
C h a p t e r
9
ACL Configuration
Table of Contents
ACL Overview ...................................................................77
NP-Based ACL Overview .....................................................78
Configuring ACLs ...............................................................79
Configuring Event Linkage ACL Rule .....................................85
Applying NP-Based ACL ......................................................87
ACL Configuration Example .................................................88
ACL Maintenance and Diagnosis...........................................89
ACL Overview
Packet filtering can help limit network traffic and restrict network
use by certain users or devices.
ACL
can filter traffic as it passes
through a router and permit or deny packets at specified inter-
faces.
An ACL is a sequential collection of permit and deny conditions that
apply to packets. When a packet is received on an interface, the
switch compares the fields in the packet against any applied ACL
to verify that the packet has the required permissions to be for-
warded, based on the criteria specified in the access lists. It tests
packets against the conditions in an access list one by one. The
first match determines whether the switch accepts or rejects the
packets because the switch stops testing conditions after the first
match. The order of conditions in the list is critical. When there
are no conditions matched, the switch rejects the packets. If there
are no restrictions, the switch forwards the packet; otherwise, the
switch drops the packet.
Packet matching rules defined by the ACL are also used in other
conditions where distinguishing traffic is needed. For instance, the
matching rules can define the traffic classification rule in the
QoS
.
ZXR10 8900 series switch provides seven types of ACLs:
�
Standard ACL
Only source IP addresses are matched against the ACL.
�
Extended ACL
Source/destination
IP
address,
IP
protocol
type,
TCP
source/destination port number, TCP-control, UDP source/des-
tination port number,
ICMP
type, ICMP code, DiffServ Code
Point (
DSCP
),
ToS
and precedence are matched against the
ACL.
Confidential and Proprietary Information of ZTE CORPORATION
77