87
Table of Contents
Linksys
Table of Contents
Linksys
1 Create one or more of the following types of ACLs:
a MAC-based ACL by using the MAC Based ACL page and the MAC
Based ACE page
b IPv4-Based ACL by using the IPv4 Based ACL page and the IPv4
Based ACE page
c IPv6-Based ACL by using the IPv6 Based ACL page and the IPv6
Based ACE page
2 Associate the ACL with interfaces by using the ACL Binding page
Modifying ACLs Workflow
An ACL can only be modified if it is not in use The following describes the
process of unbinding an ACL in order to modify it:
1 If the ACL has been associated with an interface, unbind it from the
interface using the ACL Binding page
2 If the ACL is part of the class map and not bound to an interface, then it
can be modified
3 If the ACL is part of a class map contained in a policy bound to an
interface, you must perform the chain of unbinding as follows:
•
Unbind the policy containing the class map from the interface by
using Policy Binding
•
Delete the class map containing the ACL from the policy using the
Configuring a Policy (Edit)
•
Delete the class map containing the ACL, by using Defining Class
Mapping page
•
Only then can the ACL be modified, as described in this section
MAC-Based ACL
MAC-based ACLs are used to filter traffic based on Layer 2 fields MAC-based
ACLs check all frames for a match
MAC-based ACLs are defined in the MAC Based ACL page The rules are
defined in the MAC-Based ACE page
To define a MAC-based ACL:
STEP 1 Click Configuration > Access Control List > MAC Based ACL
This page contains a list of all currently-defined MAC-based ACLs
STEP 2 Click Add
STEP 3 Enter the name of the new ACL in the ACL Name field ACL names are
case-sensitive
STEP 4 Click Apply The MAC-based ACL is saved to the Running
Configuration file
MAC-Based ACE
To add rules (ACEs) to an ACL:
STEP 1 Click Configuration > Access Control List > MAC-based ACE
STEP 2 Select an ACL, and click Search The ACEs in the ACL are listed
STEP 3 Click Add
STEP 4 Enter the parameters
•
ACL Name—Select the name of the ACL to which an ACE is being added
ACE Settings
•
ACE Priority—Enter the priority of the ACE ACEs with higher priority are
processed first One is the highest priority
•
Action on Matched Packets—Select the action taken upon a match The
options are:
•
Permit—Forward packets that meet the ACE criteria
•
Deny—Drop packets that meet the ACE criteria
•
Shutdown—Drop packets that meet the ACE criteria, and disable
the port from where the packets were received Such ports can be
reactivated from the Port Settings page
•
Destination MAC Address—Select Any if all destination addresses are
acceptable or User Defined to enter a destination address or a range of
destination addresses
•
Destination MAC Address Value—Enter the MAC address to which the
destination MAC address is to be matched and its mask (if relevant)
•
Destination MAC Wildcard Mask—Enter the mask to define a range of
MAC addresses Note that this mask is different than in other uses, such as
subnet mask Here, setting a bit as 1 indicates don’t care and 0 indicates
to mask that value
Содержание Smart Switch LGS3XX
Страница 1: ...Smart Switch LGS3XX User Guide ...