Configuring the Session ACL
First you need to configure a sessionACLAccess Control List. ACL is a common way of restricting certain types of traffic on a physical port.that “permits” corporate traffic to be forwarded to themanaged deviceand that routes, or locally bridges, local traffic.
The following procedure describes how to configure sessionACLAccess Control List. ACL is a common way of restricting certain types of traffic on a physical port.:
1.In the node hierarchy, navigate to the tab.
2.Click to create a new policy.
3.Enter the name in the field.
4.Select from the drop-down list.
5.Click .
6.Select the policy created and click under table.
7.Select option in the field.
8.Click .
9.To complete creating the rule:
a.Select or from the drop-down list.
b.Select from the drop-down list.
c.Select from the drop-down list.
d.Select from the drop-down list.
e.Select from the drop-down list.
f.Select for IPv4 or for IPv6 from the drop-down list.
g.Click .
10.To create a new forwarding rule:
a.Select policy created and click in the table.
b.Select option in the field.
c.Click .
d.Select or from the drop-down list.
e.Select from the drop-down list.
f.Select from the drop-down list.
g.Click in the drop-down list.
h.In the window, click in the table.
i.Select from the drop-down list.
j.Enter the public IP address of themanaged devicein the field.
k.Enter thenetmaskNetmask is a 32-bit mask used for segregating IP address into subnets. Netmask defines the class and range of IP addresses.or range in the field.
l.Click . The new alias appears in the drop-down list.
m.Click .
11.Navigate to the > tab.
Roles can be created only in themanaged device. |
a.Click to create a new role.
b.Enter the role name in the field.
c.Click .
d.Click the new role created.
e.Click .
f.Click .
g.Select 选择和选择策略创建的 drop-down list.
h.Click .
12.Click .
13.In the window, select the check box and click .
The followingCLICommand-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions.commands configure sessionACLAccess Control List. ACL is a common way of restricting certain types of traffic on a physical port.:
Ifdhcp serverinap system profileis enabled:
(host) [md] (config) #ip access-list session
(host) [md] (config) #user any any route src-nat
Ifdhcp serverinap system profileis disabled:
(host) [md] (config) #ip access-list session
(host) [md] (config) #any any any permit
(host) [md] (config) #user-role
(host) [md] (config) #session-acl
To configure anACLAccess Control List. ACL is a common way of restricting certain types of traffic on a physical port.to Restrict Local Debug Homepage Access, seeConfiguring an ACL to Restrict Local Debug Homepage Access on page 1. |