User Manual

Table Of Contents
Manage Device Security
597
M4200 and M4300 Series ProSAFE Managed Switches Web Management User Manual
Logging. When set to Enable, logging is enabled for this ACL rule (subject to
resource availability in the device). If the access list trap flag is also enabled, this
causes periodic traps to be generated indicating the number of times this rule was hit
during the current report interval. A fixed 5-minute report interval is used for the entire
system. A trap is not issued if the ACL rule hit count is zero for the current interval.
This field is visible for a Deny action.
Egress Queue. The hardware egress queue identifier used to handle all packets
matching this IP ACL rule. Valid range of queue IDs is 0 to 6. This field is visible when
Permit is chosen as the action.
Match Every. Select True or False. True signifies that all packets must match the
selected IP ACL and rule and are either permitted or denied. In this case, since all
packets match the rule, the option of configuring other match criteria is not offered. To
configure specific match criteria for the rule, remove the rule and recreate it, or
reconfigure Match Every to False for the other match criteria to be visible.
Mirror Interface. The specific egress interface where the matching traffic stream is
copied in addition to being forwarded normally by the device. This field cannot be set
if a redirect interface is already configured for the ACL rule. This field is visible for a
Permit action.
Redirect Interface. The specific egress interface where the matching traffic stream is
forced, bypassing any forwarding decision normally performed by the device. This
field cannot be set if a mirror interface is already configured for the ACL rule. This field
is enabled for a Permit action.
Src IP Address. Enter an IP address using dotted-decimal notation to be compared
to a packet’s source IP address as a match criteria for the selected IP ACL rule.
Src IP Mask. Specify the IP mask in dotted-decimal notation to be used with the
source IP address.
Rate Limit Conform Data Rate. Value of Rate Limit Conform Data Rate specifies the
conforming data rate of IP ACL Rule. Valid values are 1 to 4294967295 in Kbps.
Rate Limit Burst Size. Value of Rate Limit Burst Size specifies burst size of the IP
ACL rule. Valid values are 1 to 128 in Kbytes.
Time Range. Name of time range associated with the IP ACL rule.
9. Click the Apply button.
The updated configuration is sent to the switch. Configuration changes take effect
immediately.
The Rule Status field on IP Rules page displays whether the ACL rule is active or
inactive. Blank means that no timer schedules are assigned to the rule.