Access control lists (ACLs) often reside on a firewall router or a router connecting two internal networks. However, NETGEAR Smart Switches and fully managed switches also let you set up ACLs, which can control the traffic entering the network. When you configure ACLs, you can selectively admit or reject inbound traffic, thereby controlling access to your network or to specific resources on your network. With ACLs, only authorized users can access specific resources while blocking any unwarranted attempts to reach network resources. ACLs are used to provide traffic flow control, restrict contents, decide which types of traffic are forwarded or blocked, and provide security for the network.
You can set up ACLs to control traffic at Layer 2 or Layer 3:
- MAC ACLs are used for Layer 2.
- IPv4 ACLs and IPv6 ACLs are used for Layer 3.
Each ACL contains a set of rules that apply to inbound traffic. Each rule specifies whether the contents of a specific field must be used to permit or deny access to the network, and each rule might apply to one or more of the fields within a packet.
The following platform-dependent limitations apply to ACLs:
- The maximum of number of ACLs on a switch is 100, which can be a combination of MAC ACLs, basic IPv4 ACL, extended IPv4 ACLs, and IPv6 ACLs.
- The maximum number of rules per ACL is 50. On some legacy switches, the maximum number is 10, or 8.
- Stacked switches do not support redirection.
- Smart Switches and legacy fully managed switches support ACLs for inbound traffic only. However, current fully managed switches support ACLs for inbound and outbound traffic.
- A switch does not support MAC ACLs and IP ACLs on the same interface.
For more information, see the following support articles:
- What are MAC access control lists (ACLs) and how do they work with my NETGEAR Smart Switch or fully managed switch?
- What are IP access control lists (ACLs) and how do they work with my NETGEAR Smart Switch or fully managed switch?
- How do I configure access control lists (ACLs) on my NETGEAR Smart Switch or fully managed switch?
For configuration examples, see the following support articles:
- How do I create an IP access control list (ACL) to allow TCP and UDP traffic between two IP addresses using the traditional user interface on a NETGEAR Smart Switch or fully managed switch?
- How do I create an IP access control list (ACL) to allow TCP and UDP traffic between two IP addresses using the Smart user interface on a NETGEAR Smart Switch?
- How do I create an IP access control list (ACL) to allow TCP and UDP traffic between two IP addresses using CLI commands on a NETGEAR fully managed switch?