C
HAPTER
4
| Configuring the Switch
Access Control Lists
– 126 –
■
IP Fragment - Specifies the fragment offset settings for this rule.
This involves the settings for the More Fragments (MF) bit and the
Fragment Offset (FRAG OFFSET) field for an IPv4 frame. (Options:
Any - any value is allowed, Yes - IPv4 frames where the MF bit is set
or the FRAG OFFSET field is greater than zero must match this
entry, No - IPv4 frames where the MF bit is set or the FRAG OFFSET
field is greater than zero must not match this entry; Default: Any)
■
IP Option - Specifies the options flag setting for this rule. (Options:
Any - any value is allowed, Yes - IPv4 frames where the options flag
is set must match this entry, No - IPv4 frames where the options
flag is set must not match this entry; Default: Any)
■
SIP Filter - Specifies the source IP filter for this rule.
(Options: Any - no source IP filter is specified, Host - specifies the
source IP address in the SIP Address field, Network - specifies the
source IP address and source IP mask in the SIP Address and SIP
Mask fields; Default: Any)
■
DIP Filter - Specifies the destination IP filter for this rule.
(Options: Any - no destination IP filter is specified, Host - specifies
the destination IP address in the DIP Address field, Network -
specifies the destination IP address and destination IP mask in the
DIP Address and DIP Mask fields; Default: Any)
Response to take when a rule is matched
◆ Action - Permits or denies a frame based on whether it matches an
ACL rule. (Default: Permit)
◆ Rate Limiter - Specifies a rate limiter (page 119) to apply to the port.
(Range: 1-14; Default: Disabled)
◆ Port Copy - Defines a port to which matching frames are copied.
(Range: 1-28; Default: Disabled)
◆ Logging - Enables logging of matching frames to the system log.
(Default: Disabled)
Open the System Log Information menu (page 148) to view any entries
stored in the system log for this entry. Related entries will be displayed
under the “Info” or “All” logging levels.
◆ Shutdown - Shuts down a port when a macthing frame is seen.
(Default: Disabled)
◆ Counter - Shows he number of frames which have matched any of the
rules defined for this ACL.
VLAN Parameters
◆ VLAN ID Filter - Specifies the VLAN to filter for this rule.
(Options: Any, Specific (1-4095); Default: Any)