SMC Networks SMC8624/48T manual Configuring an IP based ACL

Models: SMC8624/48T

1 556
Download 556 pages 10.96 Kb
Page 121
Image 121

ACCESS CONTROL LISTS

Web – Configure the mask to match the required rules in the IP ingress or egress ACLs. Set the mask to check for any source or destination address, a specific host address, or an address range. Include other criteria to search for in the rules, such as a protocol type or one of the service types. Or use a bitmask to search for specific protocol port(s) or TCP control code(s).

Then click Add.

Figure 3-32. Configuring an IP based ACL

CLI – This shows that the entries in the mask override the precedence in which the rules are entered into the ACL. In the following example, packets with the source address 10.1.1.1 are dropped because the “deny

10.1.1.1255.255.255.255” rule has the higher precedence according the “mask host any” entry.

3-73

Page 121
Image 121
SMC Networks SMC8624/48T manual Configuring an IP based ACL