XS712T Smart Switch

criteria to a particular queue or redirect the traffic to a particular port. A default deny all rule is the last rule of every list.

2.Apply the access list to an interface in the inbound direction.

The XS712T Smart Switch allows ACLs to be bound to physical ports and LAGs.The switch software supports MAC ACLs and IP ACLs.

MAC ACL Example Configuration

The following example shows how to create a MAC-based ACL that permits Ethernet traffic from the Sales department on specified ports and denies all other traffic on those ports.

1.From the MAC ACL screen, create an ACL with the name Sales_ACL for the Sales department of your network (see MAC ACL on page 215).

By default, this ACL will be bound on the inbound direction, which means the switch will examine traffic as it enters the port.

2.From the MAC Rules screen, create a rule for the Sales_ACL with the following settings:

ID. 1

Action. Permit

Assign Queue. 0

Match Every. False

CoS. 0

Destination MAC. 01:02:1A:BC:DE:EF

Destination MAC Mask. 00:00:00:00:FF:FF

Source MAC. 02:02:1A:BC:DE:EF

Source MAC Mask. 00:00:00:00:FF:FF

VLAN ID. 2

For more information about MAC ACL rules, see MAC Rules on page 216.

3.From the MAC Binding Configuration screen, assign the Sales_ACL to Ethernet ports 6, 7, and 8, and then click Apply (seeMAC Binding Configuration on page 218).

288

Page 288
Image 288
NETGEAR XS712T-100NES MAC ACL Example Configuration, Assign Queue Match Every. False CoS, Destination MAC Mask Ffff, 288