Chapter 10 Firewall
P-660HN-51 User’s Guide
133
TCP Flag Mask This field is displayed only when you select Specific Protocol in Select Protocol and
TCP/UDP or TCP as the protocol.
You can select the TCP flags you want to check in this field. Select one or a
combination of the following TCP flags:
• SYN: synchronize flag
• ACK: acknowledge flag
• URG: urgent flag
• PSH: push flag
• RST: reset flag
• FIN: finish flag
TCP Flag This field is displayed only when you select Specific Protocol in Select Protocol and
TCP/UDP or TCP as the protocol.
After specifying the TCP flags to check, you can select the TCP flags you want to
set. If a flag is set, the bit number is 1. If a flag is not set, the bit number is 0. The Zyxel
Device will take the action that you select in the Policy field below to the TCP flags
that are set.
You can only set the TCP flags that you have selected to check in the TCP Flag
Mask field.
Policy Use the drop-down list box to select whether to discard (DROP), deny and send an
ICMP destination-unreachable message to the sender of (REJECT) or allow the
passage of (ACCEPT) packets that match this rule.
Direction Use the drop-down list box to select the direction of traffic to which this rule
applies.
Enable Rate Limit Select this check box to set a limit on the upstream/downstream transmission rate
for the specified protocol.
Specify how many packets per minute or second the transmission rate is.
Scheduler Rules Select a schedule rule for this ACL rule form the drop-down list box. You can
configure a new schedule rule by click Add new rule. This will bring you to the
Advanced > Scheduler Rules screen.
Apply Click Apply to save your changes.
Cancel Click Cancel to exit this screen without saving.
Table 43 Access Control: Add/Edit (continued)
LABEL DESCRIPTION