SNR S2989G-48TX-RPS — настройка функций безопасности и VLAN-ACL в сетевых устройствах [339/553]

Превью страниц Страница 339 / 553
SNR S2989G-48TX-DC [339/553] Vlan acl
S2989G-24TX Operation Manual
Chapter 6 Security Function Configuration
6-66
In configuring and using SSL, the SSL function may fail due to reasons such as
physical connection failure or wrong configurations. The user should ensure the following:
First good condition of the physical connection;
Second all interface and link protocols are in the UP state (use
“show interface” command);
Then, make sure SSL function is enabled (use ip http secure-
server command );
Don’t use the default port number if configured port number, pay
attention to the port number when input the web wide;
If SSL is enabled, SSL should be restarted after changes on the
port configuration and encryption configuration;
IE 7.0 or above should be used for use of des-cbc-sha;
If the SSL problems remain unsolved after above try, please use
debug SSL and other debugging command and copy the DEBUG
message within 3 minutes, send the recorded message to technical
server center of our company.
6.8
VLAN-ACL
6.8.1
Introduction to VLAN-ACL
The user can configure ACL policy to VLAN to implement the accessing control of all
ports in VLAN, and VLAN-ACL enables the user to expediently manage the network. The
user only needs to configure ACL policy in VLAN, the corresponding ACL action can takes
effect on all member ports of VLAN, but it does not need to solely configure on each
member port.
When VLAN ACL and Port ACL are configured at the same time, the principle of
denying firstly is used. When the packets match VLAN ACL and Port ACL at the same
time, as long as one rule is drop, then the final action is drop.
Egress ACL can implement the filtering of the packets on egress and ingress direction,
the packets match the specific rules can be allowed or denied. ACL can support IP ACL,
MAC ACL, MAC-IP ACL, IPv6 ACL. Ingress direction of VLAN can bind four kinds of ACL
at the same time, there are four resources on egress direction of VLAN, IP ACL and MAC
ACL engage one resource severally, MAC-IP ACL and IPv6 ACL engage two resources
severally, so egress direction of VLAN can not bind four kinds of ACL at the same time.
When binding three kinds of ACL at the same time, it should be the types of IP, MAC,
MAC-IP or IP, MAC, IPv6. When binding two kinds of ACL at the same time, any

Содержание

666

Узнайте, как правильно настраивать функции безопасности, такие как SSL, и управлять VLAN-ACL для эффективного контроля доступа в сети. Следуйте рекомендациям для устранения проблем.