3Com SuperStack 4 Configuration Manual page 194

5500g-ei family
Hide thumbs Also See for SuperStack 4:
Table of Contents

Advertisement

206
C
8: ACL C
HAPTER
ONFIGURATION
ACL Supported by the
Switch
Configuring ACL
specifies the match-order of an access control rule, it cannot be modified later,
unless all the content is deleted and the match-order specified again.
The case includes: ACL cited by route policy function, ACL used for control logon
user, and so on.
The depth-first principle is to put the statement specifying the smallest range of
packets on the top of the list. This can be implemented through comparing the
wildcards of the addresses. The smaller the wildcard is, the less hosts it can specify.
For example, 129.102.1.1 0.0.0.0 specifies a host, while 129.102.1.1 0.0.255.255
specifies a network segment, 129.102.0.1 through 129.102.255.255. Obviously,
the former one is listed ahead in the access control list.
The specific standard is as follows.
For basic access control list statements, compare the source address wildcards
directly. If the wildcards are the same, follow the configuration sequence.
For the advanced access control list, compare the source address wildcards first. If
they are the same, then compare the destination address wildcards. For the same
destination address wildcards, compare the ranges of port numbers, the one with
the smaller range is listed ahead. If the port numbers are in the same range, follow
the configuration sequence.
The table below lists the limits to the numbers of different types of ACL on a
Switch.
Table 223 Quantitative Limitation to the ACL
Item
Numbered basic ACL.
Numbered advanced ACL.
Numbered Layer-2 ACL.
Numbered user-defined ACL.
The sub items of an ACL
ACL configuration includes:
Configuring Time-Range
Defining ACL
Activating ACL
The above three steps must be done in sequence. Configure the time range first
and then define the ACL (using the defined time range in the definition), then
activate the ACL to validate it.
Configuring Time-Range
The process of configuring a time-range includes: configuring the hour-minute
range, date ranges and period range. The hour-minute range is expressed in units
of minute, hour. Date range is expressed in units of minute, hour, date, month and
year. The periodic time range is expressed as the day of the week.
Value range
2000 to 2999
3000 to 3999
4000 to 4999
5000 to 5999
0 to 65534

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Superstack 4 5500g-ei series

Table of Contents