IBM 8260 Switch User Manual


 
Source Address
This is the source address of the IP datagram against which the source
address of the IP datagram currently being processed is compared. A
value of 0.0.0.0 serves as a wildcard, indicating all IP addresses.
Source Mask
This is the address mask which is
logically ANDed
with the source
address in the table and the source address in the IP datagram. The two
results are then compared using the
operator
parameter.
Destination Address
This is the destination address of the IP datagram against which the
destination address of the IP datagram currently being processed is
compared. A value of 0.0.0.0 serves as a wildcard, indicating all IP
addresses.
Destination Mask
: This is the address mask which is
logically ANDed
with the destination address in the table and the destination address in
the IP datagram. The two results are then compared using the
operator
parameter.
Option
This parameter specifies whether an IP datagram with the options set in
the frame header should be subjected to the specified tests. This
parameter can have a
false
or
true
value.
False
means that the IP
datagram with options is not subjected to security tests. This parameter
has no affect on IP datagrams with no options.
Operand
This field specifies the number of the TCP or UDP destination port to be
compared with the incoming packet, according to the value configured
for
operator
.
Note: When displaying the contents of the IP security table, only a subset of
parameters set for each entry are displayed on the screen. To view the
remaining parameters, highlight the entry and press the Enter key.
An IP Security table may contain up to 64 entries.
2. Create an
IP Security Access List
to specify whether received or transmitted
(or both) packets are to be checked for each IP Security table defined in the
previous step. It also defines the action to be taken when a received or
transmitted packet matches the criteria defined in the Security table. To
define the IP security access list, you must select
IP Security Access List
from the
IP Menu
. An example of the panel which is displayed is shown in
Figure 184 on page 307.
306 8260 Multiprotocol Intelligent Switching Hub