•
This switch supports ACLs for ingress filtering only. You can only
bind one IP ACL to any port and one MAC ACL globally for ingress
filtering. In other words, only two ACLs can be bound to an
interface - Ingress IP ACL and Ingress MAC ACL.
The order in which active ACLs are checked is as follows:
1. User-defined rules in the Ingress MAC ACL for ingress ports.
2. User-defined rules in the Ingress IP ACL for ingress ports.
3. Explicit default rule (permit any any) in the ingress IP ACL for ingress
ports.
4. Explicit default rule (permit any any) in the ingress MAC ACL for
ingress ports.
5. If no explicit rule is matched, the implicit default is permit all.
Command
Groups
IP ACLs
MAC ACLs
ACL Information Displays ACLs and associated rules; shows ACLs
IP ACLs
Command
access-list ip
permit, deny
permit, deny
Table 4-33 Access Control Lists
Function
Configures ACLs based on IP addresses, TCP/UDP
port number, protocol type, and TCP control code
Configures ACLs based on hardware addresses, packet
format, and Ethernet type
assigned to each port
Table 4-34 IP ACLs
Function
Creates an IP ACL and enters configuration
mode
Filters packets matching a specified source
IP address
Filters packets meeting the specified criteria,
including source and destination IP address,
TCP/UDP port number, protocol type, and
TCP control code
A
C
CCESS
ONTROL
L
C
IST
OMMANDS
Page
4-117
4-127
4-133
Mode
Page
GC
4-118
STD-ACL 4-119
EXT-ACL 4-120
4-117
Need help?
Do you have a question about the SMC TigerStack IV SMC6224M and is the answer not in the manual?
Questions and answers