Q O S/Acl Operation; Acl Overview - 3Com 7700 Configuration Manual

Hide thumbs Also See for 7700:
Table of Contents

Advertisement

7

ACL Overview

Q
S/ACL O
O
ACL Overview
Configuring ACL
Displaying and Debugging ACL
QoS Overview
User LogonACL Control Configuration
A series of matching rules are required for the network devices to identify the
packets to be filtered. After identifying the packets, the switch can permit or deny
them to pass through according to the defined policy. The Access Control List
(ACL) is used to implement these functions.
ACL classifies the data packets with a series of matching rules, including source
address, destination address and port number. The switch verifies the data packets
with the rules in ACL and decides to forward or discard them.
The data packet matching rules that are defined by ACL can also be called in some
other cases requiring traffic classification, such as defining traffic classification for
QoS.
An access control rule includes several statements. Different statements specify
different ranges of packets. When matching a data packet with the access control
rule, the issue of match-order arises.
Filtering or Classifying the Data Transmitted by the Hardware
ACL can be used to filter or classify the data transmitted by the hardware of
switch. In this case, the match order of ACL's sub-rules is determined by the switch
hardware. The match order defined by the user is not effective.
This type of filtering includes ACL cited by the QoS function, ACL used to filter the
packet transmitted by the hardware, and so on.
Filtering or Classifying the Data Transmitted by the Software
ACL can be used to filter or classify the data treated by the software of switch. The
user can determine the match order of ACL's sub-rules. There are two
match-orders; configuration, which follows the user-defined configuration order
when matching the rule; and automatic, which follows the system sorting
automatically when matching the rule (depth-first principle). After you specify the
match-order of an access control rule, you cannot modify it later unless you delete
all the contents and specify the match-order again.
PERATION

Advertisement

Table of Contents
loading

Table of Contents