Chapter5ServiceConguration
5.11ACLConguration
ACLOverview
AnAccessControlList(ACL)isasequentialcollectionofpermissionsthatapplyto
packets.Whenapacketisreceivedonaninterface,theswitchcomparestheeldsin
thepacketagainstappliedACLstoverifythatthepackethastherequiredpermissionsto
beforwarded,basedonthecriteriaspeciedintheaccesslists.Ittestspacketsagainst
theconditionsinanaccesslistonebyone.Therstmatchdetermineswhetherthe
switchacceptsorrejectsthepacketsbecausetheswitchstopstestingconditionsafter
therstmatch.Theorderofconditionsinthelistiscritical.Ifnoconditionsmatch,the
switchrejectsthepackets.Iftherearenorestrictions,theswitchforwardsthepacket.
Otherwise,theswitchdropsthepacket.
TheZXR105250supportsthefollowingfunctions.
lTheZXR105250providestwobindingtypes,includingphysicalportandVLANport.
lACLrulescanbeadded,deleted,andsorted.
1.RulescanbeaddedtoaconguredACL.RegularIDnumberrangeis1-500.
2.ConguredACLcanbedeletedregularly.IfthespeciedACLinstancenumber
orrulenumberisnotcongured,afalsemessagewillreturn.
3.ManyrulesofanACLcanbesorted.Itisnecessarytospecifythepositionwhere
arulenumbershouldbemoved.
lAnACLcanbecomevalidaccordingtotheconguredtimerange.Afterconguring
absoluteorrelativetimerangeontheswitch,thetimerangecanbeappliedtotherule
oftheACL.Thiscausestheruletobevalidaccordingtothetimerangespecication.
lTheZXR105250providesthefollowingtentypesofACLs:
1.BasicACL:OnlymatchesthesourceIPaddress.
2.ExtendedACL:MatchesthesourceIPaddress,destinationIPaddress,IP
protocoltype,TCPsourceportnumber,TCPdestinationportnumber,UDP
sourceportnumber,UDPdestinationportnumber,ICMPtype,ICMPCodeand
DiffServCodePoint(DSCP).
3.L2ingressACL:MatchesthesourceMACaddress,destinationMACaddress,
sourceVLANIDand802.1ppriorityvalue,Ethernetnetworktypeand
DSAP/SSAP .
4.HybridingressACL:MatchessourceIPv4/IPv6address,destinationIPv4/IPv6
address,IPprotocoltype,TCPsourceportnumber,TCPdestinationportnumber,
UDPsourceportnumber,UDPdestinationportnumber,DiffServCodePoint
(DSCP),sourceMACaddress,destinationMACaddress,sourceVLANIDand
802.1ppriorityvalue.
5.GlobalACL:MatchesthesourceIPaddress,destinationIPaddress,IPprotocol
type,TCPsourceportnumber,TCPdestinationportnumber,UDPsourceport
number,UDPdestinationportnumber,DiffServCodePoint(DSCP),sourceMAC
address,destinationMACaddress,sourceVLANIDand802.1ppriorityvalue.
6.BasicegressACL:OnlymatchessourceIPaddress.
5-43
SJ-20131111172707-002|2013-11-27(R1.0)ZTEProprietaryandCondential