Page 140
Configuring Access Control Lists
Adding a Rule to an Extended MAC ACL
To add a rule to an Extended MAC ACL:
1.
From the ACL identifier list, select the ID of the extended MAC ACL. The ID is up to 31 alphanu-
meric characters.
2.
Click
Add Rule
.
The Add MAC ACL Rule page appears.
Service Type
The service type to match in the IP header. The options in this menu are alternative ways of
specifying a match condition for the same Service Type field in the IP header, but each
service type uses a different user notation. After you select the service type, specify the value
for the service type in the appropriate field. Only the field associated with the selected service
type can be configured. The services types are as follows:
IP DSCP – Matches the packet IP DiffServ Code Point (DSCP) value to the rule. The
DSCP value is defined as the high-order six bits of the Service Type octet in the IP
header.
IP Precedence – Matches the IP Precedence value to the rule. The IP Precedence field
in a packet is defined as the high-order three bits of the Service Type octet in the IP
header.
IP TOS Bits – Matches on the Type of Service (TOS) bits in the IP header. The IP TOS
field in a packet is defined as all eight bits of the Service Type octet in the IP header. For
example, to check for an IP TOS value having bits 7 and 5 set and bit 1 clear, where bit
7 is most significant, use a TOS Bits value of 0xA0 and a TOS Mask of 0xFF.
TOS Bits – Requires the bits in a packet's TOS field to match the two-digit hexadeci-
mal number entered in this field.
TOS Mask – The bit positions that are used for comparison against the IP TOS field in
a packet.
Rule Attributes
Assign Queue
The number that identifies the hardware egress queue that will handle all packets matching
this rule.
Interface
The interface to use for the action:
Redirect – Allows traffic that matches a rule to be redirected to the selected interface
instead of being processed on the original port. The redirect function and mirror function
are mutually exclusive.
Mirror – Provides the ability to mirror traffic that matches a rule to the selected interface.
Mirroring is similar to the redirect function, except that in flow-based mirroring a copy of
the permitted traffic is delivered to the mirror interface while the packet itself is forwarded
normally through the device.
Committed Rate / Burst
Size
The allowed transmission rate for frames on the interface (Committed Rate), and the number
of bytes allowed in a temporary traffic burst (Burst Rate).
Field
Description