An ACL classifies packets according to matching rules. The rules can be source addresses, destination addresses, or the port numbers of the packets.
Table 1 describes the parameters on the page.
Parameter |
Description |
|
|---|---|---|
ACL Type |
Indicates the ACL type, including:
|
|
IP Version |
To create an IPv4 or IPv6 ACL, click the IPv4 or IPv6 check box.
NOTE:
If you select Layer 2 ACL, the IP version cannot be set. |
|
ACL ID |
ACL Number |
Indicates the number of an ACL. It identifies an ACL. The value of the ACL number is an integer, including:
NOTE:
|
ACL Name |
Indicates the name of an ACL. The ACL name must be unique.
NOTE:
|
|
Step |
Indicates the interval between two rule IDs.
NOTE:
The Step text box is unavailable after you set IP Version to IPv6. |
|
ACL Description |
Indicates the description of an ACL. This parameter is optional.
NOTE:
The Description text box of the ACL is unavailable after you set IP Version to IPv6. |
|
If the ACL is a basic ACL, the rule page is displayed.
Table 2 describes the parameters on the page.
Parameter |
Description |
|
|---|---|---|
Rule Number |
Indicates the number of a rule.
NOTE:
If you do not specify a rule number, the system automatically allocates a number for the rule. The rule number cannot be changed. |
|
Action |
Indicates whether to permit or deny packets. The default action is to permit. |
|
Log |
Indicates whether to record logs when packets are permitted. To record logs when packets are permitted, click the check box. NOTE:
The basic ACL and basic IPv6 ACL in the S2700EI switches do not support this parameter. |
|
Match IP |
All Source IP |
Indicates that packets from any IP address are permitted. |
Specify Source IP |
Enter the specified IP address and the reverse mask. By default, all source IP addresses are specified.
NOTE:
|
|
Time Range Name |
Click Select to set the time range name.
NOTE:
The time range name is displayed on the configuration result page. |
|
Fragment |
Indicates that the rule is valid for only non-initial fragments. NOTE:
The basic ACL and basic IPv6 ACL in the S2700EI switches do not support this parameter. |
|
If the ACL is an advanced ACL, the rule page is displayed.
Table 3 describes the parameters on the page.
Parameter |
Description |
|
|---|---|---|
Rule Number |
Indicates the number of a rule.
NOTE:
If you do not specify a rule number, the system automatically allocates a number for the rule. The rule number cannot be changed. |
|
Action |
Indicates whether to permit or deny packets. The default action is to permit. |
|
Log |
Indicates whether to record logs when packets are permitted. NOTE:
The advanced ACL and advanced IPv6 ACL of the S2700EI switches do not support this parameter. |
|
Protocol Type |
Indicates the type of the protocol. The advanced ACL supports the following protocols:
The advanced IPv6 ACL supports the following protocols:
|
|
ICMP Parameters (Type/Code) |
Indicates the type and code of ICMP packets, which are valid only when the protocol of packets is ICMP. If this parameter is not specified, all types of ICMP packets are matched. The IGMP packets can be matched based on:
NOTE:
The advanced ACL and advanced IPv6 ACL of the S2700EI switches do not support this parameter. |
|
Match IP |
All Source IP |
Indicates that packets from any IP address are permitted. |
Specify Source IP |
Enter the specified IP address and the reverse mask. By default, all source IP addresses are specified.
NOTE:
|
|
All Destination IP |
Indicates that packets from any IP address are permitted. |
|
Point Destination IP |
Enter the specified IP address and the reverse mask. By default, all destination IP addresses are specified.
NOTE:
|
|
Match Port |
Source Port |
This parameter is valid only when the protocol type is TCP or UDP. If this parameter is not specified, TCP or UDP packets with any source port are matched. Select a matching source port from the drop-down list box. The value can be equal, greater, smaller, or in the range. Enter the TCP or UDP port number in the text box. |
Destination Port |
This parameter is valid only when the protocol type is TCP or UDP. If this parameter is not specified, TCP or UDP packets with any destination port are matched. Select a matching destination port from the drop-down list box. The value can be equal, greater, smaller, or in the range. Enter the TCP or UDP port number in the text box. |
|
Match Priority |
IP Precedence |
Indicates that packets are filtered based on the precedence field. By default, this parameter is empty. |
DSCP Value |
Specifies the Differentiated Services CodePoint (DSCP). NOTE:
|
|
TOS |
Indicates that packets are filtered based on the type field. This parameter is optional. |
|
Time Range Name |
Click Select to set the time range name.
NOTE:
The time range name is displayed on the configuration result page. |
|
Fragment |
Indicates that the rule is valid for only non-initial fragments. NOTE:
The advanced ACL and advanced IPv6 ACL of the S2700EI switches do not support this parameter. |
|
If the ACL is a basic ACL, the rule page is displayed.
Table 4 describes the parameters on the page.
Parameter |
Description |
|
|---|---|---|
Rule Number |
Indicates the number of a rule.
