Manage Device Security
222
NETGEAR 24-Port Gigabit Smart Managed Pro Switch with PoE+ and 2 SFP Ports Model GS724TPv2
• True. Signifies that all packets must match the selected ACL and rule and are either
permitted or denied. In this case, since all packets match the rule, the option of
configuring other match criteria is not offered.
10. Specify the additional match criteria for the selected ACL type.
The rest of the rule match criteria fields available for configuration depend on the selected
ACL type. For information about the possible match criteria fields, see the following table.
11. For this procedure (in which an ACL based on the destination MAC address is created),
configure the following settings:
a. In the Destination MAC field, specify the destination MAC address that must be
compared against the information in an Ethernet frame.
The valid format is xx:xx:xx:xx:xx:xx. The BPDU keyword can be specified using a
destination MAC address of 01:80:C2:xx:xx:xx.
b. In the Destination MAC Mask field, specify the destination MAC address mask that
must be compared against the information in an Ethernet frame.
The valid format is xx:xx:xx:xx:xx:xx. The BPDU keyword can be specified using a
destination MAC mask of 00:00:00:ff:ff:ff.
ACL Based On Fields
Destination MAC
• Destination MAC. Specify the destination MAC address to compare against
an Ethernet frame. The valid format is xx:xx:xx:xx:xx:xx. The BPDU keyword
might be specified using a destination MAC address of 01:80:C2:xx:xx:xx.
• Destination MAC Mask. Specify the destination MAC address mask, which
represents the bits in the destination MAC address to compare against an
Ethernet frame. The valid format is xx:xx:xx:xx:xx:xx. The BPDU keyword
might be specified using a destination MAC mask of 00:00:00:ff:ff:ff.
• VLAN. Specify the VLAN ID to match within the Ethernet frame.
Source MAC
• Source MAC. Specify the source MAC address to compare against an
Ethernet frame. The valid format is xx:xx:xx:xx:xx:xx.
• Source MAC Mask. Specify the source MAC address mask, which
represents the bits in the source MAC address to compare against an
Ethernet frame. The valid format is (xx:xx:xx:xx:xx:xx).
• VLAN. Specify the VLAN ID to match within the Ethernet frame.
Destination IPv4
• Destination IP Address. Specify the destination IP address.
• Destination IP Mask. Specify the destination IP address mask.
Source IPv4
• Source IP Address. Specify the source IP address.
• Source IP Mask. Specify the source IP address mask.
Destination IPv4 L4 Port
• Destination L4 port (protocol). Specify the destination IPv4 L4 port
protocol.
• Destination L4 port (value). Specify the destination IPv4 L4 port value.
Source IPv4 L4 Port
• Source L4 port (protocol). Specify the source IPv4 L4 port protocol.
• Source L4 port (value). Specify the source IPv4 L4 port value.