ACCESS CONTROL LISTS

For example, use the code value and mask below to catch packets with the following flags set:

-SYN flag valid, use control-code 2, control bitmask 2

-Both SYN and ACK valid, use control-code 18, control bitmask 18

-SYN valid and ACK invalid, use control-code 2, control bitmask 18

Web – Specify the action (i.e., Permit or Deny). Specify the source and/or destination addresses. Select the address type (Any, Host, or IP). If you select “Host,” enter a specific address. If you select “IP,” enter a subnet address and the mask for an address range. Set any other required criteria, such as service type, protocol type, or TCP control code. Then click Add.

Figure 3-37 ACL Configuration - Extended IP

CLI – This example adds two rules:

1.Accept any incoming packets if the source address is in subnet 10.7.1.x. For example, if the rule is matched; i.e., the rule (10.7.1.0 & 255.255.255.0) equals the masked address (10.7.1.2 & 255.255.255.0), the packet passes through.

2.Allow TCP packets from class C addresses 192.168.1.0 to any destination address when set for destination TCP port 80 (i.e., HTTP).

3-83

Page 133
Image 133
SMC Networks TigerSwitch manual ACL Configuration Extended IP

TigerSwitch specifications

The SMC Networks TigerSwitch series represents a robust line of Ethernet switches designed to cater to a wide range of networking needs, from small businesses to enterprise environments. With a strong emphasis on performance, reliability, and ease of use, the TigerSwitch series has garnered a reputation for delivering effective solutions for today’s demanding data communication requirements.

One of the standout features of the TigerSwitch is its support for Gigabit Ethernet, which enables higher data transfer rates and reduced latency. This performance boost is crucial for businesses that rely on bandwidth-heavy applications such as VoIP, video conferencing, and large file transfers. Many models in the series come with multiple Gigabit Ethernet ports, providing businesses with the flexibility to connect various devices and expand their networks seamlessly.

The TigerSwitch series also incorporates advanced Layer 2 switching capabilities, including features such as VLAN support and QoS (Quality of Service). VLAN support allows network administrators to segment network traffic, enhancing security and improving overall network performance. By segregating traffic based on user groups or applications, VLANs help manage bandwidth more effectively. QoS is particularly important in environments where voice and video services compete for bandwidth, as it prioritizes critical applications ensuring minimal interruptions in service quality.

Another key characteristic of the TigerSwitch is its user-friendly management interface. Many models come with web-based management capabilities, making it simpler for network administrators to configure settings, monitor performance, and troubleshoot issues. Additionally, the series supports SNMP (Simple Network Management Protocol), allowing for centralized network management and monitoring, which is essential for larger networks.

The TigerSwitch series also promotes energy efficiency, aligning with modern eco-friendly practices. Many of the switches feature Power over Ethernet (PoE) support, allowing them to deliver power to connected devices such as IP cameras and wireless access points over the same Ethernet cable used for data. This not only simplifies cabling requirements but also contributes to reducing overall power consumption, which is a consideration for both cost savings and environmental impact.

In conclusion, the SMC Networks TigerSwitch series stands out due to its combination of performance, advanced features, and ease of management. With its Gigabit Ethernet capabilities, VLAN and QoS support, user-friendly interfaces, and energy-efficient design, the TigerSwitch is well-equipped to meet the diverse needs of modern networking environments, offering reliable solutions that cater to both current demands and future expansions.