User Manual

Table Of Contents
Managing Device Security
486
M6100 Web Management User Guide
Only when you select Other in the list of port keys, can you enter your own port number.
If you leave the Other field empty, it means any.
The Destination IP TCP possible port names are bgp, domain, echo, ftp, ftp-data,
http, smtp, telnet, www, pop2, pop3.
The Destination IP UDP possible port names are domain, echo, ntp, rip, snmp, tftp,
time, who.
Each of these values translates into its equivalent port number, which is used as both the
start and end of the port range. This is an optional configuration.
21. Use Destination L4 Port Action to specify relevant matching conditions for L4 port
numbers in the current extended ACL rule:
Equal IP ACL rule matches only if the layer 4 source port number is equal to the
specified port number or port key.
Less Than IP ACL rule matches if the layer 4 source port number is less than the
specified port number or port key.
Greater Than IP ACL rule matches if the layer 4 source port number is greater than
the specified port number or port key.
Not Equal IP ACL rule matches only if the layer 4 source port number is not equal to
the specified port number or port key.
22. When you select the Range option, IP ACL rule matches only if the layer 4 port number is
within the specified port range. The Start Port and End Port parameters identify the first and
last ports that are part of the port range. They have values from 0 to 65535.
The possibility of entering your own port number is available only when Other is selected
in the list of port keys. The Destination L4 Start Port starting port, Destination L4 End Port
ending port, and all ports in between will be a part of the layer 4 port range. If these fields
are left empty, it means any.
23. IGMP Type - When IGMP type is specified, IP ACL rule matches with the specified IGMP
message type. Possible values are in the range 0 to 255. If this field is left empty, it means
any.
24. ICMP Type and ICMP Code - The ICMP Type and ICMP Code fields are enabled only if the
protocol is ICMP. Use the ICMP Type and ICMP Code fields to specify a match condition for
ICMP packets.
When the ICMP Type option is selected, IP ACL rule matches with the specified ICMP
message type, a possible type number is in the range from 0 to 255.
When the ICMP Code option is specified, IP ACL rule matches with the specified
ICMP message code. Possible values for Code could be in the range from 0 to 255.
If these fields are left empty, it means any.
When the Message option is selected, choose the type of the ICMP message to
match with the selected IP ACL rule. Specifying Message implies that both ICMP type
and ICMP code are specified. ICMP message is decoded into corresponding ICMP
type and ICMP code within that ICMP type. IPv4 ICMP message types are: echo,
echo-reply, host-redirect, mobile-redirect, net-redirect, net-unreachable, redirect,