Access Control Lists 3

CLI – This example allows SNMP access for a specific client.

Console(config)#management snmp-client 10.1.2.3

4-28

Console(config)#end

 

Console#show management all-client

 

Management IP Filter

 

HTTP-Client:

 

 

 

Start IP address

End IP address

 

-----------------------------------------------

 

SNMP-Client:

 

 

Start IP address

End IP address

 

-----------------------------------------------

 

1.

10.1.2.3

10.1.2.3

 

TELNET-Client:

 

 

Start IP address

End IP address

 

-----------------------------------------------

 

Console#

Access Control Lists

Access Control Lists (ACL) provide packet filtering for IP frames (based on address, protocol, Layer 4 protocol port number or TCP control code) or any frames (based on MAC address or Ethernet type). To filter incoming packets, first create an access list, add the required rules and then bind the list to a specific port.

Configuring Access Control Lists

An ACL is a sequential list of permit or deny conditions that apply to IP addresses, MAC addresses, or other more specific criteria. This switch tests ingress or egress packets against the conditions in an ACL one by one. A packet will be accepted as soon as it matches a permit rule, or dropped as soon as it matches a deny rule. If no rules match for a list of all permit rules, the packet is dropped; and if no rules match for a list of all deny rules, the packet is accepted.

Command Usage

The following restrictions apply to ACLs:

Each ACL can have up to 32 rules.

The maximum number of ACLs is 88.

However, due to resource restrictions, the average number of rules bound to the ports should not exceed 20.

This switch supports ACLs for ingress filtering only. However, you can only bind one IP ACL to any port and one MAC ACL globally for ingress filtering. In other words, only two ACLs can be bound to an interface - Ingress IP ACL and Ingress

MAC ACL.

The order in which active ACLs are checked is as follows:

1.User-defined rules in the Ingress MAC ACL for ingress ports.

2.User-defined rules in the Ingress IP ACL for ingress ports.

3-57

Page 93
Image 93
LevelOne GSW-2692 manual Configuring Access Control Lists, CLI This example allows Snmp access for a specific client

GSW-2692 specifications

The LevelOne GSW-2692 is an advanced Layer 2 Gigabit Ethernet switch that is designed to cater to the networking needs of both small and medium-sized enterprises. Highly regarded for its reliability and performance, the GSW-2692 offers 24 Gigabit Ethernet ports, enabling seamless and high-speed data transfers across connected devices. With its robust design and versatile capabilities, this switch has earned its place as an essential component in modern IT infrastructure.

One of the standout features of the GSW-2692 is its extensive support for advanced networking technologies. The switch includes support for IEEE 802.1Q VLAN tagging, which allows users to create separate virtual networks for improved traffic management and enhanced security. By segregating network traffic, businesses can optimize bandwidth usage and reduce congestion, contributing to overall increased network performance.

Additionally, the GSW-2692 supports Spanning Tree Protocol (STP) and Rapid Spanning Tree Protocol (RSTP), ensuring loop-free network topology. This capability is crucial in larger networking environments where multiple switches are interconnected, as it prevents broadcast storms and enhances network resilience. The switch also includes features such as port mirroring, which provides administrators with the capability to monitor network traffic in real-time for troubleshooting and analysis.

Power over Ethernet (PoE) support is another significant advantage of the GSW-2692. With PoE functionality, it enables the switch to deliver electrical power along with data to connected devices such as IP cameras, VoIP phones, and wireless access points, eliminating the need for additional power sources and simplifying installations.

In terms of physical characteristics, the LevelOne GSW-2692 is designed for efficient heat dissipation and features a fanless design, which ensures silent operation. Its desktop or rack-mountable options make it flexible for various installation environments. The switch also features a web-based management interface, which simplifies the configuration and monitoring processes, allowing for intuitive management of network settings.

Overall, the LevelOne GSW-2692 stands out as a feature-rich, reliable, and high-performance networking solution that meets the demands of modern enterprises. Its combination of advanced technologies, scalability, and ease of use makes it an excellent choice for businesses looking to enhance their network infrastructure.