<source-tcp/udp-port>
<destination-tcp/udp-port> Enter the destination TCP or UDP port number.
match-all <tcp-flags>
match-any <tcp-flags>
Filtering traffic with ICMP packets
Use the following parameters if you want to filter traffic that contains ICMP packets. These
parameters apply only if you specified icmp as the <ip-protocol> value.
BigIron RX Series Configuration Guide
53-1001810-01
Configuring numbered and named ACLs
Enter the source TCP or UDP port number.
If you specified TCP for <ip-protocol>, you can specify which flags inside the TCP
header need to be matched. Specify any of the following flags for <tcp-flags>:
•
+ | – urg = Urgent
•
+ | – ack= Acknowledge
•
+ | – psh + Push
•
+ | – rst = Reset
•
+ | – syn = Synchronize
•
+ | – fin = Finish
Use a + or – to indicate if the matching condition requires the bit to be set to 1 (+) or
0 (–), separating each entry with a space.
Enter match-all if you want all the flags you specified to be matched from an
"established TCP session; use match-any of any of the flags will be matched.
21
525