Motorola WiNG 5.7.1 System Reference Manual page 499

Table of Contents

Advertisement

Figure 6-13 WLAN Security - IP Firewall Rules - IP Firewall Rules Add Criteria screen
NOTE: Only those selected IP ACL filter attributes display. Each value can have its
current settings adjusted by selecting that IP ACL's column to display a pop-up to adjust
that one value.
9. Define the following parameters for either inbound or outbound IP firewall rules:
Precedence
Allow
DNS Name
DNS Match Type
Source
Specify or modify a precedence for this IP policy between 1-1500. Rules with lower
precedence are always applied to packets first. If modifying a precedence to apply a
higher integer, it will move down the table to reflect its lower priority.
Every IP firewall rule is made up of matching criteria rules. The action defines what to do
with the packet if it matches the specified criteria. The following actions are supported:
• Deny - Instructs the firewall to prohibit a packet from proceeding to its destination.
• Allow - Instructs the firewall to allow a packet to proceed to its destination.
Specify the DNS Name which may be a full domain name, a portion of a domain name or
a suffix. This name is used for the DNS Match Type criteria.
Specify the DNS matching criteria that the DNS Name can be matched against. This can
be configured as an exact match for a DNS domain name, a suffix for the DNS name or a
domain that contains a portion of the DNS name. If traffic matches the configured criteria
in the DNS Match Type, that rule will be applied to the ACL.
Select the source IP address or network group configuration used as a basis matching
criteria for this IP ACL rule. Source options include:
• Any – Indicates any host device in any network.
• Network – Indicates all hosts in a particular network. Subnet mask information has to
be provided for filtering based on network.
• Host – Indicates a single host with a specific IP address.
• Alias – Indicates a collection of IP addresses or hostnames or IP address ranges which
are configured as a single unit. This is for ease of configuration of ACLs. When
selected, all IP addresses or hostnames or IP address ranges are used in this ACL.
6 - 29

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents