Netgear GS516TP Software Administration Manual - Page 146

IP Binding Configuration, Security > ACL > Advanced > IP Binding Configuration

Page 146 highlights

GS516TP Gigabit Smart Switches • Select one of the keywords from the list: DOMAIN, ECHO, FTP, FTPDATA, HTTP, SMTP, SNMP, TELNET, TFTP, and WWW. Each of these values translates into its equivalent port number, which is used as both the start and end of a port range. • Destination Prefix and Prefix Length. Enter a prefix of up to 128 bit combined with prefix length to be compared to a packet's destination IP address as a match criteria for the selected IPv6 ACL rule. The valid range for a prefix length is 0 - 128. • Destination L4 Port. Specify a packet's destination layer 4 port as a match condition for the selected IPv6 ACL rule. Destination port information is optional. Destination port information can be specified in two ways: • Select keyword other from the drop-down list, and specify the number of the port. The valid range is 0 - 65535. • Select one of the keywords from the list: DOMAIN, ECHO, FTP, FTPDATA, HTTP, SMTP, SNMP, TELNET, TFTP, and WWW. Each of these values translates into its equivalent port number, which is used as both the start and end of a port range. • IPv6 DSCP Service. Select the IPv6 DSCP service. If you prefer, you can select the Other option in the drop-down list and enter the numeric value of the DSCP in the adjacent field. The DSCP is defined as the high-order 6 bits of the service type octet in the IPv6 header. This configuration is optional. Enter an integer from 0 to 63. 4. To add an IPv6 rule, select the global check box and click ADD. To delete a IPv6 rule, select the checkbox of the rule you want to delete and click DELETE. Click APPLY to submit the changes to the switch.  Configuration changes take effect immediately. IP Binding Configuration When an ACL is bound to an interface, all the rules that have been defined are applied to the selected interface. Use the IP Binding Configuration screen to assign ACL lists to ACL Priorities and Interfaces.  To configure IP ACL interface bindings: 1. Select Security > ACL > Advanced > IP Binding Configuration. 2. Select an existing IP ACL from the ACL ID menu. The packet filtering direction for ACL is Inbound, which means the IP ACL rules are applied to traffic entering the port. 3. Specify an optional sequence number to indicate the order of this access list relative to other access lists already assigned to this interface and direction. A low number indicates high precedence order. If a sequence number is already in use for this interface and direction, the specified access list replaces the currently attached access list using that sequence number. If you do not specify the sequence number, a sequence number that is one greater than the highest sequence number currently in use for this interface and direction is used. The valid range is 1-2147483647. 4. Click the appropriate orange bar to display the available ports or LAGs. 146

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208

146
GS516TP Gigabit Smart Switches
Select one of the keywords from the list: DOMAIN, ECHO, FTP, FTPDATA, HTTP,
SMTP, SNMP, TELNET, TFTP, and WWW. Each of these values translates into its
equivalent port number, which is used as both the start and end of a port range.
Destination Prefix
and
Prefix Length
. Enter a prefix of up to 128 bit combined with
prefix length to be compared to a packet's destination IP address as a match criteria
for the selected IPv6 ACL rule. The valid range for a prefix length is 0 - 128.
Destination L4 Port
. Specify a packet's destination layer 4 port as a match condition
for the selected IPv6 ACL rule. Destination port information is optional. Destination
port information can be specified in two ways:
Select keyword
other
from the drop-down list, and specify the number of the port.
The valid range is 0 - 65535.
Select one of the keywords from the list: DOMAIN, ECHO, FTP, FTPDATA, HTTP,
SMTP, SNMP, TELNET, TFTP, and WWW. Each of these values translates into its
equivalent port number, which is used as both the start and end of a port range.
IPv6 DSCP Service
. Select the IPv6 DSCP service. If you prefer, you can select the
Other
option in the drop-down list and enter the numeric value of the DSCP in the
adjacent field. The DSCP is defined as the high-order 6 bits of the service type octet
in the IPv6 header. This configuration is optional. Enter an integer from 0 to 63.
4.
To add an IPv6 rule, select the global check box and click
ADD
.
To delete a IPv6 rule, select the checkbox of the rule you want to delete and click
DELETE
.
Click
APPLY
to submit the changes to the switch.
Configuration changes take effect immediately.
IP Binding Configuration
When an ACL is bound to an interface, all the rules that have been defined are applied to the
selected interface. Use the IP Binding Configuration screen to assign ACL lists to ACL
Priorities and Interfaces.
To configure IP ACL interface bindings:
1.
Select
Security > ACL > Advanced > IP Binding Configuration
.
2.
Select an existing IP ACL from the
ACL ID
menu.
The packet filtering direction for ACL is Inbound, which means the IP ACL rules are
applied to traffic entering the port.
3.
Specify an optional sequence number to indicate the order of this access list relative to other
access lists already assigned to this interface and direction.
A low number indicates high precedence order. If a sequence number is already in use
for this interface and direction, the specified access list replaces the currently attached
access list using that sequence number. If you do not specify the sequence number, a
sequence number that is one greater than the highest sequence number currently in use
for this interface and direction is used. The valid range is 1–2147483647.
4.
Click the appropriate orange bar to display the available ports or LAGs.