24-13
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
Chapter24 ACL Editor
Rules Windows
Mask
If you selected A Network or if you selected A Host Name or IP address, either
select the wildcard mask from this list, or enter a custom wildcard mask. A binary
0 in a wildcard mask means that the corresponding bit in a packets IP address
must match exactly. A binary 1 in a wildcard mask means that the corresponding
bit in the packets IP address need not match.
Hostname/IP
If you selected A Host Name or IP address in the Type field, enter the name oro
the IP address of the host. If you enter a hostname, th e router must be configured
to use a DNS server.
Description
You can enter a short description of the entry in this field. The description must
be fewer than 100 characters long.

Log Matches Against This Entry

If you have specified syslog in System Properties, you can check this box;
matches will be recorded in the system log.
Add an Extended Rule Entry
An extended rule entry allows you to permit or deny traffic based on its source
and destination and on the protocol and service specified in the packet.
Note Any traffic that does not match the criteria in one of the rule entries you create is
implicitly denied. To ensure that traffic you do not intend to deny is permitted, you
must append explicit permit entries to the rule that you are configuring.
Action
Select the action you want the router to take when a packet matches the criteria in
the rule entry. The choices are Permit and Deny. If you are creating an entry for
an IPSec rule, the choices are protect the traffic and don’t protect the traffic.