Chapter8
ACLConguration
ThenetworkdevicesusetheAccessControlList(ACL)tolterthedatapacketsandcontrol
thepolicyroutesandspecialows.ACLsetsaseriesofmatchingrulestoidentifythe
objectstobeltered,andpermitsordeniesthecorrespondingdatapackettopassthrough
accordingtothepresetpolicies.
AnACLcancontainoneormorerules.Theserulesenablethedevicetopermitordeny
thematchingtrafcaccordingtospecicparameters.AnACLcomparesthetrafcwith
eachruletillitndsamatchedrule.ThelastruleinanACLisanimplicitdenyrule.
OneinterfacesupportsonlyoneACL.
TheZXA10C300supportsthefollowingfourtypesofACLs:
lStandardACL
ThestandardACLisonlymatchedbythesourceIPaddress.
lExtendedACL
TheextendedACLismatchedbythesourceIPaddress,destinationIPaddress,
IPprotocoltype,TCP/UDPsource/destinationportnumber,ICMPtype,IGMPtype,
DSCP,T oS,andIPpriority.
lLayer-2ACL
Thelayer-2ACLismatchedbythesourceMACaddress,destinationMACaddress,
sourceVLANID,layer-2Ethernetprotocoltype,and802.1ppriorityvalue.
lHybridACL
ThehybridACLismatchedbythesourceMACaddress,destinationMAC
address,sourceVLANID,sourceIPaddress,destinationIPaddress,TCP/UDP
source/destinationportnumber,includingallthematchingeldsofthepreceding
threetypes.
lIPv6hybridACL
ItistheIPv6-basedhybridACL.
TableofContents
ConguringaStandardACL.......................................................................................8-2
ConguringanExtendedACL....................................................................................8-3
ConguringaLayer-2ACL.........................................................................................8-4
ConguringaHybridACL...........................................................................................
8-6
ConguringanIPv6HybridACL.................................................................................8-7
8-1
SJ-20130520164529-007|2013-06-30(R1.0)ZTEProprietaryandCondential