ECS3510-26P_Management Guide R02

Table Of Contents
C
HAPTER
13
| Security Measures
Access Control Lists
– 322 –
Figure 174: Configuring a Standard IPv4 ACL
CONFIGURING AN
EXTENDED IPV4 ACL
Use the Security > ACL (Configure ACL - Add Rule - IP Extended) page to
configure an Extended IPv4 ACL.
CLI REFERENCES
"permit, deny, redirect-to (Extended IPv4 ACL)" on page 714
"show ip access-list" on page 718
"Time Range" on page 572
COMMAND USAGE
Due to a ASIC limitation, the switch only checks the leftmost six priority
bits. This presents no problem when checking DSCP or IP Precedence bits,
but limits the checking of ToS bits (underlined in the following example) to
the leftmost three bits, ignoring the right most fourth bit.
For example, if you configured an access list to deny packets with a ToS of
7 (000011
10), the highlighted bit would be ignored, and the access list
would drop packets with a ToS of both 6 and 7.
PARAMETERS
These parameters are displayed:
Type – Selects the type of ACLs to show in the Name list.
Name – Shows the names of ACLs matching the selected type.
Action – An ACL can contain any combination of rules which permit or
deny a packet, or re-direct a packet to another port.
Table 21: Priority Bits Processed by Extended IPv4 ACL
DSCP
Precedence ToS
76543210