ES4710BD 10 Slots L2/L3/L4 Chassis Switch
The following rules apply:
zAn access list can consist of several rules. Filtering of packets compares packet conditions to the rules, from the first rule to the first matched rule; the rest of the rules will not be processed.
zGlobal default action applies only to IP packets in the incoming direction on the ports. For non- incoming IP packets and all outgoing packets, the default forward action is “permit”.
zGlobal default action applies only when packet flirter is enabled on a port and no ACL is bound to that port, or no binding ACL matches.
zWhen an access list is bound to the outgoing direction of a port, the action in the rule can only be “deny”.
12.2ACL configuration
12.2.1ACL Configuration Task Sequence
1. Configuring access list
(1) Configuring a numbered standard IP access list
(2) Configuring an numbered extended IP access list
(3) Configuring a standard IP access list based on nomenclature
a)Create an standard IP access list based on nomenclature
b)Specify multiple “permit” or “deny” rule entries.
c)Exit ACL Configuration Mode
(4) Configuring an extended IP access list based on nomenclature.
a)Create an extensive IP access list based on nomenclature
b)Specify multiple “permit” or “deny” rule entries.
c)Exit ACL Configuration Mode
2.Configuring the packet filtering function
(1)Enable global packet filtering function
(2)Configure default action.
3.Bind access list to a specific direction of the specified port.
1. Configuring access list
(1) Configuring a numbered standard IP access list
Command
Global Mode
Explanation
267