User Manual

Table Of Contents
S350 Series 8-Port Gigabit Ethernet Smart Switch Models GS308T and GS310TP
Manage Device Security User Manual274
6. From the ACL ID menu, select the IP ACL for which you want to add a rule.
For extended IP ACLs, this must be an ID in the range from 101 to 199 or a name.
7. Click the Add button.
8. Configure the following match criteria for the rule:
Sequence Number. Enter a number in the range from 1 to 2147483647 that is used to
identify the rule. An extended IP
ACL can contain up to 50 rules.
Action. Select the ACL forwarding action, which is one of the following:
-
Permit. Forward packets that meet the ACL criteria.
Egress Queue
. If the selection from the Action menu is Permit, select the
hardware egress queue identifier that is used to handle all packets matching this
IP ACL rule.
The range of queue IDs is 0 to 7.
- Deny. Drop packets that meet the ACL criteria.
Logging
. If the selection form the Action menu is Deny, you can enable logging
for the ACL by selecting the
Enable radio button. (Logging is subject to resource
availability in the device.)
Interface. For a Permit action, use either a mirror interface or a redirect interface:
- Select the Mirror radio button and use the menu to specify the egress interface to
which the matching traffic stream is copied, in addition to being forwarded
normally by the device.
- Select the Redirect radio button and use the menu to specify the egress interface
to which the matching traffic stream is forced, bypassing any forwarding decision
normally performed by the device.