Rockwell Automation Publication 1783-UM007G-EN-P - February 2017 187
Configure Switch Features Chapter 7
3. To define the ACL entry, click Add in the table area, and then complete
the fields.
4. Click Save.
5. Repeat Steps 3 and 4 to create as many conditions as needed.
6. To order the conditions in the list, use the Move buttons
.
7. Click Submit.
Field Description
Permit To permit traffic, check the checkbox.
To deny traffic, clear the checkbox.
An access list must contain at least one permit statement or all packets are denied entry into
the network.
Protocol (Extended ACL only). Type the following:
• The name or number of an IP protocol (AHP, EIGRP, ESP, GRE, ICMP, IGMP, IGRP, IP, IPINIP,
NOS, OSPF, PCP, PIM, TCP, or UDP)
or
• An integer in the range of 0…255 representing an IP protocol number
To match any internet protocol, including ICMP, TCP, and UDP, type IP.
Source Type Choose the source from which the packet is sent:
• Host
•Any
• Network
Source Address Type the address of the network or host from which the packet is sent.
Source Wildcard Type an ACL mask for the source.
Source Operator (Extended ACL only). To compare the source, choose an operator from the pull-down menu.
Source Port (Extended ACL only). Type the source port number to compare.
Valid values: 0…65535
Destination Type (Extended ACL only). Choose the type of the destination to which the packet is sent:
• Host
•Any
• Network
Dest Address (Extended ACL only). Type the network or host number to which the packet is sent.
Dest Wildcard (Extended ACL only). Type an ACL mask for the destination.
Dest Operator (Extended ACL only). To compare the destination, choose an operator from the pull-down
menu.
Dest Port (Extended ACL only). Type the destination port number to compare.
Valid values: 0…65535
IMPORTANT The order of the conditions is critical to whether a packet is
forwarded. The first condition in the list that matches a packet
allows the packet to be forwarded. After the first match, the switch
stops testing.