C
HAPTER
13
| Security Measures
Access Control Lists
– 287 –
◆ Type – The following filter modes are supported:
■
IP Standard: IPv4 ACL mode filters packets based on the source
IPv4 address.
■
IP Extended: IPv4 ACL mode filters packets based on the source
or destination IPv4 address, as well as the protocol type and
protocol port number. If the “TCP” protocol is specified, then you
can also filter packets based on the TCP control code.
■
IPv6 Standard: IPv6 ACL mode filters packets based on the source
IPv6 address.
■
IPv6 Extended: IPv6 ACL mode filters packets based on the
source or destination IP address, as well as the type of the next
header and the flow label (i.e., a request for special handling by
IPv6 routers).
■
MAC – MAC ACL mode filters packets based on the source or
destination MAC address and the Ethernet frame type (RFC 1060).
■
ARP – ARP ACL specifies static IP-to-MAC address bindings used for
ARP inspection (see "ARP Inspection" on page 301).
WEB INTERFACE
To configure the name and type of an ACL:
1. Click Security, ACL.
2. Select Configure ACL from the Step list.
3. Select Add from the Action list.
4. Fill in the ACL Name field, and select the ACL type.
5. Click Apply.
Figure 154: Creating an ACL
To show a list of ACLs:
1. Click Security, ACL.
2. Select Configure ACL from the Step list.