
386
APPENDIX B : GLOSSARY
A
ACE
ACE is an acronym for
A
ccess
C
ontrol
E
ntry. It describes access permission associated with a particular ACE ID.
There are three ACE frame types (Ethernet Type, ARP, and IPv4) and two ACE actions (permit and deny). The ACE also
contains many detailed, different parameter options that are available for individual application.
ACL
ACL is an acronym for
A
ccess
C
ontrol
L
ist. It is the list table of ACEs, containing access control entries that specify
individual users or groups permitted or denied to specific traffic objects, such as a process or a program.
Each accessible traffic object contains an identifier to its ACL. The privileges determine whether there are specific traffic
object access rights.
ACL implementations can be quite complex, for example, when the ACEs are prioritized for the various situation. In
networking, the ACL refers to a list of service ports or network services that are available on a host or server, each with a
list of hosts or servers permitted or denied to use the service. ACL can generally be configured to control inbound traffic,
and in this context, they are similar to firewalls.
There are 3 web-Pages associated with the manual ACL configuration:
ACL|Access Control List
: The web Page shows the ACEs in a prioritized way, highest (top) to lowest (bottom). Default
the table is empty. An ingress frame will only get a hit on one ACE even though there are more matching ACEs. The first
matching ACE will take action (permit/deny) on that frame and a counter associated with that ACE is incremented. An ACE
can be associated with a Policy, 1 ingress port, or any ingress port (the whole switch). If an ACE Policy is created then that
Policy can be associated with a group of ports under the "Ports" web-Page. There are number of parameters that can be
configured with an ACE. Read the Web Page help text to get further information for each of them. The maximum number of
ACEs is 64.
ACL|Ports
: The ACL Ports configuration is used to assign a Policy ID to an ingress port. This is useful to group ports to
obey the same traffic rules. Traffic Policy is created under the "Access Control List" - Page. You can you also set up
specific traffic properties (Action / Rate Limiter / Port copy, etc) for each ingress port. They will though only apply if the
frame gets past the ACE matching without getting matched. In that case a counter associated with that port is incremented.
Содержание NS3702-24P-4S
Страница 1: ...NS3702 24P 4S User Manual P N 1072832 REV 00 01 ISS 14JUL14 ...
Страница 65: ...65 Buttons Click to apply changes Click to undo any changes made locally and revert to previously saved values ...
Страница 102: ...102 Figure 4 5 4 LACP Port Configuration Page Screenshot ...
Страница 119: ...119 Figure 4 6 4 VLAN Membership Status for Static User Page Screenshot ...
Страница 124: ...124 Figure 4 6 6 Private VLAN Membership Configuration page screenshot ...
Страница 135: ...135 VLAN 3 Port 3 Port 6 The screen in Figure 4 6 18 appears Figure 4 6 17 Private VLAN Port Setting ...
Страница 140: ...140 Figure 4 6 21 Group Name to VLAN Mapping Table Page Screenshot ...
Страница 164: ...164 Figure 4 8 2 Multicast Flooding ...
Страница 184: ...184 Figure 4 8 15 MLD Snooping Port Group Filtering Configuration Page Screenshot ...
Страница 204: ...204 Figure 4 9 6 QoS Egress Port Tag Remarking Page Screenshot ...
Страница 209: ...209 QoS Class QoS Class value can be any of 0 7 DPL Drop Precedence Level 0 1 ...
Страница 251: ...251 Figure 4 11 3 Authentication Method Configuration Page Screenshot ...
Страница 286: ...286 Figure 4 11 11 RADIUS Server Configuration Screenshot ...
Страница 290: ...290 Figure 4 11 17 Add User Properties Screen Figure 4 11 18 Add User Properties Screen ...
Страница 298: ...298 non committed changes will be lost ...
Страница 349: ...349 Figure 4 16 2 PoE Configuration Screenshot ...
Страница 355: ...355 Figure 4 16 5 PoE Status Screenshot ...