Netgear GS752TP GS728TP/GS728TPP/GS752TP Software Administration Manual - Page 205

IP Binding Configuration, Destination Prefix and Prefix Length

Page 205 highlights

GS752TP, GS728TP, and GS728TPP Gigabit Smart Switches • Select keyword other from the drop-down list, and specify the number of the port. The valid range is 0 - 65535. • Select one of the keywords from the list: DOMAIN, ECHO, FTP, FTPDATA, HTTP, SMTP, SNMP, TELNET, TFTP, and WWW. Each of these values translates into its equivalent port number, which is used as both the start and end of a port range. • Destination Prefix and Prefix Length. Enter a prefix of up to 128 bit combined with prefix length to be compared to a packet's destination IP address as a match criteria for the selected IPv6 ACL rule. The valid range for a prefix length is 0 - 128. • Destination L4 Port. Specify a packet's destination layer 4 port as a match condition for the selected IPv6 ACL rule. Destination port information is optional. Destination port information can be specified in two ways: • Select keyword other from the drop-down list, and specify the number of the port. The valid range is 0 - 65535. • Select one of the keywords from the list: DOMAIN, ECHO, FTP, FTPDATA, HTTP, SMTP, SNMP, TELNET, TFTP, and WWW. Each of these values translates into its equivalent port number, which is used as both the start and end of a port range. • IPv6 DSCP Service. Select the IPv6 DSCP service. If you prefer, you can select the Other option in the drop-down list and enter the numeric value of the DSCP in the adjacent field. The DSCP is defined as the high-order 6 bits of the service type octet in the IPv6 header. This configuration is optional. Enter an integer from 0 to 63. 4. To add an IPv6 rule, select the global check box and click ADD. To delete a IPv6 rule, select the checkbox of the rule you want to delete and click DELETE. Click APPLY to submit the changes to the switch. Configuration changes take effect immediately. IP Binding Configuration When an ACL is bound to an interface, all the rules that have been defined are applied to the selected interface. Use the IP Binding Configuration screen to assign ACL lists to ACL Priorities and Interfaces.  To configure IP ACL interface bindings: 1. Select Security  ACL > Advanced  IP Binding Configuration. Managing Device Security 205

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275

Managing Device Security
205
GS752TP, GS728TP, and GS728TPP Gigabit Smart Switches
Select keyword
other
from the drop-down list, and specify the number of the port.
The valid range is 0 - 65535.
Select one of the keywords from the list: DOMAIN, ECHO, FTP, FTPDATA, HTTP,
SMTP, SNMP, TELNET, TFTP, and WWW. Each of these values translates into its
equivalent port number, which is used as both the start and end of a port range.
Destination Prefix and Prefix Length
. Enter a prefix of up to 128 bit combined with
prefix length to be compared to a packet's destination IP address as a match criteria
for the selected IPv6 ACL rule. The valid range for a prefix length is 0 - 128.
Destination L4 Port
. Specify a packet's destination layer 4 port as a match condition
for the selected IPv6 ACL rule. Destination port information is optional. Destination
port information can be specified in two ways:
Select keyword
other
from the drop-down list, and specify the number of the port.
The valid range is 0 - 65535.
Select one of the keywords from the list: DOMAIN, ECHO, FTP, FTPDATA, HTTP,
SMTP, SNMP, TELNET, TFTP, and WWW. Each of these values translates into its
equivalent port number, which is used as both the start and end of a port range.
IPv6 DSCP Service
. Select the IPv6 DSCP service. If you prefer, you can select the
Other
option in the drop-down list and enter the numeric value of the DSCP in the
adjacent field. The DSCP is defined as the high-order 6 bits of the service type octet
in the IPv6 header. This configuration is optional. Enter an integer from 0 to 63.
4.
To add an IPv6 rule, select the global check box and click
ADD
.
To delete a IPv6 rule, select the checkbox of the rule you want to delete and click
DELETE
.
Click
APPLY
to submit the changes to the switch.
Configuration changes take effect immediately.
IP Binding Configuration
When an ACL is bound to an interface, all the rules that have been defined are applied to the
selected interface. Use the IP Binding Configuration screen to assign ACL lists to ACL
Priorities and Interfaces.
To configure IP ACL interface bindings:
1.
Select
Security
ACL
>
Advanced
IP Binding Configuration
.