Filter For Mac Addresses - ABB EDS500 Series Function Manual

Ethernet & dsl switches
Hide thumbs Also See for EDS500 Series:
Table of Contents

Advertisement

Functions
Every access list can contain up to 16 rules.
Creating the first rule of an access list determines if this is a deny list or a permit list.
Subsequent, deviating commands are ignored.
Each rule can define several criterias that all have to match before the action of the rule is
executed.
Example:
"Allow all Ethernet frames with a defined source MAC address and a defined target TCP port".
The following criteria ( Chapter 2.25.2, "Filter for MAC Addresses" to Chapter 2.25.6, "Filter for
TCP and UDP Ports" ) can be freely combined in all of the 16 rules (several commands per rule).
Commands for access list management:
< s h o w a c c e s s - l i s t >
< s h o w a c c e s s - l i s t { 1 - 1 6 } >
< a c c e s s - l i s t { 1 - 1 6 } c l e a r >
< a c c e s s - l i s t { 1 - 1 6 } c l e a r r u l e { 1 - 1 6 } >
< a c c e s s - l i s t { . . . } e t h e r t y p e { . . . } >
< a c c e s s - l i s t { 1 - 1 6 } { d e n y - r u l e | p e r m i t - r u l e } { 1 - 1 6 }
e t h e r t y p e { a r p | i p | { 0 x 0 8 0 0 - 0 x f f f f } } >
< a c c e s s - l i s t { . . . } i p [ . . . ] { . . . } >
< a c c e s s - l i s t { 1 - 1 6 } { d e n y - r u l e | p e r m i t - r u l e } { 1 - 1 6 } i p
[ { d e s t i n a t i o n | s o u r c e } { I P a d d r e s s } [ { s u b n e t m a s k } ] ] >
< a c c e s s - l i s t { . . . } m a c [ . . . ] { . . . } >
< a c c e s s - l i s t { 1 - 1 6 } { d e n y - r u l e | p e r m i t - r u l e } { 1 - 1 6 } m a c
{ d e s t i n a t i o n | s o u r c e } { a a - b b - c c - d d - e e - f f | a a b b . c c d d . e e f f |
a a b b c c d d e e f f } >
< a c c e s s - l i s t { . . . } p r o t o c o l { . . . } >
< a c c e s s - l i s t { 1 - 1 6 } { d e n y - r u l e | p e r m i t - r u l e } { 1 - 1 6 }
p r o t o c o l { t c p | u d p | i c m p | { 0 - 2 5 5 } } >
< a c c e s s - l i s t { . . . } t c p d s t - p o r t { . . . } >
< a c c e s s - l i s t { 1 - 1 6 } { d e n y - r u l e | p e r m i t - r u l e } { 1 - 1 6 } t c p
d s t - p o r t { 0 - 6 5 5 3 5 } >
< a c c e s s - l i s t { . . . } t c p s r c - p o r t { . . . } >
< a c c e s s - l i s t { 1 - 1 6 } { d e n y - r u l e | p e r m i t - r u l e } { 1 - 1 6 } t c p
s r c - p o r t { 0 - 6 5 5 3 5 } >
< a c c e s s - l i s t { . . . } u d p d s t - p o r t { . . . } >
< a c c e s s - l i s t { 1 - 1 6 } { d e n y - r u l e | p e r m i t - r u l e } { 1 - 1 6 } u d p
d s t - p o r t { 0 - 6 5 5 3 5 } >
< a c c e s s - l i s t { . . . } u d p s r c - p o r t { . . . } >
< a c c e s s - l i s t { 1 - 1 6 } { d e n y - r u l e | p e r m i t - r u l e } { 1 - 1 6 } u d p
s r c - p o r t { 0 - 6 5 5 3 5 } >
2.25.2

Filter for MAC Addresses

The target MAC address and the source MAC address of an Ethernet frame can be checked. To
treat broadcast frames use the target MAC address ff-ff-ff-ff-ff-ff.
Commands to filter for MAC addresses:
< a c c e s s - l i s t { 1 - 1 6 } { d e n y - r u l e | p e r m i t - r u l e } { 1 - 1 6 } m a c
{ d e s t i n a t i o n | s o u r c e } { a a - b b - c c - d d - e e - f f | a a b b . c c d d . e e f f |
a a b b c c d d e e f f } >
1KGT151021 V000 1
Access Lists
87

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents