D-Link DWS-4026 Product Manual - Page 348

Table 219, IP ACL Rule Configuration Fields Cont., Field, Description, Assign Queue ID

Page 348 highlights

D-Link Unified Access System Software User Manual 12/10/09 Field Rule Rule ID Action Logging Assign Queue ID Mirror Interface Match Every Protocol Keyword Protocol Number Source IP Address Table 219: IP ACL Rule Configuration Fields (Cont.) Description Select an existing Rule ID to modify or select Create Rule to configure a new ACL Rule. New rules cannot be created if the maximum number of rules has been reached. For each rule, a packet must match all the specified criteria in order to be true against that rule and for the specified rule action (Permit/Deny) to take place. This field is only available if you select Create Rule from the Rule field. Enter a new Rule ID which is a whole number in the range of 1 to 12 that will be used to identify the rule. After you click Submit, the new ID is created and you can configure the rule settings. The number of rules you can create in an ACL is platform dependent. Selects the ACL forwarding action. Click Configure to change the action. Select the desired action from the dropdown menu, and then click Submit or Cancel to return to the Rule Configuration page. Possible values are; • Permit. Forwards packets which meet the ACL criteria. • Deny. Drops packets which meet the ACL criteria. This field is only visible for a Deny Action. When set to True, logging is enabled for this ACL rule (subject to resource availability in the device). If the Access List Trap Flag is also enabled, this will cause periodic traps to be generated indicating the number of times this rule went into effect during the current report interval. A fixed 5 minute report interval is used for the entire system. A trap is not issued if the ACL rule hit count is zero for the current interval. This field is only visible when the Action is Permit. Use this field to specify the hardware egress queue identifier used to handle all packets matching this AP ACL Rule. Click Configure, and then enter an identifying queue number (0 to 7) in the appropriate field. Click Submit or Cancel to return to the Rule Configuration page. This field is only visible when the Action is Permit. Use this field to specify the specific egress interface where the matching traffic stream is copied in addition to being forwarded normally by the device. Click Configure, and then select an interface from the dropdown list. Packets that meet the rule are mirrored on the interface you select. Click Submit or Cancel to return to the Rule Configuration page. Requires a packet to match the criteria of this ACL. Click Configure, and then select True or False from the dropdown list. Then click Submit or Cancel to return to the Rule Configuration page. True signifies that all packets will match the selected IP ACL and Rule and will be either permitted or denied. Match Every is exclusive to the other filtering rules, so if Match Every is True, the other rules on the screen do not appear. To configure specific match criteria for the rule, remove the rule and re-create it, or reconfigure 'Match Every' to 'False' for the other match criteria to be visible. Specify that a packet's IP protocol is a match condition for the selected IP ACL rule. The possible values are ICMP, IGMP, IP, TCP, and UDP. Either the 'Protocol Keyword' field or the 'Protocol Number' field can be used to specify an IP protocol value as a match criteria. Click Configure, and then select the protocol keyword from the dropdown list. Click Submit or Cancel to return to the Rule Configuration page. Specify that a packet's IP protocol is a match condition for the selected IP ACL rule and identify the protocol by number. The protocol number is a standard value assigned by IANA and is interpreted as a integer from 0 to 255. Either the 'Protocol Number' field or the 'Protocol Keyword' field can be used to specify an IP protocol value as a match criteria. Requires a packet's source port IP address to match the address listed here. Click Configure, and then enter an IP Address in the appropriate field using dotted-decimal notation. The address you enter is compared to a packet's source IP Address. You also configure the Source IP Mask on the page. Page 348 Configuring Access Control Lists Document 34CSFP6XXUWS-SWUM100-D7

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518
  • 519
  • 520
  • 521
  • 522
  • 523
  • 524
  • 525
  • 526
  • 527
  • 528
  • 529
  • 530
  • 531
  • 532
  • 533
  • 534
  • 535
  • 536
  • 537
  • 538
  • 539
  • 540
  • 541
  • 542
  • 543
  • 544
  • 545
  • 546
  • 547
  • 548
  • 549
  • 550
  • 551
  • 552
  • 553
  • 554
  • 555
  • 556
  • 557
  • 558
  • 559
  • 560
  • 561
  • 562
  • 563
  • 564
  • 565
  • 566
  • 567
  • 568
  • 569
  • 570
  • 571
  • 572
  • 573
  • 574
  • 575
  • 576

