Advanced ACL

In this user interface, you can create advanced ACL rules. You can also change the existing advanced ACL rules.

Navigation Path

In the NE Explorer, click the NE and choose Security > ACL from the Function Tree. Click Advanced ACL tab.

Parameters

Table 1 Parameters relevant to the advanced ACL

Field

Value

Description

Rule No.

For example: 5

Displays the rule number.

Operation Type

Permit, Deny

Sets the operation type of this basic ACL rule. For example, if the Operation Type is Permit, all the IP packet that applies to this rule can be transmitted by this NE.

Source IP Address

For example: 192.168.0.1

Sets the source IP address.

Source Wildcard

For example: 192.255.255.0

Sets the source wildcard. The wildcard can define a range of the IP addresses.

Sink IP Address

For example: 192.168.0.100

Sets the sink IP address.

Sink Wildcard

For example: 192.255.255.0

Sets the sink wildcard. The wildcard can define a range of the IP addresses.

Protocol Type

IP, TCP, UDP, ICMP

Defaut: IP

Sets the type of the transmission protocol.

Source Port

For example: 1

Sets the source port number.

You can only set this parameter while the Protocol Type is TCP or UDP.

Sink Port

For example: 2

Sets the sink port number.

You can only set this parameter while the Protocol Type is TCP or UDP.

ICMP Protocol Type

information request (obsolete), source quench (elementary flow control), echo request (Ping request), time exceeded, information reply (obsolete), address mask reply, destination unreachable, parameter problem, address mask request, timestamp request, route advertisement, timestamp reply, route solicitation, redirect, echo reply

Sets the ICMP protocol type.

You can only set this parameter while the Protocol Type is ICMP.

ICMP Code Type

information request (obsolete), source quench (elementary flow control), echo request (Ping request), time exceeded, information reply (obsolete), address mask reply, destination unreachable, parameter problem, address mask request, timestamp request, route advertisement, timestamp reply, route solicitation, redirect, echo reply

Sets the ICMP code type.

You can only set this parameter while the Protocol Type is ICMP.


Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.