
5-40
Cisco Wireless LAN Controller Configuration Guide
OL-13826-01
Chapter 5 Configuring Security Solutions
Configuring and Applying Access Control Lists
Step 7 Follow these steps to configure a rule for this ACL:
a. The controller supports up to 64 rules for each ACL. These rules are listed in order from 1 to 64. In
the Sequence field, enter a value (between 1 and 64) to determine the order of this rule in relation
to any other rules defined for this ACL.
Note If rules 1 through 4 are already defined and you add rule 29, it is added as rule 5. If you add
or change a sequence number for a rule, the sequence numbers for other rules adjust to
maintain a contiguous sequence. For instance, if you change a rule’s sequence number from
7 to 5, the rules with sequence numbers 5 and 6 are automatically reassigned as 6 and 7,
respectively.
b. From the Source drop-down box, choose one of these options to specify the source of the packets to
which this ACL applies:
• Any—Any source (This is the default value.)
• IP Address—A specific source. If you choose this option, enter the IP address and netmask of
the source in the edit boxes.
c. From the Destination drop-down box, choose one of these options to specify the destination of the
packets to which this ACL applies:
• Any—Any destination (This is the default value.)
• IP Address—A specific destination. If you choose this option, enter the IP address and netmask
of the destination in the edit boxes.
d. From the Protocol drop-down box, choose the protocol ID of the IP packets to be used for this ACL.
These are the protocol options:
• Any—Any protocol (This is the default value.)
• TCP—Transmission Control Protocol
• UDP—User Datagram Protocol
• ICMP—Internet Control Message Protocol
• ESP—IP Encapsulating Security Payload
• AH—Authentication Header
• GRE—Generic Routing Encapsulation
• IP in IP—Internet Protocol (IP) in IP. Permits or denies IP-in-IP packets.
• Eth Over IP—Ethernet-over-Internet Protocol
• OSPF—Open Shortest Path First
• Other—Any other Internet Assigned Numbers Authority (IANA) protocol
Note If you choose Other, enter the number of the desired protocol in the Protocol edit box.
You can find the list of available protocols and their corresponding numbers here:
http://www.iana.org/assignments/protocol-numbers/protocol-numbers.xml
Note The controller can permit or deny only IP packets in an ACL. Other types of packets (such
as ARP packets) cannot be specified.
Komentáře k této Příručce