User Manual

Table Of Contents
Manage Device Security
663
M6100, M5300, and M7100 Series Managed Switches
The source IP UDP port names are domain, echo, ntp, rip, snmp, tftp, time, who.
Each of these values translates into its equivalent port number, which is used as both the
start and end of the port range.
Only when you select Other in the list of port keys, can you enter your own port number.
If you leave the Other field empty, it means any.
22. When you select the Range option, IP ACL rule matches only if the Layer 4 port number is
within the specified port range.
The Start Port and End Port parameters identify the first and last ports that are part of the
port range. They values can range from 0 to 65535.
The possibility of entering your own port number is available only when Other is selected
in the list of port keys. The starting port, ending port, and all ports in between are a part of
the Layer 4 port range. If these fields are left empty, it means any.
The wildcard mask determines which bits are used and which bits are ignored. A wildcard
mask of 0.0.0.0 indicates that none of the bits are important. A wildcard of
255.255.255.255 indicates that all of the bits are important.
23. In the Dst field, specify a destination IP address, using dotted-decimal notation, and with a
relevant wildcard mask.
This is compared to a packet's destination IP address as a match criteria for the selected
extended IP ACL rule.
24. Select the IP Address option and enter an IP address with a relevant wildcard mask to
apply this criteria.
If these fields are left empty, it means any.
25. When you select the Host option, the wildcard mask is configured as 0.0.0.0.
If this field is left empty, it means any.
26. In the Destination IP Mask field, specify the IP mask, in dotted-decimal notation, to be used
with the destination IP address value.
27. In the Dst L4 Port and Dst L4 Range fields, specify the Layer 4 destination port match
condition for the selected extended IP ACL rule.
These options are available only when the protocol is set to TCP or UDP.
Only when you select Other in the list of port keys, can you enter your own port number.
If you leave the Other field empty, it means any.
The destination IP TCP possible port names are bgp, domain, echo, ftp, ftp-data, http,
smtp, Telnet, www, pop2, pop3.
The destination IP UDP possible port names are domain, echo, ntp, rip, snmp, tftp,
time, who.
Each of these values translates into its equivalent port number, which is used as both the
start and end of the port range. This is an optional configuration.
28. Use Destination L4 Port Action to specify relevant matching conditions for L4 port
numbers in the current extended ACL rule: