Chapter30 More About....
Meanings of the Permit and Deny Keywords
30-6
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
Reserved Addresses
You must not use the following addresses in the range of addresses that you
specify:
The network/subnetwork IP address.
The broadcast address on the network.
Meanings of the Permit and Deny Keywords
Rule entries can be used in access rules, NAT rules, IPSec rules, and in access
rules associated with route maps. Permit and Deny have various meanings
depending on which type of rule is using it.
Services and Ports
This topic lists services you can specify in rules, an d their corresponding port
numbers. It also provides a short description of each service.
This topic is divided into the following areas:
TCP Services
UDP Services
ICMP Message Types
Rule Type Meaning of Permit Meaning of Deny
Access rule Allow matching traffic in or out of the
interface to which the rule has been
applied.
Drop matching traffic.
NAT rule Translate the IP address of matching
traffic to the specified inside local
address or outside local address.
Do not translate the address.
IPSec rule
(Extended only)
Encrypt traffic with matching address. Do not encrypt traffic. Allow it to be
sent unencrypted.
Access rule used in
route map
Protect matching addresses from NAT
translation.
Do not protect matching addresses from
NAT translation.