ACCESS CONTROL LISTS

Src/Dst SubMask – Subnet mask for source or destination address. (See SubMask in the preceding section.)

Protocol – Specifies the protocol type to match as TCP, UDP or Others, where others indicates a specific protocol number (0-255).

(Options: TCP, UDP, Others; Default: TCP)

Src/Dst Port – TCP or UDP source/destination port number. (Range: 0-65535)

Control Code – Decimal number (representing a bit string) that specifies flag bits in byte 14 of the TCP header. (Range: 0-63)

Control Bitmask – Decimal number representing the code bits to match.

The control bitmask is a decimal number (for an equivalent binary bit mask) that is applied to the control code. Enter a decimal number, where the equivalent binary bit “1” means to match a bit and “0” means to ignore a bit. The following bits may be specified:

-1 (fin) – Finish

-2 (syn) – Synchronize

-4 (rst) – Reset

-8 (psh) – Push

-16 (ack) – Acknowledgement

-32 (urg) – Urgent pointer

For example, use the code value and mask below to catch packets with the following flags set:

-SYN flag valid, use “control-code 2 2”

-Both SYN and ACK valid, use “control-code 18 18”

-SYN valid and ACK invalid, use “control-code 2 18”

3-45

Page 93
Image 93
SMC Networks SMC6724L3 manual Access Control Lists