© Copyright Lenovo 2017
Chapter 7: Access Control Lists
125
ACL Groups
To
assist
in
organizing
multiple
ACLs
and
assigning
them
to
ports,
you
can
place
ACLs
into
ACL
Groups,
thereby
defining
complex
traffic
profiles.
ACLs
and
ACL
Groups
can
then
be
assigned
on
a
per
‐
port
basis.
Any
specific
ACL
can
be
assigned
to
multiple
ACL
Groups,
and
any
ACL
or
ACL
Group
can
be
assigned
to
multiple
ports.
If,
as
part
of
multiple
ACL
Groups,
a
specific
ACL
is
assigned
to
a
port
multiple
times,
only
one
instance
is
used.
The
redundant
entries
are
ignored.
Individual
ACLs
The
CN4093
supports
up
to
256
ACLs.
Each
ACL
defines
one
filter
rule
for
matching
traffic
criteria.
Each
filter
rule
can
also
include
an
action
(permit
or
deny
the
packet).
For
example:
Access
Control
List
Groups
An
Access
Control
List
Group
(ACL
Group)
is
a
collection
of
ACLs.
For
example:
ACL
Groups
organize
ACLs
into
traffic
profiles
that
can
be
more
easily
assigned
to
ports.
The
CN4093
supports
up
to
256
ACL
Groups.
Note:
ACL
Groups
are
used
for
convenience
in
assigning
multiple
ACLs
to
ports.
ACL
Groups
have
no
effect
on
the
order
in
which
ACLs
are
applied
(see
).
All
ACLs
assigned
to
the
port
(whether
individually
assigned
or
part
of
an
ACL
Group)
are
considered
as
individual
ACLs
for
the
purposes
of
determining
their
order
of
precedence.
Assigning ACL Groups to a Port
To
assign
an
ACL
Group
to
a
port,
use
the
following
commands:
ACL
1:
VLAN
=
1
SIP
=
10.10.10.1
(255.255.255.0)
Action
=
permit
ACL Group 1
ACL
1:
VLAN
=
1
SIP
=
10.10.10.1
(255.255.255.0)
Action
=
permit
ACL
2:
VLAN
=
2
SIP
=
10.10.10.2
(255.255.255.0)
Action
=
deny
ACL
3:
Priority
=
7
DIP
=
10.10.10.3
(255.255.255.0)
Action
=
permit
CN 4093(config)#
interface port
<port
number>
CN 4093(config-if)#
access-control group
<ACL
group
number>
CN 4093(config-if)#
exit
Содержание Flex System Fabric CN4093
Страница 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Страница 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Страница 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Страница 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Страница 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Страница 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Страница 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Страница 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Страница 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Страница 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Страница 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Страница 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Страница 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Страница 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Страница 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Страница 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Страница 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Страница 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Страница 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Страница 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Страница 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Страница 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Страница 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Страница 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Страница 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Страница 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Страница 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Страница 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Страница 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Страница 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Страница 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Страница 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Страница 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Страница 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Страница 633: ......
Страница 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...