We have learnt the aspects affecting the services during the network construction through the previous sections. People are legal, packets are legal, and packet forwarding rate is normal. All seem to be harmonious. However, there is a huge amount of information in the network. Not all information can be accessed by the public.
The Access Control List (ACL) of the switch can identify the information of users, such as source MAC, destination MAC, source IP, destination IP, port number, VLAN ID and protocol type. However, all the information is identified by hardware. Simply speaking, identification is faster than packet transmission. Therefore, it is unnecessary to concern about forwarding.
What is the function of ACL?
For example, to enable only the management to access Server A (confidential server), use the ACL as below:
Permit IP (1) (IP address of Leader 1) to access IP (A) (IP address of Server A)
Permit IP (1) (IP address of Leader 2) to access IP (A) (IP address of Server A)……
Deny all the other users to access IP (A).
Conclusions
Together with right control, users can enable the following functions on the access layer:
1. Find out who is using the network.
2. Fraud packets are not allowed to access the network.
3. Violent attack packets are not allowed to access the network.
4. People cannot access the forbidden areas.
The Four Compliance Rule hereby takes effect. The access switch screens the packets accessing the network and thus provides a secure environment for data forwarding and service operation.
Ruijie Networks websites use cookies to deliver and improve the website experience.
See our cookie policy for further details on how we use cookies and how to change your cookie settings.
Cookie Manager
When you visit any website, the website will store or retrieve the information on your browser. This process is mostly in the form of cookies. Such information may involve your personal information, preferences or equipment, and is mainly used to enable the website to provide services in accordance with your expectations. Such information usually does not directly identify your personal information, but it can provide you with a more personalized network experience. We fully respect your privacy, so you can choose not to allow certain types of cookies. You only need to click on the names of different cookie categories to learn more and change the default settings. However, blocking certain types of cookies may affect your website experience and the services we can provide you.
Through this type of cookie, we can count website visits and traffic sources in order to evaluate and improve the performance of our website. This type of cookie can also help us understand the popularity of the page and the activity of visitors on the site. All information collected by such cookies will be aggregated to ensure the anonymity of the information. If you do not allow such cookies, we will have no way of knowing when you visited our website, and we will not be able to monitor website performance.
This type of cookie is necessary for the normal operation of the website and cannot be turned off in our system. Usually, they are only set for the actions you do, which are equivalent to service requests, such as setting your privacy preferences, logging in, or filling out forms. You can set your browser to block or remind you of such cookies, but certain functions of the website will not be available. Such cookies do not store any personally identifiable information.
Contact Us
How can we help you?