Owner's Manual
328
Access Profile Editor
This panel lists the access profiles available on the selected device. You can
Add
, or
Edit
ACLs for
the selected device in this screen. Select a listed ACL and click
Remove
to delete it. Click
Add
, or
select a listed interface and click
Edit,
and the editor opens (the lower portion of the screen) with
the following fields:
-
ACL Name
—The identifier for the ACL.
Click
Add
, or
Edit
to add rules for an ACL. Click
Apply to ACE Table
to accept your configured
rules. Configured rules for the ACL appear listed below the
Add, Edit
and
Remove
buttons. screen.
When you click
Add
, or select a listed ruleset and click
Edit,
an editor opens (the lower portion of
the screen) with the following fields:
Access Profile Rule
-
Prioriity
—Rule priority that determines which ACE is matched to a packet based on a first-
match basis. Check
Auto-Gen
to automatically generate the priority. When the packet
matches a rule, user groups are either granted or denied device management access. The rule
order is set by defining a rule number within the Profile Rules Table. The rule number is
essential to matching packets to rules, as packets are matched on a first-fit basis. (1-65535)
-
Action
—Indicates the ACL forwarding action. The possible field values are:
Permit —Forwards packets which meet the ACL criteria.
Deny—Drops packets which meet the ACL criteria.
Shutdown—Drops packet that meet the ACL criteria, and disables the port to which the
packet was addressed.
-
Management Method
—The management method for which the access profile is defined. Users
with this access profile can access the device using the management method selected.
-
Source Ip/Mask
—The source IP and IP address mask for the source to which this rule applies.
-
Interface
—The interface type to which the rule applies. This is an optional field. This rule can
apply to a selected port, LAG, or VLAN by selecting the appropriate option and interface.
Assigning an access profile to an interface denies access via other interfaces. If you select
(
Any
) as an access profile, device access is granted all interfaces.
Click
Apply
to accept your edits, or
Cancel
to abandon them. Click
Refresh
to renew the device
information on this screen or
Configure
to send your edits to the device.