05.03.2013 Views

ProSafe 7000 Managed NETGEAR Switch Software Administration ...

ProSafe 7000 Managed NETGEAR Switch Software Administration ...

ProSafe 7000 Managed NETGEAR Switch Software Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

MAC ACLs<br />

112 | Chapter 10. ACLs<br />

<strong>ProSafe</strong> <strong>7000</strong> <strong>Managed</strong> <strong>Switch</strong> Release 8.0.3<br />

MAC ACLs are Layer 2 ACLs. You can configure the rules to inspect the following fields of a<br />

packet (limited by platform):<br />

• Source MAC address with mask.<br />

• Destination MAC address with mask.<br />

• VLAN ID (or range of IDs).<br />

• Class of Service (CoS) (802.1p) .<br />

• EtherType:<br />

- Secondary CoS (802.1p).<br />

- Secondary VLAN (or range of IDs).<br />

• L2 ACLs can apply to one or more interfaces.<br />

• Multiple access lists can be applied to a single interface: the sequence number<br />

determines the order of execution.<br />

• You cannot configure a MAC ACL and an IP ACL on the same interface.<br />

• You can assign packets to queues using the assign queue option.<br />

• You can redirect packets using the redirect option.<br />

IP ACLs<br />

IP ACLs classify for Layer 3. Each ACL is a set of up to 10 rules applied to inbound traffic.<br />

Each rule specifies whether the contents of a given field should be used to permit or deny<br />

access to the network, and can apply to one or more of the following fields within a packet:<br />

• Source IP address<br />

• Destination IP address<br />

• Source Layer 4 port<br />

• Destination Layer 4 port<br />

• ToS byte<br />

• Protocol number<br />

Note that the order of the rules is important: When a packet matches multiple rules, the first<br />

rule takes precedence. Also, once you define an ACL for a given port, all traffic not<br />

specifically permitted by the ACL is denied access.<br />

ACL Configuration<br />

To configure ACLs:<br />

1. Create an ACL by specifying a name (MAC ACL) or a number (IP ACL).<br />

2. Add new rules to the ACL.<br />

3. Configure the match criteria for the rules.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!