27.10.2013 Views

2.5.2 - Force10 Networks

2.5.2 - Force10 Networks

2.5.2 - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Note that the order of the rules is important: when a packet matches multiple rules in an ACL, the first rule<br />

created in the ACL takes precedence. Also, once you define an ACL for a given port, all traffic not<br />

specifically permitted by the ACL will be denied access.<br />

Loopback interface ACL: For IP ACLs, the priority given to an ACL assigned to the loopback interface<br />

affects the number of and order in which rules are applied to ports, just as if the ACL and its priority setting<br />

were assigned to each port. For details, see Protecting the Management Interface with a Loopback ACL on<br />

page 210.<br />

SFTOS supports two types of filtering: extended MAC ACLs and IP ACLs. For both types, the general<br />

process for using them is the same:<br />

1. Create the access list.<br />

2. Apply the access list either globally to all ports or to an individual interface.<br />

Common ACL Commands<br />

Note: For syntax details on ACL commands, see the Quality of Service chapter in the SFTOS<br />

Command Reference.<br />

MAC ACL Commands<br />

MAC Access Control Lists (ACLs) ensure that only authorized users have access to specific resources and<br />

block any unwarranted attempts to reach network resources.<br />

The following rules apply to MAC ACLs:<br />

• The maximum number of ACLs you can create is 100, regardless of type.<br />

• The system supports only Ethernet II frame types.<br />

• The maximum number of rules per MAC ACL is hardware-dependent.<br />

• On the S50 system, if you configure an IP ACL (see IP ACL Commands on page 208) on an interface,<br />

you cannot configure a MAC ACL on the same interface.<br />

To create a MAC ACL identified by name:<br />

— mac access-list extended name<br />

<strong>Force10</strong> (Config)#mac access-list extended ml-1<br />

Define rules for the selected MAC ACL, consisting of classification fields defined for the Layer 2<br />

header of an Ethernet frame:<br />

206 Access Control

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!