Chapter 12
| Security Measures
Access Control Lists
– 325 –
◆ Type – The following filter modes are supported:
■
IP Standard: IPv4 ACL mode filters packets based on the source IPv4
address.
■
IP Extended: IPv4 ACL mode filters packets based on the source or
destination IPv4 address, as well as the protocol type and protocol port
number. If the “TCP” protocol is specified, then you can also filter packets
based on the TCP control code.
■
IPv6 Standard: IPv6 ACL mode filters packets based on the source IPv6
address.
■
IPv6 Extended: IPv6 ACL mode filters packets based on the source or
destination IP address, as well as DSCP, and the next header type.
■
MAC – MAC ACL mode filters packets based on the source or destination
MAC address and the Ethernet frame type (RFC 1060).
■
ARP – ARP ACL specifies static IP-to-MAC address bindings used for ARP
inspection (see “ARP Inspection” on page 341).
Web Interface
To configure the name and type of an ACL:
1. Click Security, ACL.
2. Select Configure ACL from the Step list.
3. Select Add from the Action list.
4. Fill in the ACL Name field, and select the ACL type.
5. Click Apply.
Figure 198: Creating an ACL