Netgear GS716Tv2 GS716Tv2/GS724Tv3 Software Admin Manual - Page 169

Table, 31. MAC ACL Rule Configuration Fields continued, Assign Queue, Match Every, Destination MAC

Page 169 highlights

GS716Tv2 and GS724Tv3 Software Administration Manual Table 5-31. MAC ACL Rule Configuration Fields (continued) Field Assign Queue Match Every CoS Destination MAC Destination MAC Mask EtherType Key EtherType User Value Source MAC Source MAC Mask VLAN Description Specifies the hardware egress queue identifier used to handle all packets matching this ACL rule. Enter an identifying number from 0-3 in this field. Requires a packet to match the criteria of this ACL. Select True or False from the drop down menu. Match Every is exclusive to the other filtering rules, so if Match Every is True, the other rules on the screen are not available. Requires a packet's class of service (CoS) to match the CoS value listed here. Enter a CoS value between 0-7 to apply this criteria. Requires an Ethernet frame's destination port MAC address to match the address listed here. Enter a MAC address in this field. The valid format is xx:xx:xx:xx:xx:xx. If desired, enter the MAC Mask associated with the Destination MAC to match. The MAC address mask specifies which bits in the destination MAC to compare against an Ethernet frame. Use F's and zeros in the MAC mask, which is in a wildcard format. An F means that the bit is not checked, and a zero in a bit position means that the data must equal the value given for that bit. For example, if the MAC address is aa:bb:cc:dd:ee:ff, and the mask is 00:00:ff:ff:ff:ff, all MAC addresses with aa:bb:xx:xx:xx:xx result in a match (where x is any hexadecimal number). Requires a packet's EtherType to match the EtherType you select. Select the EtherType value from the drop down menu. If you select User Value, you can enter a custom EtherType value. This field is configurable if you select User Value from the EtherType drop down menu. The value you enter specifies a customized Ethertype to compare against an Ethernet frame. The valid range of values is 0x0600-0xFFFF. Requires a packet's source port MAC address to match the address listed here. Enter a MAC address in the this field. The valid format is xx:xx:xx:xx:xx:xx. If desired, enter the MAC mask for the source MAC address to match. Use Fs and zeros in the MAC mask, which is in a wildcard format. An F means that the bit is not checked, and a zero in a bit position means that the data must equal the value given for that bit. The valid format is xx:xx:xx:xx:xx:xx. Requires a packet's VLAN ID to match the ID listed here. Enter the VLAN ID to apply this criteria. The valid range is 0-4093. 2. To add a rule, complete the desired fields and click Add. Managing Device Security v1.0, July 2009 5-43

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246

GS716Tv2 and GS724Tv3 Software Administration Manual
Managing Device Security
5-43
v1.0, July 2009
2.
To add a rule, complete the desired fields and click
Add
.
Assign Queue
Specifies the hardware egress queue identifier used to handle all
packets matching this ACL rule. Enter an identifying number from 0–3 in
this field.
Match Every
Requires a packet to match the criteria of this ACL. Select True or False
from the drop down menu. Match Every is exclusive to the other filtering
rules, so if Match Every is True, the other rules on the screen are not
available.
CoS
Requires a packet’s class of service (CoS) to match the CoS value listed
here. Enter a CoS value between 0–7 to apply this criteria.
Destination MAC
Requires an Ethernet frame’s destination port MAC address to match
the address listed here. Enter a MAC address in this field. The valid
format is xx:xx:xx:xx:xx:xx.
Destination MAC Mask
If desired, enter the MAC Mask associated with the Destination MAC to
match. The MAC address mask specifies which bits in the destination
MAC to compare against an Ethernet frame. Use F’s and zeros in the
MAC mask, which is in a wildcard format. An F means that the bit is not
checked, and a zero in a bit position means that the data must equal the
value given for that bit. For example, if the MAC address is
aa:bb:cc:dd:ee:ff, and the mask is 00:00:ff:ff:ff:ff, all MAC addresses with
aa:bb:xx:xx:xx:xx result in a match (where
x
is any hexadecimal
number).
EtherType Key
Requires a packet’s EtherType to match the EtherType you select.
Select the EtherType value from the drop down menu. If you select User
Value, you can enter a custom EtherType value.
EtherType User Value
This field is configurable if you select User Value from the EtherType
drop down menu. The value you enter specifies a customized Ethertype
to compare against an Ethernet frame. The valid range of values is
0x0600–0xFFFF.
Source MAC
Requires a packet’s source port MAC address to match the address
listed here. Enter a MAC address in the this field. The valid format is
xx:xx:xx:xx:xx:xx.
Source MAC Mask
If desired, enter the MAC mask for the source MAC address to match.
Use Fs and zeros in the MAC mask, which is in a wildcard format. An F
means that the bit is not checked, and a zero in a bit position means that
the data must equal the value given for that bit. The valid format is
xx:xx:xx:xx:xx:xx.
VLAN
Requires a packet’s VLAN ID to match the ID listed here. Enter the
VLAN ID to apply this criteria. The valid range is 0–4093.
Table
5-31. MAC ACL Rule Configuration Fields (continued)
Field
Description