Precedence Order; Firewall - Motorola WS5100 Series Migration Giude

Hide thumbs Also See for WS5100 Series:
Table of Contents

Advertisement

10-4 WS5100 Series Switch Migration Guide
• TOS/DSCP bits in the IP header.
NOTE: In WS5100, only Port ACL supports the mark action. In Router ACL, the mark action
is treated as a permit action and the packet is allowed to its destination without
performing any modifications.

10.1.3 Precedence Order

The rules or ACE's within an ACL are applied to packets based on their precedence values. Every ACE has a
unique precedence value which can be between 1 and 5000. You cannot add two ACE's with the same
precedence value.
The following points need to considered when adding rules with or without precedence values.
• Every ACL entry in an ACL is associated with a precedence value which is unique for every entry. You
cannot enter two different entries in an ACL with the same precedence value. This value can be between
1 and 5000.
• Specifying a precedence value with each ACL entry is not mandatory and if you do not want to specify
one then the system automatically generates a precedence value starting with 10. Subsequent entries
are added with precedence values of 20, 30 and so on. 10 is the default offset between any two ACEs in
an ACL.
However, if the user specifies a precedence value with an entry, then that value overrides the system
default value.
• If an entry with a max precedence value of 5000 exists, then you cannot add a new entry with a
precedence value higher than this. In such a case, system throws an error saying Rule with max
precedence value exists. In such a case you either have to delete that entry or add new entries with
precedence values less than 5000.
• Rules within an ACL are displayed in ascending order of precedence.
• When matching rules against a received packet, rules with lower precedence values are matched first.
NOTE: ACEs with lower precedence are always applied first to packets. Hence, it is
advised to add more specific entries in the ACL first then the general ones. While
displaying the ACL, the entries are displayed in ascending order of precedence.

10.2 Firewall

The Firewall functionality in WS5100 switch supports packets received on Layer 3 interfaces only. No
firewall protection is applied for packets getting switched. The firewall protects against various network
level attacks and inspects each packet for possible corruption that can initiate some kind of attack.
The Firewall detects the following list of attacks:
• LAND attack– where Source IP = Destination IP and Source Port = Destination Port.
• Fragment death– caused by overflowing fragment length.
• Traceroute attack– caused by modifying IP TTL value.
• Xmas scan– all TCP flags set in TCP header.
• TCP fin scan
• TCP NULL scan– No flags set in TCP header.

Advertisement

Table of Contents
loading

Table of Contents