2.Configuration items for an advanced IPv4 ACL rule

Item

 

Description

 

 

 

 

Select the advanced IPv4 ACL for which you want to

Select Access Control List (ACL)

 

configure rules.

 

Available ACLs are advanced IPv4 ACLs that have been

 

 

 

 

 

 

 

 

configured.

 

 

 

 

 

 

 

 

 

Select the Rule ID option and type a number for the rule.

Rule ID

 

If you do not specify the rule number, the system will

 

 

 

 

assign one automatically.

 

 

 

 

 

 

 

 

 

Select the operation to be performed for packets matching

Operation

 

the rule.

 

Permit—Allows matched packets to pass.

 

 

 

 

 

 

 

 

Deny—Drops matched packets.

 

 

 

 

 

 

 

 

 

Select this option to apply the rule to only non-first

Check Fragment

 

fragments.

 

If you do no select this option, the rule applies to all

 

 

 

 

 

 

 

 

fragments and non-fragments.

 

 

 

 

 

 

 

 

 

Select this option to keep a log of matched packets.

Check Logging

 

A log entry contains the ACL rule number, operation for

 

the matched packets, protocol that IP carries,

 

 

 

 

source/destination address, source/destination port

 

 

 

 

number, and number of matched packets.

 

 

 

 

 

 

Source IP Address

 

Select the Source IP Address option and type a source IPv4

 

 

 

 

address and a source wildcard mask, in dotted decimal

 

Source Wildcard

 

IP Address Filter

 

notation.

 

 

 

 

Destination IP Address

 

Select the Source IP Address option and type a source IP

 

 

 

 

 

 

address and a source wildcard mask, in dotted decimal

 

Destination Wildcard

 

 

 

notation.

 

 

 

 

 

 

 

 

 

Select the protocol to be carried by IP.

Protocol

 

If you select 1 ICMP, you can configure the ICMP message

 

type and code; if you select 6 TCP or 17 UDP, you can

 

 

 

 

 

 

 

 

configure the TCP or UDP port.

 

 

 

 

 

 

Named ICMP Type

 

Specify the ICMP message type and code.

 

 

 

 

 

 

 

These items are available only when you select 1 ICMP

 

 

 

 

ICMP Type

ICMP Type

 

from the Protocol drop-down box.

 

 

 

If you select Other from the Named ICMP Type drop-down

 

 

 

 

 

 

 

 

ICMP Code

 

box, you need to type values in the ICMP Type and ICMP

 

 

Code fields. Otherwise, the two fields will take the default

 

 

 

 

values, which cannot be changed.

 

 

 

 

 

 

 

 

 

Select this option to make the rule match packets used for

 

Check Established

 

establishing and maintaining TCP connections.

 

 

These items are available only when you select 6 TCP from

TCP/UDP Port

 

 

the Protocol drop-down box.

 

 

 

 

 

 

Source

Operator

 

Select the operators and type the source port numbers and

 

 

 

 

Port

 

destination port numbers as required.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

418