Netgear XCM8810 - 8800 SERIES 10-SLOT CHASSIS SWITCH ユーザーズマニュアル
344
|
Chapter 13. ACLs
NETGEAR 8800 User Manual
}
entry premium_16 {
if match {
source-address 211.10.16.0/24;
} then {
permit;
redirect-name premium_subscriber;
}
}
3.
Apply the modified ACL policy file or dynamic ACL into a port, VLAN, or VLAN and Port. (For
example: user1 VLAN: 192.168.1.0/30, user2 VLAN: 192.168.1.4/30)
example: user1 VLAN: 192.168.1.0/30, user2 VLAN: 192.168.1.4/30)
config access-list premium_user vlan user1 ingress
config access-list premium_user vlan user2 ingress
4.
Finally, check the current flow-redirect status.
BD-8810.47 # show flow-redirect "premium_subscriber"
Name : premium_subscriber VR Name : VR-Default
NO-ACTIVE NH : FORWARD HC TYPE : PING
NH COUNT : 2 ACTIVE IP : 192.168.2.3
Index STATE Pri IP ADDRESS STATUS INTERVAL MISS
======================================================================
0 ENABLED 200 192.168.2.2 DOWN 2 2
1 ENABLED 100 192.168.2.3 UP 2 2
BD-8810.48 # show flow-redirect
Flow-Redirect Name NH_CNT ACTIVE IP VR Name D/F HC
=================================================================
premium_subscriber 2 192.168.2.3 VR-Default F PING
ACL Troubleshooting
The following commands are designed to help troubleshoot and resolve ACL configuration
issues.
issues.
*switch # show access-list usage [acl-mask | acl-rule | acl-slice | acl-range]
port <port>
show access-list usage <TAB>
acl-mask ACL Mask table resource summary
acl-range ACL Range table resource summary