User Manual

Table Of Contents
8-Port or 16-Port Gigabit Smart Managed Pro Switch Model GS418TPP, GS510TLP, and GS510TPP
Manage Device Security User Manual374
Fragments. Either select the Enable radio button to allow initial fragments (that is,
the fragment bit is asserted) or leave the default Disable radio button selected to
prevent initial fragments from being used.
This option is not valid for rules that match L4 information such as a TCP port number,
because that information is carried in the initial packet.
Service Type. Select a service type match condition for the extended IP ACL rule.
The possible options are IP DSCP, IP precedence
, and IP TOS, which are alternative
methods to specify a match criterion for the same service type field in the IP header
.
Each method uses a different user notation. After you make a selection, you can
specify the appropriate values:
- IP DSCP. This is an optional configuration. Specify the IP Dif
fServ Code Point
(DSCP) field. The DSCP is defined as the high-order 6 bits of the service type
octet in the IP header. Enter an integer from 0 to 63. To select the IP DSCP, select
one of the DSCP keywords from the menu. To specify a numeric value, select
Other and a field displays in which you can enter numeric value of the DSCP.
- IP Precedence.
This is an optional configuration.
The IP precedence field in a
packet is defined as the high-order 3 bits of the service type octet in the IP header.
Enter an integer from 0 to 7.
- IP TOS. This is an optional configuration.
The IP ToS field in a packet is defined
as all 8 bits of the service type octet in the IP header. The ToS bits value is a
hexadecimal number that is composed of numbers 00 to 09 and AA to FF. The
ToS mask value is a hexadecimal number that is composed of numbers 00 to FF.
The ToS mask denotes the bit positions in the ToS bits value that are used for
comparison against the IP ToS field in a packet.
For example, to check for an IP ToS value for which bit 7 is set and is the most
significant value, for which bit 5 is set, and for which bit 1 is cleared, use a
T
oS
bits value of 0xA0 and a ToS mask of 0xFF.
9. Click the Apply button.
Your settings are saved.
Modify the match criteria for an extended IPv4 ACL rule
To modify the match criteria for an existing extended IPv4 ACL rule:
1. Connect your computer to the same network as the switch.
You can use a WiFi or wired connection to connect your computer to the network, or
connect directly to a switch that is off-network using an Ethernet cable.
2. Launch a web browser.
3. In the address field of your web browser, enter the IP address of the switch.
If you do not know the IP address of the switch, see
Change the default IP address of the
switch on page 13.
The login window opens.