97
ACL
AnAccessControlList(ACL)allowsyoutodeneclas-
si¬cationrulesorestablishcriteriatoprovidesecurity
to your network by blocking unauthorized users and
allowingauthorizedus¬erstoaccessspecicareasor
resources. ACLs can provide basic security for access to
the network by controling whether packets are forward-
ed or blocked at the Switch ports. Access Control Lists
(ACLs)areltersthatallowyoutoclassifydatapackets
according to a particular content in the packet header,
such as the source address, destination address, source
port number, destination port number, and more. Packet
classiersidentifyowsformoreefcientprocessing.
Eachlterdenestheconditionsthatmustmatchfor
inclusioninthelter.ACLs(AccessControlLists)provide
packetlteringforIPframes(basedontheprotocol,
TCP/UDP port number or frame type) or layer 2 frames
(based on any destination MAC address for unicast,
broadcast, or multicast, or based on VLAN ID or VLAN tag
priority). ACLs can be used to improve performance by
blockingunnecessarynetworktrafcortoimplementse-
curitycontrolsbyrestrictingaccesstospecicnetwork
resources or protocols. Policies can be used to differen-
tiate service for client ports, server ports, network ports,
or guest ports. They can also be used to strictly control
networktrafcbyonlyallowingincomingframesthat
match the source MAC and source IP address on a spe-
cicport.ACLsarecomposedofAccessControlEntries
(ACEs),whicharerulesthatdeterminetrafcclassica-
tions. Each ACE is a considered as a single rule, and up to
256rulesmaybedenedoneachACL,withupto3000
rulesglobally.ACLsareusedtoprovidetrafcowcon-
trol, restrict contents of routing updates, and determine
whichtypesoftrafcareforwardedorblocked.This
criterioncanbespeciedonabasisoftheMACaddress
or IP address.