Creating Ipv4-Acls Or Ipv6-Acls With The Ip-Acl Wizard - HP Cisco MDS 9216 - Fabric Switch Configuration Manual

Cisco mds 9000 family fabric manager configuration guide, release 3.x (ol-8222-10, april 2008)
Hide thumbs Also See for Cisco MDS 9216 - Fabric Switch:
Table of Contents

Advertisement

Chapter 42
Configuring IPv4 and IPv6 Access Control Lists
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m

Creating IPv4-ACLs or IPv6-ACLs with the IP-ACL Wizard

Traffic coming into the switch is compared to IPv4-ACL or IPv6-ACL filters based on the order that the
filters occur in the switch. New filters are added to the end of the IPv4-ACL or the IPv6-ACL. The switch
keeps looking until it has a match. If no matches are found when the switch reaches the end of the filter,
the traffic is denied. For this reason, you should have the frequently hit filters at the top of the filter.
There is an implied deny for traffic that is not permitted. A single-entry IPv4-ACL or IPv6-ACL with
only one deny entry has the effect of denying all traffic.
To configure an IPv4-ACL or an IPv6-ACL, you must complete the following tasks:
Step 1
Create an IPv4-ACL or an IPv6-ACL by specifying a filter name and one or more access condition(s).
Filters require the source and destination address to match a condition. Use optional keywords to
configure finer granularity.
Note
Step 2
Apply the access filter to specified interfaces.
To create an ordered list of IP filters in a named IPv4-ACL or IPv6-ACL profile using the IPv4-ACL
Wizard in Fabric Manager, follow these steps:
Click the IP ACL Wizard icon from the Fabric Manager toolbar (see
Step 1
Figure 42-1
You see the IP ACL Wizard.
Enter a name for the IP-ACL.
Step 2
Note
Click Add to add a new rule to this IP-ACL. You see a new rule in the table with default values.
Step 3
Modify the Source IP and Source Mask as necessary for your filter.
Step 4
Note
Choose the appropriate filter type from the Application drop-down list.
Step 5
Step 6
Choose permit or deny from the Action drop-down list.
Step 7
Repeat
OL-16184-01, Cisco MDS SAN-OS Release 3.x
The filter entries are executed in sequential order. You can only add the entries to the end of the
list. Take care to add the entries in the correct order.
IP ACL Wizard
If you are creating an IPv6-ACL, check the IPv6 check box.
The IP-ACL Wizard only creates inbound IP filters.
Step 3
through
Step 6
for additional IP filters.
Creating IPv4-ACLs or IPv6-ACLs with the IP-ACL Wizard
Figure
42-1).
Cisco MDS 9000 Family CLI Configuration Guide
42-5

Advertisement

Table of Contents
loading

Table of Contents