Brocade Communications Systems ServerIron ADX 12.4.00 Service Manual Page 82

  • Download
  • Add to my manuals
  • Print
  • Page
    / 149
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 81
70 ServerIron ADX NAT64 Configuration Guide
53-1002444-02
Configuring rule-based ACLs
5
DRAFT: BROCADE CONFIDENTIAL
If you do not specify a message type, the ACL applies to all types of ICMP messages.
The <icmp-num> parameter can be a value from 0 through 255.
The <icmp-type> parameter can have one of the following values, depending on the software
version the device is running:
any-icmp-type
echo
echo-reply
information-request
log
mask-reply
mask-request
parameter-problem
redirect
source-quench
time-exceeded
timestamp-reply
timestamp-request
unreachable
<num>
The <operator> parameter specifies a comparison operator for the TCP or UDP port number. This
parameter applies only when you specify tcp or udp as the IP protocol. For example, if you are
configuring an entry for HTTP, specify tcp eq http. You can enter one of the following operators:
eq : The policy applies to the TCP or UDP port name or number you enter after the the eq
operand.
gt: The policy applies to TCP or UDP port numbers greater than the port number or the numeric
equivalent of the port name you enter after the gt operand.
lt: The policy applies to TCP or UDP port numbers that are less than the port number or the
numeric equivalent of the port name you enter after the lt operand.
neq: The policy applies to all TCP or UDP port numbers except the port number or port name
you enter after the neq operand.
range: The policy applies to all TCP or UDP port numbers that are between the first TCP or UDP
port name or number and the second one you enter following the range parameter. The range
includes the port names or numbers you enter. For example, to apply the policy to all ports
between and including 23 (Telnet) and 53 (DNS), enter the following: range 23 53. The first
port number in the range must be lower than the last number in the range.
established: This operator applies only to TCP packets. If you use this operator, the policy
applies to TCP packets that have the ACK (Acknowledgment) or RST (Reset) bits set on (set to
“1”) in the Control Bits field of the TCP packet header. Thus, the policy applies only to
established TCP sessions, not to new sessions. Refer to Section 3.1, “Header Format”, in RFC
793 for information about this field.
NOTE
This operator applies only to destination TCP ports, not source TCP ports.
Page view 81
1 2 ... 77 78 79 80 81 82 83 84 85 86 87 ... 148 149

Comments to this Manuals

No comments