PLANET WGS3-2820 User Manual

Page 174

Advertising
background image

User’s Manual of WGS3-2820/WGS3-5220

174

4.5.1.3 IP ACL Rule Configuration

Use these screens to configure the rules for the Access Control Lists created using the Access Control List Configuration screen.

What is shown on this screen varies depending on the current step in the rule configuration process. An ACL must first be

selected to configure rules for. The rule identification, and the 'Action' and 'Match Every' parameters must be specified next. If

'Match Every' is set to false a new screen will then be presented from which the match criteria can be configured.

Figure 4-5-3

ACL Rule Configuration

Selection Criteria

IP ACL ID

- Use the pulldown menu to select the IP ACL for which to create or update a rule.

Rule

- Select an existing rule from the pulldown menu, or select 'Create New Rule.' ACL as well as an option to add

a new Rule. New rules cannot be created if the maximum number of rules has been reached. For each rule, a packet

must match all the specified criteria in order to be true against that rule and for the specified rule action (Permit/Deny)

to take place.

Configurable Data

Rule ID

- Enter a whole number in the range of 1 to 9 that will be used to identify the rule. An IP ACL may have up to

9 rules.

Action

- Specify what action should be taken if a packet matches the rule's criteria. The choices are permit or deny.

Assign Queue ID

- Specifies the hardware egress queue identifier used to handle all packets matching this IP ACL

rule. Valid range of Queue Ids is (0 to 7). This field is visible when 'Permit' is chosen as 'Action'.

Redirect Interface

- Specifies the specific egress interface where the matching traffic stream is forced, bypassing

any forwarding decision normally performed by the device. This field is visible when 'Permit' is chosen as 'Action'.

Match Every

- Select true or false from the pulldown menu. True signifies that all packets will match the selected IP

ACL and Rule and will be either permitted or denied. In this case, since all packets match the rule, the option of

Advertising
This manual is related to the following products: