当前位置:网站首页>Rtl8367 learning note 3 - ACL access control list
Rtl8367 learning note 3 - ACL access control list
2022-04-22 06:07:00 【Lithium salt block】
RTL8367 Learning notes 3——ACL
Preface
Access control list ACL Understand or simply understand the working mechanism of , Summarize the recent snail progress .
1 ACE
Access control ACL It is a feature supported by layer 3 switch for network security , It's made up of a series of rules , Each rule is called ACE(Access Control Entry).ACE The basic format is as follows :

On the second floor ACE Format
- DMAC: Purpose MAC Address
- SMAC: Source MAC Address
- VLANID: Belongs to ID Number
- COS:802.1Q User priority
- TYPE: Three layer agreement No
- ACT-PTR: action , The license / discarded
Three layers ACE Format
- DIP: Purpose IP Address
- SIP: Source IP Address
- PROTOCOL: Layer 4 agreement No
- DPORT: Destination port
- SPORT: Source port
- ACT-PTR: action , The license / discarded
Huawei instance

3 Working mechanism
Access control ACL The main functions include : flow control 、 Filter firewall 、NAT Network address translation 、QoS Data classification and routing strategy filtering .
working principle
When the network device receives a message , If flow control is not activated on the access port , The message is directly submitted to the network device forwarding process for processing ; If... Is started at the access port ACL flow control , Send the message to the inbound switch for speed restriction . The switch tries to match the message with the condition of the first rule in the access control list , If the message information meets the conditions of this rule , It is said that the message hit this rule , Execute the action set by the rule , If the action is permit, The switch allows the message to pass through the device , Submit it to the device forwarding process for speed limit processing ; If the action is deny, The switch discards the message . If the message does not meet the conditions of this rule , Continue to try to match the condition of the next rule , Until the match is successful , If the message information does not meet the conditions of any rule , The default operation is performed (permit/deny).
flow chart

summary
I feel I'm still learning very shallow , Keep trying .
reference
Switch CPU Design and implementation of flow control —— Cao Lin
Aerospace business network TCP Research and application of flow control —— Sun Fangwei
版权声明
本文为[Lithium salt block]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204220539556857.html
边栏推荐
- Jeecgboot Online form Development - control Configuration
- QT信号与槽的特点和用法
- Ad embedded learning blue bridge
- Leetcode: Sword finger offer 29 Print the matrix clockwise
- DS18B20 of Blue Bridge Cup embedded expansion board learning
- Installing GCC on AIX and using
- STM32 learning note 3 - input pin of GPIO
- Code color difference of QT learning
- 第72篇 LeetCode题目练习(五) 5.最长回文子串
- 14 - container - tuple
猜你喜欢

Blue Bridge Cup 31 day sprint Day10

QT学习之安装QT

Blue Bridge Cup embedded expansion board learning lis302dl

正点原子stm32f429官方列程编译之后用J-LINK无法下载

第86篇 LeetCode剑指Offer动态规划(三)股票的最大利润

Pytorch deep learning practice_ 10 basis of convolutional neural network CNN

LeetCode: 剑指 Offer 29. 顺时针打印矩阵.

第74篇 LeetCode题目练习(七) 7.整数反转

09 - process control - judgment statement

第90篇 LeetCode剑指Offer动态规划(七)最长不包含重复字符的子字符串
随机推荐
Add a minimize button to the CPropertySheet window
Summary of MySQL knowledge points
蓝桥杯嵌入式扩展板学习之数码管
Blue Bridge Cup embedded expansion board learning lis302dl
transform-origin基点设置'无效'问题
记录AD软件学习之坑
06 - data type
Jeecgboot online development 3
初识数据链表
Blue Bridge Cup 31 day sprint Day17
Installation of QT learning
The 7th Blue Bridge Cup embedded provincial competition: analog liquid level detection and alarm system "
The Localtime function affects performance
Out range of signed 32bit display when compiling openssl-0.9.8e
stm32单片机与LD3320语音模块交互法一
03-pycharm
Setting time and date display of QT learning
第89篇 LeetCode剑指Offer动态规划(六)把数字翻译成字符串
Oracle uses C language to write custom functions
蓝桥杯嵌入式扩展板学习之光敏电阻