Specifications
IP Access Control Lists
ExtremeWare XOS 11.0 Concepts Guide 151
first-fragments Non-IP fragmented packet or first fragmented packet. FO==0. All IP
Source-port {<number> |
<range>}
TCP or UDP source port. In place of the numeric value, you can
specify one of the text synonyms listed under destination port.
TCP, UDP
Destination-port {<number> |
<range>}
TCP or UDP destination port. Normally, you specify this match in
conjunction with the protocol match to determine which protocol
is being used on the port. In place of the numeric value, you can
specify one of the following text synonyms (the field values are
also listed): afs(1483), bgp(179), biff(512), bootpc(68),
bootps(67), cmd(514), cvspserver(2401), DHCP(67), domain(53),
eklogin(2105), ekshell(2106), exec(512), finger(79), ftp(21),
ftp-data(20), http(80), https(443), ident(113), imap(143),
kerberos-sec(88), klogin(543), kpasswd(761), krb-prop(754),
krbupdate(760), kshell(544), idap(389), login(513),
mobileip-agent(434), mobileip-mn(435), msdp(639),
netbios-dgm(138), netbios-ns(137), netbios-ssn(139), nfsd(2049),
nntp(119), ntalk(518), ntp(123), pop3(110), pptp(1723),
printer(515), radacct(1813), radius(1812), rip(520), rkinit(2108),
smtp(25), snmp(161), snmptrap(162), snpp(444), socks(1080),
ssh(22), sunrpc(111), syslog(514), tacacs-ds(65), talk(517),
telnet(23), tftp(69), timed(525), who(513), xdmcp(177),
zephyr-clt(2103), or zephyr-hm(2104).
TCP-flags <bitfield> TCP flags. Normally, you specify this match in conjunction with
the protocol match statement. In place of the numeric value, you
can specify one of the following text synonyms (the field values
are also listed): ACK(0x10), FIN(0x01), PUSH(0x08), RST(0x04),
SYN(0x02), URG(0x20), SYN_ACK(0x12).
TCP
IGMP-msg-type <number> IGMP message type. Possible values and text synonyms:
v1-report(0x12), v2-report(0x16), v3-report(0x22), V2-leave
(0x17), or query(0x11)
IGMP
ICMP-type <number> ICMP type field. Normally, you specify this match in conjunction
with the protocol match statement. In place of the numeric value,
you can specify one of the following text synonyms (the field
values are also listed): echo-reply(0), echo-request(8),
info-reply(16), info-request(15), mask-request(17),
mask-reply(18), parameter-problem(12), redirect(5),
router-advertisement(9), router-solicit(10), source-quench(4),
time-exceeded(11), timestamp(13), timestamp-reply(14), or
unreachable(3).
ICMP
Table 28: ACL match conditions (continued)
Match Conditions Description
Applicable
IP Protocols