Optimizing Performance When Using An Access Control List - Avaya Cajun P882 User Manual

Multiservice switch
Hide thumbs Also See for Cajun P882:
Table of Contents

Advertisement

Chapter 9

Optimizing Performance when Using an Access Control List

Purpose
Important
Terms used in
this section
9-30
8. Click CREATE to save your changes, or CANCEL to restore
previous settings. Once you create both access rules, all traffic
between subnet 10.1.1.0 and 10.1.2.0 is deny/filtered.
*Note: Traffic between any other 10.1.x.0 subnets are not
filtered because the access rules only deny/filter
traffic between subnets 10.1.1.0 and 10.1.2.0.
To deny/filter traffic to a specific address and not
to an entire subnet, you must specify the
destination IP address of the network node, and
use a subnet wildcard of 0.0.0.0.
To deny/filter all traffic, you must specify a
destination address of 0.0.0.0 and a wildcard of
255.255.255.255. This is useful if you want to
filter all traffic except traffic that matches a
previous rule. Ensure that you do not make this
your first rule, since ACL rules are read from the
top down and stop after the first rule match,
which ignores all subsequent rules.
* Note: This section provides a detailed discussion of the
architecture and functionality of the Avaya Multiservice
switch with respect to ACLs. This material goes well
beyond standard configuration issues by addressing
system performance, memory management and
optimization.
The purpose of this section is to explain the configuration options
when using Access Lists. Deploying an Access List affects the use of
hardware and software resources and may impact system
performance. An Access Control List (ACL), also referred to as an
Access List, is a tool for associating rules (permit, deny, prioritize for
Quality of Service (QoS)) with identified IP traffic through the
switch. This section will show how to monitor performance and
adjust configurations to optimize performance.
The following terms are used extensively in this section:
5-tuple: The five elements that fully describe the criteria of the
ACL rule: Source IP/ Mask, Destination IP/Mask, Protocol, Source
Port, Destination Port. The masks allow the user to specify a
narrow or wide range of matches. All elements are optional, but
Avaya P550R, P580, P880, and P882 Multiservice Switch User Guide, v5.3.1

Advertisement

Table of Contents
loading

This manual is also suitable for:

P550rP580P880

Table of Contents