Ways To Apply An Acl On A Switch; Types Of Acls Supported By S5600 Series Ethernet Switches - H3C S5600 Series Operation Manual

Hide thumbs Also See for S5600 Series:
Table of Contents

Advertisement

If the types of parameter are the same for multiple rules, then the sum of parameters'
weighting values of a rule determines its priority. The smaller the sum, the higher the
match priority.

Ways to Apply an ACL on a Switch

Being applied to the hardware directly
In the switch, an ACL can be directly applied to hardware for packet filtering and traffic
classification. In this case, the rules in an ACL are matched in the order determined by the
hardware instead of that defined in the ACL. For S5600 series Ethernet switches, the later
the rule applies, the higher the match priority.
ACLs are directly applied to hardware when they are used for:
Implementing QoS
Filtering the packets to be forwarded
Being referenced by upper-level software
ACLs can also be used to filter and classify the packets to be processed by software. In this
case, the rules in an ACL can be matched in one of the following two ways:
config, where rules in an ACL are matched in the order defined by the user.
auto, where the rules in an ACL are matched in the order determined by the system,
namely the "depth-first" order (Layer 2 ACLs, user-defined ACLs and IPv6 ACLs do not
support this feature).
When applying an ACL in this way, you can specify the order in which the rules in the ACL
are matched. The match order cannot be modified once it is determined, unless you delete
all the rules in the ACL and define the match order.
An ACL can be referenced by upper-layer software:
Referenced by routing policies
Used to control Telnet, SNMP and Web login users
When an ACL is directly applied to hardware for packet filtering, the switch will permit
packets if the packets do not match the ACL.
When an ACL is referenced by upper-layer software to control Telnet, SNMP and Web
login users, the switch will deny packets if the packets do not match the ACL.

Types of ACLs Supported by S5600 Series Ethernet Switches

The following types of ACLs are supported by S5600 series Ethernet switches:
Basic ACL
1-3

Hide quick links:

Advertisement

Chapters

Table of Contents
loading

This manual is also suitable for:

S5600-26cS5600-26c-pwrS5600-26fS5600-50cS5600-50c-pwr

Table of Contents