IPv4 Access Control Lists (ACLs)
Terminology
Terminology
Access Control Entry (ACE):
A policy consisting of criteria and an action
(permit or deny) to execute on a packet if it meets the criteria. The
elements composing the criteria include:
•
source IPv4 address and mask (standard and extended ACLs)
•
destination IPv4 address and mask (extended ACLs only)
•
either of the following:
–
all IPv4 traffic
–
IPv4 traffic of a specific IP protocol (extended ACLs only)
(In the cases of TCP, UDP, ICMP, and IGMP, the criteria can
include either all IP traffic of the protocol type or only the traffic
of a specific sub-type within the protocol.)
•
option to log packet matches with
deny
ACEs
•
optional use of IP precedence and ToS settings (extended ACLs only)
Access Control List (ACL):
A list (or set) consisting of one or more
explicitly configured Access Control Entries (ACEs) and terminating with
an implicit “deny” ACE. ACL types include “standard” and “extended”. See
also “Standard ACL” and “Extended ACL”. To filter IPv4 traffic, apply
either type:
•
Static Port ACL: an ACL assigned to filter inbound traffic on a specific
switch port
•
Dynamic Port ACL: dynamic ACL assigned to a port by a RADIUS
server to filter inbound traffic from an authenticated client on that
port
An ACL can be configured on a port (or static trunk) as a static port ACL.
(Dynamic port ACLs are configured on a RADIUS server.)
ACE:
See “Access Control Entry”.
ACL:
See “Access Control List”.
ACL ID:
A number or alphanumeric string used to identify an ACL. A
standard
IPv4 ACL ID can have either an alphanumeric string or a number in the
range of 1 to 99. An
extended
IPv4 ACL ID can have either an alphanumeric
string or a number in the range of 100 to 199. See also “Identifier”.
Note:
RADIUS-assigned ACLs are identified by client authentication data
and do not use the ACL ID strings described here.
9-10
Содержание PROCURVE 2910AL
Страница 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Страница 2: ......
Страница 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Страница 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Страница 156: ...TACACS Authentication Operating Notes 4 30 ...
Страница 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Страница 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Страница 516: ...Configuring Port Based and User Based Access Control 802 1X Messages Related to 802 1X Operation 12 76 ...
Страница 527: ...Configuring and Monitoring Port Security Port Security Figure 13 4 Examples of Show Mac Address Outputs 13 11 ...
Страница 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Страница 592: ...12 Index ...
Страница 593: ......
Страница 594: ... Copyright 2009 Hewlett Packard Development Company L P February 2009 Manual Part Number 5992 5439 ...