Specifications

14-12 Security ACL Commands
Defaults
Bydefault,permittedpacketsareclassifiedbasedonDSCPvalue,whichisconvertedintoan
internalCoSvalueintheswitch’sCoSmap.ThepacketisthenmarkedwithaDSCPvaluebased
ontheinternalCoSvalue.IftheACEcontainsthecosoption,thisoptionoverridestheswitch’s
CoS
mapandmarksthepacketbasedontheACE.
Mode
Enabled.
Usage
TheRoamAboutSwitchdoesnotapplysecurityACLsuntilyouactivatethemwiththecommit
securityaclcommandandmapthemtoaVLAN,port,orvirtualport,ortoauser.Ifthe
RoamAboutSwitchisresetorrestarted,anyACLsintheeditbufferarelost.
Youcannotperform
ACLfunctionsthatincludepermitting,denying,ormarkingwithaClassof
Service(CoS)levelonpacketswithamulticastorbroadcastdestinationaddress.
TheorderofsecurityACEsinasecurityACLisimportant.OnceanACLisactive,itsACEsare
checkedaccordingtotheirorderintheACL.
IfanACEcriterionismet,itsactiontakesplaceand
anyACEsthatfollowareignored.
ACEsarelistedintheorderinwhichyoucreatethem,unlessyoumovethem.Topositionsecurity
ACEswithinasecurityACL,usebeforeeditbufferindexandmodifyeditbufferindex.
established ForTCP
packetsonly,appliestheACEonlytoestablishedTCPsessionsand
nottonewTCPsessions.
beforeeditbuffer
index
InsertsthenewACEinfrontofanotherACEinthesecurityACL.Specify
thenumberoftheexistingACEintheeditbuffer.Indexnumbersstartat1.
(Todisplaytheedit
buffer,useshowsecurityacleditbuffer.)
modifyeditbuffer
index
ReplacesanACEinthesecurityACLwiththenewACE.Specifythe
numberoftheexistingACEintheeditbuffer.Indexnumbersstartat1.(To
displaytheeditbuffer,useshowsecurityacleditbuffer.)
hits Tracksthenumberof
packetsthatarefilteredbasedonasecurityACL,for
allmappings.
Notes:
•The any option is supported for the source or destination IP address and mask. This option is
equivalent to 0.0.0.0 255.255.255.255.
•The any option is shown in the configuration file as 0.0.0.0 255.255.255.255, regardless of
whether you specify any or 0.0.0.0 255.255.255.255 when you configure the ACE.
Note: The dscp codepoint is added. This option enables you to filter based on a packet’s
Differentiated Services Code Point (DSCP) value.