This page is for creating new access lists, or for changing the settings of existing access lists.
Enter the settings, and then press the "Confirm" button.
If there are no mistakes in the input content of the confirmation screen, press the "OK" button.
-
Access list
-
Select the access list type from the following items.
-
IPv4 access list
-
IPv6 access list
-
MAC access list
-
When changing the settings, the access list type cannot be changed.
-
The IPv6 access list settings cannot be configured when the stack function is enabled.
-
Access list ID
-
Set the configurable access list ID from the following ranges, according to the access list type.
-
IPv4 access lists
-
IPv6 access lists
-
MAC access lists
-
When changing the settings, the access list ID cannot be changed.
-
Description
-
Control conditions
-
Specify the control conditions for the access list.
-
Up to 256 control conditions can be configured per access list.
-
Press the "Add" button to display the "Control condition settings" dialog.
-
In the "Control condition settings"dialog, you can specify conditions for which traffic is permitted anddenied as per the following items.
-
Operation
-
Source address
-
Select the source address to be targeted from the following items.
-
If the wildcard mask bit is "1," the bit in the same address position will not be checked.
-
When specifying the conditions for subnet 192.168.1.0/24, do so as shown below.
-
When specifying the conditions for vendor code 00-A0-DE---*, do so as shown below.
-
Destination address
-
Protocol
-
Select the protocol to be targeted from the following items.
-
All protocols
-
TCP
-
UDP
-
ICMP
-
Specify protocol number
-
When selecting TCP or UDP as a protocol, specifying the source and destination port numbers.
-
When selecting TCP as a protocol, you can specify the conditions regarding the TCP vendor control flag.
-
If more than one bit is specified, it works under the AND condition. Packets with all the specified bits set to 1 are targets.
-
For example, you can deny only TCP connections from outside to inside by allowing only packets withACK bit or RST bit of 1 for the interface’s direction.
-
In this case, you need to settwo control conditions. One is to allow packets with an ACK bit value of 1, and the other is to allow packets with an RST bit value of 1.
-
This cannot be specified for a MAC access list or a IPv6 access list.
-
Press the "Delete" button to delete the corresponding control conditions.
-
Press the
or
icons to change the order in which the control conditions are applied.
-
When evaluating the control conditions,control conditions with earlier numbers will be evaluated first; and ifthe conditions match, the conditions that follow will not be checked.