Mapping Security Acls To Ports, Vlans, Virtual Ports, Or Distributed Maps - 3Com 3CRWX120695A, 3CRWX440095A Configuration Manual

Wireless lan switch and controller
Table of Contents

Advertisement

244
C
11: C
HAPTER
ONFIGURING AND
Mapping Security
ACLs to Ports, VLANs,
Virtual Ports, or
Distributed MAPs
M
S
ANAGING
ECURITY
Table 24 Mapping Commands
Mapping Target
User authenticated by
a password
User authenticated by
a MAC address
When assigned the Filter-Id attribute, an authenticated user with a
current session receives packets based on the security ACL. For example,
to restrict incoming packets for Natasha to those specified in acl-222,
type the following command:
WX1200# set user Natasha attr filter-id acl-222.in
success: change accepted.
You can also map a security ACL to a user group. For details, see
"Assigning a Security ACL to a User or a Group" on page 319. For more
information about authenticating and authorizing users, see "About
Administrative Access" on page 35 and "AAA Tools for Network Users"
on page 285.
Security ACLs can be mapped to ports, VLANs, virtual ports, and
Distributed MAPs. Use the following command:
set security acl map acl-name {vlan vlan-id | port port-list
[tag tag-value] | dap dap-num} {in | out}
Specify the name of the ACL, the port, VLAN, tag value(s) of the virtual
port, or the number of the Distributed MAP to which the ACL is to be
mapped, and the direction for packet filtering. For virtual ports or
Distributed MAPs, you can specify a single value, a comma-separated list
of values, a hyphen-separated range, or any combination, with no
spaces. For example, to map security ACL acl-222 to virtual ports 1
through 3 and 5 on port 2 to filter incoming packets, type the following
command:
WX1200# set security acl map acl-222 port 2 tag 1-3,5 in
success: change accepted.
Plan your security ACL maps to ports, VLANs, virtual ports, and
Distributed MAPs so that only one security ACL filters a flow of packets. If
more than one security ACL filters the same traffic, you cannot guarantee
the order in which the ACE rules are applied.
ACL
S
Commands
set user username attr filter-id acl-name.in
set user username attr filter-id acl-name.out
set mac-user username attr filter-id acl-name.in
set mac-user username attr filter-id acl-name.out

Advertisement

Table of Contents
loading

Table of Contents