SNR S2989G-24TX-UPS — настройка функций безопасности с помощью ACL в сетевых устройствах [274/553]

Превью страниц Страница 274 / 553
SNR S2989G-24TX-UPS [274/553] Introduction to acl
S2989G-24TX Operation Manual
Chapter 6 Security Function Configuration
6-1
Chapter 6 Security Function
Configuration
6.1
ACL
6.1.1
Introduction to ACL
ACL (Access Control List) is an IP packet filtering mechanism employed in switches,
providing network traffic control by granting or denying access the switches, effectively
safeguarding the security of networks. The user can lay down a set of rules according to
some information specific to packets, each rule describes the action for a packet with
certain information matched: “permit” or “deny”. The user can apply such rules to the
incoming direction of switch ports, so that data streams in the incoming direction of
specified ports must comply with the ACL rules assigned.
6.1.1.1 Access-list
Access-list is a sequential collection of conditions that corresponds to a specific rule.
Each rule consist of filter information and the action when the rule is matched. Information
included in a rule is the effective combination of conditions such as source IP, destination
IP, IP protocol number and TCP port, UDP port. Access-lists can be categorized by the
following criteria:
Filter information based criterion: IP access-list (layer 3 or higher information),
MAC access-list (layer 2 information), and MAC-IP access-list (layer 2 or layer 3
or higher).
Configuration complexity based criterion: standard and extended, the extended
mode allows more specific filtering of information.
Nomenclature based criterion: numbered and named.
Description of an ACL should cover the above three aspects.
6.1.1.2 Access-group
When a set of access-lists are created, they can be applied to traffic of incoming

Содержание

666

Изучите, как использовать списки контроля доступа (ACL) для управления сетевым трафиком и повышения безопасности в сетевых устройствах. Узнайте о правилах и фильтрации.