Chapter7ServiceConguration
ACLConfiguration
ACLOverview
AnAccessControlList(ACL)isasequentialcollectionofpermit
anddenyconditionsthatapplytopackets.Whenapacketisre-
ceivedonaninterface,theswitchcomparestheeldsinthepacket
againstanyappliedACL’stoverifythatthepackethastherequired
permissionstobeforwarded,basedonthecriteriaspeciedinthe
accesslists.Ittestspacketsagainsttheconditionsinanaccess
listonebyone.Therstmatchdetermineswhethertheswitch
acceptsorrejectsthepacketsbecausetheswitchstopstesting
conditionsaftertherstmatch.Theorderofconditionsinthelist
iscritical.Ifnoconditionsmatch,theswitchrejectsthepackets.
Iftherearenorestrictions,theswitchforwardsthepacket.oth-
erwise,theswitchdropsthepacket.
ZXR102920/2928/2952/2936-FIsupportsthefollowingfunctions.
1.ZXR102920/2928/2952/2936-FIprovidestwobindingtypes
includingphysicalportandTrunkGroups.Whenaphysicalport
isaddedintoaTrunkGroupsandhasbeenboundedanACL,
currentboundwillbereleasedrst,otherwise,afalsemessage
willreturn.WhenACLisappliedtoTrunkGroups,physicalport
willbeboundwithACLautomatically.
2.ACLrulecanbeadded,deleted,sorted.
i.RulecanbeaddedtoaconguredACL.RegularIDnumber
rangeis1-500.
ii.ConguredACLcanbedeletedregularly.Ifthespecied
ACLinstancenumberorrulenumberhasn’tbeencong-
ured,afalsemessagewillreturn.
iii.ManyrulesofanACLcanbesortedandonlyneedtospecify
theplacewhererulenumberneedtobemoved.
3.AnACLcanbecomevalidaccordingtoconguredtimerange.
Afterconguringabsoluteorrelativetimerangeontheswitch,
timerangecanbeappliedtotheruleofACL.Thiscausesthe
ruletobevalidaccordingtothetimerangespecication.
4.ZXR102920/2928/2952/2936-FIprovidesthefollowingve
typesofACLs:
i.BasicACL:OnlymatchsourceIPaddress.
ii.ExtendedACL:MatchsourceIPaddress,destinationIPad-
dress,IPprotocoltype,TCPsourceportnumber ,TCPdes-
tinationportnumber ,UDPsourceportnumber ,UDPdes-
tinationportnumber ,ICMPtype,ICMPCodeandDiffServ
CodePoint(DSCP).
iii.L2ACL:MatchsourceMACaddress,destinationMACad-
dress,sourceVLANIDand802.1ppriorityvalue.
iv.MatchSourceIPV4/IPV6address,destinationIPV4/IPV6
address,IPprotocoltype,TCPsourceportnumber ,TCP
destinationportnumber ,UDPsourceportnumber ,UDP
destinationportnumber ,DiffServCodePoint(DSCP),
CondentialandProprietaryInformationofZTECORPORATION147