Create a new ACL |
-
Click > .
-
Fill in the following fields:
If you want the ACL to apply to only specific ports, select this option then specify the ports and the behavior for the ports (, , or ). This causes the ACL Behavior setting to be ignored in favor of the individual port behavior settings.
The macros are predefined IP address groups. For example, applies the ACL behavior to a device’s current DHCP server IP addresses while Default DHCP applies it to the current Default DHCP server IP address.
-
Click to save the Access Control List.
By default, the ACL is enabled. If you do not want it enabled at this time, deselect the box.
|
Use one of the following formats:
-
xxx.xxx.xxx.xxx: Standard dotted-decimal notation for a single address. For example, 123.45.167.100.
-
xxx.xxx.xxx.xxx/n: Standard CIDR (Classless Inter-Domain Routing) notation. For example, 123.45.167.100/24 matches all IP addresses that start with 123.45.167.
-
www.domain_name: Standard domain name notation. For example, www.novell.com.
-
www.domain_name/n: Standard CIDR (Classless Inter-Domain Routing) notation for a domain name. For example, www.novell.com/16.
IMPORTANT:To enforce the ACL, an IP address range is expanded to individual IP addresses. A large range can consume significant resources on the device and impact performance. To minimize this impact, define ranges that include only the IP addresses you want to control.
Use the following format when specifying a MAC address: xx:xx:xx:xx:xx:xx. For example, 01:23:45:67:89:ab. |
Copy an existing ACL from another policy |
-
Click > .
-
Select the Firewall policies whose ACL you want to copy.
-
Click .
|
All ACLs included in the other Firewall policies are copied. If necessary, you can edit the copied ACLs after they are added to the list. |
Import an ACL from a policy export file |
-
Click > .
-
Click to display the Select File dialog box.
-
Click , select the export file, then click .
-
Click to add the ACLs to the list.
|
All ACLs included in the export file are imported. If necessary, you can edit the imported ACLs after they are added to the list.
For information about exporting ACLs, see Export an ACL. |
Enable or disable an ACL |
-
Locate the ACL in the list
-
In the column, select the check box to enable the ACL.
or
Deselect the check box to disable the ACL.
|
When you add an ACL it is enabled by default. You can disable an ACL to save it in the policy but no longer apply it. |
Edit an ACL |
-
Click the ACL name.
-
Modify the fields as desired.
-
Click .
|
|
Rename an ACL |
-
Select the check box next to the ACL name, then click > .
-
Modify the name as desired.
-
Click .
|
|
Export an ACL |
-
Select the check box next to the ACL name.
You can select multiple ACLs to export.
-
Click > .
-
Save the file.
The default name given to the file is sharedComponents.xml. You can change the name if desired. Do not change the .xml extension.
|
|
Delete an ACL |
-
Select the check box next to the ACL name, then click .
-
Click to confirm deletion of the ACL.
|
|