Netgear GS728TPP GS728TP/GS728TPP/GS752TP Software Administration Manual - Page 204

Rule ID, Action, Logging, Match Every, Protocol, other, Source Prefix and Prefix Length

Page 204 highlights

GS752TP, GS728TP, and GS728TPP Gigabit Smart Switches The following screen appears: 3. Configure the settings for the new rule. • Rule ID. Enter a whole number in the range of 1-10 that is used to identify the rule. An IPv6 ACL might have up to 10 rules. • Action. Specify what action must be taken if a packet matches the rule's criteria. The choices are Permit or Deny. • Logging. When set to Enable, logging is enabled for this ACL rule (subject to resource availability in the device). If the access list trap flag is also enabled, this causes periodic traps to be generated indicating the number of times this rule was hit during the current report interval. A fixed 5-minute report interval is used for the entire system. A trap is not issued if the ACL rule hit count is 0 for the current interval. This field is visible for a deny action. • Match Every. Select Enable or Disable. Enable signifies that all packets that match the selected IPv6 ACL and rule are either permitted or denied. In this case, since all packets match the rule, the option of configuring other match criteria is not offered. To configure specific match criteria for the rule, remove the rule and recreate it, or for Match Every select Disable for the other match criteria to be visible. • Protocol. There are two ways to configure IPv6 protocol: • After selecting protocol keyword other, specify an integer ranging from 0 to 255. This number represents the IPv6 protocol. • Select name of a protocol from the existing list of IPv6, ICMPv6, TCP, and UDP. • Source Prefix and Prefix Length. Specify the IPv6 Prefix combined with IPv6 Prefix length of the network or host from which the packet is being sent. The valid range for the prefix length is 0-128. • Source L4 Port. Specify a packet's source layer 4 port as a match condition for the selected IPv6 ACL rule. Source port information is optional. Source port information can be specified in two ways: Managing Device Security 204

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275

Managing Device Security
204
GS752TP, GS728TP, and GS728TPP Gigabit Smart Switches
The following screen appears:
3.
Configure the settings for the new rule.
Rule ID
. Enter a whole number in the range of 1–10 that is used to identify the rule.
An IPv6 ACL might have up to 10 rules.
Action
. Specify what action must be taken if a packet matches the rule's criteria. The
choices are Permit or Deny.
Logging
. When set to Enable, logging is enabled for this ACL rule (subject to
resource availability in the device). If the access list trap flag is also enabled, this
causes periodic traps to be generated indicating the number of times this rule was hit
during the current report interval. A fixed 5-minute report interval is used for the entire
system. A trap is not issued if the ACL rule hit count is 0 for the current interval. This
field is visible for a deny action.
Match Every
. Select Enable or Disable. Enable signifies that all packets that match
the selected IPv6 ACL and rule are either permitted or denied. In this case, since all
packets match the rule, the option of configuring other match criteria is not offered. To
configure specific match criteria for the rule, remove the rule and recreate it, or for
Match Every select Disable for the other match criteria to be visible.
Protocol
. There are two ways to configure IPv6 protocol:
After selecting protocol keyword
other
, specify an integer ranging from 0 to 255.
This number represents the IPv6 protocol.
Select name of a protocol from the existing list of IPv6, ICMPv6, TCP, and UDP.
Source Prefix and Prefix Length
. Specify the IPv6 Prefix combined with IPv6 Prefix
length of the network or host from which the packet is being sent. The valid range for
the prefix length is 0–128.
Source L4 Port
. Specify a packet's source layer 4 port as a match condition for the
selected IPv6 ACL rule. Source port information is optional. Source port information
can be specified in two ways: