Summary Of Acl Actions - IBM RackSwitch G8000 Application Manual

A top-of-rack (tor) switch
Hide thumbs Also See for RackSwitch G8000:
Table of Contents

Advertisement

Summary of ACL Actions

© Copyright IBM Corp. 2011
TCP/UDP header options (for all ACLs)
– TCP/UDP application source port and mask as shown in
– TCP/UDP application destination port as shown in
Table 9. Well-Known Application Ports
TCP/UDP
Port
Application
20
ftp-data
21
ftp
22
ssh
23
telnet
25
smtp
37
time
42
name
43
whois
53
domain
69
tftp
70
gopher
– TCP/UDP flag value as shown in
Table 10. Well-Known TCP flag values
Flag
Value
URG
0x0020
ACK
0x0010
PSH
0x0008
RST
0x0004
SYN
0x0002
FIN
0x0001
Packet format (for IPv4 ACLs and VMaps only)
– Ethernet format (eth2, SNAP, LLC)
– Ethernet tagging format
– IP format (IPv4, IPv6)
Egress port packets (for all ACLs)
Once classified using ACLs, the identified packet flows can be processed differently.
For each ACL, an action can be assigned. The action determines how the switch
treats packets that match the classifiers assigned to the ACL. G8000 ACL actions
include the following:
Pass or Drop the packet
Re-mark the packet with a new DiffServ Code Point (DSCP)
Re-mark the 802.1p field
Set the COS queue
TCP/UDP
Port
Application
79
finger
80
http
109
pop2
110
pop3
111
sunrpc
119
nntp
123
ntp
143
imap
1645/1812
144
news
161
snmp
162
snmptrap
Table 10
Table 9
Table 9
TCP/UDP
Port
Application
179
bgp
194
irc
220
imap3
389
ldap
443
https
520
rip
554
rtsp
Radius
1813
Radius
1985
Accounting
hsrp
Chapter 7. Access Control Lists
81

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents