Chapter 4 Service Configuration
Parameter Description
Parameter
Description
<
1-500
>
Rule number.
permit
If the condition matches, access is permitted.
deny
If the condition matches, access is denied.
icmp
This rule only matches ICMP message. Non-ICMP message
ignores this rule.
<
source-ipaddr
>
IP address of the source network or host transmitting packets. It is
a 32-bit IP address expressed in dotted decimal notation.
<
sip-mask
>
Source mask used for sources. It is a 32-bit IP address expressed
in dotted decimal notation.
any
(first)
The any keyword is used as the abbreviation of the source 0.0.0.0
and the source mask 0.0.0.0.
<
destination-ipaddr
>
Destination network or host of the transmitted packet. It is a 32-bit
IP address expressed in dotted decimal notation.
<
dip-mask
>
Destination mask used for destination. It is a 32-bit IP address
expressed in dotted decimal notation.
any
(second)
The any keyword is used as the abbreviation of the destination
0.0.0.0 and the destination mask 0.0.0.0
icmp-type
<
0-254
>
This rule is only valid for messages with the specified icmp-type
value. Ignore this rule for other messages. The range of icmp-type
is 0 to 254.
The icmp-type parameter will resolve some known icmp types.
Also the type number can be directly entered.
<
icmp-code
>
This rule is only valid for messages with the specified <
icmp-code
>
value. Ignore this rule for other messages. The range of
<
icmp-code
> is 0 to 254.
dscp
<
0-63
>
This rule is only valid for messages with the specified DSCP value.
Ignore this rule for other messages. The range of DSCP is 0 to 63.
fragment
This rule is only valid for fragment messages. Non–fragment
messages ignore this rule.
Guidelines
The ICMP rule can match ICMP packets with specified source IP addresses, any source IP
address, specified destination IP addresses, any destination IP address, ICMP-type fields,
ICMP-code fields, DSCP fields, or IP fragment fields.
4-221
SJ-20130731155059-003|2013-11-27 (R1.0)
ZTE Proprietary and Confidential