Netgear FS728TLP Web Management User Guide - Page 214

Every menu is False. If the selection is True, they are masked out., The following fields, menus

Page 214 highlights

ProSAFE FS526Tv2, FS726Tv2, and FS728TLP Smart Switches Settings Description Egress Queue Specify the egress queue that is used to handle all packets that match the ACL rule. From the menu, select the queue ID (0, 1, 2, 3, 4, 5, 6, or 7). This setting can override the existing queue ID for a packet. Match Every Specify whether all packets need to match the rule: • True. All packets need to match the rule. Other rules are not considered, and the fields and buttons below the Match Every field are masked out. • False. Not all packets need to match the rule. Other rules are also considered. CPU Notification Mode Note: This menu applies only to model 728TLP. Specify whether PoE power is turned off to a port if the ACL rejects the traffic from the port: • Enable. PoE power to the port is turned off. To reestablish PoE power to the port, turn on the PoE power manually (see Configure the PoE Ports on page 75). • Disable. PoE power to the port is not turned off. This menu is available only if the selection from the Action menu is Deny. The following fields, menus, and radio buttons are available only if the selection from the Match Every menu is False. (If the selection is True, they are masked out). Configure only the settings that apply to your network and configuration. Protocol Type Specify the protocol that needs to be compared against the information in a packet: Other, ICMP, IGMP, IP, TCP, or UDP. If you select Other, enter a protocol number in the range from 0 to 255 in the field next to the menu. Src IP Address Specify the IP address of the source device that needs to be compared against the address information in a packet. Enter an IP address in the dotted-decimal notation. Src IP Mask Specify the source IP mask that is associated with the source IP address. The IP mask specifies which bits in the source IP address need to be compared against the address information in a packet. This field is required when you configure a source IP address. Src L4 Port Dst IP Address Note: A subnet mask of 255.255.255.255 indicates that none of the bits are important. A subnet mask of 0.0.0.0 indicates that all of the bits are important. For example, if you apply source IP mask 0.0.0.255 to IP address 192.168.0.10, the ACL applies to IP addresses 192.168.0.0 through 192.168.0.255. Specify the TCP or UDP source port that needs to be compared against the information in a packet: Other, domain, echo, ftp, ftpdata, http, smtp, snmp, telnet, tftp, or www. Each of these selections is translated into the associated port number, which is used as both the start port and end port of the port range. If you select Other, enter a port number in the range from 0 to 65535 in the field next to the menu. Specify the IP address of the destination device that needs to be compared against the address information in a packet. Enter an IP address in the dotted-decimal notation. Manage Access Control Lists 214

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335

Manage Access Control Lists
214
ProSAFE FS526Tv2, FS726Tv2, and FS728TLP Smart Switches
Egress Queue
Specify the egress queue that is used to handle all packets that match the ACL
rule.
From the menu, select the queue ID (
0
,
1
,
2
,
3
,
4
,
5
,
6
, or
7
). This setting can
override the existing queue ID for a packet.
Match Every
Specify whether all packets need to match the rule:
True
. All packets need to match the rule. Other rules are not considered,
and the fields and buttons below the Match Every field are masked out.
False
. Not all packets need to match the rule. Other rules are also
considered.
CPU Notification Mode
Note:
This menu
applies only to model
728TLP.
Specify whether PoE power is turned off to a port if the ACL
rejects the traffic from the port:
Enable
. PoE power to the port is turned off. To
reestablish PoE power to the port, turn on the PoE
power manually (see
Configure the PoE Ports
on
page
75).
Disable
. PoE power to the port is not turned off.
This menu is
available only if
the selection from
the Action menu
is Deny.
The following fields, menus, and radio buttons are available only if the selection from the Match
Every menu is False. (If the selection is True, they are masked out).
Configure only the settings that apply to your network and configuration.
Protocol Type
Specify the protocol that needs to be compared against the information in a
packet:
Other
,
ICMP
,
IGMP
,
IP
,
TCP
, or
UDP
.
If you select Other, enter a protocol number in the range from 0 to 255 in the field
next to the menu.
Src IP Address
Specify the IP address of the source device that needs to be compared against
the address information in a packet.
Enter an IP address in the dotted-decimal notation.
Src IP Mask
Specify the source IP mask that is associated with the source IP address. The IP
mask specifies which bits in the source IP address need to be compared against
the address information in a packet. This field is required when you configure a
source IP address.
Note:
A subnet mask of 255.255.255.255 indicates that none of the bits are
important. A subnet mask of 0.0.0.0 indicates that all of the bits are important.
For example, if you apply source IP mask 0.0.0.255 to IP address 192.168.0.10,
the ACL applies to IP addresses 192.168.0.0 through 192.168.0.255.
Src L4 Port
Specify the TCP or UDP source port that needs to be compared against the
information in a packet:
Other
,
domain
,
echo
,
ftp
,
ftpdata
,
http
,
smtp
,
snmp
,
telnet
,
tftp
, or
www
.
Each of these selections is translated into the associated port number, which is
used as both the start port and end port of the port range.
If you select Other, enter a port number in the range from 0 to 65535 in the field
next to the menu.
Dst IP Address
Specify the IP address of the destination device that needs to be compared
against the address information in a packet.
Enter an IP address in the dotted-decimal notation.
Settings
Description