Configuring Device Security
Defining Access Control
ESW 500 Series Switches Administration Guide
161
5
Add IP Based ACL Page
The
Add IP Based ACL Page
contains the following fields:
•
ACL Name — Defines the user-defined IP based ACLs.
•
New Rule Priority — Indicates the rule priority, which determines which rule is
matched to a packet on a first-match basis.
•
Protocol — Creates an ACE based on a specific protocol. For a list of available
protocols, see the Protocol field description in the
IP Based ACL Page
above.
•
Source Port — Defines the TCP/UDP source port to which the ACE is matched.
This field is active only if 800/6-TCP or 800/17-UDP are selected in the Select
from List drop-down list. The possible field range is 0 - 65535.
•
Destination Port — Defines the TCP/UDP destination port. This field is active
only if 800/6-TCP or 800/17-UDP are selected in the Select from List drop-
down list. The possible field range is 0 - 65535.
•
TCP Flags — Filters packets by TCP EtherChannel. Filtered packets are either
forwarded or dropped. Filtering packets by TCP EtherChannels increases
packet control, which increases network security. Once the box is checked,
there are other parameters that can be selected from the dropdown menu:
-
Urg — Urgent
-
Ack — Acknowledgement