Motorola WiNG 5.7.1 System Reference Manual page 643

Table of Contents

Advertisement

Action
Source
Destination
Protocol
Network Service Alias
Source Port
Destination Port
Every IP firewall rule is made up of matching criteria rules. The action defines what to do
with the packet if it matches the specified criteria. The following actions are supported:
• Deny - Instructs the firewall to prohibit a packet from proceeding to its destination.
• Allow - Instructs the firewall to allow a packet to proceed to its destination.
Select the source for creating the ACL. Source options include:
• Any – Indicates any host device in any network.
• Network – Indicates all hosts in a particular network. Subnet mask information has to
be provided for filtering based on network.
• Host – Indicates a single host with a specific IP address.
• Alias – Indicates a collection of IP addresses or hostnames or IP address ranges which
are configured as a single unit. This is for ease of configuration of ACLs. When
selected, all IP addresses or hostnames or IP address ranges are used in this ACL.
Select the destination for creating the ACL. Destination options include:
• Any – Indicates any host device in any network.
• Network – Indicates all hosts in a particular network. Subnet mask information has to
be provided for filtering based on network.
• Host – Indicates a single host with a specific IP address.
• Alias – Indicates a collection of IP addresses or hostnames or IP address ranges which
are configured as a single unit. This is for ease of configuration of ACLs. When
selected, all IP addresses or hostnames or IP address ranges are used in this ACL.
Set a service alias as a set of configurations consisting of protocol and port mappings.
Both source and destination ports are configurable. Set an alphanumeric service alias
(beginning with a $) and include the protocol as relevant.
The service alias is a set of configurations consisting of protocol and port mappings. Both
source and destination ports are configurable. Set an alphanumeric service alias
(beginning with a $ character and containing one special character) and include the
protocol as relevant. Selecting either tcp or udp displays an additional set of specific TCP/
UDP source and destinations port options.
If using either tcp or udp as the protocol, define whether the source port for incoming IP
ACL rule application is any, equals or an administrator defined range. If not using tcp or
udp, this setting displays as N/A. This is the data local origination virtual port designated
by the administrator. Selecting equals invokes a spinner control for setting a single
numeric port. Selecting range displays spinner controls for Low and High numeric range
settings. A source port cannot be a destination port.
If using either tcp or udp as the protocol, define whether the destination port for incoming
IP ACL rule application is any, equals or an administrator defined range. If not using tcp or
udp, this setting displays as N/A. This is the data local origination virtual port designated
by the administrator. Selecting equals invokes a spinner control for setting a single
numeric port. Selecting range displays spinner controls for Low and High numeric range
settings.
8 - 19

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents