User Guide

OmniAccess SafeGuard OS Administration Guide
347
Chapter 9: End Point Validation
source Specifies the source endpoint of the traffic.
It can be any of the following:
any – Wildcard, which matches all source
host – IP address or MAC address of the
host
macmask – MAC mask of the host
network – IP address of the subnet
network-zone – MAC address, IP address,
network address, or address range
range – IP address range
role – a user role
NOT – Negates the from criteria, except
for ‘any’
destination Specifies the destination endpoint of the
traffic. It can be any of the following:
any – Wildcard, which matches all
destination.
host – IP address of the host
network – IP address of the subnet
network-zone – IP address, network
address, or address range
range – IP address range
NOT – Negates the from criteria, except
for ‘any’
protocol Matches the IP protocol of the traffic. It can
be any of the following:
any – Wildcard, which matches TCP or
UDP protocols and application
tcp – TCP
udp – UDP; specify protocol port number
and the port operation:
1 to 65535 – End port or the start of the
end port
GE – Greater than or equal to
NE – Not equal to
LE – Less than or equal to
range – Destination TCP port range
out-of-range – Out of the destination TCP
port range
bypass The only valid action is bypass, which
bypasses EPV policy.