
182
7.2.
Access Control List
Access control list
(
ACL
) is a list of permissions attached to an object. The list specifies
who or what is allowed to access the object and what operations are allowed to be
performed on the object.
ACL function allows user to configure a few rules to reject packets from the specific ingress
ports or all ports. These rules will check the packets’ source MAC address and destination
MAC address. If packets match these rules, the system will do the actions “deny”. “deny”
means rejecting these packets.
The Action Resolution engine collects the information (action and metering results) from
the hit entries: if more than one rule matches, the actions and meter/counters are taken from
the policy associated with the matched rule with highest priority.
L2 ACL Support:
1. Filter a specific source MAC address.
Command:
source mac host MACADDR
2. Filter a specific destination MAC address.
Command:
destination mac host MACADDR
3. Filter a range of source MAC address.
Command:
source mac MACADDR MACADDR
The second MACADDR is a mask, for example: ffff.ffff.0000
4. Filter a range of destination MAC address.
Command:
destination mac MACADDR MACADDR
The second MACADDR is a mask, for example: ffff.ffff.0000
L3 ACL Support:
1. Filter a specific source IP address.
Command:
source ip host IPADDR
2. Filter a specific destination IP address.
Command:
destination ip host IPADDR
3. Filter a range of source IP address.
Command:
source ip IPADDR IPADDR
The second IPADDR is a mask, for example: 255.255.0.0
4. Filter a range of destination IP address.
Command:
destination ip IPADDR IPADDR
L4 ACL Support:
1. Filter a UDP/TCP source port.
2. Filter a UDP/TCP destination port.
Notices:
Maximum profile
: 64.
Maximum profile name length : 16.
Содержание NGI-M05-C1
Страница 49: ...49 Refresh Click Refresh to begin configuring this screen afresh...
Страница 53: ...53 1000 full 1000Mbps Full duplex force mode 1000 full n 1000Mbps Full duplex auto negotiation mode...
Страница 62: ...62 Apply Click Apply to take effect the settings Refresh Click Refresh to begin configuring this screen afresh...
Страница 76: ...76 global state is enabled user must enable per VLAN states to enable the IGMP Snooping on the specific VLAN...
Страница 122: ...122...
Страница 125: ...125 Refresh Click Refresh to begin configuring this screen afresh...
Страница 151: ...151 Download Clicks the Download button to download all of the regisers information to load host...