Alcatel 9000 Guía de usuario Pagina 572

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 702
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 571
Creating Condition Groups For ACLs Configuring ACLs
page 27-8 OmniSwitch 6800/6850/9000 Network Configuration Guide June 2006
Important. If you set the global bridged disposition (using the qos default bridged disposition
command) to deny or drop, it will result in dropping all Layer 2 traffic from the switch that does not
match any policy to accept traffic. You must create policies (one for source and one for destination) to
allow traffic on the switch.
If you set the bridged disposition to deny or drop, and you configure Layer 2 ACLs, you will need two
rules for each type of filter. For more information, see “Layer 2 ACLs” on page 27-10.
Creating Condition Groups For ACLs
Condition groups for ACLs are made up of multiple IP addresses, MAC addresses, services, or IP ports to
which you want to apply the same disposition. Instead of creating a separate condition for each policy rule,
create a condition group and associate the group with the condition. This reduces the number of rules you
would have to configure (one for each address, service, or port).
The commands used for creating condition groups include:
policy network group
policy mac group
policy service
policy service group
policy port group
For example:
-> policy network group netgroup2 10.10.5.1 10.10.5.2 10.10.5.3
-> policy condition cond2 source network group netgroup2
This command configures a network group (netgroup2) of three IP addresses. The network group is then
configured as part of a policy condition (cond2). The condition specifies that the addresses in the group
are source addresses. (For all condition groups except service groups, the policy condition specifies
whether the condition group is a source or destination group.)
If a network group was not used, a separate condition would have to be created for each IP address. Subse-
quently, a corresponding rule would have to be created for each condition. Using a network group reduces
the number of rules required.
For more details about using groups in policy conditions, see “Using Condition Groups in Policies” on
page 26-35 in Chapter 26, “Configuring QoS.”
Configuring ACLs
This section describes in detail the procedures for configuring ACLs. For more information about how to
configure policies in general, see Chapter 26, “Configuring QoS.” Command syntax is described in detail
in the OmniSwitch CLI Reference Guide.
The basic commands for configuring ACL rules are the same as those for configuring policy rules:
policy condition
policy action
policy rule
Vista de pagina 571
1 2 ... 567 568 569 570 571 572 573 574 575 576 577 ... 701 702

Comentarios a estos manuales

Sin comentarios