Chapter9
ACLConfiguration
TableofContents
ACLOverview...................................................................77
NP-BasedACLOverview.....................................................78
ConguringACLs...............................................................79
ConguringEventLinkageACLRule.....................................85
ApplyingNP-BasedACL......................................................87
ACLCongurationExample.................................................88
ACLMaintenanceandDiagnosis...........................................89
ACLOverview
Packetlteringcanhelplimitnetworktrafcandrestrictnetwork
usebycertainusersordevices.ACLcanltertrafcasitpasses
througharouterandpermitordenypacketsatspeciedinter-
faces.
AnACLisasequentialcollectionofpermitanddenyconditionsthat
applytopackets.Whenapacketisreceivedonaninterface,the
switchcomparestheeldsinthepacketagainstanyappliedACL
toverifythatthepackethastherequiredpermissionstobefor-
warded,basedonthecriteriaspeciedintheaccesslists.Ittests
packetsagainsttheconditionsinanaccesslistonebyone.The
rstmatchdetermineswhethertheswitchacceptsorrejectsthe
packetsbecausetheswitchstopstestingconditionsaftertherst
match.Theorderofconditionsinthelistiscritical.Whenthere
arenoconditionsmatched,theswitchrejectsthepackets.Ifthere
arenorestrictions,theswitchforwardsthepacket;otherwise,the
switchdropsthepacket.
PacketmatchingrulesdenedbytheACLarealsousedinother
conditionswheredistinguishingtrafcisneeded.Forinstance,the
matchingrulescandenethetrafcclassicationruleintheQoS.
ZXR108900seriesswitchprovidesseventypesofACLs:
�StandardACL
OnlysourceIPaddressesarematchedagainsttheACL.
�ExtendedACL
Source/destinationIPaddress,IPprotocoltype,TCP
source/destinationportnumber ,TCP-control,UDPsource/des-
tinationportnumber ,ICMPtype,ICMPcode,DiffServCode
Point(DSCP),ToSandprecedencearematchedagainstthe
ACL.
CondentialandProprietaryInformationofZTECORPORATION77