Access Mask Precedence Numbers; Specifying A Default Rule; The Permit-Established Keyword; Adding Access Mask, Access List, And Rate Limit Entries - Extreme Networks ExtremeWare 7.2e Installation And User Manual

Software version 7.2e
Table of Contents

Advertisement

IP Access Lists (ACLs)
forwarded. A permit access list can also apply a QoS profile to the packet and modify the packet's
802.1p value and the DiffServ code point.

Access Mask Precedence Numbers

The access mask precedence number determines the order in which each rule is examined by the switch
and is optional. Access control list entries are evaluated from highest precedence to lowest precedence.
Precedence numbers range from 1 to 25,600, with the number 1 having the highest precedence, but an access
mask without a precedence specified has a higher precedence than any access mask with a precedence
specified. The first access mask defined without a specified precedence has the highest precedence.
Subsequent masks without a specified precedence have a lower precedence, and so on.

Specifying a Default Rule

You can specify a default access control list to define the default access to the switch. You should use an
access mask with a low precedence for the default rule access control list. If no other access control list
entry is satisfied, the default rule is used to determine whether the packet is forwarded or dropped. If
no default rule is specified, the default behavior is to forward the packet.
NOTE
If your default rule denies traffic, you should not apply this rule to the Summit 400-48t port used as a
management port.
Once the default behavior of the access control list is established, you can create additional entries using
precedence numbers.
The
permit-established
Keyword
The
keyword is used to directionally control attempts to open a TCP session.
permit-established
Session initiation can be explicitly blocked using this keyword.
The permit-established keyword denies the access control list. Having a permit-established access
control list blocks all traffic that matches the TCP source/destination, and has the SYN=1 and ACK=0
flags set.

Adding Access Mask, Access List, and Rate Limit Entries

Entries can be added to the access masks, access lists, and rate limits. To add an entry, you must supply
a unique name using the
command, and supply a number of optional parameters. For access
create
lists and rate limits, you must specify an access mask to use. To modify an existing entry, you must
delete the entry and retype it, or create a new entry with a new unique name.
To add an access mask entry, use the following command:
create access-mask <name> ...
To add an access list entry, use the following command:
create access-list <name> ...
To add a rate limit entry, use the following command:
create rate-limit <name> ...
ExtremeWare 7.2e Installation and User Guide
145

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents