R3204P16-HP Load Balancing Module Security Configuration Guide-6PW101
56
Item Descri
p
tion
Operation
Select the operation to be performed for packets matching the rule.
•
Permit: Allows matching packets to pass.
•
Deny: Denies matching packets.
Time Range
Select a time range for the rule.
If you select None, the rule will always be effective.
Available time ranges are configured by selecting Security > Time Range from
the navigation tree.
Source MAC Address
Select the Source MAC Address check box and specify the source MAC address
and wildcard.
Source Wildcard
Destination MAC Address
Select the Destination MAC Address check box and specify the destination MAC
address and wildcard.
Destination Wildcard
LSAP Type
Select the LSAP Type check box and specify the DSAP and SSAP fields in the LLC
encapsulation by configuring the following two items:
•
LSAP Type: Specifies the encapsulation format.
•
LSAP Wildcard: Specifies the LSAP mask.
LSAP Wildcard
Protocol Type
Select the Protocol Type check box and specify the link layer protocol by
configuring the following two items:
•
Protocol Type: Specifies a protocol type in Ethernet_II and Ethernet_SNAP
frames.
•
Protocol Wildcard: Specifies a protocol type mask.
Protocol Wildcard
Return to ACL configuration task list.
Configuring ACL acceleration
Select Security > ACL from the navigation tree to enter the page shown in Figure 54. All existing ACLs are
displayed in the right pane. You can enable or disable ACL acceleration for an ACL through the ACL
Acceleration column:
• indicates that the ACL is not accelerated. You can click the Start Accelerating
link to enable ACL acceleration.
• indicates that the ACL is accelerated. You can click the Stop Accelerating link
to disable ACL acceleration.
• indicates that the ACL has been modified after it was configured with ACL
acceleration. You can click the Start Accelerating link to enable ACL acceleration again, making
changes to the ACL take effect.
Return to ACL configuration task list.
ACL configuration example
Network requirements
As shown in Figure 62, configure an ACL to deny hosts in the R&D and Marketing departments to access
the salary server, and allow hosts in the Accounting department to access the salary server.