Planet XGS3-42000R User Manual page 465

4-slot layer 3 ipv6/ ipv4 routing chassis switch
Table of Contents

Advertisement

The number of ACLs that can be successfully bound depends on the content of the A CL bound and the
hardware resource limit. Users will be prompted if an A CL cannot be bound due to hardware res ourc e
limitation.
If an access-list contains same filtering information but conflicting action rules, binding to the port will
fail with an error message. For instance, configuring "permit tcp any any-destination" and "deny tcp any
any-destination" at the same time is not permitted.
Viruses such as "worm. blaster" can be blocked by configuring A CL to block specific ICMP packets or
specific TCP or UDP port packet.
If the physical mode of an interface is TRUNK, ACL can only be configured through physical interfac e
mode.
ACL configured in the physical mode can only be disabled in the physical mode. Those configured in
the VLAN interface configuration mode can only be disabled in the VLAN int erface mode.
When a physical interface is added into or removed from a VLAN (with the trunk interfac es as
exceptions), A CL configured in t he corres ponding VLA N will be bound or unbound respectively. If A CL
configured in the target VLA N, which is configured in VLA N interface mode, conflicts with existing A CL
configuration on t he int erface, which is configured in physical interface mode, the configuration will fail
to effect.
When no physical interfac es are configured in the V LAN, the ACL c onfiguration of the VLA N will be
removed. And it can not recover if new interfaces are added to the VLA N.
When the interface mode is changed from access mode to trunk mode, the ACL configured in VLA N
interface mode which is bound to physical interface will be removed. And when the interface mode is
changed from trunk mode to access mode, ACL configured in VLAN1 interface mode will be bound to
the physical interface. If binding fails, the changing will fail either.
When removing a VLA N configuration, if there are any A CLs bound to the VLA N, the ACL will be
removed from all the physical interfaces belonging to the VLAN, and it will be bound to VLA N 1 A CL(if
ACL is configured in VLAN1). If VLA N 1 ACL binding fails, the VLAN removal operation will fail..
46-21

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents