Qtech QSW-3300-28F-AC-AC [629/693] Ip access control list commands

Qtech QSW-3300-28F-AC-AC [629/693] Ip access control list commands
IP Access Control List Commands
Software User Manual
CLI Command Reference
Page 646
ACL Name: mac1
Outbound Interface(s): control-plane
Sequence Number: 10
Action.............................permit
Source MAC Address................ 00:00:00:00:AA:BB
Source MAC Mask....................FF:FF:FF:FF:00:00
Committed Rate.....................32
Committed Burst Size...............16
Sequence Number: 25
Action.............................permit
Source MAC Address................ 00:00:00:00:AA:BB
Source MAC Mask....................FF:FF:FF:FF:00:00
Destination MAC Address........... 01:80:C2:00:00:00
Destination MAC Mask...............00:00:00:FF:FF:FF
Ethertype..........................ipv6
VLAN...............................36
CoS Value..........................7
Assign Queue.......................4
Redirect Interface.................0/34
Committed Rate.....................32
Committed Burst Size...............16
IP Access Control List Commands
This section describes the commands you use to configure IP Access Control List (ACL) settings. IP ACLs
ensure that only authorized users have access to specific resources and block any unwarranted attempts to
reach network resources.
The following rules apply to IP ACLs:
Switch software does not s
upport IP ACL configuration for IP packet fragments.
The maximum number of ACLs you can c
reate is hardware dependent. The limit applies to all ACLs,
regardless of type.
The maximum number of rules per IP ACL is
hardware dependent.
On 5630x platforms, if you configure a MAC ACL on an interface, you cannot configure an IP ACL on the
same interfac
e.
Wildcard masking for ACLs operates differently from a subnet mask. A wildcard mask is in essence the
inverse of a subnet mask. With a subnet mask, the mask has ones (1's) in the bit positions that are used for
the network address, and has zeros (0's) for the bit positions that are not used. In contrast, a wildcard mask
has (0’s) in a bit position that must be check
ed. A 1 in a bit position of the ACL mask indicates the
corresponding bit can be ignored.

Содержание

Скачать