Chapter 12
| Security Measures
Access Control Lists
–
288
–
◆
Action
–
An ACL can contain any combination of permit or deny rules.
◆
Source Address Type
–
Specifies the source IP address type. Use “Any” to
include all possible addresses, “Host” to specify a specific host address in the
Address field, or “IPv6
-
Prefix” to specify a range of addresses. (Options:
Any,
Host, IPv6-Prefix; Default: Any)
◆
Destination Address Type
–
Specifies the destination IP address type. Use
“Any” to include all possible addresses, or “IPv6
-
Prefix” to specify a range of
addresses. (Options: Any, IPv6-Prefix; Default: Any)
◆
Source
/
Destination IPv6 Address
–
An IPv6 address or network class. The
address must be formatted according to RFC 2373 “IPv6 Addressing
Architecture,”
using 8 colon-separated 16-bit hexadecimal values. One double
colon may be used in the address to indicate the appropriate number of zeros
required to fill the undefined fields.
◆
Source
/
Destination Prefix-Length
–
A decimal value indicating how many
contiguous bits (from the left) of the address comprise the prefix; i.e., the
network portion of the address. (Range: 0-128 bits for the source prefix; 0-8 bits
for the destination prefix)
◆
DSCP
–
DSCP traffic class. (Range: 0-63)
◆
Source Port
–
Protocol
7
source port number. (Range: 0-65535)
◆
Source Port Bit Mask
–
Decimal number representing the port bits to match.
(Range: 0-65535)
◆
Destination Port
–
Protocol
7
destination port number. (Range: 0-65535)
◆
Destination Port Bit Mask
–
Decimal number representing the port bits to
match. (Range: 0-65535)
◆
Next Header
–
Identifies the type of header immediately following the IPv6
header. (Range: 0-255)
Optional internet-layer information is encoded in separate headers that may be
placed between the IPv6 header and the upper-layer header in a packet. There
are a small number of such extension headers, each identified by a distinct Next
Header value. IPv6 supports the values defined for the IPv4 Protocol field in
RFC 1700, and includes these commonly used headers:
0 : Hop-by-Hop Options (RFC 2460)
6 : TCP Upper-layer Header (RFC 1700)
17 : UDP Upper-layer Header (RFC 1700)
43
: Routing (RFC 2460)
44
: Fragment (RFC 2460)
50
: Encapsulating Security Payload (RFC 2406)
51
: Authentication (RFC 2402)
7. Includes TCP, UDP or other protocol types.
Summary of Contents for GEL-5261
Page 14: ...14 Contents Glossary 551 Index 559...
Page 26: ...26 Figures...
Page 30: ...30 Section I Getting Started...
Page 42: ...42 Section II Web Configuration IP Services on page 527...
Page 45: ...Chapter 2 Using the Web Interface NavigatingtheWebBrowserInterface 45 Figure 1 Dashboard...
Page 62: ...62 Chapter 2 Using the Web Interface NavigatingtheWebBrowserInterface...
Page 180: ...Chapter 6 Address Table Settings Issuing MAC Address Traps 180...
Page 208: ...Chapter 8 Congestion Control Storm Control 208 Figure 121 Configuring Storm Control...
Page 228: ...228 Chapter 10 Quality of Service Attaching a Policy Map to a Port...
Page 332: ...Chapter 12 Security Measures ARP Inspection 332 Figure 207 Displaying the ARP Inspection Log...
Page 436: ...Chapter 13 Basic Administration Protocols LBD Configuration 436...
Page 488: ...488 Chapter 14 Multicast Filtering Filtering MLD Query Packets on an Interface...
Page 498: ...Chapter 15 IP Tools Address Resolution Protocol 498...
Page 517: ...517 Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 interface...
Page 542: ...540 Section III Appendices...
Page 560: ...Glossary 558...
Page 570: ...568 Index E062017 ST R01...