Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Add_workflow_for_techpubs
AUTH2ghoppe
AUTH1jharvey
JIRAIDAUTHCHOR-1152
REV5ghoppe
REV6ghoppe
REV3ghoppe
REV1kolakalk

Panel

In this section:

Table of Contents
maxLevel3

...

  1. In the left navigation panel, click on Access Control Lists and click on the desired table.

  2. Click the Create Access Control List Entry ( ) icon.

  3. Enter the desired configuration. See SWe Lite and Modifying Rules for IPv4 Access Control Lists. For sample configurations, see SWe Lite and Modifying Rules for IPv4 Access Control Lists.

  4. Click OK.

    Panel
    borderStylenone

    Caption
    0Figure
    1Create Rule Entry


    Image Modified

Modifying a Rule

...

Panel
bgColor#FAFAFA
borderStylenone

Specifies the action to be taken upon packets matching this rule. Valid selections: Deny Allow (default, packets matching this rule are not accepted) or Allow Deny (packets matching this rule are not accepted).

IANA IP Protocol Number

...

Panel
bgColor#FAFAFA
borderStylenone

Either Service or Single Port. The Services option allows you to define the service for either UDP or TCP protocol. The Single Port option should be used to specify a specific source or destination port number. This field is available only when either TCP or UDP is selected from the Protocol drop down box.

Service

Panel
bgColor#FAFAFA
borderStylenone

Services available for either TCP or UDP. Only those Ports for which the SBC 1000/2000 is a server are available as Services. This field is available only when UDP or TCP is selected from the SWe Lite and Modifying Rules for IPv4 Access Control Lists drop down box.

Precedence

When this is the
Protocol selection... 
...the Service
choices are:
TCP
  • HTTPS
  • HTTP
  • SSH
UDP
  • SNMP
  • DHCP
  • DNS
  • RIP

Precedence

Panel
bgColor#FAFAFA
Panel
bgColor#FAFAFA
borderStylenone

Every rule should have a unique precedence value. Value range is 1 - 65535, and default is 1.

Bucket Size

Panel
bgColor#FAFAFA
borderStylenone

????

Fill Rate

Panel
bgColor#FAFAFA
borderStylenone

????

.

Bucket Size

Panel
bgColor#FAFAFA
borderStylenone

The policing bucket size (in packets). It represents a credit balance that should be consumed before the packets are discarded. The consumed credits reside in the bucket and gets reduced for every packet received.

 0-255 packets/second

Fill Rate

Panel
bgColor#FAFAFA
borderStylenone

The number of packets to add to the bucket credit balance (in packets/second). If a packet is received at a rate exceeding this fill rate, it is discarded subjected to the discard rate set in the IP Policing Alarm profile or in the Policer Alarm monitoring this Media Port. The bucket credit balance is always less than the configured bucket size regardless of the size of this increment.

0-25000 packet/second.

Interface Name

Panel
bgColor#FAFAFA
borderStylenone

A drop-down menu that allows the user to select an interface name of the available interfaces from the systemto which this ACL rule should be applied.

Source Panel - Field Definitions

...

Panel
bgColor#FAFAFA
borderStylenone

The port number associated with the source packets subject to this rule. This field is available only when TCP or UDP is selected from the Protocol drop down box and Single Port is selected from the Port Selection Method drop down box.

Destination Panel - Field Definitions

...

Panel
bgColor#FAFAFA
borderStylenone

The port number associated with the source packets subject to this rule. This field is available only when TCP or UDP is selected from the Protocol drop down box and Single Port is selected from the Port Selection Method drop down box.

Sample ACL Rule Configuration

...