This page shows the ACL, which is made up of the ACEs defined on this switch. Each row describes the ACE that is defined. The maximum number of ACEs is 256 on each switch.
Click on the lowest plus sign to add a new ACE to the list. The reserved ACEs used for internal protocol, cannot be edited or deleted, the order sequence cannot be changed and the priority is highest.
Object | Description |
---|---|
Ingress Port | Indicates the ingress port of the ACE. Possible values are:
|
Policy / Bitmask | Indicates the policy number and bitmask of the ACE. |
Frame Type | Indicates the frame type of the ACE. Possible values are:
|
Action | Indicates the forwarding action of the ACE.
|
Rate Limiter | Indicates the rate limiter number of the ACE. Valid values are 1 – 16. When Disabled is displayed, the rate limiter operation is disabled. |
Port Redirect | Indicates the port redirect operation of the ACE. Frames matching the ACE are redirected to the port number. The allowed values are Disabled or a specific port number. When Disabled is displayed, the port redirect operation is disabled. |
Mirror | Specify the mirror operation of this port. Frames
matching the ACE are mirrored to the destination mirror port. The allowed
values are:
The default value is Disabled. |
Counter | The counter indicates the number of times the ACE was hit by a frame. |
Modification Buttons | You can modify each ACE (Access Control Entry) in the table using the following buttons: : Inserts a new ACE before the current row. : Edits the ACE row. : Moves the ACE up the list. : Moves the ACE down the list. : Deletes the ACE. : The lowest plus sign adds a new entry at the bottom of the ACE listings. |
Buttons | |
---|---|
Refresh the page automatically every three seconds. | |
Refresh the page immediately. Any non-committed changes will be lost. | |
Clear the counters or dynamic entries. | |
Remove all entries. |
The ACE Configuration page includes the following fields:
Object | Description |
---|---|
Ingress Port | Select the ingress port for which this ACE applies.
|
Policy Filter | Specify the policy number filter for this ACE.
|
Policy Value | When Specific is selected for the policy filter, you can enter a specific policy value. The allowed range is 0 to 255. |
Policy Bitmask | When Specific is selected for the policy filter, you can enter a specific policy bitmask. The allowed range is 0x0 to 0xff. Notice the usage of bitmask, if the binary bit value is “0”, it means this bit is “don't-care”. The real matched pattern is [policy_value & policy_bitmask]. For example, if the policy value is 3 and the policy bitmask is 0x10 (bit 0 is “don't-care” bit), then policy 2 and 3 are applied to this rule. |
Frame Type | Select the frame type for this ACE. These frame types are mutually exclusive.
|
Action | Specify the action to take with a frame that hits this ACE.
|
Rate Limiter | Specify the rate limiter in number of base units. Valid values are 1 – 16. Disabled indicates that the rate limiter operation is disabled. |
Port Redirect | Frames that hit the ACE are redirected to the port number specified here. The rate limiter will affect these ports. The allowed range is the same as the switch port number range. Disabled indicates that the port redirect operation is disabled and the specific port number of 'Port Redirect' can't be set when action is permitted. |
Mirror | Specify the mirror operation of this port. Frames
matching the ACE are mirrored to the destination mirror port. The rate
limiter will not affect frames on the mirror port. Valid values are:
The default value is Disabled. |
Logging | Specify the logging operation of the ACE. Notice that
the logging message doesn't include the 4 bytes CRC information.Valid values
are:
Note: The logging feature only works when the packet
length is less than 1518 (without VLAN tags)
and the System Log memory size and logging rate is
limited.
|
Shutdown | Specify the port shut down operation of the ACE.
Valid values are:
Note: The shutdown feature only works when the packet
length is less than 1518 (without VLAN tags).
|
Counter | The counter indicates the number of times the ACE was hit by a frame. |
MAC Parameters | |
SMAC Filter | (Only displayed when the frame type is Ethernet Type or ARP.)
