What is acl logging, What are time-based acls – Dell POWEREDGE M1000E User Manual

Page 546

Advertising
background image

546

Configuring Access Control Lists

Using ACLs to mirror traffic is considered to be flow-based mirroring since

the traffic flow is defined by the ACL classification rules. This is in contrast to

port mirroring, where all traffic encountered on a specific interface is

replicated on another interface.

What Is ACL Logging

ACL Logging provides a means for counting the number of “hits” against an

ACL rule. When you configure ACL Logging, you augment the ACL deny

rule specification with a "log" parameter that enables hardware hit count

collection and reporting. The switch uses a fixed five minute logging interval,

at which time trap log entries are written for each ACL logging rule that

accumulated a non-zero hit count during that interval. You cannot configure

the logging interval.

What Are Time-Based ACLs?

The time-based ACL feature allows the switch to dynamically apply an

explicit ACL rule within an ACL for a predefined time interval by specifying a

time range on a per-rule basis within an ACL, so that the time restrictions are

imposed on the ACL rule.
With a time-based ACL, you can define when and for how long an individual

rule of an ACL is in effect. To apply a time to an ACL, first you define a

specific time interval and then apply it to an individual ACL rule so that it is

operational only during the specified time range, for example, during a

specified time period or on specified days of the week.
A time range can be absolute (specific time) or periodic (recurring). If an

absolute and periodic time range entry are defined within the same time

range, the periodic timer is active only when the absolute timer is active.

NOTE:

Adding a conflicting periodic time range to an absolute time range will

cause the time range to become inactive. For example, consider an absolute time

range from 8:00 AM Tuesday March 1st 2011 to 10 PM Tuesday March 1st 2011.

Adding a periodic entry using the 'weekend' keyword will cause the time-range

to become inactive because Tuesdays are not on the weekend.

Advertising