP address wildcard masks.
Then, compare packets against the rule configured with more zeros in the source IP address
wildcard mask.
3) If the numbers of zeros in the source IP address wildcard masks are the same, look at the
destination IP address wildcard masks. Then, compare packets against the rule configured with
more zeros in the destination IP address wildcard mask.
4) If the numbers of zeros in the destination IP address wildcard masks are the same, look at the
Layer 4 port number ranges, namely the TCP/UDP port number ranges. Then compare packets
against the rule configured with the smaller port number range.
5) If the port number ranges are the same, compare packets against the rule configured first.
Depth-first match for an Ethernet frame header ACL
The following shows how your device performs depth-first match in an Ethernet frame header ACL:
1) Sort rules by source MAC address mask first and compare packets against the rule configured with
more ones in the source MAC address mask.
2) If two rules are present with the same number of ones in their source MAC address masks, look at
the destination MAC address masks. Then, compare packets against the rule configured with
more ones in the destination MAC address mask.
3) If the numbers of ones in the destination MAC address masks are the same, compare packets
against the one configured first.
The comparison of a packet against ACL rules stops immediately after a match is found. The packet is
then processed as per the rule.
IPv4 ACL Step
Meaning of the step
The step defines the difference between two neighboring numbers that are automatically assigned to
ACL rules by the device. For example, with a step of 5, rules are automatically numbered 0, 5, 10, 15,
and so on. By default, the step is 5.
Содержание S5810 Series
Страница 307: ...ii Configured Multicast Group Policy Fails to Take Effect 1 32...
Страница 648: ...1 8 Return to the upper directory Sysname cd Display the current working directory Sysname pwd flash...
Страница 812: ...1 7 Role Slave Sysname stack_3 DeviceD Device type S5810 50S MAC address 000f e200 1003...