Configuring an Extended IPv4 ACL

Complete the following steps to configure an extended IPv4 ACL.

  1. From the main menu, select Security > ACL.
    All the configured ACLs are listed in the main pane. You can perform the following actions:
    • Add an ACL: Continue to step 2 to add a new ACL.
    • Edit an ACL: Click the icon to display the Edit Access List dialog box. You can delete the existing rule or add new rules. Make the necessary changes and click Apply to apply the changes.
    • Delete an ACL: Click the icon to display the Delete Access List dialog box. Click Apply to delete the ACL.
  2. Click the icon to display the Add Access List dialog box.

    Adding an Extended IPv4 ACL

  3. Click the IPv4 tab and complete the following fields:
    • Name/ID: Enter a unique ACL name or number. If entering a name, the name must begin with an alphabetical character and can contain up to 47 alphanumeric characters.
    • Type: Select Extended from the list to create an extended IPv4 ACL.
  4. For Rules, click the icon to add ACL rules with the following parameters:
    • Seq: Assign a sequence number to the ACL rule; select a value (1–65000) using the spinner.
    • Action: Select Permit or Deny from the list to filter the traffic according to the rules.
    • Protocol: Select the protocol type (IP, TCP, or UDP) to be specified as a match for filtering.
    • Source IP: Enter the source IP address for which you want to filter the subnet.
    • Destination IP: Enter the destination IP address for which you want to filter the subnet.
    • Source Port: Specify the source port of the specified protocol (applies to TCP and UDP only).
    • Destination Port: Specify the destination port of the specified protocol (applies to TCP and UDP only).
    • DSCP Matching: Allows filtering by DSCP value; select a value (0–63) using the spinner.
    • DSCP Marking: Assign the DSCP value for the packet; select a value (0–63) using the spinner.
    • Internal Priority: Assign the internal queuing priority (traffic class) for the packet; select a value (0–7) using the spinner.
  5. Click Apply to create the extended IPv4 ACL.