D-Link DWS-4026 [351/741] Section 7 configuring access control lists

D-Link DWS-4026 [351/741] Section 7 configuring access control lists
ConfiguringAccessControlLists
D-Link UnifiedWiredandWirelessAccessSystem
November2011 Page351
DLinkUWSUserManual
Section7:ConfiguringAccessControlLists
AccessControlLists(ACLs)ensurethatonlyauthorizedusershaveaccesstospecificresourceswhileblocking
offanyunwarrantedattemptstoreachnetworkresources.ACLsareusedtoprovidetrafficflowcontrol,restrict
contentsofroutingupdates,decidewhichtypesoftrafficareforwardedorblocked,andaboveallprovide
securityfo
rthenetwork.DLinkDWS4000SeriessoftwaresupportsIPv4andMACACLs.Thetotalnumberof
MACandIPACLssupportedbyDLinkDWS4000Seriessoftwareis100.
TheAccessControlListsfoldercontainslinkstothefollowingfoldersandwebpages:
“ConfiguringIPAccessControlLists”
“M
ACAccessContr olLists”
“ACLInterfaceConfiguration”
YoufirstcreateanIPv4basedorMACbasedruleandassignauniqueACLID.Then,youdefinetherules,which
canidentifyprotocols,sourceanddestinationIPandMACaddresses,andotherpacketmatchingcriteria.
Finally,youusetheIDnumbertoas
signtheACLtoaport.
ConfiguringIPAccessControlLists
IPaccesscontrollists(ACL)allownetworkmanagerstodefineclassificationactionsandrulesforspecificports.
ACLsarecomposedofaccesscontrolentries(ACE),orrules,thatconsistofthefiltersthatdeterminetraffic
classifications.ThetotalnumberofrulesthatcanbedefinedforeachACLis12.Theserule
sarematched
sequentiallyagainstapacket.Whenapacketmeetsthematchcriteriaofarule,thespecifiedruleaction
(Permit/Deny)istaken,includingdroppingthepacketordisablingtheport,andtheadditionalrulesarenot
checkedforamatch.Forexample,anetworkadministratordefinesanACLruletha
tsaysportnumber20can
receiveTCPpackets.Howev er,ifaUDPpacketisreceivedthepacketisdropped.
ToconfigureanACL:
1. Usethe“IPACLConfiguration”pagetodefinetheIPACLtypeandassignanIDtoit.
2. Usethe“IPACLRuleConfiguration”pagetocr
eaterulesfortheACL.
3. Usethe“ACLInterfaceConfiguration”pagetoassigntheACLbyitsIDnumbertoaport.

Содержание

Похожие устройства

Скачать