QoS Application Guide
29
Security Application Guide
ACL function supports access control security for MAC address, IP address, Layer4 Port, and Type of
Service. Each has five actions: Deny, Permit, Queue Mapping, CoS Marking, and Copy Frame. User can
set default ACL rule to Permit or Deny. To get more clearly for these ACL function, see following table.
Default ACL Rule
Actions
Deny
Permit
Queue
Mapping
CoS Marking
Copy Frame
Permit
(a)
(b)
(c)
(d)
(e)
Deny
(f)
(g)
(h)
(i)
(j)
Brief descriptions of the above table:
(a): Permit all frames, but deny frames set in ACL entry.
(b): Permit all frames.
(c): Permit all frames, and to do queue mapping of the transmitting frames.
(d): Permit all frames, and to change CoS value of the transmitting frames.
(e): Permit all frames, and to copy frame which set in ACL entry to a defined GE port.
(f): Deny all frames.
(g): Deny all frames, but permit frames set in ACL entry.
(h): Deny all frames.
(i): Deny all frames.
(j): Deny all frames, but to copy frame which set in ACL entry to a defined GE port.
Case 1: ACL for MAC address
For MAC address ACL, it can filter on source MAC address, destination MAC address, or both. When it
filters on both MAC address, packets coincident with both rules will take effect. In other words, it does
not do filter if it only coincident with one rule.
If user want to filter only one directional MAC address, the other MAC address just set to all zero. It
means don’t care portion. Besides MAC address, it also supports VLAN and Ether type for filter
additionally. Certain VLAN or Ether type under these MAC address will take effect. If user doesn’t care
VLAN or Ether type, he can just set to zero values. Following are examples about the above table:
Case 1:
(a)
User can set default ACL Rule of GE port as “Permit”, then to bind a suitable profile with “deny” action for
ACL. It means GE port can pass through all packets but not ACL entry of the profile binding.
Содержание MLB-E4203-28-F
Страница 1: ...MLB E4203 28 F MLB E4204 28 G F 28 Ports L2 Managed Gigabit Switch USER MANNUAL ...
Страница 4: ...CONTENTS ii ...
Страница 5: ...1 Preface Scope Audience Safety Instructions Documentation Conventions ...
Страница 6: ...2 ...
Страница 8: ...Preface 4 ...
Страница 9: ...5 Overview Overview Panel Introduction Technical Specifications ...
Страница 10: ...6 ...
Страница 14: ...Quick Installation 10 Dimensions unit mm ...
Страница 16: ...Quick Installation 12 Quick Installation Equipment Mounting Cable Connecting Equipment Configuration ...
Страница 81: ...77 7 On the host with IP 172 16 100 10 could receive alarm trap which record link down up information ...