User Manual

Table Of Contents
Manage Device Security
668
M6100, M5300, and M7100 Series Managed Switches
If the access list trap flag is also enabled, this causes periodic traps to be generated
indicating the number of times this rule was hit during the current report interval. A fixed 5
minute report interval is used for the entire system. A trap is not issued if the ACL rule hit
count is zero for the current interval. This field is visible for a Deny action.
11. Use Assign Queue ID to specify the hardware egress queue identifier used to handle all
packets matching this IPv6 ACL rule.
Valid range of queue IDs is 0 to 7. This field is visible for a Permit action.
12. Use Mirror Interface to specify the specific egress interface where the matching traffic
stream is copied in addition to being forwarded normally by the device.
This field cannot be set if a redirect interface is already configured for the ACL rule. This
field is visible for a Permit action.
13. Use Redirect Interface to specify the specific egress interface where the matching traffic
stream is forced, bypassing any forwarding decision normally performed by the device.
This field cannot be set if a mirror interface is already configured for the ACL rule. This
field is visible for a Permit action.
14. In the Match Every field, select True or False.
True signifies that all packets must match the selected IPv6 ACL and rule and are either
permitted or denied. In this case, since all packets match the rule, the option of
configuring other match criteria is not offered. To configure specific match criteria for the
rule, remove the rule and recreate it, or reconfigure Match Every to False for the other
match criteria to be visible.
15. There are two ways to configure IPv6 Protocol Type:
Specify an integer ranging from 1 to 255 after selecting the protocol keyword other.
This number represents the IP protocol.
Select the name of the protocol from the existing list of Internet Protocols (IPv6),
Transmission Control Protocol (TCP), User Datagram Protocol (UDP), and Internet
Control Message Protocol (ICMPv6).
16. Use TCP Flag to specify that a packet's TCP flag is a match condition for the selected IPv6
ACL rule.
The TCP flag values are URG, ACK, PSH, RST, SYN, FIN. Each TCP flag can be set
separately. the possible values are as follows:
Ignore. A packet matches this ACL rule whether the TCP flag in this packet is set or
not.
Set (+). A packet matches this ACL rule if the TCP flag in this packet is set.
Clear (-). A packet matches this ACL rule if the TCP flag in this packet is not set.
When Established is specified, a match occurs if either RST or ACK specified bits are
set in the TCP header.
The following fields are enabled only when TCP protocol is selected:
- Protocol. There are two ways to configure IPv6 protocol.