Case 3: Deny IP packets to specific Class C network
Purpose:
Verify a positive and negative matches to network IP address with a Class C (24 bit mask) , no matter the rule defined
as permit or deny.
1.
Any packets pass through the switch will be dropped – if the Destination IP Addresses match specific Class
C.
2.
Any packets pass through the switch will be forwarded – if the Destination IP Addresses not match specific
Class C.
Case Design:
Action
Match
Source IP Address
Destination IP Address
Device Connection and Configuration:
Target
Any
DENY
IP
Any
Class C
172.16.0.0 / 255.255.255.0
ID
Source Address
3
Any
Stream
Destination Address
172.16.0.0 /
255.255.255.0
Protocol
Any
- 82 -