Netgear GSM7212P GSM5212P/GSM7212P/GSM7212F/GSM7224P User Manual - Page 299

Match Every, Protocol Keyword, TCP Flag, Src IP Address, Src IP Mask, Src L4 Port, Service Type

Page 299 highlights

Web Management User Guide cannot be set if a Redirect Interface is already configured for the ACL rule. This field is visible for a 'Permit' Action. • Match Every - Select true or false from the pull-down menu. True signifies that all packets will match the selected IP ACL and Rule and will be either permitted or denied. In this case, since all packets match the rule, the option of configuring other match criteria will not be offered. To configure specific match criteria for the rule, remove the rule and re-create it, or re-configure 'Match Every' to 'False' for the other match criteria to be visible. • Protocol Keyword - Specify that a packet's IP protocol is a match condition for the selected IP ACL rule. The possible values are ICMP, IGMP, IP, TCP, and UDP. • TCP Flag - Specify that a packet's TCP flag is a match condition for the selected IP ACL rule. The TCP flag values are URG,ACK,PSH,RST,SYN,FIN. Each TCP flag has these possible values below and can be set separately. • Ignore -A packet matches this ACL rule whatever the TCP flag in this packet is set or not. • Set(+) - A packet matches this ACL rule if the TCP flag in this packet is set. • Clear(-) - A packet matches this ACL rule if the TCP flag in this packet is not set. • Src IP Address - Enter an IP address using dotted-decimal notation to be compared to a packet's source IP Address as a match criteria for the selected IP ACL rule. • Src IP Mask - Specify the IP Mask in dotted-decimal notation to be used with the Source IP Address value. • Src L4 Port - Specify a packet's source layer 4 port as a match condition for the selected extended IP ACL rule. This is an optional configuration. The possible values are DOMAIN, ECHO, FTP, FTPDATA, HTTP, SMTP, SNMP, TELNET, TFTP, and WWW. Each of these values translates into its equivalent port number, which is used as both the start and end of the port range. • Dst IP Address - Enter an IP address using dotted-decimal notation to be compared to a packet's destination IP Address as a match criteria for the selected extended IP ACL rule. • Dst IP Mask - Specify the IP Mask in dotted-decimal notation to be used with the Destination IP Address value. • Dst L4 Port - Specify the destination layer 4 port match conditions for the selected extended IP ACL rule. The possible values are DOMAIN, ECHO, FTP, FTPDATA, HTTP, SMTP, SNMP, TELNET, TFTP, and WWW. Each of these values translates into its equivalent port number, which is used as both the start and end of the port range. This is an optional configuration. • Service Type - Select a Service Type match condition for the extended IP ACL rule from the pull-down menu. The possible values are IP DSCP, IP precedence, and IP TOS, which are alternative ways of specifying a match criterion for the same Service Type field in the IP header, however each uses a different user notation. After a selection is made the appropriate value can be specified. • IP DSCP - Specify the IP DiffServ Code Point (DSCP) field. The DSCP is defined as the high-order six bits of the Service Type octet in the IP header. This is an optional configuration. Enter an integer from 0 to 63. The IP DSCP is selected by 299

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385

299
Web Management User Guide
cannot be set if a Redirect Interface is already configured for the ACL rule. This field
is visible for a 'Permit' Action.
Match Every
- Select true or false from the pull-down menu. True signifies that all
packets will match the selected IP ACL and Rule and will be either permitted or
denied. In this case, since all packets match the rule, the option of configuring other
match criteria will not be offered. To configure specific match criteria for the rule,
remove the rule and re-create it, or re-configure 'Match Every' to 'False' for the other
match criteria to be visible.
Protocol Keyword
- Specify that a packet's IP protocol is a match condition for the
selected IP ACL rule. The possible values are ICMP, IGMP, IP, TCP, and UDP.
TCP Flag
- Specify that a packet's TCP flag is a match condition for the selected IP
ACL rule. The TCP flag values are URG,ACK,PSH,RST,SYN,FIN. Each TCP flag has
these possible values below and can be set separately.
Ignore -A packet matches this ACL rule whatever the TCP flag in this packet is set
or not.
Set(+) - A packet matches this ACL rule if the TCP flag in this packet is set.
Clear(-) - A packet matches this ACL rule if the TCP flag in this packet is not set.
Src IP Address
- Enter an IP address using dotted-decimal notation to be compared
to a packet's source IP Address as a match criteria for the selected IP ACL rule.
Src IP Mask
- Specify the IP Mask in dotted-decimal notation to be used with the
Source IP Address value.
Src L4 Port
- Specify a packet's source layer 4 port as a match condition for the
selected extended IP ACL rule. This is an optional configuration. The possible values
are DOMAIN, ECHO, FTP, FTPDATA, HTTP, SMTP, SNMP, TELNET, TFTP, and
WWW. Each of these values translates into its equivalent port number, which is used
as both the start and end of the port range.
Dst IP Address
- Enter an IP address using dotted-decimal notation to be compared
to a packet's destination IP Address as a match criteria for the selected extended IP
ACL rule.
Dst IP Mask
- Specify the IP Mask in dotted-decimal notation to be used with the
Destination IP Address value.
Dst L4 Port
- Specify the destination layer 4 port match conditions for the selected
extended IP ACL rule. The possible values are DOMAIN, ECHO, FTP, FTPDATA,
HTTP, SMTP, SNMP, TELNET, TFTP, and WWW. Each of these values translates into
its equivalent port number, which is used as both the start and end of the port range.
This is an optional configuration.
Service Type
- Select a Service Type match condition for the extended IP ACL rule
from the pull-down menu. The possible values are IP DSCP, IP precedence, and IP
TOS, which are alternative ways of specifying a match criterion for the same Service
Type field in the IP header, however each uses a different user notation. After a
selection is made the appropriate value can be specified.
IP DSCP
- Specify the IP DiffServ Code Point (DSCP) field. The DSCP is defined
as the high-order six bits of the Service Type octet in the IP header. This is an
optional configuration. Enter an integer from 0 to 63. The IP DSCP is selected by