Chapter 5 | Advanced Configuration |
The MAC Based ACL screen allows a MAC based ACL to be defined. ACEs can be added only if the ACL is not bound to an interface.
ACL Name Displays the
New ACL Name Specifies a new
Delete ACL Deletes the selected ACL.
Action Indicates the ACL forwarding action. Possible field values are:
•• Permit Forwards packets which meet the ACL criteria.
•• Deny Drops packets which meet the ACL criteria.
•• Shutdown Drops packet that meet the ACL criteria, and disables the port to which the packet was addressed.
Source MAC Address Matches the source MAC address to which packets are addressed to the ACE.
Wildcard Mask Defines the source IP address wildcard mask. Wildcard masks specify which bits are used and which bits are ignored. A wild card mask of 255.255.255.255 indicates that no bit is important. A wildcard of 0.0.0.0 indicates that all the bits are important. For example, if the source IP address 149.36.184.198 and the wildcard mask is 255.36.184.00, the first eight bits of the IP address are ignored, while the last eight bits are used.
Dest. MAC Address Matches the destination MAC address to which packets are addressed to the ACE.
Wildcard Mask Defines the destination IP address wildcard mask.
VLAN ID Matches the packet’s VLAN ID to the ACE. The possible field values are 2 to 4094.
Ether Type Specifies the packet’s Ethernet type.
The Add to List button adds the configured MAC Based ACLs to the MAC Based ACL Table at the bottom of the screen.
Security > ACL Binding
Security > ACL Binding
When an ACL is bound to an interface, all the ACE rules that have been defined are applied to the selected interface. Whenever an ACL is assigned on a port or LAG, flows from that ingress interface that do not match the ACL are matched to the default rule, which is Drop unmatched packets.
Interface Indicates the interface to which the ACL is bound.
ACL Name Indicates the ACL which is bound to the interface.
The Add to List button adds the ACL Binding configuration to the ACL Binding Table at the bottom of the screen.
Security > RADIUS
Security > RADIUS
33 |