User Manual

Table Of Contents
Manage Device Security
661
M6100, M5300, and M7100 Series Managed Switches
The default admin user name is admin and the default admin password is blank, that is,
do not enter a password.
6. Click the Login button.
The web management interface menu displays.
7. Select Security > ACL > Advanced > IP Extended Rules.
8. ACL ID/Name - Select the IP ACL for which to create or update a rule.
9. Configure Rule ID by entering a whole number in the range of 1 to 1023 that is used to
identify the rule.
An IP ACL can have up to 1023 rules.
10. In the Action list, specify the action to take if a packet matches the rule's criteria.
The choices are Permit or Deny.
11. Set Logging to Enable.
This enables logging for this ACL rule (subject to resource availability in the device). If the
access list trap flag is also enabled, this causes periodic traps to be generated indicating
the number of times this rule was hit during the current report interval. A fixed 5-minute
report interval is used for the entire system. A trap is not issued if the ACL rule hit count is
zero for the current interval. This field is visible for a Deny action.
12. In the Assign Queue ID, specify the hardware egress queue identifier used to handle all
packets matching this IP ACL rule.
The valid range of queue IDs is 0 to 6.
13. Use the Mirror Interface field to specify the specific egress interface where the matching
traffic stream is copied, in addition to being forwarded normally by the device.
This field cannot be set if a redirect interface is already configured for the ACL rule. This
field is visible for a Permit action.
14. Use the Redirect Interface field to specify the specific egress interface where the matching
traffic stream is forced, bypassing any forwarding decision normally performed by the
device.
This field cannot be set if a mirror interface is already configured for the ACL rule. This
field is enabled for a Permit action.
15. In the Match Every list, select True or False.
True signifies that all packets must match the selected IP ACL and rule and are either
permitted or denied. In this case, since all packets match the rule, the option of