82
RackSwitch G8000: Application Guide
Assigning Individual ACLs to a Port
Once you configure an ACL, you must assign the ACL to the appropriate ports.
Each port can accept multiple ACLs, and each ACL can be applied for multiple
ports. ACLs can be assigned individually, or in groups.
To assign an individual ACLs to a port, use the following IP Interface Mode
commands:
When multiple ACLs are assigned to a port, higher-priority ACLs are considered
first, and their action takes precedence over lower-priority ACLs. ACL order of
precedence is discussed in the next section.
Note:
When IPv6 ACLs are applied to a port, some IPv4 ACLs are restricted from
being applied to the same port. Only IPv4 ACLs 1 through 256 may be
applied to ports that also use IPv6 ACLs.
To create and assign ACLs in groups, see
.
ACL Order of Precedence
When multiple ACLs are assigned to a port, the order in which the ACLs are applied
to port traffic (or whether they are applied at all) depends on the following factors:
•
The precedence group in which the ACL resides;
•
The ACL number;
•
Whether a prior ACL in the precedence group is also matched;
•
And whether the ACL action is compatible with preceding ACLs.
ACLs are automatically divided into precedence groups as follows:
Precedence Group 1 includes ACL 1—128.
Precedence Group 2 includes ACL 129—256.
Precedence Group 3 includes ACL 257—384.
Precedence Group 4 includes ACL 385—512.
The switch processes each precedence group in numeric sequence; Precedence
group 1 is evaluated first, followed by precedence group 2, and so on.
Within each precedence group, ACLs assigned to the port are processed in numeric
sequence, based on ACL number. Lower-numbered ACLs take precedence over
higher-numbered ACLs. For example, ACL 1 (if assigned to the port) is evaluated first
and has top priority within precedence group 1.
For each precedence group, only the first assigned ACL that matches the port traffic
is considered. If multiple ACLs in the precedence group match the traffic, only the
one with the lowest ACL number is considered. The others in the precedence group
are ignored.
One ACL match from each precedence group is permitted, meaning that up to four
ACL matches may be considered for action: one from precedence group 1, one from
precedence group 2, and so on.
RS G8000(config)#
interface port
<port>
RS G8000(config-ip)#
access-control list
<IPv4 ACL number>
RS G8000(config-ip)#
access-control list6
<IPv6 ACL number>
Содержание RackSwitch G8000
Страница 1: ...RackSwitch G8000 Application Guide...
Страница 2: ......
Страница 3: ...RackSwitch G8000 Application Guide...
Страница 16: ...16 RackSwitch G8000 Application Guide...
Страница 22: ...20 RackSwitch G8000 Application Guide...
Страница 23: ...Copyright IBM Corp 2011 21 Part 1 Getting Started...
Страница 24: ...22 RackSwitch G8000 Application Guide...
Страница 54: ...52 RackSwitch G8000 Application Guide...
Страница 55: ...Copyright IBM Corp 2011 53 Part 2 Securing the Switch...
Страница 56: ...54 RackSwitch G8000 Application Guide...
Страница 92: ...90 RackSwitch G8000 Application Guide...
Страница 94: ...92 RackSwitch G8000 Application Guide...
Страница 144: ...142 RackSwitch G8000 Application Guide...
Страница 145: ...Copyright IBM Corp 2011 143 Part 4 Advanced Switch ing Features...
Страница 146: ...144 RackSwitch G8000 Application Guide...
Страница 148: ...146 RackSwitch G8000 Application Guide...
Страница 182: ...180 RackSwitch G8000 Application Guide...
Страница 184: ...182 RackSwitch G8000 Application Guide...
Страница 212: ...210 RackSwitch G8000 Application Guide...
Страница 258: ...256 RackSwitch G8000 Application Guide...
Страница 286: ...284 RackSwitch G8000 Application Guide...
Страница 294: ...292 RackSwitch G8000 Application Guide...
Страница 298: ...296 RackSwitch G8000 Application Guide...
Страница 310: ...308 RackSwitch G8000 Application Guide...
Страница 311: ...Copyright IBM Corp 2011 309 Part 7 Network Management...
Страница 312: ...310 RackSwitch G8000 Application Guide...
Страница 320: ...318 RackSwitch G8000 Application Guide...
Страница 332: ...330 RackSwitch G8000 Application Guide...
Страница 334: ...332 RackSwitch G8000 Application Guide...
Страница 345: ...Copyright IBM Corp 2011 343 Part 9 Appendices...
Страница 346: ...344 RackSwitch G8000 Application Guide...
Страница 357: ...Copyright IBM Corp 2011 Appendix C Notices 355 Taiwan Class A compliance statement...
Страница 358: ...356 RackSwitch G8000 Application Guide...