User Manual

Table Of Contents
M4300 Intelligent Edge Series Fully Managed Stackable Switches
Manage Switch Security User Manual624
Action. Specify what action is taken if a packet matches the rule’s criteria. The choice
is Permit or Deny.
Logging. When set to Enable, logging is enabled for this
ACL rule (subject to
resource availability in the device). If the access list trap flag is also enabled, this
causes periodic traps to be generated indicating the number of times this rule was hit
during the current report interval. A fixed 5-minute report interval is used for the entire
system. A trap is not issued if the ACL rule hit count is zero for the current interval.
This field is visible for a Deny action.
Egress Queue.
The hardware egress queue identifier used to handle all packets
matching this IPv6 ACL rule. Valid range of queue IDs is 0 to 7. This field is visible
when Permit is chosen as the action.
Interface. For a Permit action, use either a mirror interface or a redirect interface:
- Select the Mirror Interface radio button and use the menu to specify the egress
interface to which the matching traf
fic stream is copied, in addition to being
forwarded normally by the device.
- Select the Redirect Interface radio button and use the menu to specify the
egress interface to which the matching traf
fic stream is forced, bypassing any
forwarding decision normally performed by the device.
Match Every. From the menu, select T
rue or False.
True signifies that all packets must match the selected IPv6 ACL and rule and are
either permitted or denied. In this case, because all packets match the rule, the option
of configuring other match criteria is not available.
To configure specific match criteria
for the rule, remove the rule and recreate it, or select False from the Match Every
menu.
Protocol Type. Specify the IPv6 protocol
Type in one of the following ways:
- From the Protocol T
ype menu, select IPv6, TCP, UDP, or ICMPv6.
- From the Protocol T
ype menu, select Other, and in the associated field, specify
an integer ranging from 1 to 255. This number represents the IPv6 protocol.
TCP Flag. For each
TCP flag, specify whether or not a packet’s TCP flag must be
matched. The TCP flag values are URG, ACK, PSH, RST, SYN, and FIN. You can set
each TCP flag separately to one of the following options:
- Ignore.
The packet’s TCP flag is ignored. This is the default setting.
- Set (+).
A packet matches this ACL rule if the TCP flag in this packet is set.
- Clear (-).
A packet matches this ACL rule if the TCP flag in this packet is not set.
Note: If the RST and ACK flags are set, the option Established is available,
indicating that a match occurs if either the RST- or ACK-specified bits
are set in the packet’s header.
Src. In the Src field, enter a source IPv6 address to be compared to a packet’
s
source IPv6 address as a match criteria for the selected IPv6 ACL rule:
- If you select the IPv6 Address radio button, enter an IPv6 address to apply this
criteria. If this field is left empty
, it means any.