S1700 Managed Series Ethernet Switches
Web User Manual
6 ACL Configuration
Issue 05 (2012-10-25)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
88
Table 6-6
Parameters of Extending IP Rules
Item
Description
ACL ID
ACL ID that entry rules belongs to.
Rule ID
Enter an ID for rule and the range is 1~65535. If not specified, the
system will distribute automatically.
Action
Specify switch to permit or deny data stream that matches to the rule.
Protocol Type
Specify IP protocol type that needs to be matched data.
Match IP Address
Source IP address: All Source IP - specify this rule to be applied to all
IP data packages; Specify Source IP/Mask - specify this rule to be
applied to the IP data package of specified IP address/mask. The IP
address will match the whole field if no mask entered.
Destination IP address: All Destination IP – specify this rule to be
applied to all IP data packages; Specify Destination IP/Mask - specify
this rule to be applied to the IP data package of specified IP
address/mask. The IP address will match the whole field if no mask
entered.
Match Port
Specify the TCP / UDP source port and destination port for data to be
matched.
Match Priority
Specify the IP priority and TOS fields for data to be matched.
TCP Flag
Specify the TCP flag field for data to be matched.
Match ICMP
Specify the matched data fields, including the ICMP type and ICMP
Message Code.
Fragments
Use checkbox to specify whether to match packet fragmentation for
this kind of protocol.
Time Range Name
Click the Select button to specify the effective period of the rules.
Step 3
Configure the needed parameter.
Step 4
Click Apply button to apply all the changes made.
----End
Create a Rule for Extending IPv6
Step 1
Click ACL>ACL Profile.
Step 2
Click a created extending IPv6 rule in ACL list, and click New button in the list box of ACL
Rule, opening the configuration page shown as the figure below.