Qtech QSW-8200-52T-AC [20/114] Ip ipv6 mac mac ip access group interface mode

Qtech QSW-8200-52T-AC [20/114] Ip ipv6 mac mac ip access group interface mode
User Manual
Chapter 1. Commands for ACL 20
www.qtech.ru
ACL. Ingress direction of the port can bind four kinds of ACL at the same time, there are
four resources on egress direction of the port, IP ACL and MAC ACL engage one
resource severally, MAC-IP ACL and IPv6 ACL engage two resources severally, so egress
direction of the port can not bind four kinds of ACL at the same time. When binding
three kinds of ACL at the same time, it should be the types of IP, MAC, MAC-IP or IP,
MAC, IPv6. When binding two kinds of ACL at the same time, any combination of ACL
type is valid. Each type can only apply one on the port.
At present, notice the following contents when binding Egress ACL to port.
IP ACL that match tcp/udp range can not be bound
MAC-IP ACL that match tcp/udp range can not be bound
IP ACL that match flowlabel can not be bound
There are four kinds of packet head field based on concerned: MAC ACL, IP ACL, MAC-IP
ACL and IPv6 ACL; to some extent, ACL filter behavior (permit, deny) has a conflict when
a data packet matches multi types of four ACLs. The strict priorities are specified for
each ACL based on outcome veracity. It can determine final behavior of packet filter
through priority when the filter behavior has a conflict.
When binding ACL to port, there are some limits as below:
Each port can bind a MAC-IP ACL, a IP ACL, a MAC ACL and a IPv6 ACL;
When binding four ACLs and data packet matching the multi ACLs simultaneity, the
priority from high to low are shown as below,
o Ingress IPv6 ACL
o Ingress MAC-IP ACL
o Ingress MAC ACL
o Ingress IP ACL
Example: Binding AAA access-list to entry direction of port.
Switch(Config-If-Ethernet1/0/5)#ip access-group aaa in
1.18 {ip|ipv6|mac|mac-ip} access-group (Interface Mode)
This command is not supported by switch.
1.19 mac access extended
Command: mac-access-list extended <name>
no mac-access-list extended <name>
Functions: Define a name-manner MAC ACL or enter access-list configuration mode,
no mac-access-list extended <name>” command deletes this ACL.
Parameters: <name> name of access-list excluding blank or quotation mark, and it
must start with letter, and the length cannot exceed 32. (remark: sensitivity on capital
or small letter.)
Command Mode: Global mode

Содержание

Похожие устройства