ZXR102900ESeriesConīægurationGuide
4.12ACLConīguration
ACLOverview
AnAccessControlList(ACL)isasequentialcollectionofpermitanddenyconditionsthat
applytopackets.Whenapacketisreceivedonaninterface,theswitchcomparesthe
īæeldsinthepacketagainstanyappliedACLāstoverifythatthepackethastherequired
permissionstobeforwarded,basedonthecriteriaspeciīæedintheaccesslists.Ittests
packetsagainsttheconditionsinanaccesslistonebyone.Theīærstmatchdetermines
whethertheswitchacceptsorrejectsthepacketsbecausetheswitchstopstesting
conditionsaftertheīærstmatch.Theorderofconditionsinthelistiscritical.Ifnoconditions
match,theswitchrejectsthepackets.Iftherearenorestrictions,theswitchforwardsthe
packet.otherwise,theswitchdropsthepacket.
TheZXR102900Esupportsthefollowingfunctions.
lTheZXR102900EprovidestwobindingtypesincludingphysicalportandVLANport.
lACLrulecanbeadded,deleted,sorted.
1.RulecanbeaddedtoaconīæguredACL.RegularIDnumberrangeis1-500.
2.ConīæguredACLcanbedeletedregularly.IfthespeciīæedACLinstancenumber
orrulenumberhasnātbeenconīægured,afalsemessagewillreturn.
3.ManyrulesofanACLcanbesortedandonlyneedtospecifytheplacewhererule
numberneedtobemoved.
lAnACLcanbecomevalidaccordingtoconīæguredtimerange.Afterconīæguring
absoluteorrelativetimerangeontheswitch,timerangecanbeappliedtotheruleof
ACL.Thiscausestheruletobevalidaccordingtothetimerangespeciīæcation.
lTheZXR102900EprovidesthefollowingīævetypesofACLs:
1.BasicACL:OnlymatchsourceIPaddress.
2.ExtendedACL:MatchsourceIPaddress,destinationIPaddress,IPprotocoltype,
TCPsourceportnumber,TCPdestinationportnumber,UDPsourceportnumber,
UDPdestinationportnumber,ICMPtype,ICMPCodeandDiffServCodePoint
(DSCP).
3.L2ingressACL:MatchsourceMACaddress,destinationMACaddress,source
VLANIDand802.1ppriorityvalue,EthernetnetworktypeandDSAP/SSAP .
4.HybridingressACL:MatchSourceIPv4/IPv6address,destinationIPv4/IPv6
address,IPprotocoltype,TCPsourceportnumber,TCPdestinationportnumber,
UDPsourceportnumber,UDPdestinationportnumber,DiffServCodePoint
(DSCP),sourceMACaddress,destinationMACaddress,sourceVLANIDand
802.1ppriorityvalue.
5.GlobalACL:MatchSourceIPaddress,destinationIPaddress,IPprotocoltype,
TCPsourceportnumber,TCPdestinationportnumber,UDPsourceportnumber,
UDPdestinationportnumber,DiffServCodePoint(DSCP),sourceMACaddress,
destinationMACaddress,sourceVLANIDand802.1ppriorityvalue.
6.BasicegressACL:OnlymatchsourceIPaddress.
7.ExtendedegressACL:MatchsourceIPaddress,destinationIPaddress,IP
protocoltype,TCPsourceportnumber,TCPdestinationportnumber,UDP
4-42
SJ-20120409144109-002|2012-07-02(R1.0)ZTEProprietaryandConīædential