< Home

VLAN ACL

Context

You can configure ACL rules and apply the ACL to a VLAN to filter the VLAN packets. The ACL rule configuration includes source and destination IP addresses, protocol type, source and destination port numbers.

Procedure

  • Query the ACL rules applied to VLANs.
    1. Click Configuration to display the Configuration page.
    2. Choose Security Services > ACL in the navigation tree to display the ACL page.
    3. Click the VLAN ACL tab to display the VLAN ACL page, as shown in Figure 1.

      Figure 1 VLAN ACL

    4. Select the ID of the VLAN to which the ACL rules are applied. The record is displayed in the ACL Rule List area, as shown in Figure 2.

      Figure 2 Querying ACL rules

  • Copy the ACL rules that have been applied to a VLAN to another VLAN.
    1. Click Configuration to display the Configuration page.
    2. Choose Security Services > ACL in the navigation tree to display the ACL page.
    3. Click the VLAN ACL tab to display the VLAN ACL page.
    4. Select the ID of the VLAN to which the ACL rules have been applied. Click Copy To to display the Copy To page, as shown in Figure 3.

      Figure 3 Copying ACL rules

    5. Enter the ID of the destination VLAN to which the ACL rules are applied, and click OK.
  • Create ACL rules.

    1. Click Configuration to display the Configuration page.

    2. Choose Security Services > ACL in the navigation tree to display the ACL page.

    3. Click the VLAN ACL tab to display the VLAN ACL page.

    4. Select the ID of the VLAN to which ACL rules need to be applied, and create the ACL rules.

      • If no record is displayed in the ACL Rule List area, click on the right of Operation or Add on the left of Ascend. A record of ACL Rule List is displayed in the ACL Rule List area. Set the ACL rule parameters.

      • If the existing ACL rule records are displayed in the ACL Rule List area, click on the right of Operation or Add on the left of Ascend or on the right of Delete. A new record of ACL Rule List is displayed in the ACL Rule List area. Set the ACL rule parameters, as shown in Figure 4.

        If you click on the right of Operation or Add on the left of Ascend, a new record of ACL Rule List is inserted to the first line in the ACL Rule List area. If you click Add on the right of Delete, a new record of ACL Rule List is inserted below the current line in the ACL Rule List area.

        Figure 4 Creating ACL rules

        Table 1 describes the parameters for creating ACL rules.

        Table 1 Parameters for creating ACL rules

        Parameter

        Description

        Source IP address

        Indicates the source IP address. The default value is any, indicating that any source IP address can be specified.

        Mask of Source IP

        Indicates the mask of the source IP address. The default value is 0 (0.0.0.0).

        Destination IP address

        Indicates the destination IP address. The default value is any, indicating that any destination IP address can be specified.

        Mask of Destination IP

        Indicates the mask of the destination IP address. The default value is 0 (0.0.0.0).

        Protocol type

        Indicates the protocol type, including:
        • ip
        • tcp
        • udp
        • icmp
        The default protocol type is IP.

        Source Port Num

        Indicates the source port number.

        This parameter is valid only when the protocol type is TCP or UDP. If this parameter is not specified, TCP or UDP packets with any source port are matched.

        Dest Port Num

        Indicates the destination port number.

        This parameter is valid only when the protocol type is TCP or UDP. If this parameter is not specified, TCP or UDP packets with any destination port are matched.

        Action

        Indicating the action matching a packet, including:
        • permit
        • deny
        The default action is permit.

        Operation

        • Delete
        • Add
    5. Click Apply.

  • Edit ACL rules.

    1. Click Configuration to display the Configuration page.

    2. Choose Security Services > ACL in the navigation tree to display the ACL page.

    3. Click the VLAN ACL tab to display the VLAN ACL page.

    4. Select the ID of the VLAN to which ACL rules have been applied, and edit the ACL rules.

      • Edit ACL rule entries.

        Modify the ACL rule parameters in the ACL Rule List area.

      • Adjust the ACL rule entry sequence.

        Select a record of ACL Rule List in the ACL Rule List area. Click Ascend or Descend to adjust the ACL rule entry sequence.

    5. Click Apply.

  • Delete ACL rules.

    1. Click Configuration to display the Configuration page.

    2. Choose Security Services > ACL in the navigation tree to display the ACL page.

    3. Click the VLAN ACL tab to display the VLAN ACL page.

    4. Select the ID of the VLAN to which the ACL rules have been applied. In the ACL Rule List area, click Delete next to the record to be deleted or select records and click Delete next to Descend to delete the ACL rules in batches.

    5. Click Apply.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic