D-Link DGS-6600-48TS Configuration Guide - Page 423
Applying Access Control Lists to Interfaces, show access-list, ip access-group
View all D-Link DGS-6600-48TS manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 423 highlights
Volume 8-Security & Authentication / Chapter 38-Access Control Lists (ACL) ACL Configuration Commands In the following example, the user displays all the access control lists that have been setup on the Switch: DGS-6600:2>show access-list access-list name access-list type First-Floor-Filter mac ext-acl Block-Server mac ext-acl Management ip acl Test ip acl IT-Management ip acl Strict-Control ip ext-acl Telnet-Management ip ext-acl TestTel ip ext-acl Web-Management ip ext-acl server-security ip ext-acl ipv6-control ipv6 ext-acl Total Entries : 11 DGS-6600:2> Applying Access Control Lists to Interfaces The user can apply up to one MAC access control list, one IP access control list, and one IPv6 access control list to an interface in the ingress direction. If a MAC access control list, an IP access control list, and an IPv6 access control list are applied to an interface, the device will check the MAC access control list for an ingress packet first. If the packet matches a criteria statement in the MAC access control list and is permitted, the device will continue to check the IP access control list if the packet is an IPv4 packet or an IPv6 access control list if the packet is an IPv6 packet. If a deny statement is matched in the IP access control list, the packet will be dropped without any further ACL checking. Use the following commands to apply an IP/MAC access control list to an interface and verify the settings: Command ip access-group NAME ipv6 access-group NAME mac access-group NAME show access-group [interface INTERFACE-ID] [ip [NAME] | mac [NAME] | ipv6 [NAME]] Explanation Applies an IP access control list to an interface for ingress traffic. Applies an IPv6 access control list to an interface for ingress traffic. Applies a MAC access control list to an interface for ingress traffic. Displays the access control list configuration. DGS-6600 Configuration Guide 423