4-63
Device Manager Guide, Cisco ACE 4700 Series Application Control Engine Appliance
OL-26645-02
Chapter 4 Configuring Virtual Contexts
Configuring Security with ACLs
Source
Source Network Defines the network traffic being received from the source network to the ACE:
• Any—Select the Any radio button to indicate that network traffic from any source is
allowed.
• IP/Netmask—(IPv4 address type) Use this field to limit access to a specific source IP
address. Enter the source IPv4 address that is allowed for this ACL and select its subnet
mask.
• IP/Prefix-length—(IPv6 address type) Use this field to limit access to a specific source IP
address. Enter the source IPv6 address that is allowed for this ACL and its prefix length.
• Network Object Group—Select a source network object group to apply to this ACL.
Source Port Operator This field appears if you select TCP or UPD in the Protocol field.
Choose the operand to use to compare source port numbers:
• Equal To—The source port must be the same as the number in the Source Port Number
field.
• Greater Than—The source port must be greater than the number in the Source Port
Number field.
• Less Than—The source port must be less than the number in the Source Port Number
field.
• Not Equal To—The source port must not equal the number in the Source Port Number
field.
• Range—The source port must be within the range of ports specified by the Lower Source
Port Number field and the Upper Source Port Number field.
Source Port Number This field appears if you select Equal To, Greater Than, Less Than, or Not Equal To in the
Source Port Operator field.
Enter the port name or number from which you want to permit or deny access.
Lower Source Port Number This field appears if you select Range in the Source Port Operator field.
Enter the number of the lowest port from which you want to permit or deny access. Valid
entries are integers from 0 to 65535. The number in this field must be less than the number
entered in the Upper Source Port Number field.
Upper Source Port Number This field appears if you select Range in the Source Port Operator field.
Enter the port number of the upper port from which you want to permit or deny access. Valid
entries are integers from 0 to 65535. The number in this field must be greater than the number
entered in the Lower Source Port Number field.
Table 4-17 Extended ACL Configuration Options (continued)
Field Description
Comments to this Manuals