46
SIGNAMAX LLC • www.signamax.eu
ACL Configuration
ACL is short for Access Control Lists and called Access List briefly. It is an
orderly rule set. The included rules are called Access Control Entry (ACE).
The ACL and its related objects, action groups and meters in Signamax
S34xx switch are organized according to the logical relationship as shown
in the following figure to realize packet filtering, packet classification and
traffic control.
ACL
ACE1
(
permit ...
)
deny any
ACLn
(
permit ...
)
ACL2
(
deny ...
)
...
Action Group 1
Action1
Action2
...
Action Group 2
Action1
Action2
...
Action Group 3
Action1
Action2
...
Traffic Meter 1
Traffic Meter 2
Global
对对
Port
对对
VLAN
对对
There are three kinds of objects that can apply ACL in Signamax S34xx
switch, including global object, VLAN object and port object. Global
object refers to the switch and the ACL takes effect on all packets
entering the switch; VLAN object refers to a VLAN configured on the
switch and the ACL takes effect on all packets entering the VLAN; Port
object refers to the port or aggregation port on the switch and the ACL
takes effect on all packets entering the port.
The effect ranges of the ACL on the three objects have overlapping
part, so the conflict of ACL actions appears (for example, an ACE with
action as deny is matched on the port, while an ACE with action as
permit is matched on the VLAN to which the port belongs). To solve the
problem, 065-7434 Signamax 24-Port 10/100 L3 Switch endures each
kind of objects with priorities. When the ACL actions are conflicting,
process it according to the order of Port
>
VLAN
>
Global.
Содержание 065-7434
Страница 1: ...24 Port 10 100 L3 Switch Model 065 7434 Configuration Guide Revision A1 ...
Страница 245: ...245 SIGNAMAX LLC www signamax eu Application Example Example of configuring DHCP Snooping ...
Страница 302: ...302 SIGNAMAX LLC www signamax eu Default status no switching interface ...
Страница 368: ......
Страница 655: ...287 SIGNAMAX LLC www signamax eu Sub VLAN members in the system ...