EasyManuals Logo
Home>Cisco>Switch>SF352-08P

Cisco SF352-08P Administration Guide

Cisco SF352-08P
762 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #616 background imageLoading...
Page #616 background image
Access Control
Overview
396 Cisco 350, 350X and 550X Series Managed Switches, Firmware Release 2.4, ver 0.4
22
Up to 256 ACEs can be configured on a single port or in a single ACL.
When a packet matches an ACE filter, the ACE action is taken and that ACL processing is
stopped. If the packet does not match the ACE filter, the next ACE is processed. If all ACEs of
an ACL have been processed without finding a match, and if another ACL exists, it is
processed in a similar manner.
NOTE If no match is found to any ACE in all relevant ACLs, the packet is dropped (as a default
action). Because of this default drop action you must explicitly add ACEs into the ACL to
permit the desired traffic, including management traffic, such as Telnet, HTTP or SNMP that is
directed to the device itself. For example, if you do not want to discard all the packets that do
not match the conditions in an ACL, you must explicitly add a lowest priority ACE into the
ACL that permits all the traffic.
If IGMP/MLD snooping is enabled on a port bound with an ACL, add ACE filters in the ACL
to forward IGMP/MLD packets to the device. Otherwise, IGMP/MLD snooping fails at the
port.
The order of the ACEs within the ACL is significant, since they are applied in a first-fit
manner. The ACEs are processed sequentially, starting with the first ACE.
ACLs can be used for security, for example by permitting or denying certain traffic flows, and
also for traffic classification and prioritization in the QoS Advanced mode.
NOTE A port can be either secured with ACLs or configured with advanced QoS policy, but not both.
There can only be one ACL per port, with the exception that it is possible to associate both an
IP-based ACL and an IPv6-based ACL with a single port.
To associate more than one ACL with a port, a policy with one or more class maps must be
used.
The following types of ACLs can be defined (depending on which part of the frame header is
examined):
• MAC ACL—Examines Layer 2 fields only, as described in Defining MAC-based
ACLs
Sx550X 3K 3K
SG350XG/SX350X 2K 2K
SG350 and Sx350 1K 1K
Sx250 512 512
Device Max ACLs Max ACEs

Table of Contents

Other manuals for Cisco SF352-08P

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco SF352-08P and is the answer not in the manual?

Cisco SF352-08P Specifications

General IconGeneral
BrandCisco
ModelSF352-08P
CategorySwitch
LanguageEnglish

Related product manuals