Linksys SGE2000 Cisco SGE2000, SGE2000P Gigabit Ethernet Switch Reference Guid - Page 84

Add MAC Based ACL ACL Name, New Rule Priority, Source Address, VLAN ID, Ether Type, Action

Page 84 highlights

Chapter 4 SGE2000/SGE2000P Gigabit Ethernet Switch Reference Guide Add MAC Based ACL Page The Add MAC Based ACL Page contains the following fields: • ACL Name - Displays the user-defined MAC based ACLs. • New Rule Priority - Indicates the ACE priority, which determines which ACE is matched to a packet on a first-match basis. The possible field values are 1-2147483647. • Source Address - MAC Address - Matches the source MAC address to which packets are addressed to the ACE. - Mask - Indicates the source MAC Address wild card mask. Wildcards are used to mask all or part of a source IP Address. Wild card masks specify which bits are used and which bits are ignored. A wild card mask of ff: ff:ff:ff:ff:ff indicates that no bit is important. A wildcard of 00.00.00.00.00.00 indicates that all the bits are important. For example, if the source IP address 14.36.18.19.1.1 and the wildcard mask is 255.36.184.00.00.00, the middle two bits of the IP address are used, while the last three bits are ignored. • Destination Address - MAC Address - Matches the destination MAC address to which packets are addressed to the ACE. - Mask - Indicates the destination MAC Address wild card mask. Wildcards are used to mask all or part of a destination IP Address. Wild card masks specify which bits are used and which bits are ignored. A wild card mask of ff: ff:ff:ff:ff:ff indicates that no bit is important. A wildcard of 00.00.00.00.00.00 indicates that all the bits are important. For example, if the source IP address 14.36.18.19.1.1 and the wildcard mask is 255.36.184.00.00.00, the middle two bits of the IP address are used, while the last three bits are ignored. • VLAN ID - Matches the packet's VLAN ID to the ACE. The possible field values are 1 to 4095. • CoS - Class of Service of the packet. • CoS Mask - Wildcard bits to be applied to the CoS. • Ether Type - The Ethernet type of the packet. • Action - Indicates the ACL forwarding action. The possible field values are: 76 Chapter 4: Configuring Device Security Defining Access Control

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286

76
Chapter 4: Configuring Device Security
Defining Access Control
SGE2000/SGE2000P Gigabit Ethernet Switch Reference Guide
Chapter
4
Add MAC Based ACL Page
The
Add MAC Based ACL Page
contains the following fields:
ACL Name
— Displays the user-defined MAC based ACLs.
New Rule Priority
Indicates the ACE priority, which determines which ACE is matched to a packet on a
first-match basis. The possible field values are 1-2147483647.
Source Address
MAC Addres
s — Matches the source MAC address to which packets are addressed to the
ACE.
Mask
Indicates the source MAC Address wild card mask. Wildcards are used to mask all
or part of a source IP Address. Wild card masks specify which bits are used and which bits
are ignored. A wild card
mask of ff: ff:ff:ff:ff:ff indicates that no bit is important. A wildcard of
00.00.00.00.00.00 indicates that all the bits are important. For example, if the source IP address
14.36.18.19.1.1 and the wildcard mask is 255.36.184.00.00.00, the middle two bits of the IP address
are used, while the last three bits are ignored.
Destination Address
MAC Address
Matches the destination MAC address to which packets are addressed to the ACE.
Mask
Indicates the destination MAC Address wild card mask. Wildcards are used to mask all or
part
of a destination IP Address. Wild card masks specify which bits are used and which bits
are ignored. A wild card mask of ff: ff:ff:ff:ff:ff indicates that no bit is important. A wildcard
of 00.00.00.00.00.00 indicates that all the bits are important. For example, if the source IP
address 14.36.18.19.1.1 and the wildcard mask is 255.36.184.00.00.00, the middle two bits
of the IP address are used, while the last three bits are ignored.
VLAN ID
Matches the packet’s VLAN ID to the ACE. The possible field values are 1 to 4095.
CoS
Class of Service of the packet.
CoS Mask
— Wildcard bits to be applied to the CoS.
Ether Type
The Ethernet type of the packet.
Action
Indicates the ACL forwarding action. The possible field values are: