Concept Guide

Table Of Contents
497| ip access-list session Dell Networking W-Series ArubaOS 6.5.x| Reference Guide
Parameter Description
appcategory: application category name. (For a complete list of supported
applications, issue the command show dpi application all.)
tcp destination port number: specify the TCP port number (0-65535)
tcp source: TCP/UDP source port number
udp: specify the UDP port number (0-65535)
web-cc-category: name of an a web content category. For the full list of available web
content categories, issue the command show web-cc categories.
web-cc-reputation: any of the predefined web content reputation levels.
l high-risk
l low-risk
l moderate-risk
l suspicious
l trustworthy
<action>
Action if rule is applied, which can be one of the following:
deny: Reject packets. Applicable to both IPv4 and IPv6.
dst-nat: Performs destination NAT on packets. Forward packets from source network
to destination; re-mark them with destination IP of the target network. This action
functions in tunnel/decrypt-tunnel forwarding mode. User should configure the NAT
pool in the controller.
dual-nat: Performs both source and destination NAT on packets. Source IP and
destination IP is changed as per the NAT pool configured. This action functions in
tunnel/decrypt-tunnel forwarding mode. User should configure the NAT pool in the
controller.
permit: Forward packets. Applicable to both IPv4 and IPv6.
redirect: Specify the location to which packets are redirected. The following are
applicable only to IPv4:
l Datapath destination ID (0-65535).
l esi-group: Specify the ESI server group configured with the esi group command.
l tunnel: Specify the ID of the tunnel configured with the interface tunnel command.
webcc-reputation: Assign one of the predefined web content reputation levels to the
packets.
The following are applicable only to IPv6:
l tunnel:Specify the ID of the tunnel configured with the interface tunnel command.
l tunnel-group: Specify the tunnel-group configured with the interface tunnel
command.
route: Specify the next hop to which packets are routed, which can be one of the
following:
l dst-nat: Destination IP changes to the IP configured from the NAT pool. This action
functions in bridge/split-tunnel forwarding mode. User should configure the NAT
pool in the controller.
l src-nat:Source IP changes to RAP’s external IP. This action functions in bridge/split-