Chapter7
ACLConfiguration
TableofContents
ACLOverview...................................................................59
ConguringACL................................................................60
ACLCongurationExample.................................................66
ACLMaintenanceandDiagnosis...........................................68
ACLOverview
Packetlteringcanhelplimitnetworktrafcandrestrictnetwork
usebycertainusersordevices.ACL’scanltertrafcasitpasses
througharouterandpermitordenypacketsatspeciedinter-
faces.
AnACLisasequentialcollectionofpermitanddenyconditions
thatapplytopackets.Whenapacketisreceivedonaninterface,
theswitchcomparestheeldsinthepacketagainstanyapplied
ACL’stoverifythatthepackethastherequiredpermissionstobe
forwarded,basedonthecriteriaspeciedintheaccesslists.It
testspacketsagainsttheconditionsinanaccesslistonebyone.
Therstmatchdetermineswhethertheswitchacceptsorrejects
thepacketsbecausetheswitchstopstestingconditionsafterthe
rstmatch.Theorderofconditionsinthelistiscritical.Ifno
conditionsmatch,theswitchrejectsthepackets.Ifthereareno
restrictions,theswitchforwardsthepacket;otherwise,theswitch
dropsthepacket.
PacketmatchingrulesdenedbytheACLarealsousedinother
conditionswheredistinguishingtrafcisneeded.Forinstance,the
matchingrulescandenethetrafcclassicationruleintheQoS.
ZXR105900/5200providesthefollowingsixtypesofACLs:
�StandardACL:OnlymatchthesourceIPaddress.
�ExtendedACL:Matchthefollowingitems:SourceIPaddress,
destinationIPaddress,IPprotocoltype,TCPsourceportnum-
ber ,TCPdestinationportnumber ,UDPsourceportnumber ,
UDPdestinationportnumber ,ICMPtype,ICMPCode,DiffServ
CodePoint(DSCP),ToSandPrecedence.
�L2ACL:MatchsourceMACaddress,destinationMACaddress,
sourceVLANID,L2Ethernetprotocoltypeand802.1ppriority
value.
�HybridACL:MatchsourceMACaddress,destinationMACad-
dress,sourceVLANID,sourceIPaddress,destinationIPad-
CondentialandProprietaryInformationofZTECORPORATION59