ACL Configuration Examples 155

Table 168 Display and Debug ACL

 

 

 

Operation

Command

 

 

Display the information about the ACL

display acl running-packet-filter { all

running state

interface { interface-name interface-type

 

interface-num } }

Clear ACL counters

reset acl counter { all acl-number

 

acl-name }

 

 

The matched information of the display acl config command specifies the rules treated by the switch’s CPU. The matched information of the transmitted data by the switch can be displayed with the display qos-infotraffic-statisticcommand.

For a description of the syntax of these commands, see the Switch 7750 Command Reference Guide.

ACL Configuration Examples

Access Control

This section provides examples for the following configurations:

Access Control

Basic ACL

Link ACL

The interconnection between different departments on a company network is implemented through the 100M ports of the Switch 7750. The payment query server of the Financial Dept. is accessed through Ethernet1/0/1 (at 129.110.1.2). The ACL must be properly configured to prevent departments other than the Office of President from having access to the payment query server between 8:00 AM and 6:00 PM. The Office of President (at 129.111.1.2) can access the server without limitation.

Figure 37 Access Control Configuration Example

Office of President 129.111.1.2

Pay query server 129.110.1.2

 

#3

#4

 

 

 

 

 

#1

 

#2

 

Switch

 

Financial Department

 

 

Administration Department

 

 

subnet address

subnet address

 

 

10.120.0.0

10.110.0.0

Connected to

a router

In the following configuration steps, only the commands related to ACL configurations are listed.

Page 155
Image 155
3Com 10014298 manual ACL Configuration Examples, Access Control