10.4 Application Example for ACL
Network Requirements
1. The manager of the R&D department can access to the forum of the company and the Internet
without any forbiddance. The MAC address of the manager is 00-64-A5-5D-12-C3.
2. The staff of the R&D department can not access to the Internet but can visit the forum.
3. The staff of the marketing department can access to the Internet but can not visit the forum.
4. The R&D department and marketing department can not communicate with each other.
Network Diagram
Configuration Procedure
Step Operation Description
1 Configure for
requirement 1
On ACL→ACL Config→ACL Create page, create ACL 11.
On ACL→ACL
Config→MAC ACL page, select ACL 11, create Rule 1,
configure the operation as Permit, configure the S-MAC as
00-64-A5-5D-12-C3 and mask as FF-FF-FF-FF-FF-FF.
On ACL→P
olicy Config→Policy Create page, create a policy named
manager.
On ACL→P
olicy Config→Action Create page, add ACL 11 to Policy
manager.
On ACL→P
olicy Binding→Port Binding page, select Policy manager
to bind to port 3.
121