Specify the source MAC filter for this ACE.
|
SMAC Value | When Specific is selected for the SMAC filter, you can enter a specific source MAC address. Valid format is “xx-xx-xx-xx-xx-xx” or “xx.xx.xx.xx.xx.xx” or “xxxxxxxxxxxx” (x is a hexadecimal digit). A frame that hits this ACE matches this SMAC value. |
DMAC Filter | Specify the destination MAC filter for this ACE.
|
DMAC Value | When Specific is selected for the DMAC filter, you can enter a specific destination MAC address. The legal format is “xx-xx-xx-xx-xx-xx” or “xx.xx.xx.xx.xx.xx” or “xxxxxxxxxxxx” (x is a hexadecimal digit). A frame that hits this ACE matches this DMAC value. |
VLAN Parameters | |
802.1Q Tagged | Specify whether frames can hit the action according
to the 802.1Q tagged. The allowed values are:
The default value is Any. |
VLAN ID Filter | Specify the VLAN ID filter for this ACE.
|
VLAN ID | When Specific is selected for the VLAN ID filter, you can enter a specific VLAN ID number. Valid values are 1 – 4095. A frame that hits this ACE matches this VLAN ID value. |
Tag Priority | Specify the tag priority for this ACE. A frame that hits this ACE matches this tag priority. Valid values are 0 – 7 or range 0-1, 2-3, 4-5, 6-7, 0-3 and 4-7. The value Any means that no tag priority is specified (tag priority is “don't-care”.) |
ARP Parameters | |
ARP/RARP | Specify the available ARP/RARP opcode (OP) flag for this ACE.
|
Request/Reply | Specify the available Request/Reply opcode (OP) flag for this ACE.
|
Sender IP Filter | Specify the sender IP filter for this ACE.
|
Sender IP Address | When Host or Network is selected for the sender IP filter, you can enter a specific sender IP address in dotted decimal notation. |
Sender IP Mask | When Network is selected for the sender IP filter, you can enter a specific sender IP mask in dotted decimal notation. |
Target IP Filter | Specify the target IP filter for this specific ACE.
|
Target IP Address | When Host or Network is selected for the target IP filter, you can enter a specific target IP address in dotted decimal notation. |
Target IP Mask | When Network is selected for the target IP filter, you can enter a specific target IP mask in dotted decimal notation. |
ARP Sender MAC Match | Specify whether frames can hit the action according to their sender hardware address field (SHA) settings.
|
RARP Target MAC Match | Specify whether frames can hit the action according to their target hardware address field (THA) settings.
|
IP/Ethernet Length | Specify whether frames can hit the action according to their ARP/RARP hardware address length (HLN) and protocol address length (PLN) settings.
|
IP | Specify whether frames can hit the action according to their ARP/RARP hardware address space (HRD) settings.
|
Ethernet | Specify whether frames can hit the action according to their ARP/RARP protocol address space (PRO) settings.
|
IP Parameters | |
IP Protocol Filter | Specify the IP protocol filter for this ACE.
|
IP Protocol Value | When Specific is selected for the IP protocol value, you can enter a specific value. Valid values are 1 – 255. A frame that hits this ACE matches this IP protocol value. |
IP TTL | Specify the Time-to-Live settings for this ACE.
|
IP Fragment | Specify the fragment offset settings for this ACE. This involves the settings for the More Fragments (MF) bit and the Fragment Offset (FRAG OFFSET) field for an IPv4 frame.
|
IP Option | Specify the options flag setting for this ACE.
|
SIP Filter | Specify the source IP filter for this ACE.
|
SIP Address | When Host or Network is selected for the source IP filter, you can enter a specific SIP address in dotted decimal notation. |
SIP Mask | When Network is selected for the source IP filter, you can enter a specific SIP mask in dotted decimal notation. |
DIP Filter | Specify the destination IP filter for this ACE.
|
DIP Address | When Host or Network is selected for the destination IP filter, you can enter a specific DIP address in dotted decimal notation. |
DIP Mask | When Network is selected for the destination IP filter, you can enter a specific DIP mask in dotted decimal notation. |
IPv6 Parameters | |
Next Header Filter | Specify the IPv6 next header filter for this ACE.
