D-Link DWS-4026 Product Manual - Page 354

Table 221, MAC ACL Rule Configuration Fields, Field, Description, Destination MAC Address

Page 354 highlights

D-Link Unified Access System Software User Manual 12/10/09 Field MAC ACL Rule Rule ID Action Logging Assign Queue ID Match Every Mirror Interface CoS Destination MAC Address Destination MAC Mask EtherType Key Table 221: MAC ACL Rule Configuration Fields Description Specifies an existing MAC ACL. To set up a new MAC ACL use the "MAC Access Control Lists" page. Select an existing Rule ID to modify or select Create Rule to configure a new ACL Rule. Enter a whole number in the range of 1 to 12 that will be used to identify the rule. New rules cannot be created if the maximum number of rules has been reached. For each rule, a packet must match all the specified criteria in order to be true against that rule and for the specified rule action (Permit/Deny) to take place. This field is only available if you select Create Rule from the Rule field. Enter a new Rule ID. After you click Submit, the new ID is created and you can configure the rule settings. You can create up to 12 rules for each ACL. Specify what action should be taken if a packet matches the rule's criteria: • Permit: Forwards packets that meet the ACL criteria. • Deny: Drops packets that meet the ACL criteria. This field is only visible for a Deny Action. When set to True, logging is enabled for this ACL rule (subject to resource availability in the device). If the Access List Trap Flag is also enabled, this will cause periodic traps to be generated indicating the number of times this rule went into effect during the current report interval. A fixed 5 minute report interval is used for the entire system. A trap is not issued if the ACL rule hit count is zero for the current interval. This field is only visible when the Action is Permit. Specifies the hardware egress queue identifier used to handle all packets matching this ACL rule. Click Configure, and then enter an identifying number from 0 to 6 in the appropriate field. Click Submit or Cancel to return to the Rule Configuration page. Requires a packet to match the criteria of this ACL. Click Configure, and then select True or False from the dropdown list. Then click Submit or Cancel to return to the Rule Configuration page. Match Every is exclusive to the other filtering rules, so if Match Every is True, the other rules on the screen do not appear. False indicates that it is not mandatory for every packet to match the selected ACL Rule. This field is only visible when the Action is Permit. Specifies the specific egress interface where the matching traffic stream is copied in addition to being forwarded normally by the device. Specifies the 802.1p user priority to compare against an Ethernet frame. Requires a packet's class of service (CoS) to match the CoS value listed here. Click Configure, and then enter a CoS value between 0 and 7 to apply this criteria. Click Submit or Cancel to return to the Rule Configuration page. Requires an Ethernet frame's destination port MAC address to match the address listed here. Click Configure, and then enter a MAC address in the appropriate field. The valid format is xx_xx_xx_xx_xx_xx. The BPDU keyword may be specified using a Destination MAC Address of 01:80:C2:xx:xx:xx. Click Submit or Cancel to return to the Rule Configuration page. If desired, enter the MAC Mask associated with the Destination MAC to match. The MAC address mask specifies which bits in the destination MAC to compare against an Ethernet frame. Use F's and zeros in the MAC mask, which is in a wildcard format. An F means that the bit is not checked, and a zero in a bit position means that the data must equal the value given for that bit. For example, if the MAC address is aa_bb_cc_dd_ee_ff, and the mask is 00_00_ff_ff_ff_ff, all MAC addresses with aa_bb_xx_xx_xx_xx result in a match (where x is any hexadecimal number). Click Submit or Cancel to return to the Rule Configuration page. Requires a packet's EtherType to match the EtherType you select. Click Configure, and then select the EtherType value from the dropdown menu. If you select User Value, you can enter a custom EtherType value. Page 354 Configuring Access Control Lists Document 34CSFP6XXUWS-SWUM100-D7

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518
  • 519
  • 520
  • 521
  • 522
  • 523
  • 524
  • 525
  • 526
  • 527
  • 528
  • 529
  • 530
  • 531
  • 532
  • 533
  • 534
  • 535
  • 536
  • 537
  • 538
  • 539
  • 540
  • 541
  • 542
  • 543
  • 544
  • 545
  • 546
  • 547
  • 548
  • 549
  • 550
  • 551
  • 552
  • 553
  • 554
  • 555
  • 556
  • 557
  • 558
  • 559
  • 560
  • 561
  • 562
  • 563
  • 564
  • 565
  • 566
  • 567
  • 568
  • 569
  • 570
  • 571
  • 572
  • 573
  • 574
  • 575
  • 576

