Configuration Guide
Access
Control List Configuration
Configuring Security Tunnel
Applying a secure ACL globally means that the ACL is a security tunnel. A general ACL is installed on
a port or port map; a security tunnel is installed on an interface or globally. The difference between
them arises in priority. The security tunnel takes precedence over port security (that is the IP binding
under port security), 802.1x and secure ACL. The global security tunnel takes effect for all ports,
unless you set a port as an exception port.
Note
1 A security tunnel supports permit and deny rules.
2 The global security tunnel takes no effect for an exception port.
3 The security tunnel policies enabled on an interface take precedence
over the global security tunnel.
4 Without IP authorization, using a security tunnel in 802.1x will reduce
the permitted authentication number at large extent, which is in
accordance with the one under IP authorization.
5 It is strongly recommended to configure a security tunnel before
authentication, so as to avoid the case that resource exhaustion causes
the authenticated users cannot access the Interface due to the
configuration of security tunnel midway.
You can use an exist ACL to configure a security tunnel
In the privileged configuration mode, execute the following commands to configure a global security
tunnel:
Command
Function
Ruijie#
configure terminal
Enter the global configuration mode.
Ruijie(config)#
security global access-group
acl-name
Configure a global security tunnel.
In the privileged configuration mode, execute the following commands to set an exception port:
Command
Function
Ruijie#
configure terminal
Enter the global configuration mode.
Ruijie#
interface
interface-id
Enter the interface configuration mode.
Ruijie(config)#
security uplink enable
Set the interface as an exception port..
If a security tunnel is configured under the interface, remove the security tunnel and then set the
interface as the exception port.
In the privileged configuration mode, execute the following commands to configure a security tunnel
on the interface:
Command
Function
Ruijie#
configure terminal
Enter the global configuration mode.
Ruijie#
interface
interface-id
Enter the interface configuration mode.
Содержание RG-S2900G-E Series
Страница 1: ...RG S2900G E Series Switch RGOS Configuration Guide Release 10 4 2b12 p1 ...
Страница 91: ...Configuration Guide Configuring PoE Configuration ...
Страница 133: ...Configuration Guide EEE Configuration ...
Страница 319: ...Configuration Guide QinQ Configuration ...
Страница 408: ......
Страница 409: ...IP Routing Configuration 1 Static Route Configuration ...
Страница 412: ......
Страница 413: ...Multicast Configuration 1 IGMP Snooping Configuration 2 MLD Snooping Configuration ...
Страница 621: ...Configuration Guide CPU Protection Configuration udp helper 180 4 dhcp client 180 4 lacp 180 4 ...
Страница 757: ......
Страница 758: ...ACL QoS Configuration 1 Access Control List Configuration 2 QoS Configuration ...
Страница 801: ...Reliability Configuration 1 RLDP Configuration 2 TPP Configuration 3 SEM Configuration ...
Страница 901: ...Configuration Guide ERSPAN Configuration ...
Страница 902: ...Web based Configuration 1 Web based Configuration ...