Filtering Traffic With Access Control Lists; Assigning Acl Policies And Responses - AMX NXA-ENET8-2POE Operation/Reference Manual

Gigabit ethernet layer 2 poe switch
Hide thumbs Also See for NXA-ENET8-2POE:
Table of Contents

Advertisement

Filtering Traffic With Access Control Lists

An Access Control List (ACL) is a sequential list of permit or deny conditions that apply to IP addresses, MAC
addresses, or other more specific criteria.
The NXA-ENET8-2POE tests ingress packets against the conditions in an ACL one by one. A packet will be
accepted as soon as it matches a permit rule, or dropped as soon as it matches a deny rule. If no rules match,
the frame is accepted.
Other actions can also be invoked when a matching packet is found, including rate limiting, copying matching
packets to another port or to the system log, or shutting down a port.

Assigning ACL Policies and Responses

Use the ACL Port Configuration page to define a port to which matching frames are copied, enable logging, or
shut down a port when a matching frame is seen. Note that rate limiting (configured with the Rate Limiter
menu, see page 72) is implemented regardless of whether or not a matching packet is seen.
FIG. 53
ACL Port Configuration
ACL Port Configuration parameters
• Port
• Policy ID
• Action
• Rate Limiter ID
• Redirect to
• Mirror
• Logging
• Shutdown
• Counter
NXA-ENET8-2POE Gigabit Ethernet Layer 2 PoE Switch
Port Identifier.
An ACL policy configured on the ACL Configuration page (see page 71).
(Range: 1-8; Default: 1, which is undefined)
Permits or denies a frame based on whether it matches a rule defined in the
assigned policy. (Default: Permit)
Specifies a rate limiter (page 72) to apply to the port. (Range: 1-15; Default:
Disabled)
Defines a port to which matching frames are re-directed. (Range: 1-28; Default:
Disabled) To use this function, Action must be set to Deny for the local port.
Mirrors matching frames from this port. (Default: Disabled) To use this function,
the destination port to which traffic is mirrored must be configured on the Mirror
Configuration page (see the Configuring Port Mirroring section on page 140).
ACL-based port mirroring set by this parameter and port mirroring set on the gen-
eral Mirror Configuration page are implemented independently. To use ACL-based
mirroring, enable the Mirror parameter on the ACL Ports Configuration page. Then
open the Mirror Configuration page, set the Port to mirror on field to the required
destination port, and leave the Mode field Disabled.
Enables logging of matching frames to the system log. (Default: Disabled)
Open the System Log Information menu (page 199) to view any entries stored in
the system log for this entry. Related entries will be displayed under the Info or All
logging levels.
Shuts down a port when a matching frame is seen. (Default: Disabled)
The number of frames which have matched any of the rules defined in the
selected policy.
Configuring the NXA-ENET8-2POE
71

Advertisement

Table of Contents
loading

Table of Contents