User Manual

Table Of Contents
S350 Series 8-Port Gigabit Ethernet Smart Switch Models GS308T and GS310TP
Manage Device Security User Manual256
ACL Wizard Example
In the following figure, the ACL rule is configured to check for packet matches on ports 4, 5,
and 9 and on LAG 1. Only the Inbound option is valid. Packets that include a source address
in the 192.168.4.0/16 network are permitted to be forwarded by the interfaces. All other
packets are dropped because every ACL includes an implicit deny all rule as the last rule.
The previous figure shows a sample for model GS310TP.
For information about the ACL Wizard, see
Use the ACL Wizard to Create a Simple ACL on
page 251.
Configure a Basic MAC ACL
A MAC ACL consists of a set of rules that are matched sequentially against a packet. When a
packet meets the match criteria of a rule, the specified rule action (Permit or Deny) is taken,
and the additional rules are not checked for a match.
Multiple steps are involved in defining a MAC ACL and applying it to the switch:
1. Create a MAC ACL ID (see Add a MAC ACL on page 257).
2. Create a MAC rule (see
Configure MAC ACL Rules on page 259).
3. Associate the MAC ACL with one or more interfaces (see
Configure MAC Bindings on
page 263).
You can view or delete MAC ACL configurations in the MAC Binding table (see
View or
Delete MAC ACL Bindings in the MAC Binding Table on page 265.