|
Next Header Value | When Specific is selected for the IPv6 next header value, you can enter a specific value. Valid values are 0 - 255. A frame that hits this ACE matches this IPv6 protocol value. |
SIP Filter | Specify the source IPv6 filter for this ACE.
|
SIP address | When Specific is selected for the source IPv6 filter, you can enter a specific SIPv6 address. The field only supported last 32 bits for IPv6 address. |
SIP BitMask | When Specific is selected for the source IPv6 filter, you can enter a specific SIPv6 mask. The field only supported last 32 bits for IPv6 address. Notice the usage of bitmask, if the binary bit value is 0, it means this bit is “don't-care”. The real matched pattern is [sipv6_address & sipv6_bitmask] (last 32 bits). For example, if the SIPv6 address is 2001::3 and the SIPv6 bitmask is 0xFFFFFFFE (bit 0 is “don't-care” bit), then SIPv6 address 2001::2 and 2001::3 are applied to this rule. |
Hop Limit | Specify the hop limit settings for this ACE.
|
ICMP Parameters | |
ICMP Type Filter | Specify the ICMP filter for this ACE.
|
ICMP Type Value | When Specific is selected for the ICMP filter, you can enter a specific ICMP value. Valid values are 0 – 255. A frame that hits this ACE matches this ICMP value. |
ICMP Code Filter | Specify the ICMP code filter for this ACE.
|
ICMP Code Value | When Specific is selected for the ICMP code filter, you can enter a specific ICMP code value. Valid values are 0 – 255. A frame that hits this ACE matches this ICMP code value. |
TCP/UDP Parameters | |
TCP/UDP Source Filter | Specify the TCP/UDP source filter for this ACE.
|
TCP/UDP Source No. | When Specific is selected for the TCP/UDP source filter, you can enter a specific TCP/UDP source value. Valid values are 0 – 65535. A frame that hits this ACE matches this TCP/UDP source value. |
TCP/UDP Source Range | When Range is selected for the TCP/UDP source filter, you can enter a specific TCP/UDP source range value. Valid values are 0 – 65535. A frame that hits this ACE matches this TCP/UDP source value. |
TCP/UDP Destination Filter | Specify the TCP/UDP destination filter for this ACE.
|
TCP/UDP Destination Number | When Specific is selected for the TCP/UDP destination filter, you can enter a specific TCP/UDP destination value. Valid values are 0 – 65535. A frame that hits this ACE matches this TCP/UDP destination value. |
TCP/UDP Destination Range | When Range is selected for the TCP/UDP destination filter, you can enter a specific TCP/UDP destination range value. Valid values are 0 – 65535. A frame that hits this ACE matches this TCP/UDP destination value. |
TCP FIN | Specify the TCP “No more data from sender” (FIN) value for this ACE.
|
TCP SYN | Specify the TCP “Synchronize sequence numbers” (SYN) value for this ACE.
|
TCP RST | Specify the TCP “Reset the connection” (RST) value for this ACE.
|
TCP PSH | Specify the TCP “Push Function” (PSH) value for this ACE.
|
TCP ACK | Specify the TCP “Acknowledgment field significant” (ACK) value for this ACE.
|
TCP URG | Specify the TCP “Urgent Pointer field significant” (URG) value for this ACE.
|
Ethernet Type Parameters | |
EtherType Filter | Specify the Ethernet type filter for this ACE.
|
Ethernet Type Value | When Specific is selected for the EtherType filter, you can enter a specific EtherType value. The allowed range is 0x600 to 0xFFFF, excluding 0x800(IPv4), 0x806(ARP) and 0x86DD(IPv6). A frame that hits this ACE matches this EtherType value. |
Buttons | |
---|---|
Save changes. | |
Undo any changes and revert to previously saved values. | |
Undo any changes and return to the previous page. |