Netgear FS728TLP Web Management User Guide - Page 195

Click the, button., Enable, Disable, Other, domain, ftpdata, telnet, IP DSCP, IP Precedence, IP TOS

Page 195 highlights

ProSAFE FS526Tv2, FS726Tv2, and FS728TLP Smart Switches Settings Description CPU Notification Mode Note: This menu applies only to model 728TLP. This menu is available only if you selected a Deny link on the ACL Wizard screen and is masked out if you selected a Permit link. Specify whether PoE power is turned off to a port if the ACL rejects the traffic from the port: • Enable. PoE power to the port is turned off. To reestablish PoE power to the port, turn on the PoE power manually (see Configure the PoE Ports on page 75). • Disable. PoE power to the port is not turned off. Protocol Type (Optional) Specify the protocol that needs to be compared against the information in a packet: All, ICMP, IGMP, IP, TCP, UDP, or Other. If you select Other, enter a protocol number in the range from 0 to 255 in the field next to the menu. Src L4 Port or Dst L4 Port Specify the TCP or UDP source or destination port that needs to be compared against the information in a packet: Other, domain, echo, ftp, ftpdata, http, smtp, snmp, telnet, tftp, or www. Each of these selections is translated into the associated port number, which is used as both the start port and end port of the port range. If you select Other, enter a port number in the range from 0 to 65535 in the field next to the menu. Service Type (Optional) Specify the service type match conditions for the extended IP ACL rule. The possible values are IP DSCP, IP precedence, and IP ToS, which are alternative ways of specifying a match criterion for the same service type field in the IP header. Each service type uses a different user notation. Select one of the following radio buttons, and specify the value that is associated with the service type: • IP DSCP. Specifies the IP DiffServ Code Point (DSCP) field, which is defined as the high-order 6 bits of the service type octet in the IP header. Select an IP DSCP value from the menu. To specify a numeric value in the field next to the menu, select other from the menu, and enter an integer in the range from 0 to 63 in the field. • IP Precedence. Specifies the IP precedence field, which is defined as the high-order 3 bits of the service type octet in the IP header. In the field next to the radio button, enter an integer in the range from 0 to 7. • IP TOS. Specifies the Type of Service (ToS) bits, which is defined as all 8 bits of the service type octet in the IP header. In the first field next to the radio button, enter the 2-digit hexadecimal ToS bits number in the range from 00 to FF. In the second and rightmost field, enter the 2-digit hexadecimal ToS mask number, also in the range from 00 to FF. The ToS mask number specifies the bit positions that are used for comparison against the IP ToS field in a packet. For example, to check for an IP ToS value that has both bit 7 (the most significant bit) and bit 5 set and that has bit 1 clear, enter 0xA0 as the ToS bits number, and enter 0xFF as the ToS mask number. 7. Click the Apply button. Manage Access Control Lists 195

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335

Manage Access Control Lists
195
ProSAFE FS526Tv2, FS726Tv2, and FS728TLP Smart Switches
7.
Click the
Apply
button.
CPU Notification Mode
Note:
This menu
applies only to model
728TLP.
This menu is available only if you selected a Deny link on the ACL Wizard
screen and is masked out if you selected a Permit link.
Specify whether PoE power is turned off to a port if the ACL rejects the traffic
from the port:
Enable
. PoE power to the port is turned off. To reestablish PoE power to the
port, turn on the PoE power manually (see
Configure the PoE Ports
on
page
75).
Disable
. PoE power to the port is not turned off.
Protocol Type
(Optional) Specify the protocol that needs to be compared against the
information in a packet:
All
,
ICMP
,
IGMP
,
IP
,
TCP
,
UDP
, or
Other
.
If you select Other, enter a protocol number in the range from 0 to 255 in the
field next to the menu.
Src L4 Port
or
Dst L4 Port
Specify the TCP or UDP source or destination port that needs to be compared
against the information in a packet:
Other
,
domain
,
echo
,
ftp
,
ftpdata
,
http
,
smtp
,
snmp
,
telnet
,
tftp
, or
www
.
Each of these selections is translated into the associated port number, which is
used as both the start port and end port of the port range.
If you select Other, enter a port number in the range from 0 to 65535 in the field
next to the menu.
Service Type
(Optional) Specify the service type match conditions for the extended IP ACL
rule. The possible values are IP DSCP, IP precedence, and IP ToS, which are
alternative ways of specifying a match criterion for the same service type field in
the IP header. Each service type uses a different user notation.
Select one of the following radio buttons, and specify the value that is
associated with the service type:
IP DSCP
. Specifies the IP DiffServ Code Point (DSCP) field, which is
defined as the high-order 6 bits of the service type octet in the IP header.
Select an IP DSCP value from the menu. To specify a numeric value in the
field next to the menu, select
other
from the menu, and enter an integer in
the range from 0 to 63 in the field.
IP Precedence
. Specifies the IP precedence field, which is defined as the
high-order 3 bits of the service type octet in the IP header. In the field next
to the radio button, enter an integer in the range from 0 to 7.
IP TOS
. Specifies the Type of Service (ToS) bits, which is defined as all
8
bits of the service type octet in the IP header.
In the first field next to the radio button, enter the 2-digit hexadecimal ToS
bits number in the range from 00 to FF. In the second and rightmost field,
enter the 2-digit hexadecimal ToS mask number, also in the range from 00
to FF.
The ToS mask number specifies the bit positions that are used for
comparison against the IP ToS field in a packet. For example, to check for
an IP ToS value that has both bit 7 (the most significant bit) and bit 5 set
and that has bit
1 clear, enter 0xA0 as the ToS bits number, and enter 0xFF
as the ToS mask number.
Settings
Description