Cabletron Systems SSIM-R8-02 Specifikace Strana 300

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 394
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 299
ACL Basics
280 Enterasys Xpedition User Reference Manual
ACL Basics
An ACL consists of one or more rules describing a particular type of IP or IPX traffic.
ACLs can be simple, consisting of only one rule, or complicated with many rules. Each
rule tells the XP to either permit or deny packets that match selection criteria specified in
the rule.
Each ACL is identified by a name. The name can be a meaningful string, such as denyftp or
noweb or it can be a number such as 100 or 101.
For example, the following ACL has a rule that permits all IP packets from subnet
10.2.0.0/16 to go through the XP:
Defining Selection Criteria in ACL Rules
Selection criteria in the rule describe characteristics about a packet. In the example above,
the selection criteria are IP packets from 10.2.0.0/16.
The selection criteria you can specify in an ACL rule depends on the type of ACL you are
creating. For IP, TCP, and UDP ACLs, the following selection criteria can be specified:
Source IP address
Destination IP address
Source port number
Destination port number
Type of Service (TOS)
The accounting keyword specifies that LFAP accounting information about the flows
that match the permit rule are sent to the configured Flow Accounting Server (FAS).
See Chapter 27, LFAP Configuration Guide, for more information.
For IPX ACLs, the following selection criteria can be specified:
Source network address
Destination network address
Source IPX socket
Destination IPX socket
acl 101 permit ip 10.2.0.0/16
Zobrazit stránku 299
1 2 ... 295 296 297 298 299 300 301 302 303 304 305 ... 393 394

Komentáře k této Příručce

Žádné komentáře