Configuring acl acceleration, Acl configuration example – H3C Technologies H3C SecBlade LB Cards User Manual
Page 38
27
Table 8 Configuration items
Item Description
Rule ID
Select the Rule ID box, and enter a number for the rule.
If you do not specify the rule ID, the system assigns one automatically.
If the rule already exists, the configuration overwrites the old rule.
Operation
Select the operation to be performed for matching packets:
•
Permit—Allows matching packets to pass.
•
Deny—Denies matching packets.
Time Range
Select a time range for the rule.
If you select None, the rule is always effective.
Available time ranges are configured by selecting Security > Time Range from
the navigation tree.
Source MAC Address
Select the Source MAC Address box, and specify the source MAC address and
wildcard.
Source Wildcard
Destination MAC Address
Select the Destination MAC Address box, and specify the destination MAC
address and wildcard.
Destination Wildcard
LSAP Type
Select the LSAP Type box, and specify the DSAP and SSAP fields in the LLC
encapsulation by configuring the following items:
•
LSAP Type—Specifies the encapsulation format.
•
LSAP Wildcard—Specifies the LSAP mask.
LSAP Wildcard
Protocol Type
Select the Protocol Type box, and specify the link layer protocol by configuring
the following items:
•
Protocol Type—Specifies a protocol type in Ethernet_II and Ethernet_SNAP
frames.
•
Protocol Wildcard—Specifies a protocol type mask.
Protocol Wildcard
Configuring ACL acceleration
Select Security > ACL from the navigation tree to enter the page shown in
. All existing ACLs are
displayed. You can enable or disable ACL acceleration for an ACL through the ACL Acceleration column:
•
indicates that the ACL is not accelerated. Click the Start Accelerating link to
enable ACL acceleration.
•
indicates that the ACL is accelerated. Click the Stop Accelerating link to
disable ACL acceleration.
•
indicates that the ACL has been modified after it was configured with ACL
acceleration. Click the Start Accelerating link to enable ACL acceleration again, making changes
to the ACL take effect.
ACL configuration example
IPv4 ACLs are used together with NAT. For ACL configuration example, see Network Management
Configuration Guide.