User's Manual

Table Of Contents
Configuration Guide of XGS-5240-Series
45-26
Ethernet1/0/2: IP Ingress access-list used is 1, traffic-statistics Disable.
Ethernet1/0/5: IP Ingress access-list used is 1, traffic-statistics Disable.
Ethernet1/0/7: IP Ingress access-list used is 1, traffic-statistics Disable.
45.4 ACL Troubleshooting
Checking for entries in the ACL is done in a top-down order and ends whenever a
n entry is matched.
Default rule will be used only if no ACL is bound to the incoming dire
ction of the port, or no ACL entry is matched.Each ingress port can bi
nd one MAC-IP ACL, one IP ACL, one MAC ACL, one IPv6 ACL (via
the physical interface mode or Vlan interface mode).
When binding four ACL and packet matching several ACL at the s
ame time, the priority relations are as follows in a top-down order.
If the priority is same, then the priority of configuration at first is
higher.
Ingress IPv6 ACL
Ingress MAC-IP ACL
Ingress IP ACL
Ingress MAC ACL
The number of ACLs that can be successfully bound depends on the content of th
e ACL bound and the hardware resource limit. Users will be prompted if an ACL c
annot be bound due to hardware resource limitation.
If an access-list contains same filtering information but conflicting action rules, bindi
ng to the port will fail with an error message. For instance, configuring “permit tcp
any any-destination” and “deny tcp any any-destination” at the same time is not pe
rmitted.
Viruses such as “worm.blaster” can be blocked by configuring ACL to block specific
ICMP packets or specific TCP or UDP port packet.
If the physical mode of an interface is TRUNK, ACL can only be configured throug
h physical interface mode.
ACL configured in the physical mode can only be disabled in the physical mod
e. Those configured in the VLAN interface configuration mode can only be disa
bled in the VLAN interface mode.
When a physical interface is added into or removed from a VLAN (with the tru
nk interfaces as exceptions), ACL configured in the corresponding VLAN will b
e bound or unbound respectively. If ACL configured in the target VLAN, which
is configured in VLAN interface mode, conflicts with existing ACL configuration