3Com 2924-SFP User Guide - Page 70

Match IP Precedence, Action, Apply, Modifying IP Based, Permit, Shutdown

Page 70 highlights

70 CHAPTER 4: MANAGING DEVICE SECURITY ■ Match IP Precedence - Matches the packet IP Precedence value to the ACE. Either the DSCP value or the IP Precedence value is used to match packets to ACLs. ■ Action - Indicates the ACL forwarding action. In addition, the port can be shut down, a trap can be sent to the network administrator, or packet is assigned rate limiting restrictions for forwarding. The options are as follows: ■ Permit - Forwards packets which meet the ACL criteria. ■ Deny - Drops packets which meet the ACL criteria. ■ Shutdown - Drops packet that meets the ACL criteria, and disables the port to which the packet was addressed. Ports are reactivated from the Port Administration Setup Page. 2 Select an ACL from the ACL Name drop-down list. 3 Define the rule setup fields. 4 Click Apply. The ACL rule setup is enabled, and the device is updated. Modifying IP Based ACLs The IP Based ACL Modify Page allows the network administrator to modify IP Based ACLs settings. Monitor users have no access to this page. Figure 34 IP Based ACL Modify Page

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216

70
C
HAPTER
4: M
ANAGING
D
EVICE
S
ECURITY
Match IP Precedence
— Matches the packet IP Precedence value to
the ACE. Either the DSCP value or the IP Precedence value is used to
match packets to ACLs.
Action
— Indicates the ACL forwarding action. In addition, the port
can be shut down, a trap can be sent to the network administrator, or
packet is assigned rate limiting restrictions for forwarding. The options
are as follows:
Permit
— Forwards packets which meet the ACL criteria.
Deny
— Drops packets which meet the ACL criteria.
Shutdown
— Drops packet that meets the ACL criteria, and
disables the port to which the packet was addressed. Ports are
reactivated from the
Port Administration Setup Page
.
2
Select an ACL from the
ACL Name
drop-down list.
3
Define the rule setup fields.
4
Click
Apply
. The ACL rule setup is enabled, and the device is updated.
Modifying IP Based
ACLs
The
IP Based ACL Modify Page
allows the network administrator to
modify IP Based ACLs settings.
Monitor users have no access to this page.
Figure 34
IP Based ACL Modify Page