142
C
7: Q
S/ACL O
HAPTER
O
ACL Supported by
Ethernet Switch
Configuring ACL
PERATION
For basic ACL statements, source address wildcards are compared directly. If
■
the wildcards are the same, the configuration sequence is used.
For the ACL based on the interface filter, the rule that is configured with any is
■
listed at the end, while others follow the configuration sequence.
For the advanced ACL, source address wildcards are compared first. If they are
■
the same, then destination address wildcards are compared. For the same
destination address wildcards, ranges of port numbers are compared and the
smaller range is listed first. If the port numbers are in the same range, the
configuration sequence is used.
For the Switch 7700, ACLs are divided into the following categories:
Numbered basic ACL
■
Named basic ACL
■
Numbered advanced ACL
■
Named advanced ACL
■
Numbered interface ACL
■
Named interface ACL.
■
Numbered Layer-2 ACL
■
Named Layer-2 ACL
■
The Table 1 lists the limits to the numbers of different ACL on a switch
Table 1 Quantitative Limitation to the ACL
Item
Numbered basic ACL
Numbered advanced ACL
Numbered Layer-2 ACL
Numbered interface ACL
Named basic ACL
Named advanced ACL
Named interface ACL.
Named Layer-2 ACL.
The sub items of an ACL
Maximum sub items for all
ACL ( for Salience I )
Maximum sub items for all
ACL ( for iSalience I )
Maximum sub items for all
ACL ( for Salience II )
ACL configuration includes the tasks described in the following sections:
Configuring the Time Range
■
Selecting the ACL Mode
■
Defining ACL
■
Value range
1 to 99
100 to 199
200 to 299
1000 to 1999
-
-
-
-
0 to 127
-
-
-
.
.
Maximum
99
100
100
1000
1000
1000
1000
1000
128
1536
768
1536