D-Link Unified Access System
Software User Manual
12/10/09
Page
354
Configuring Access Control Lists
Document
34CSFP6XXUWS-SWUM100-D7
Table 221:
MAC ACL Rule Configuration Fields
Field
Description
MAC ACL
Specifies an existing MAC ACL. To set up a new MAC ACL use the
“MAC Access
Control Lists”
page.
Rule
Select an existing Rule ID to modify or select Create Rule to configure a new ACL
Rule. Enter a whole number in the range of 1 to 12 that will be used to identify the rule.
New rules cannot be created if the maximum number of rules has been reached. For
each rule, a packet must match all the specified criteria in order to be true against that
rule and for the specified rule action (Permit/Deny) to take place.
Rule ID
This field is only available if you select Create Rule from the Rule field. Enter a new
Rule ID. After you click
Submit
, the new ID is created and you can configure the rule
settings. You can create up to 12 rules for each ACL.
Action
Specify what action should be taken if a packet matches the rule's criteria:
Permit
: Forwards packets that meet the ACL criteria.
Deny
: Drops packets that meet the ACL criteria.
Logging
This field is only visible for a Deny Action. When set to True, logging is enabled for this
ACL rule (subject to resource availability in the device). If the Access List Trap Flag is
also enabled, this will cause periodic traps to be generated indicating the number of
times this rule went into effect during the current report interval. A fixed 5 minute report
interval is used for the entire system. A trap is not issued if the ACL rule hit count is
zero for the current interval.
Assign Queue ID
This field is only visible when the Action is Permit. Specifies the hardware egress
queue identifier used to handle all packets matching this ACL rule. Click Configure,
and then enter an identifying number from 0 to 6 in the appropriate field. Click
Submit
or
Cancel
to return to the Rule Configuration page.
Match Every
Requires a packet to match the criteria of this ACL. Click
Configure
, and then select
True or False from the dropdown list. Then click
Submit
or
Cancel
to return to the Rule
Configuration page. Match Every is exclusive to the other filtering rules, so if Match
Every is True, the other rules on the screen do not appear. False indicates that it is not
mandatory for every packet to match the selected ACL Rule.
Mirror Interface
This field is only visible when the Action is Permit. Specifies the specific egress
interface where the matching traffic stream is copied in addition to being forwarded
normally by the device.
CoS
Specifies the 802.1p user priority to compare against an Ethernet frame. Requires a
packet’s class of service (CoS) to match the CoS value listed here. Click
Configure
,
and then enter a CoS value between 0 and 7 to apply this criteria. Click
Submit
or
Cancel
to return to the Rule Configuration page.
Destination MAC Address
Requires an Ethernet frame’s destination port MAC address to match the address
listed here. Click
Configure
, and then enter a MAC address in the appropriate field.
The valid format is xx_xx_xx_xx_xx_xx. The BPDU keyword may be specified using a
Destination MAC Address of 01:80:C2:xx:xx:xx. Click
Submit
or
Cancel
to return to
the Rule Configuration page.
Destination MAC Mask
If desired, enter the MAC Mask associated with the Destination MAC to match. The
MAC address mask specifies which bits in the destination MAC to compare against an
Ethernet frame. Use F’s and zeros in the MAC mask, which is in a wildcard format. An
F means that the bit is not checked, and a zero in a bit position means that the data
must equal the value given for that bit. For example, if the MAC address is
aa_bb_cc_dd_ee_ff, and the mask is 00_00_ff_ff_ff_ff, all MAC addresses with
aa_bb_xx_xx_xx_xx result in a match (where
x
is any hexadecimal number). Click
Submit
or
Cancel
to return to the Rule Configuration page.
EtherType Key
Requires a packet’s EtherType to match the EtherType you select. Click
Configure
,
and then select the EtherType value from the dropdown menu. If you select User
Value, you can enter a custom EtherType value.