Allow Only FTP Service
This ACL will only allow FTP traffic to traverse this port. This will only allow Active FTP sessions to the server. The assumption is that this VLAN is a default deny, and only this traffic is permitted.
Allow Only FTP Procedure
- Open a Panorama PON (EMS) session, click on the Profile icon button and the ACL tab.
- Select the EMS ACL Create a new profile icon and name the ACL profile to FTP Only.
- Click on the Create Rule button and perform the following steps:

Step 1: Enter "FTP-Only" in Filter Name: entry box:
Step 2: Select "Extended ACL" from the ACL Type: Dropdown
Step 3: Select "Permit" from the Action: Dropdown
Step 4: Select "Any Mac(s)" from the SourceMAC(s): dropdown
Step 5: Click on the Add button to add the MAC address and bit count to the Source Mac(s) window
Step 6: Select the MAC address entry in the Source Mac(s) window
Step 7: Enter "1" in the Max MAC(s) entry box
Step 8: Enter "1" in the Max IPs Per MAC entry box
Step 9: Select "TCP(06)" from the Protocol: Radio Selections
Step 10: Select "Single" from the Distribution: Radio Selections
Step 11: Add "20" to the Distribution Port: entry box
Step 12: Click on the Save button to save the rule profile
- Click on the Apply button to add the ACL profile to the Profile Name window list.
- After the Profile has been generated, the ACL status is displayed. Click on the Close button to complete the ACL profile.
On this page