Chapter 1 Acl Configuration; Introduction To Acl; Acl Implementation Mode On Switch - Huawei Quidway S3100 Series Operation Manual

Table of Contents

Advertisement

Operation Manual – ACL
Quidway S3100 Series Ethernet Switches

Chapter 1 ACL Configuration

1.1 Introduction to ACL

Access control list (ACL) is used mainly to identify traffic. A series of matching rules
are required for a network device to identify the packets to be filtered. Packets are
identified first before they are permitted or denied according to previously defined
policy.
ACL classifies packets according to a series of matching rules. Packets can be
classified by source address, destination address and port number, and so on.
Matching rules defined in ACL can also be used in some other cases requiring traffic
classification, such as QoS traffic classification.
ACL falls into the following categories depending on their applications:
Basic ACL, where rules are defined on the basis of Layer 3 source IP address.
Advanced ACL, where rules are defined on the basis of Layers 3 and 4
information, such as source IP address, destination IP address, the types and
features of the protocols carried by IP.
Layer 2 ACL, where rules are defined on the basis of Layer 2 information, such as
source MAC address, destination MAC address, VLAN priority, and Layer 2
protocol type.

1.1.1 ACL Implementation Mode on Switch

I. Implemented by hardware
ACL can be delivered to hardware directly for packets to be filtered and classified. In
this case, the matching order of ACL rules is determined by hardware instead of the
customized one.
An ACL operates in this mode when it is used for implementing QoS or is used to filter
the packets to be forwarded.
II. Implemented by upper layer modules
ACL can also be used to filter or classify the packets processed by the software
running on switch. In this case, ACL rules can be matched in the order the rules are
defined or in the order determined by the system (that is, in depth-first order).
The matching order of the existing rules of an ACL cannot be modified. To enable the
rules to be matched in a new order, you can remove all the rules and define them
again in the desired order.
An ACL operates in this mode when it is used to control logon users.
Huawei Technologies Proprietary
1-1
Chapter 1 ACL Configuration

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents