Manage Device Security
324
Insight Managed 28-Port Gigabit Ethernet Smart Cloud Switch with 2 SFP 1G & 2 SFP+ 10G Fiber Ports
The relevant matching conditions for L4 port numbers are as follows:
•
Equal
. IP ACL rule matches only if the Layer 4 source port number is equal to
the specified port number or port protocol.
•
Not Equal
. IP ACL rule matches only if the Layer 4 source port number is not
equal to the specified port number or port protocol.
•
Less Than
. IP ACL rule matches if the Layer 4 source port number is less
than the specified port number.
•
Greater Than
. IP ACL rule matches if the Layer 4 source port number is
greater than the specified port number.
-
Range radio button
. If you select the
Range
radio button, the IP ACL rule
matches only if the Layer 4 source port number is within the specified port range.
The starting port, ending port, and all ports in between are a part of the Layer 4
port range.
The
Start Port
and
End Port
fields identify the first and last ports that are part of
the port range. The values can range from 0 to 65535.
You can either enter the port range yourself or select one of the following
protocols from the menu:
•
The destination IP TCP port protocols are
domain
,
echo
,
ftp
,
ftpdata
,
www-http
,
smtp
,
telnet
,
pop2
,
pop3
, and
bgp
.
•
The destination IP UDP port protocols are
domain
,
echo
,
snmp
,
ntp
,
rip
,
time
,
who
, and
tftp
.
Each of these values translates into its equivalent port number, which is used as
both the start and end of the port range.
Select
Other
from the menu to enter a port number. If you select
Other
from the
menu but leave the field blank, it means
any
.
The wildcard mask determines which bits are used and which bits are ignored. A
wildcard mask of 0.0.0.0 indicates that
none
of the bits are important. A wildcard
of 255.255.255.255 indicates that
all
of the bits are important.
•
Dst
. In the
Dst
field, enter a destination IP address, using dotted-decimal notation, to
be compared to a packet’s destination IP address as a match criterion for the selected
IP ACL rule:
-
If you select the
IP Address
radio button, enter an IP address with a relevant
wildcard mask to apply this criteria. If this field is left empty, it means
any
.
-
If you select the
Host
radio button, the wildcard mask is configured as 0.0.0.0. If
this field is left empty, it means
any
.
The wildcard mask determines which bits are used and which bits are ignored. A
wildcard mask of 0.0.0.0 indicates that
none
of the bits are important. A wildcard of
255.255.255.255 indicates that
all
of the bits are important.