27.03.2014 Views

Intel® NetStructure™ 6000 Switch

Intel® NetStructure™ 6000 Switch

Intel® NetStructure™ 6000 Switch

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

C H A P T E R 5<br />

Managing the <strong>Switch</strong><br />

IP access control and access lists do not apply to frames that are<br />

switched within the same VLAN. If the devices are on the same<br />

VLAN, they maintain their IP connectivity and are able to ping or<br />

Telnet each other even though ACL rules may forbid IP traffic<br />

between the two.<br />

IP connection between an end station and the <strong>6000</strong> switch is never<br />

subjected to ACL rules. An end station can Telnet the switch or use<br />

an SNMP agent for management activities.<br />

The IP Access Control configuration is stored in NVRAM.<br />

ACL rules<br />

The order rules are applied to an incoming packet are determined by<br />

the order that a rule was entered into the ACL. The <strong>6000</strong> switch<br />

supports a maximum of 128 filtering rules.<br />

The source IP address and source wildcard mask or destination IP<br />

address and destination wildcard mask represents a single host or a<br />

range of hosts in a network.<br />

A wildcard mask is a method used to define a range of host IP<br />

addresses with an accompanying network or subnet IP address. It<br />

uses the same notation as the dotted decimal IP address. The wildcard<br />

mask cannot overlap with the corresponding network or subnet<br />

address.<br />

Network/<br />

Subnet<br />

Address<br />

Wildcard Mask Examples<br />

Wildcard<br />

Mask<br />

172.18.1.0 0.0.0.255<br />

172.18.2.0 0.0.0.7<br />

Description<br />

All the host addresses in the range<br />

172.18.1.0. through 172.18.1.255,<br />

All the host addresses in the range<br />

172.18.2.0. through 172.18.2.7,<br />

172.18.3.0 0.0.255.255 Invalid since address and mask overlap,<br />

For a single device or host, the address must be the designated IP<br />

address of the device and the wildcard mask must be 0.0.0.0 or the<br />

word “host.”<br />

permit 172.18.1.2 0.0.0.0 172.18.3.2 0.0.0.0<br />

or<br />

permit 172.18.1.2 host 172.18.3.2 host<br />

188

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!