11-17
Cisco 12000/10700 v3.1.1 Router Manager User Guide
OL-4455-01
Chapter 11 Layer 3 QoS Access List Configuration
Dynamic—Def i nes th e selected acce ss lis t to be dy n ami c. Dynamic acces s li sts gra nt acces s per use r to
a specific source or destination host through a user authentication process. You can allow user access
through a firewall d ynamically, without compromising security restrictions.
Dynamic List
Name—Defin es a name for the dynamic list (only available if Dynamic bu tton is selected).
Ti me Out —Specifies the absolute length of time (in minutes) that a temporary access list entry can
remain in a dyn amic access list. The def ault (0) is an infi nite length of time an d allows an en try to remain
perman ently (o nly available if Dynami c button is select ed).
Source and Destination
The Source an d De stin ati on are as cont ai n th e foll owing fields:
Host Type—Indicates the hosts for which the access action are available. Possible values for this field
include the following:
•Any—Al l hos ts
•A.B.C.D—Specified IP address with wild card bits
•Host Hostname—Only the specified hostname
•Host A.B.C.D—Only the specified IP address
Host Name—Name of the host (or source of the packet) for which the access action is applicable.
IP Addre ss—IP address of the host (or source of the packet) for which the access action is applicable.
Wild Card—If the access action is applicable for more than one host, then this field should be used as a
mask. For exa mple , the wi ld c ard 255 .2 55.255 .25 5 e ffectively represe nts any.
Port Crite ria—Criteria to be applied on the specified port (interface) number. Poss ible valu es are as
follows:
•None—Port number is insignificant
•Equa l To—Equal to the port number
•Not Equal To —Not equal to the port number
•Greater Than—Greater than the port number
•Less Tha n—Less than the port number
•Range—Port nu mber rang e
Port
The Port sub-area in the Source and Destination areas contains the following fields:
Number—Port (interface) number from/to where the packet is sent or destined.
Range—Defines wh ich port (interface) numbers will be allowed through this filter.