C
HAPTER
4: M
ANAGING
D
EVICE
S
ECURITY
Destination IP Address
— Matches the destination IP address to
which packets are addressed to the ACL.
Wild Card Mask
— Indicates the destination IP Address
wildcard mask. Wildcards are used to filter a destination IP
Address. Masks specify which bits are used and which bits are
ignored. A wildcard mask of 255.255.255.255 indicates that
no bit is important. A wildcard mask of 0.0.0.0 indicates that
all bits are important.
For example, if the destination IP address 149.36.184.198 and
the wildcard mask is 255.255.0.0, the first two bytes of the IP
address are used, while the last two bytes are ignored.
Match DSCP
— Matches the packet DSCP value to the ACL. Either
the DSCP value or the IP Precedence value is used to match
packets to ACLs.
Match IP Precedence
— Matches the packet IP Precedence value
to the ACE. Either the DSCP value or the IP Precedence value is
used to match packets to ACLs.
Action
— Indicates the ACL forwarding action. The options are as
follows:
Permit
— Forwards packets which meet the ACL criteria.
Deny
— Drops packets which meet the ACL criteria.