D-Link Unified Access System
Software User Manual
12/10/09
Page
348
Configuring Access Control Lists
Document
34CSFP6XXUWS-SWUM100-D7
Rule
Select an existing Rule ID to modify or select Create Rule to configure a new ACL
Rule. New rules cannot be created if the maximum number of rules has been reached.
For each rule, a packet must match all the specified criteria in order to be true against
that rule and for the specified rule action (Permit/Deny) to take place.
Rule ID
This field is only available if you select Create Rule from the Rule field. Enter a new
Rule ID which is a whole number in the range of 1 to 12 that will be used to identify the
rule. After you click
Submit
, the new ID is created and you can configure the rule
settings. The number of rules you can create in an ACL is platform dependent.
Action
Selects the ACL forwarding action. Click
Configure
to change the action. Select the
desired action from the dropdown menu, and then click
Submit
or
Cancel
to return to
the Rule Configuration page. Possible values are;
Permit.
Forwards packets which meet the ACL criteria.
Deny.
Drops packets which meet the ACL criteria.
Logging
This field is only visible for a Deny Action. When set to True, logging is enabled for this
ACL rule (subject to resource availability in the device). If the Access List Trap Flag is
also enabled, this will cause periodic traps to be generated indicating the number of
times this rule went into effect during the current report interval. A fixed 5 minute report
interval is used for the entire system. A trap is not issued if the ACL rule hit count is
zero for the current interval.
Assign Queue ID
This field is only visible when the Action is Permit. Use this field to specify the hardware
egress queue identifier used to handle all packets matching this AP ACL Rule. Click
Configure
, and then enter an identifying queue number (0 to 7) in the appropriate field.
Click
Submit
or
Cancel
to return to the Rule Configuration page.
Mirror Interface
This field is only visible when the Action is Permit. Use this field to specify the specific
egress interface where the matching traffic stream is copied in addition to being
forwarded normally by the device. Click
Configure
, and then select an interface from
the dropdown list. Packets that meet the rule are mirrored on the interface you select.
Click
Submit
or
Cancel
to return to the Rule Configuration page.
Match Every
Requires a packet to match the criteria of this ACL. Click
Configure
, and then select
True or False from the dropdown list. Then click
Submit
or
Cancel
to return to the Rule
Configuration page. True signifies that all packets will match the selected IP ACL and
Rule and will be either permitted or denied. Match Every is exclusive to the other
filtering rules, so if Match Every is True, the other rules on the screen do not appear.
To configure specific match criteria for the rule, remove the rule and re-create it, or
reconfigure ‘Match Every’ to ‘False’ for the other match criteria to be visible.
Protocol Keyword
Specify that a packet’s IP protocol is a match condition for the selected IP ACL rule.
The possible values are ICMP, IGMP, IP, TCP, and UDP. Either the ‘Protocol
Keyword’ field or the ‘Protocol Number’ field can be used to specify an IP protocol
value as a match criteria. Click
Configure
, and then select the protocol keyword from
the dropdown list. Click
Submit
or
Cancel
to return to the Rule Configuration page.
Protocol Number
Specify that a packet’s IP protocol is a match condition for the selected IP ACL rule
and identify the protocol by number. The protocol number is a standard value assigned
by IANA and is interpreted as a integer from 0 to 255. Either the ‘Protocol Number’ field
or the ‘Protocol Keyword’ field can be used to specify an IP protocol value as a match
criteria.
Source IP Address
Requires a packet’s source port IP address to match the address listed here. Click
Configure
, and then enter an IP Address in the appropriate field using dotted-decimal
notation. The address you enter is compared to a packet's source IP Address. You
also configure the Source IP Mask on the page.
Table 219:
IP ACL Rule Configuration Fields (Cont.)
Field
Description