Owner's Manual

Chapter 13. ACLs | 329
NETGEAR 8800 User Manual
Figure 20. ACL Entry One Through onehundred_twentynine
As entries are configured on the switch, the slices are programmed to implement the rules,
and the rule memory is filled with the matching values for the rules. If a compatible slice is
available, each entry is added to that slice.
Compatible and Conflicting Rules
The slices can support a variety of different ACL match conditions, but there are some
limitations on how you combine the match conditions in a single slice. A slice is divided up
into fields, and each field uses a single selector. A selector is a combination of match
conditions or packet conditions that are used together. To show all the possible combinations,
the conditions in
Table 34 are abbreviated.
Table 34. Abbreviations Used in Field Selector Tables
Abbreviation Condition
Ingress
DIP destination address <prefix> (IPv4 addresses only)
SIP source address <prefix> (IPv4 addresses only)
IP-Proto protocol <number>
XM_079
Slice A Rules (128)
Slice B
Rules (128)