Nortel Networks 2300 Switch User Manual


 
407
Nortel WLAN—Security Switch 2300 Series Configuration Guide
Configuring and managing security
ACLs
About security access control lists
A security access control list (ACL) filters packets for the purpose of discarding them, permitting them, or permitting
them with modification (marking) for class-of-service (CoS) priority treatment. A typical use of security ACLs is to
enable users to send and receive packets within the local intranet, but restrict incoming packets to the server in which
confidential salary information is stored.
Nortel provides a very powerful mapping application for security ACLs. In addition to being assigned to physical ports,
VLANs, virtual ports in a VLAN, or Distributed APs, ACLs can be mapped dynamically to a user’s session, based on
authorization information passed back from the AAA server during the user authentication process.
About security access control lists . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 407
Creating and committing a security ACL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 410
Mapping security ACLs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 422
Modifying a security ACL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 426
Using ACLs to change CoS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 431
Enabling prioritization for legacy voice over IP . . . . . . . . . . . . . . . . . . . . . . . . . . . . 434
Security ACL configuration scenario . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 442