![Riverstone Networks WICT1-12 Скачать руководство пользователя страница 540](http://html1.mh-extra.com/html/riverstone-networks/wict1-12/wict1-12_user-manual_1466194540.webp)
24-10 Riverstone Networks RS Switch Router User Guide Release 8.0
Using ACLs
Access Control List Configuration
24.3.4
Using ACLs as Profiles
You can use the
acl
command to define a
profile
. A profile specifies the criteria that addresses, flows, hosts, or packets
must meet to be relevant to certain RS features. Once you have defined an ACL profile, you can use the profile with
the configuration command for that feature. For example, the Network Address Translation (NAT) feature on the RS
allows you to create address pools for dynamic bindings. You use ACL profiles to represent the appropriate pools of
IP addresses.
The following RS features use ACL profiles:
Note the following about using profile ACLs:
•
Only IP ACLs can be used as Profile ACLs. ACLs for non-IP protocols
cannot
be used as Profile
ACLs.
•
The
permit/deny
keywords, while required in the ACL rule definition, are
disregarded
in the
configuration commands for the above-mentioned features. In other words, the configuration
commands will act upon a specified Profile ACL whether or not the Profile ACL rule contains the
permit
or
deny
keyword.
•
Only certain ACL rule parameters are relevant for each configuration command. For example, the
configuration command to create NAT address pools for dynamic bindings (the
nat create
dynamic
command) only looks at the source IP address in the specified ACL rule. The destination
IP address, ports, and TOS parameters, if specified, are ignored.
Specific usage of Profile ACLs is described in more detail in the following sections.
Using Profile ACLs with the IP Policy Facility
The IP policy facility uses a Profile ACL to define criteria that determines which packets should be forwarded
according to an IP policy. Packets that meet the criteria defined in the Profile ACL are forwarded according to the
ip-policy
command that references the Profile ACL.
Table 24-1 Features that use ACl profile
RS Feature
ACL Profile Usage
IP policy
Specifies the packets that are subject to the IP routing policy.
Dynamic NAT
Defines local address pools for dynamic bindings.
Port mirroring
Defines traffic to be mirrored.
Rate limiting
Specifies the incoming traffic flow to which rate limiting is applied.
Web caching
Specifies which HTTP traffic should always (or never) be redirected to the cache servers.
Specifies characteristics of Web objects that should not be cached.
Содержание WICT1-12
Страница 1: ...36 007 07 Rev 0A RS Switch Router User Guide Release 8 0...
Страница 7: ...Riverstone Networks RS Switch Router User Guide Release 8 0 vii J J J J J 2 5 5J 5 A H B J 5J H...
Страница 160: ...8 26 Riverstone Networks RS Switch Router User Guide Release 8 0 Configuring PPP OC 12 ATM Configuration Guide...
Страница 216: ...13 6 Riverstone Networks RS Switch Router User Guide Release 8 0 Configuration Example RIP Configuration Guide...
Страница 258: ...15 24 Riverstone Networks RS Switch Router User Guide Release 8 0 Displaying IS IS Information IS IS Configuration Guide...
Страница 308: ...16 50 Riverstone Networks RS Switch Router User Guide Release 8 0 BGP Configuration Examples BGP Configuration Guide...
Страница 530: ...23 10 Riverstone Networks RS Switch Router User Guide Release 8 0 Configuration Examples IPX Routing Configuration...
Страница 546: ...24 16 Riverstone Networks RS Switch Router User Guide Release 8 0 Monitoring ACLs Access Control List Configuration...
Страница 582: ...26 20 Riverstone Networks RS Switch Router User Guide Release 8 0 Limiting Traffic Rate QoS Configuration...
Страница 586: ...27 4 Riverstone Networks RS Switch Router User Guide Release 8 0 Monitoring Broadcast Traffic Performance Monitoring...