Configuring and Managing Security ACLs 361

Determining the ACE Order

The set security acl command creates a new entry in the edit buffer and appends the new entry as a rule at the end of an ACL, unless you specify otherwise. The order of ACEs is significant, because the earliest ACE takes precedence over later ACEs. To place the ACEs in the correct order, use the parameters before editbuffer-indexand modify edit- buffer-index. The first ACE is number 1.

To specify the order of the commands, use the following parameters:

before editbuffer-indexinserts an ACE before a specific location.

modify editbuffer-indexchanges an existing ACE.

If the security ACL you specify when creating an ACE does not exist when you enter set security acl ip, the specified ACL is created in the edit buffer. If the ACL exists but is not in the edit buffer, the ACL reverts, or is rolled back, to the state when its last ACE was committed, but it now includes the new ACE.

For details, see “Placing One ACE before Another” on page 371 and “Modifying an Existing Security ACL” on page 372.

Nortel WLAN Security Switch 2300 Series Configuration Guide

Page 361
Image 361
Nortel Networks 2300 manual Determining the ACE Order