Specifications

Creating and Committing a Security ACL
RoamAbout Mobility System Software Configuration Guide 15-5
Wildcard Masks
WhenyouspecifysourceanddestinationIPaddressesinanACE,youmustalsoincludeamask
foreachintheformsourceipaddrmaskanddestinationipaddrmask.
Themaskisawildcardmask.ThesecurityACLchecksthebitsinIPaddressesthatcorrespondto
any0
s(zeros)inthemask, butdoesnotcheckthebitsthatcorrespondto1s(ones)inthemask.
SpecifytheIPaddressandwildcardmaskindotteddecimalnotation.Forexample,theIPaddress
andwildcardmask10.0.0.0and0.255.255.255matchallIPaddressesthatbeginwith10in
thefirst
octet.
Class of Service
Classofservice(CoS)assignmentdeterminestheprioritytreatmentofpacketstransmittedbya
RAS,correspondingtoaforwardingqueueontheAP.Table 152showstheresultsofCoS
prioritiesyouassigninsecurityACLs.
12
Table 15-1 Common IP Protocol Numbers
Number IP Protocol
1 Internet Message Control Protocol (ICMP)
2 Internet Group Management Protocol (IGMP)
6 Transmission Control Protocol (TCP)
9 Any private interior gateway (used by Cisco for Internet Gateway Routing Protocol)
17 User Datagram Protocol (UDP)
46 Resource Reservation Protocol (RSVP)
47 Generic Routing Encapsulation (GRE) protocol
50 Encapsulation Security Payload for IPSec (IPSec-ESP)
51 Authentication Header for IPSec (IPSec-AH)
55 IP Mobility (Mobile IP)
88 Enhanced Interior Gateway Routing Protocol (EIGRP)
89 Open Shortest Path First (OSPF) protocol
103 Protocol Independent Multicast (PIM) protocol
112 Virtual Router Redundancy Protocol (VRRP)
115 Layer Two Tunneling Protocol (L2TP)
Table 15-2 Class-of-Service (CoS) Packet Handling
WMM Priority Desired CLI CoS Value to Enter
Background 1 or 2
Best effort 0 or 3
Video 4 or 5
Voice 6 or 7