EasyManua.ls Logo

ELTEX MES1000 User Manual

ELTEX MES1000
231 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #205 background imageLoading...
Page #205 background image
MES1000, MES2000 Ethernet Switches 205
As soon as at least one record has been added to ACL, the last record is set by default to
deny-any-any that means that all packets, which do not fulfil ACL requirements, will be
ignored.
Table 5.247Configuration commands for MAC-based ACLs
Command
Action
permit
{any|{source source- wildcard}
{any|destination destination_wildcard}
[vlan vlan_id]
[cos cos cos_wildcard] [eth-type]
[time-range range_name] [index index]
[offset-list offset_list_name]
Adds a permit filtration record. Packets which fulfil the record's requirements
will be processed by the switch.
deny
{any|{source source- wildcard}
{any|{ destination destination_wildcard}}
[vlan vlan_id]
[cos cos cos_wildcard] [eth-type]
[time-range range_name]
[disable-port|log-input] [index index]
[offset-list offset_list_name]
Adds a deny filtration record. Packets which fulfil the record's requirements
will be blocked by the switch. If the disable-port keyword is specified, the
physical interface receiving the packet will be disabled.
If the log-input keyword is specified, the physical a message will be sent to the
system log.
offset-list name { offset_base offset mask
value}
Creates a user templates list with the name specified in the name field. The
name should contain from 1 to 32 characters.
One command may contain up to 4 templates having the following
parameters:
offset_basebasic offset. Possible values:
L2beginning of Ethertype offset
outer-tagbeginning of STAG offset
inner-tagbeginning of CTAG offset
src-macbeginning of source MAC offset
dst-macbeginning of destination MAC offset
offsetbyte offset within a packet. Basic offset is considered as a starting
point.
maskmask. Packet analysis is performed only for the bytes digits which
have "1" specified as defined in the mask.
valuethe set value.
no offset-list name
Removes a previously created list.
5.31.4 Access List Time Range Configuration (time-range)
This section describes time range configuration commands for ACL.
To create and enter the 'time-range' configuration profile editing mode, use the following
command: time-range range_name. For example, to create the time range profile named http-allowed,
you have to execute the following commands:
console#
console# configure
console(config)# time-range http-allowed
console(config-time-range)#
Table 5.248 Time interval configuration mode commands
Parameter
Value
Action
absolute start hh:mm day month year
hh:mm: (0..23):(0..5)
day: 1..31
month: Jan .. Dec
Set the absolute time and date, when the access list takes
effect.
no absolute start
Remove the time limit

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the ELTEX MES1000 and is the answer not in the manual?

ELTEX MES1000 Specifications

General IconGeneral
ModelMES1000
LayerL2
VLANNot supported
TypeUnmanaged
Power SupplyExternal 5V DC
Operating Temperature0°C to +40°C
Storage Temperature-40°C to +70°C
Humidity10 to 90% (non-condensing)

Summary

2 PRODUCT DESCRIPTION

2.2 Device Functions

Lists and describes the basic, MAC address processing, and second-layer OSI functions of the switches.

3 INSTALLATION AND CONNECTION

4 DEVICE STARTUP, INITIAL CONFIGURATION

4.3 Configuration procedure

Outlines the necessary information and steps for initial device configuration.

5 DEVICE MANAGEMENT COMMAND LINE INTERFACE

5.2 Basic commands

Lists and describes fundamental commands available in EXEC and Privileged EXEC modes.

5.10 Interface configuration

Covers configuration of Ethernet interfaces, port channels, and VLAN interfaces.

5.27 Security functions

Explains security functions, including port security, port-based authentication (802.1x), DHCP snooping, ARP inspection, and MAC address notification.

5.31 ACL Configuration (Access Control Lists)

Explains Access Control Lists for filtering traffic based on IP, MAC addresses, and TCP/UDP ports.

6 SERVICE MENU, CHANGE OF SOFTWARE

Related product manuals