
Industrial Managed
Ethernet Switch
User Manual
錯誤
!
使用
[
常用
]
索
引標籤將
Heading
1,Product Manual
套用到您想要在此處
顯示的文字。
Page
124
of
191
The main ACL entries for filtering by IP layer (also called L3 filtering) as shown in Figure 2.138 include IP Protocol,
Source IP Address, Destination IP address, TCP/UDP Source Port, TCP/UDP Destination Port and TOS. Table
2.48 describes definition of each in details. Once again, note that if any field is empty, that ACL entry will be ignored.
Figure 2.138 Security Access Control List Information Webpage (IP Based Filtering)
Table 2.48 Description of Main ACL Entries for L3 Filtering in ACL Webpage
ACL Entry
Definition
Range
IP Protocol
The Protocol field of the IPv4 packet header
.
The
followings are examples
.
The value 1 is for an
ICMP packet
.
The value 6 is for the TCP packet
.
The value 17 is for the UDP packet
.
The item value is between 0~65535
.
Source or
Destination
IP Addresses
IP address are the fields of the IPv4 header. The
Mask item is a bit mask for comparing range.
For every non
-
zero bits in the Mask, its
relative bit in the IP address will be
compared
.
If the Mask is 0
.
0
.
0
.
0, then
this condition is always accepted
.
If the
Mask is empty, it is considered equal to
the Mask of 255.255.255.255 and all of
bits in the IP Address are compared
.
TCP
/
UDP
Source Port
/
TCP
/
UDP
Destination
Port
The fields of TCP
/
UDP frame header
.
It is used to
filter the application services
.
For example, the
TCP Destination Port 21 is for the FTP service, the
TCP Destination Port 23 is for the Telnet service
and the TCP Destination Port 80 is for the HTTP
service
.
To select which ports will follow the filter rule and
what action to take, check the checkbox
corresponding to that port and select choice of
“Deny”
or
“Permit”
in the action field
.
If this ACL
entry is match, rejecting packet if
‘Deny’ is
The item value is between 0~65535
.