NOTE:
If you do not specify a rule number, the system automatically allocates a number for the rule. The rule number cannot be changed. |
|
Action |
Indicates whether to permit or deny packets. The default action is to permit. |
|
Match MAC |
Source MAC |
Indicates the source MAC address used by the ACL rule. The value is in H-H-H format. |
Mask |
Indicates the mask of the source MAC address used by the ACL rule. The value is in the format H-H-H. The default value contains only Fs. |
|
Destination MAC |
Indicates the destination MAC address used by the ACL rule. The value is in H-H-H format. |
|
Mask |
Indicates the mask of the destination MAC address used by the ACL rule. The value is in the format H-H-H. The default value contains only Fs. |
|
Match Protocol Type |
Packet Encapsulation Format |
Indicates the encapsulation format of protocol packets. The value can be ether-ii, 802.3, or snap. |
Layer 2 Protocol |
Indicates the type of Layer 2 protocols. |
|
Layer 2 Protocol Mask |
Indicates the mask of the Layer 2 protocol. |
|
Source VLAN ID |
Indicates the source VLAN ID. |
|
Source VLAN ID Mask |
Indicates the mask of the source VLAN ID. The value is in hexadecimal notation. It ranges from 0 to 0xFFF. The default value is 0xFFF. |
|
802.1p Priority |
Indicates the 802.1p priority of the ACL. By default, this parameter is empty. |
|
Time Range Name |
Click Select to set the time range name.
NOTE:
The time range name is displayed on the configuration result page. |
|
Table 5 describes the parameters on the page.
Parameter |
Description |
||
|---|---|---|---|
Flow Filter |
Indicates whether to enable the Flow Filter. This parameter is optional. |
||
Traffic Statistics |
Indicates whether to enable the traffic statistics. The value can be Enable or Disable. By default, the value is Disable. |
||
Configure Traffic Policing |
CIR |
Specifies the committed information rate (CIR), which is the allowed rate at which traffic can pass through. |
|
PIR |
Specifies the peak information rate (PIR), which is the maximum rate at which traffic can pass through. NOTE:
|
||
CBS |
Specifies the committed burst size (CBS), which is the committed burst volume of traffic that can pass through. NOTE:
The value of the S2700EI switches ranges from 8192 to 4294967295. |
||
PBS |
Specifies the peak burst size (PBS), which is the peak burst volume of traffic that can pass through. The default value of PBS is related to the value of PIR. NOTE:
The S2700EI switches do not support this parameter. |
||
Green Packets NOTE:
The S2700EI switches do not support this parameter. |
Green Packets |
Indicates whether green packets are allowed to pass through. The action can be pass or discard. By default, the action is pass. |
|
Re-mark 802.1P Priority |
Indicates whether to re-mark the 802.1p priority. |
||
Re-mark DSCP Priority |
Indicates whether to re-mark the DSCP priority. |
||
Yellow Packets NOTE:
The S2700EI switches do not support this parameter. |
Yellow Packets |
Indicates whether yellow packets are allowed to pass through. The action can be pass or discard. By default, the action is pass. |
|
Re-mark 802.1P Priority |
Indicates whether to re-mark the 802.1p priority. |
||
Re-mark DSCP Priority |
Indicates whether to re-mark the DSCP priority. |
||
Red Packets NOTE:
The S2700EI switches do not support this parameter. |
Red Packets |
Indicates whether red packets are allowed to pass through. The action can be pass or discard. By default, the action is discard. |
|
Re-mark 802.1P Priority |
Indicates whether to re-mark the 802.1p priority. |
||
Re-mark DSCP Priority |
Indicates whether to re-mark the DSCP priority. |
||
Configure Re-mark Action |
802.1P Priority |
Select the check box of 802.1p to configure the 802.1p priority. |
|
Local Priority |
Select the check box of the local priority to configure the local priority. NOTE:
You cannot set both the 802.1p priority and the local priority for redirection in a traffic behavior. |
||
IP Priority |
Select the check box of the IP precedence to configure the IP precedence. NOTE:
The S2700EI switch do not support the function. |
||
DSCP Priority |
Select the check box of DSCP to configure the DSCP priority. |
||
Destination MAC |
Select the corresponding check box to configure the destination MAC address. The value is in the format H-H-H. Each H represents four hexadecimal digits. NOTE:
The S2700EI switches do not support this parameter. |
||
VLAN ID |
Select the check box of VLAN ID to configure VLAN ID. |
||
Inner VLAN |
Select the check box of the inner VLAN to configure the inner VLAN. NOTE:
The S2700EI, S2700EI-52P, S2710SI-52P or S3700 switches do not support this parameter. |
||
Configure Flow Mirroring |
Observing Port Index |
Indicates the ID of the observing interface where all matching flows are mirrored. |
|
Observing Port |
Indicates the observing interface where all matching flows are mirrored, for example, Ethernet 0/0/1. |
||
Configure Redirection Action NOTE:
The S2700EI switches do not support this parameter. |
CPU |
Indicates that packets are redirected to the CPU. |
|
Redirect to Interface |
Indicates the interface where packets are redirected, for example, Ethernet 0/0/1. |
||
Redirect to Next Hop IP |
NOTE:
|
||
Table 6 describes the parameters on the page.
Parameter |
Description |
|
|---|---|---|
Name |
Indicates all the interfaces on the device. |
|
Inbound |
|
|
Outbound NOTE:
The S2700EI , S2710SI-52P or S3700 switches do not support this parameter. |
NOTE:
You can select the inbound and outbound interfaces or one of them at one time. |
|
Table 7 describes the parameters on the page.
Parameter |
Description |
|
|---|---|---|
VLAN ID |
|
|
Direction NOTE:
The S2700EI or S3700 switches do not support this parameter. |
NOTE:
You can select the inbound and outbound interfaces or one of them at one time. |
|
icon to open the Edit ACL page. If an ACL rule is not created, the system displays a message indicating an empty ACL when you click the Apply tab.
Table 8 describes the parameters on the page.