Application Guide
38
Security Application Guide
ACL function supports access control security for MAC address, IP address, Layer4 Port, and Type of
Service. Each has five actions: Deny, Permit, Queue Mapping, CoS Marking, and Copy Frame. User can
set default ACL rule to Permit or Deny. To get more clearly for these ACL function, see following table.
Default ACL Rule
Actions
Deny
Permit
Queue
Mapping
CoS Marking
Copy Frame
Permit
(a)
(b)
(c)
(d)
(e)
Deny
(f)
(g)
(h)
(i)
(j)
Brief descriptions of the above table:
(a): Permit all frames, but deny frames set in ACL entry.
(b): Permit all frames.
(c): Permit all frames, and to do queue mapping of the transmitting frames.
(d): Permit all frames, and to change CoS value of the transmitting frames.
(e): Permit all frames, and to copy frame which set in ACL entry to a defined GE port.
(f): Deny all frames.
(g): Deny all frames, but permit frames set in ACL entry.
(h): Deny all frames.
(i): Deny all frames.
(j): Deny all frames, but to copy frame which set in ACL entry to a defined GE port.
Case 1: ACL for MAC address
For MAC address ACL, it can filter on source MAC address, destination MAC address, or both. When it
filters on both MAC address, packets coincident with both rules will take effect. In other words, it does
not do filter if it only coincident with one rule.
If user want to filter only one directional MAC address, the other MAC address just set to all zero. It
means don’t care portion. Besides MAC address, it also supports VLAN and Ether type for filter
additionally. Certain VLAN or Ether type under these MAC address will take effect. If user doesn’t care
VLAN or Ether type, he can just set to zero values. Following are examples about the above table:
l
Case 1:
(a)
User can set default ACL Rule of GE port as “Permit”, then to bind a suitable profile with “deny” action for
ACL. It means GE port can pass through all packets but not ACL entry of the profile binding.
Summary of Contents for VX-IGP-1204F
Page 5: ...5 Overview Overview Faceplate Panel Introduction Technical Specifications ...
Page 7: ...7 8 10 Port PL series 12 Port PL series VX IGP 1204F ...
Page 12: ...12 Quick Installation Equipment Mounting Cable Connecting Equipment Configuration ...
Page 15: ...15 Ground Connections VX IGP 1204F must be properly grounded for optimum system performance ...
Page 74: ...74 ...
Page 77: ...77 ...
Page 81: ...81 3 Confirm the file is right then click Next twice ...