User Guide
OmniAccess SafeGuard OS Administration Guide
347
Chapter 9: End Point Validation
source Specifies the source endpoint of the traffic.
It can be any of the following:
■ any – Wildcard, which matches all source
■ host – IP address or MAC address of the
host
■ macmask – MAC mask of the host
■ network – IP address of the subnet
■ network-zone – MAC address, IP address,
network address, or address range
■ range – IP address range
■ role – a user role
■ NOT – Negates the from criteria, except
for ‘any’
destination Specifies the destination endpoint of the
traffic. It can be any of the following:
■ any – Wildcard, which matches all
destination.
■ host – IP address of the host
■ network – IP address of the subnet
■ network-zone – IP address, network
address, or address range
■ range – IP address range
■ NOT – Negates the from criteria, except
for ‘any’
protocol Matches the IP protocol of the traffic. It can
be any of the following:
■ any – Wildcard, which matches TCP or
UDP protocols and application
■ tcp – TCP
■ udp – UDP; specify protocol port number
and the port operation:
1 to 65535 – End port or the start of the
end port
GE – Greater than or equal to
NE – Not equal to
LE – Less than or equal to
range – Destination TCP port range
out-of-range – Out of the destination TCP
port range
bypass The only valid action is bypass, which
bypasses EPV policy.










