Editing And Creating Rules; Rule Criteria - Avaya G250 Administration

Media gateways
Hide thumbs Also See for G250:
Table of Contents

Advertisement

Configuring policy
Use IP wildcards to specify a range of source or destination IP addresses. The zero bits in the
wildcard correspond to bits in the IP address that remain fixed. The one bits in the wildcard
correspond to bits in the IP address that can vary. Note that this is the opposite of how bits are
used in a subnet mask.
For access control lists, you can require the packet to be part of an established TCP session. If
the packet is a request for a new TCP session, the packet does not match the rule. You can also
specify whether an access control list accepts packets that have an IP option field.

Editing and creating rules

To create or edit a policy rule, you must enter the context of the rule. If the rule already exists,
you can edit the rule from the rule context. If the rule does not exist, entering the rule context
creates the rule.
1. Enter the context of the list in which you want to create or edit a rule.
2. Type the command ip-rule, followed by the number of the rule you want to create or
edit. For example, to create rule 1, type ip-rule 1.
You can use the description command in the rule context to add a description of the rule.
This description is used in the AccessViolation Policy trap to identify and describe the IP rule in
which the trap was caused.
To view the existing rules in a list, enter the list's context and type ip show-rule. Each list
starts with a default rule. Each new rule has the same default parameters as the default rule.
The default rule appears as follows:
G350-001(super-ACL 301)# show ip-rule
Index Protocol
DSCP
----- -------- --- ---------------- --------------- ------------ --------------
Deflt
Any
Any
This rule permits all packets.

Rule criteria

Rules work in the following ways, depending on the type of list and the type of information in the
packet:
Layer 4 rules in an access control list with a Permit operation are applied to non-initial
fragments
540 Administration for the Avaya G250 and Avaya G350 Media Gateways
IP
Src
Any
Dst
Any
Wildcard
Port
Any
Any
Operation
Fragment rule
Permit
No

Advertisement

Table of Contents
loading

This manual is also suitable for:

G350

Table of Contents