Configure Mac Acls - Cisco WAP581 Administration Manual

Wireless-ac/n dual radio access point with 2.5gbe lan
Hide thumbs Also See for WAP581:
Table of Contents

Advertisement

Access Control
To delete or modify an ACL, select the ACL and then click Delete or Edit.
Note
To delete or modify a rule, select the rule in the Details Of Rule(s) area and click Delete or Edit.
Step 8
Click Apply.

Configure MAC ACLs

To configure a MAC ACL:
Step 1
Select Access Control > ACL.
Step 2
Click ✚ to add a MAC ACL.
Step 3
In the ACL Name field, enter the name to identify the ACL.
Step 4
Choose MAC as the type of ACL from the list. MAC ACLs control access based on Layer 2 criteria.
Step 5
Click ✚ and select the associated interfaces to apply the ACL and click OK. If you want to change the associated interfaces,
you can click ━ to delete the selected interface and then click ✚ to choose new associated interfaces.
Then, click More... to view the configuration parameters. Click ✚ to add a rule and configure the following parameters:
Step 6
• Rule Priority — When an ACL has multiple rules, the rules are applied to the packet or frame in the order of their
priorities. Smaller number means higher priority. The priority of the new rule will be the lowest of all explicit rules
and you can click the up or down button to change its priority. Note that there is always an implicit rule denying all
traffic with lowest priority.
• Action — Choose whether to Deny or Permit the action. The default action is Deny.
When you choose Permit, the rule allows all traffic that meets the rule criteria to enter the WAP device. Traffic that
does not meet the criteria is dropped.
When you choose Deny, the rule blocks all traffic that meets the rule criteria from entering the WAP device. Traffic
that does not meet the criteria is forwarded unless this rule is the final rule. Because there is an implicit deny all rule
at the end of every ACL, traffic that is not explicitly permitted is dropped.
• Service (ETH Type) — Choose to compare the match criteria against the value in the header of an Ethernet frame.
You can select an ETH Type from the drop down list.
• Any — Allows for any protocol.
• Select From List — Choose one of these protocol types: AppleTalk, ARP, IPv4, IPv6, IPX, NetBIOS or
PPPoE.
• Custom — Enter a custom protocol identifier to which the packets are matched. The value is a four-digit
hexadecimal number in the range of 0600 to FFFF.
• Source MAC Address — Requires the packet's source MAC address to match the address defined in the appropriate
fields.
• Any — Allows for any source MAC address.
• Single Address — Enter the source MAC address to compare against an Ethernet frame.
• Address/ Mask — Enter the source MAC address mask specifying which bits in the source MAC to compare
against an Ethernet frame.
Cisco WAP581 Wireless-AC/N Dual Radio Access Point with 2.5GbE LAN Administration Guide
Configure MAC ACLs
87

Advertisement

Table of Contents
loading

Table of Contents