A
CCESS
C
ONTROL
L
ISTS
3-65
For example, use the code value and mask below to catch packets with
the following flags set:
- SYN flag valid, use control-code 2, control bitmask 2
- Both SYN and ACK valid, use control-code 18, control bitmask
18
- SYN valid and ACK invalid, use control-code 2, control bitmask
18
Web – Specify the action (i.e., Permit or Deny). Specify the source and/or
destination addresses. Select the address type (Any, Host, or IP). If you
select “Host,” enter a specific address. If you select “IP,” enter a subnet
address and the mask for an address range. Set any other required criteria,
such as service type, protocol type, or TCP control code. Then click Add.
Figure 3-29 ACL Configuration - Extended IP