3Com 3CBLSG24 User Guide - Page 66

ICMP Code, IGMP Type, Source Address, Source Mask, Destination Address, Destination Mask, IP - Prec.

Page 66 highlights

66 CHAPTER 4: MANAGING DEVICE SECURITY ■ ICMP Code - Specifies an ICMP message code for filtering ICMP packets. ICMP packets that are filtered by ICMP message type can also be filtered by the ICMP message code. ■ IGMP Type - IGMP packets can be filtered by IGMP message type. ■ Source Address - Matches the source IP address to which packets are addressed to the ACL. ■ Source Mask - Indicates the source IP address mask. ■ Destination Address - Matches the destination IP address to which packets are addressed to the ACL. ■ Destination Mask - Indicates the destination IP address mask. ■ DSCP - Matches the packet DSCP value to the ACL. Either the DSCP value or the IP Precedence value is used to match packets to ACLs. ■ IP - Prec. - Indicates matching ip-precedence with the packet IP precedence value. ■ Action - Indicates the ACL forwarding action. In addition, the port can be shut down, a trap can be sent to the network administrator, or packet is assigned rate limiting restrictions for forwarding. The options are as follows: ■ Permit - Forwards packets which meet the ACL criteria. ■ Deny - Drops packets which meet the ACL criteria. ■ Shutdown - Drops packet that meets the ACL criteria, and disables the port to which the packet was addressed. Ports are reactivated from the Port Administration Setup Page. Defining IP Based ACLs Access Control Lists (ACL) allow network managers to define classification actions and rules for specific ingress ports. Your switch supports up to 256 ACLs. Packets entering an ingress port, with an active ACL, are either admitted or denied entry. If they are denied entry, the user can disable the port. ACLs are composed of access control entries (ACEs) that are made of the filters that determine traffic classifications. The total number of ACEs that can be defined in all ACLs together is 256. Monitor users have no access to this page.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216

66
C
HAPTER
4: M
ANAGING
D
EVICE
S
ECURITY
ICMP Code
— Specifies an ICMP message code for filtering ICMP
packets. ICMP packets that are filtered by ICMP message type can also
be filtered by the ICMP message code.
IGMP Type
— IGMP packets can be filtered by IGMP message type.
Source Address
— Matches the source IP address to which packets
are addressed to the ACL.
Source Mask
— Indicates the source IP address mask.
Destination Address
— Matches the destination IP address to which
packets are addressed to the ACL.
Destination Mask
— Indicates the destination IP address mask.
DSCP
— Matches the packet DSCP value to the ACL. Either the DSCP
value or the IP Precedence value is used to match packets to ACLs.
IP - Prec.
— Indicates matching ip-precedence with the packet IP
precedence value.
Action
— Indicates the ACL forwarding action. In addition, the port
can be shut down, a trap can be sent to the network administrator, or
packet is assigned rate limiting restrictions for forwarding. The options
are as follows:
Permit
— Forwards packets which meet the ACL criteria.
Deny
— Drops packets which meet the ACL criteria.
Shutdown
— Drops packet that meets the ACL criteria, and
disables the port to which the packet was addressed. Ports are
reactivated from the
Port Administration Setup Page
.
Defining IP Based
ACLs
Access Control Lists (ACL) allow network managers to define
classification actions and rules for specific ingress ports. Your switch
supports up to 256 ACLs. Packets entering an ingress port, with an active
ACL, are either admitted or denied entry. If they are denied entry, the user
can disable the port. ACLs are composed of access control entries (ACEs)
that are made of the filters that determine traffic classifications. The total
number of ACEs that can be defined in all ACLs together is 256.
Monitor users have no access to this page.