Allow Specific Subnet
EMS Allow Specific SubNet Procedure
- Open a Panorama PON (EMS) session, click on the Profile icon button and the ACL tab.
- Select the EMS ACL Create a new profile icon and name the ACL profile to Allow Specific Subnet-1.
- Click on the Create Rule buttonand perform the following steps:
Step 1: Enter "Subnet-X-Only" in the Filter Name: entry box:
Step 2: Select "Basic ACL" from the ACL Type: Dropdown
Step 3: Select "Permit" from the Action: Dropdown
Step 4: Select "Any Mac(s)" from the SourceMAC(s): dropdown
Step 5: Click on the Add button to add the MAC address and bit count to the Source Mac(s) window
Step 6: Select the MAC address entry in the Source Mac(s) window
Step 7: Enter "1" in the Max MAC(s) entry box
Step 8: Enter "1" in the Max IPs Per MAC entry box
Step 9: Enter the IP address "192.168.122.0" in the Bound SRC IP(s): entry box
Step 10: Add Bit count: 24" in the Bound SRC IP(s): entry box
Step 11: Click on the Add button to add the Bound SRC IP(s) and bit count to the Bound SRC IP(s): window
Step 12: Click on the Save buttonto save the rule profile
- Click on the Apply button to add the ACL profile to the Profile Name window list.
- After the Profile has been generated, the ACL status is displayed. Click on the Close button to complete the ACL profile.
CLI ACL Allow Specific SubNet Procedure
- Open a CLI session and create a Allow Specific Subnet ACL profile.
ESUx> profile acl create name=AllowSpecificSubnet-1 <enter>
success
ESUx> _
|
- From the ESUx> command line, input profile acl edit name=AllowSpecificSubnet-1 rule number=1 basic action=permit l2 et=ipv4-arp sa=any max-macs=1 l3 source-IP=192.168.122.0/24, and press Enter. Output similar to the following is displayed:
ESUx> profile acl edit name=AllowSpecificSubnet-1 rule number=1 basic action=permit l2 et=ipv4-arp sa=any max-macs=1 l3 source-IP=192.168.122.0/24 <enter> success ESUx> _
Verify the CLI entry
- From the ESUx> command line, input profile acl show name=AllowSpecificSubnet-1, and presss Enter. Output similar to the following is displayed:
ESUx> profile acl show name=AllowSpecificSubnet-1 <enter> | Access Control List Profile | |============================================================================| | Profile Name : AllowSpecificSubnet-1 | | | | Rule #1 | | Rule Identifier : Rule-1 | | Type : basic | | Action : permit | | | | Layer 2 | | Ethertype : IPv4/ARP (0x0800/0x0806) | | | | Source MAC(s) | | MAX Source MACs : 1 | | SA #1 : any | | | | Layer 3 | | | | Source IP/Subnet(s) | | | | Bound to SA #1 | | MAX Source IPs : 1 | | SIP #1 : 192.168.122.0/24/24 | | | |============================================================================| ESUx> _
Previous | Next