
Security Measures
159
Instruction Manual - NXA-ENET8-POE+
Perform these steps to add rules to an IPv4 Standard ACL:
1.
Click
Security
>
ACL
.
2.
Select
Configure ACL
from the Step list.
3.
Select
Add Rule
from the Action list.
4.
Select IP Standard from the Type list.
5.
Select the name of an ACL from the Name list.
6.
Specify the action (i.e., Permit or Deny).
7.
Select the address type (Any, Host, or IP). If you select Host, enter a specific address. If you select IP, enter a subnet address
and the mask for an address range.
8.
Click
Apply
.
Configuring an Extended IPv4 ACL
Use the Security > ACL (Configure ACL - Add Rule - IP Extended) page to configure an Extended IPv4 ACL.
The following table lists the options on this page:
FIG. 188
Configuring a Standard IPv4 ACL
Security - ACL Options
Type
Selects the type of ACLs to show in the Name list.
Name
Shows the names of ACLs matching the selected type.
Action
An ACL can contain any combination of permit or deny rules.
Source/Destination Address Type
Specifies the source or destination IP address type. Use "Any" to include all possible
addresses, "Host" to specify a specific host address in the Address field, or "IP" to specify a
range of addresses with the Address and Subnet Mask fields. (Options: Any, Host, IP; Default:
Any)
Source/Destination IP Address
Source or destination IP address
Source/Destination Subnet Mask
Subnet mask for source or destination address. (See the description for Subnet Mask on
Source/Destination Port
Source/destination port number for the specified protocol type. (Range: 0-65535)
Source/Destination Port Bit Mask
Decimal number representing the port bits to match. (Range: 0-65535)
Protocol
Specifies the protocol type to match as TCP, UDP or Others, where others indicates a specific
protocol number (0-255). (Options: TCP, UDP, Others; Default: Others)
The following items are listed under TCP:
• Control Code - Decimal number (representing a bit string) that specifies flag bits in byte 14 of
the TCP header. (Range: 0-63)
• Control Code Bit Mask - Decimal number representing the code bits to match. (Range: 0-63)
The control bit mask is a decimal number (for an equivalent binary bit mask) that is applied to the
control code. Enter a decimal number, where the equivalent binary bit "1" means to match a bit and
"0" means to ignore a bit. The following bits may be specified:
• 1 (fin) - Finish
• 2 (syn) - Synchronize
• 4 (rst) - Reset
• 8 (psh) - Push
• 16 (ack) - Acknowledgement
• 32 (urg) - Urgent pointer
For example, use the code value and mask below to catch packets with the following flags set:
• SYN flag valid, use control-code 2, control bit mask 2
• Both SYN and ACK valid, use control-code 18, control bit mask 18
• SYN valid and ACK invalid, use control-code 2, control bit mask 18