288
XS712T Smart Switch
criteria to a particular queue or redirect the traffic to a particular port. A default deny all
rule is the last rule of every list.
2. Apply the access
list to an interface in the inbound direction.
The XS712T Smart Switch allows ACLs to be bound to physical ports and LAGs.The switch
sof
tware supports MAC ACLs and IP ACLs.
MAC ACL Example Configuration
The following example shows how to create a MAC-based ACL that permits Ethernet traffic
from the Sales department on specified ports and denies all other traffic on those ports.
1. From the MAC ACL screen, create an
ACL with the name Sales_ACL for the Sales
department of your network (see MAC ACL o
n page 215).
By default, this ACL will be bound on the inboun
d direction, which means the switch will
examine traffic as it enters the port.
2. From
the MAC Rules screen, create a rule for the Sales_ACL with the following settings:
• ID. 1
• Action. Permit
• Assign Queue. 0
• Matc
h Every. False
• CoS. 0
• Destinati
on MAC. 01:02:1A:BC:DE:EF
• Destinati
on MAC Mask. 00:00:00:00:FF:FF
• Source MAC. 0
2:02:1A:BC:DE:EF
• Source MAC Mask. 00:00:0
0:00:FF:FF
• VLAN ID. 2
For more information about MAC ACL rules, see MAC Rules o
n page 216.
3. From
the MAC Binding Configuration screen, assign the Sales_ACL to Ethernet ports 6, 7,
and 8, and then click Apply (seeMAC Binding Configuration on p
age 218).