User Guide
594
Configuring ACL
ACL Configuration
D-IP/Mask
Enter the destination IP address with a mask. A value of 1 in the mask
indicates that the corresponding bit in the address will be matched.
IP Protocol
Select a protocol type from the drop-down list. The default is No Limit, which
indicates that packets of all protocols will be matched. You can also select
User-defined to customize the IP protocol.
TCP Flag
If TCP protocol is selected, you can configure the TCP Flag to be used for the
rule’s matching operations. There are six flags and each has three options,
which are *, 0 and 1. The default is *, which indicates that the flag is not used
for matching operations.
URG
: Urgent flag.
ACK
: Acknowledge flag.
PSH
: Push flag.
RST
: Reset flag.
SYN
: Synchronize flag.
FIN
: Finish flag.
S-Port / D-Port
If TCP/UDP is selected as the IP protocol, specify the source and destination
port number with a mask.
Value
: Specify the port number.
Mask
: Specify the port mask with 4 hexadacimal numbers.
DSCP
Specify a DSCP value to be matched between 0 and 63. The default is No
Limit.
IP ToS
Specify an IP ToS value to be matched between 0 and 15. The default is No
Limit.
IP Pre
Specify an IP Precedence value to be matched to be matched between 0 and
7. The default is No Limit.
Time Range
Select a time range during which the rule will take effect. The default
value is No Limit, which means the rule is always in effect. The Time Range
referenced here can be created on the
SYSTEM > Time Range
page.
Logging
Enable Logging function for the ACL rule. Then the times that the rule is
matched will be logged every 5 minutes and a related trap will be generated.
You can refer to Total Matched Counter in the ACL Rules Table to view the
matching times.
2) In the
Policy
section, enable or disable the Mirroring feature for the matched packets.
With this option enabled, choose a destination port to which the packets will be
mirrored.
Downloaded from