Chapter 17 Firewall
EX5501-B0 / AX7501-B0 / PX7501-B0 User’s Guide
214
Figure 131
Security > Firewall > Access Control
The following table describes the labels in this screen.
17.4.1 Add/Edit an ACL Rule
Click
Add
new ACL rule
or the
Edit
icon next to an existing ACL rule in the
Access Control
screen. The
following screen displays. Use this screen to accept, reject, or drop packets based on specified
parameters, such as source and destination IP address, IP Type, service, and direction. You can also
specify a limit as to how many packets this rule applies to at a certain period of time or specify a
schedule for this rule.
Table 83 Security > Firewall > Access Control
LABEL
DESCRIPTION
Add New ACL
Rule
Click this to add a filter rule for incoming or outgoing IP traffic.
#
This is the index number of the entry.
Name
This displays the name of the rule.
Src IP
This displays the source IP addresses to which this rule applies. Please note that a blank source
address is equivalent to
Any
.
Dst IP
This displays the destination IP addresses to which this rule applies. Please note that a blank
destination address is equivalent to
Any
.
Service
This displays the transport layer protocol that defines the service and the direction of traffic to
which this rule applies.
Action
This field displays whether the rule silently discards packets (
DROP
), discards packets and sends a
TCP reset packet or an ICMP destination-unreachable message to the sender (
REJECT
) or allows
the passage of packets (
ACCEPT
).
Modify
Click the
Edit
icon to edit the rule.
Click the
Delete
icon to delete an existing rule. Note that subsequent rules move up by one
when you take this action.
Click the
Move To
icon to change the order of the rule. Enter the number in the # field.