Preparing For Configurations; Configuring Mac Acl - Raisecom ISCOM2600G-HI (A) Series Configuration Manual

Table of Contents

Advertisement

Raisecom
ISCOM2600G-HI (A) Series Configuration Guide

10.1.2 Preparing for configurations

Scenario
ACL can help a network device recognize filter data packets. The device recognizes special
objects and then permits/denies packets to pass according to the configured policy.
ACL is divided into the following types:
There are 4 ACL modes according to different application environments:
Prerequisite
N/A

10.1.3 Configuring MAC ACL

Configure MAC ACL for the ISCOM2600G-HI series switch as below.
Step
1
Basic IPv4 ACL: define classification rules according to attributes carried in the header
of IP packets, such as the source IP address and destination IP address.
Extended IPv4 ACL: define classification rules according to attributes carried in the
header of IP packets, such as the source IP address, destination IP address, bearing
protocol type, and TCP or UDP port number (being 0 by default). This type can restrict
Telnet/SSH login.
MAC ACL: define classification rules according to attributes carried in the header of
Layer 2 frames, such as the source MAC address, destination MAC address, and Layer 2
protocol type. When ACL denies packets with a destination MAC address, the device
will not learn and show the source MAC address.
User ACL: this type can perform the AND operation with the mask from a specified byte
in the packet header or IP header, compares the character string extracted from the packet
with the user-defined character string, and thus find matching packets. This type supports
matching any field in the first 64 bytes of the Ethernet frame.
IPv6 ACL: define classification rules according to attributes carried in the header of IP
packets, such as the source IPv6 address, destination IPv6 address, IPv6 bearing protocol
type, and TCP or UDP port number (being 0 by default). This type can restrict
Telnet/SSH login.
Advanced ACL: define classification rules according to attributes carried in the header of
Layer 2 frames, such as the source MAC address and destination MAC address, and
attributed carried in the header of IP packets, such as the source IP address and
destination IP address.
ACL based on device
ACL based on interface
ACL based on flow from the ingress interface to egress interface
ACL based on VLAN
Command
Raisecom#config
Raisecom Proprietary and Confidential
Copyright © Raisecom Technology Co., Ltd.
Description
Enter global configuration
mode.
10 Security
398

Advertisement

Table of Contents
loading

Table of Contents