ECS4660-28F_Management Guide-R03

Table Of Contents
C
HAPTER
13
| Security Measures
Access Control Lists
– 395 –
Figure 201: Showing TCAM Utilization
SETTING THE ACL
NAME AND TYPE
Use the Security > ACL (Configure ACL - Add) page to create an ACL.
CLI REFERENCES
"access-list ip" on page 1164
"show ip access-list" on page 1169
PARAMETERS
These parameters are displayed:
ACL NameName of the ACL. (Maximum length: 32 characters)
Type – The following filter modes are supported:
IP Standard: IPv4 ACL mode filters packets based on the source
IPv4 address.
IP Extended: IPv4 ACL mode filters packets based on the source
or destination IPv4 address, as well as the protocol type and
protocol port number. If the “TCP” protocol is specified, then you
can also filter packets based on the TCP control code.
IPv6 Standard: IPv6 ACL mode filters packets based on the source
IPv6 address.
IPv6 Extended: IPv6 ACL mode filters packets based on the
source or destination IP address, as well as DSCP, next header type,
and the flow label (i.e., a request for special handling by IPv6
routers).
MAC – MAC ACL mode filters packets based on the source or
destination MAC address and the Ethernet frame type (RFC 1060).
ARP – ARP ACL specifies static IP-to-MAC address bindings used for
ARP inspection (see "ARP Inspection" on page 410).