User's Manual

Table Of Contents
51-23
51.4 ACL Troubleshooting
Checking for entries in the ACL is done in a top-down order and ends whenever an entry is matched.
Each ingress port can bind one MAC-IP ACL, one IP ACL, one MAC ACL, one IPv6 ACL (via the
physical interface mode or Vlan interface mode).
When binding four ACL and packet matching several ACL at the same time, the priority relations are as
follows in a top-down order. If the priority is same, then the priority of configuration at first is higher.
Ingress IPv6 ACL
Ingress MAC-IP ACL
Ingress IP ACL
Ingress MAC ACL
The number of ACLs that can be successfully bound depends on the content of the ACL bound and the
hardware resource limit. Users will be prompted if an ACL cannot be bound due to hardware resource
limitation.
If an access-list contains same filtering information but conflicting action rules, binding to the port will fail
with an error message. For instance, configuring “permit tcp any any-destination” and “deny tcp any
any-destination” at the same time is not permitted.
Viruses such as “worm.blaster” can be blocked by configuring ACL to block specific ICMP packets or
specific TCP or UDP port packet.