User's Manual

Table Of Contents
Users Manual of SGS-5240 Series Managed Switch
191
Extended Ipv4 Acl
ACL > Rule Configuration > Ip Extended page is used to configure an Extended IPv4 ACL.
ACL Name Shows the names of ACLs matching the selected type.
Action An ACL can contain any combination of permit or deny rules.
Source/Destination Address Type Specifies the source or destination IP address type. Use “Any” to include all possible
addresses, “Host” to specify a specific host address in the Address field, or “IP” to specify a range of addresses with the
Address and Subnet Mask fields. (Options: Any, Host, IP; Default: Any)
Source/Destination IP Address Source or destination IP address.
Source/Destination Subnet Mask Subnet mask for source or destination address. (See the description for Subnet Mask .)
Source/Destination Port Source/destination port number for the specified protocol type. (Range: 0-65535)
Source/Destination Port Bit MaskDecimal number representing the port bits to match. (Range: 0-65535)
Protocol Specifies the protocol type to match as TCP, UDP or Others, where others indicates a specific protocol number
(0-255). (Options: TCP, UDP, Others; Default: Others)
Service Type Packet priority settings based on the following criteria:
Precedence IP precedence level. (Range: 0-7)
DSCP DSCP priority level. (Range: 0-63)
Control Code Decimal number (representing a bit string) that specifies flag bits in byte 14 of the TCP header. (Range: 0-63)
Control Code Bit Mask Decimal number representing the code bits to match. (Range: 0-63) The control bit mask is a
decimal number (for an equivalent binary bitmask) that is applied to the control code. Enter a decimal number, where the
equivalent binary bit “1” means to match a bit and “0”means to ignore a bit. The following bits may be specified:
1 (fin) Finish
2 (syn) Synchronize
4 (rst) Reset
8 (psh) Push
16 (ack) Acknowledgement
32 (urg) Urgent pointer For example, use the code value and mask below to catch packets with the following flags
set:
SYN flag valid, use control-code 2, control bit mask 2
Both SYN and ACK valid, use control-code 18, control bit mask 18