Brocade Communications Systems RFS6000 System Reference Manual page 364

Provides centralized wireless lan (wlan) configuration and management
Hide thumbs Also See for RFS6000:
Table of Contents

Advertisement

6
Configuring firewalls and access control lists
Router ACLs
Router ACLs are applied to Layer 3 or VLAN interfaces. If an ACL is already applied in a particular
direction on an interface, applying a new one will replace the existing ACL. Router ACLs are
applicable only if the controller acts as a gateway, and traffic is inbound only.
The controller supports two types of Router ACLs:
Router ACLs are stateful and are not applied on every packet routed through the controller.
Whenever a packet is received from a Layer 3 interface, it is examined against existing sessions to
determine if it belongs to an established session. ACLs are applied on the packet in the following
manner.
1. If the packet matches an existing session, it is not matched against ACL rules and the session
2. If no existing sessions match the packet, it is matched against ACL rules to determine whether
A session is computed based on:
NOTE
Port and router ACLs can be applied only in an inbound direction. WLAN ACLs support applying ACLs
in the inbound and outbound direction.
Each session has a default idle time-out interval. If no packets are received within this interval, the
session is terminated and a new session must be initiated. These intervals are fixed and cannot be
configured by the user.
The default idle time-out intervals for different sessions are:
Port ACLs
The controller supports Port ACLs on physical interfaces and inbound traffic only. The following Port
ACLs are supported:
350
Standard IP ACL—Uses the source IP address as matching criteria.
Extended IP ACL—Uses the source IP address, destination IP address and IP protocol type as
basic matching criteria. It can also include other parameters specific to a protocol type (like
source and destination port for TCP/UDP protocols).
decides where to send the packet.
to accept or reject it. If ACL rules accept the packet, a new session is created and all further
packets belonging to that session are allowed. If ACL rules reject the packet, no session is
established.
Source IP address
Destination IP address
Source Port
Destination Port
ICMP identifier
Incoming interface index
IP Protocol
ICMP and UDP sessions— 30 seconds
TCP sessions— 2 hours
Standard IP ACL— Uses a source IP address as matching criteria.
Brocade Mobility RFS6000 and RFS7000 System Reference Guide
53-1001858-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Rfs7000

Table of Contents