Access Control
Configuring IPv6-based ACEs
Cisco 220 Series Smart Switches Administration Guide Release 1.1.0.x
245
17
-
Destination IP Address Value
—Enter the IP address to which the
destination MAC address will be matched and its mask (if relevant).
-
Destination IP Prefix Length
—Enter the prefix length of the IP address.
•
Source Port
—Select one of the following:
-
Any
—Match to all source ports.
-
Single
—Enter a single TCP/UDP source port to which packets are
matched. This field is active only if TCP or UDP is selected from the
Select from list
drop-down menu.
-
Range
—Select a range of TCP/UDP source ports to which the packet is
matched.
•
Destination Port
—Select one of the available values. (They are the same as
for the
Source Port
field.)
NOTE
You must select an IPv6 protocol for the ACE before you configure the
source and destination ports.
•
TCP Flags
—Select one of more TCP flags with which to filter packets.
Filtered packets are either forwarded or dropped. Filtering packets by TCP
flags increases packet control, which increases network security.
-
Set
—Match if the flag is SET.
-
Unset
—Match if the flag is Not SET.
-
Don’t care
—Ignore the TCP flag.
•
Type of Service
—Select the service type of IP packets. The options are:
-
Any
—Any service type.
-
DSCP to match
—Differentiated Serves Code Point (DSCP) to match.
-
IP Precedence to match
—IP precedence is a model of TOS (type of
service) that the network uses to help provide the appropriate QoS
commitments. This model uses the 3 most significant bits of the service
type byte in the IP header, as described in RFC 791 and RFC 1349.
ICMP
—If the ACL is based on ICMP, select the ICMP message type that will
be used for filtering purposes. The options are:
-
Any (IP)
—All message types are accepted.
-
Select from list
—Select the message type by name from the drop-down
list.