ACL
This node is only available in the NAC common mode.
Interface ACL
Context
You can configure ACL rules and apply the ACL to an interface to filter the packets received by the interface. The ACL rule configuration includes source and destination IP addresses, protocol type, source and destination port numbers.
Procedure
- Query the ACL rules applied to interfaces.
- Copy the ACL rules that have been applied to an interface
to another interface.
- Create ACL rules.
Click Configuration page.
to display theChoose ACL page.
in the navigation tree to display theClick the Interface ACL page.
tab to display theClick the icon of the interface to which the ACL rules need to be applied and create ACL rules.
If no record is displayed in the ACL Rule List area, click
on the right of Operation or Add on the left of Ascend. A record of ACL Rule List is displayed in the ACL Rule List area. Set the ACL rule parameters.
If the existing ACL rule records are displayed in the ACL Rule List area, click
on the right of Operation or Add on the left of Ascend or on the right of Delete. A new record of ACL Rule List is displayed in the ACL Rule List area. Set the ACL rule parameters, as shown in Figure 5-190.
If you click
on the right of Operation or Add on the left of Ascend, a new record of ACL Rule List is inserted to the first line in the ACL Rule List area. If you click Add on the right of Delete, a new record of ACL Rule List is inserted below the current line in the ACL Rule List area.
Table 5-107 describes the parameters for creating ACL rules.
Table 5-107 Parameters for creating ACL rulesParameter
Description
Source IP address
Indicates the source IP address. The default value is any, indicating that any source IP address can be specified.
Mask of Source IP
Indicates the mask of the source IP address. The default value is 0 (0.0.0.0).
Destination IP address
Indicates the destination IP address. The default value is any, indicating that any destination IP address can be specified.
Mask of Destination IP
Indicates the mask of the destination IP address. The default value is 0 (0.0.0.0).
Protocol type
Indicates the protocol type, including:- ip
- tcp
- udp
- icmp
Source Port Num
Indicates the source port number.
This parameter is valid only when the protocol type is TCP or UDP. If this parameter is not specified, TCP or UDP packets with any source port are matched.
Dest Port Num
Indicates the destination port number.
This parameter is valid only when the protocol type is TCP or UDP. If this parameter is not specified, TCP or UDP packets with any destination port are matched.
Action
Indicating the action matching a packet, including:- permit
- deny
Operation
- Delete
- Add
Click Apply.
- Edit ACL rules.
Click Configuration page.
to display theChoose ACL page.
in the navigation tree to display theClick the Interface ACL page.
tab to display theClick the icon of the interface to which the ACL rules have been applied and edit ACL rules.
Edit ACL rule entries.
Modify the ACL rule parameters in the ACL Rule List area.
Adjust the ACL rule entry sequence.
Select a record of ACL Rule List in the ACL Rule List area. Click Ascend or Descend to adjust the ACL rule entry sequence.
Click Apply.
- Delete ACL rules.
Click Configuration page.
to display theChoose ACL page.
in the navigation tree to display theClick the Interface ACL page.
tab to display theClick the icon of the interface to which the ACL rules have been applied. In the ACL Rule List area, click Delete next to the record to be deleted or select records and click Delete next to Descend to delete the ACL rules in batches.
Click Apply.
VLAN ACL
Context
You can configure ACL rules and apply the ACL to a VLAN to filter the VLAN packets. The ACL rule configuration includes source and destination IP addresses, protocol type, source and destination port numbers.
Procedure
- Query the ACL rules applied to VLANs.
- Copy the ACL rules that have been applied to a VLAN to another VLAN.
- Create ACL rules.
Click Configuration page.
to display theChoose ACL page.
in the navigation tree to display theClick the VLAN ACL page.
tab to display theSelect the ID of the VLAN to which ACL rules need to be applied, and create the ACL rules.
If no record is displayed in the ACL Rule List area, click
on the right of Operation or Add on the left of Ascend. A record of ACL Rule List is displayed in the ACL Rule List area. Set the ACL rule parameters.
If the existing ACL rule records are displayed in the ACL Rule List area, click
on the right of Operation or Add on the left of Ascend or on the right of Delete. A new record of ACL Rule List is displayed in the ACL Rule List area. Set the ACL rule parameters, as shown in Figure 5-194.
If you click
on the right of Operation or Add on the left of Ascend, a new record of ACL Rule List is inserted to the first line in the ACL Rule List area. If you click Add on the right of Delete, a new record of ACL Rule List is inserted below the current line in the ACL Rule List area.
Table 5-108 describes the parameters for creating ACL rules.
Table 5-108 Parameters for creating ACL rulesParameter
Description
Source IP address
Indicates the source IP address. The default value is any, indicating that any source IP address can be specified.
Mask of Source IP
Indicates the mask of the source IP address. The default value is 0 (0.0.0.0).
Destination IP address
Indicates the destination IP address. The default value is any, indicating that any destination IP address can be specified.
Mask of Destination IP
Indicates the mask of the destination IP address. The default value is 0 (0.0.0.0).
Protocol type
Indicates the protocol type, including:- ip
- tcp
- udp
- icmp
Source Port Num
Indicates the source port number.
This parameter is valid only when the protocol type is TCP or UDP. If this parameter is not specified, TCP or UDP packets with any source port are matched.
Dest Port Num
Indicates the destination port number.
This parameter is valid only when the protocol type is TCP or UDP. If this parameter is not specified, TCP or UDP packets with any destination port are matched.
Action
Indicating the action matching a packet, including:- permit
- deny
Operation
- Delete
- Add
Click Apply.
- Edit ACL rules.
Click Configuration page.
to display theChoose ACL page.
in the navigation tree to display theClick the VLAN ACL page.
tab to display theSelect the ID of the VLAN to which ACL rules have been applied, and edit the ACL rules.
Edit ACL rule entries.
Modify the ACL rule parameters in the ACL Rule List area.
Adjust the ACL rule entry sequence.
Select a record of ACL Rule List in the ACL Rule List area. Click Ascend or Descend to adjust the ACL rule entry sequence.
Click Apply.
- Delete ACL rules.
Click Configuration page.
to display theChoose ACL page.
in the navigation tree to display theClick the VLAN ACL page.
tab to display theSelect the ID of the VLAN to which the ACL rules have been applied. In the ACL Rule List area, click Delete next to the record to be deleted or select records and click Delete next to Descend to delete the ACL rules in batches.
Click Apply.