Why can Layer 2 ACLs not take effect on AR1200 series


Fixed local area network (LAN) interfaces on the AR1200 series do not support Layer 2 access control lists (ACLs).

The device delivers access control lists (ACLs) to MAC-based users only after the IP addresses are learned.

For users who access a router based on MAC addresses, the router does not deliver an ACL until the router learns the IP addresses of the users.

On AR1200 series, the Layer 2 ACL does not apply to the Layer 2 traffic between the eight fixed LAN interfaces.

Policies can still take effect when the firewall works in transparent mode.

When an ACL is referenced in a traffic policy and the ACL is matched: When the software version is a later version of V100R005, the deny action takes effect as long as the deny action is defined in the traffic behavior or ACL. If the packets match the ACL, When the software version is a later version of V100R005, the packets may match a rule with a higher priority and the action of the rule is not deny.

