![](/images/backgrounds/291895/hp-1920-16g-switch-users-manual-157638465x1.png)
For example, if the numbering step is 5 (the default), and there are five ACL rules numbered 0, 5, 9, 10, and 12, the newly defined rule is numbered 15. If the ACL does not contain any rule, the first rule is numbered 0.
Whenever the step changes, the rules are renumbered, starting from 0. For example, if there are five rules numbered 5, 10, 13, 15, and 20, changing the step from 5 to 2 causes the rules to be renumbered 0, 2, 4, 6, and 8.
Implementing
You can implement ACL rules based on the time of day by applying a time range to them. A
The following basic types of time range are available:
•Periodic time
•Absolute time
IPv4 fragments filtering with ACLs
Traditional packet filtering matches only first fragments of IPv4 packets, and allows all subsequent
To improve network security, ACL filters all packets by default, including fragments and
Configuration guidelines
When you configure an ACL, follow these guidelines:
•You cannot add a rule with, or modify a rule to have, the same permit/deny statement as an existing rule in the ACL.
•You can only modify the existing rules of an ACL that uses the match order of config. When modifying a rule of such an ACL, you can choose to change just some of the settings, in which case the other settings remain the same.
Recommend ACL configuration proceduresRecommended IPv4 ACL configuration procedure
Step |
| Remarks |
|
| Optional. |
1. | Add a time range. A rule referencing a time range | |
|
| |
|
| takes effect only during the specified time range. |
|
|
|
|
| Required. |
2. |
|
Add an IPv4 ACL. The category of the added ACL depends on the ACL number that you specify.
452