WESM zl Management and Configuration Guide WT.01.03 and greater

7-17
Access Control Lists (ACLs)
Configuring ACLs
Creating Rules for Extended IP ACLs
Configuring rules for an extended IP ACL is similar to configuring rules for
standard IP ACLs. However, these rules can also select traffic by protocol,
application, and destination IP address.
Refer to Table 7-4 to verify that a particular option is supported for the
interface to which you plan to apply the ACL. An X under the interface means
that the option is supported for that interface.
Table 7-4. Valid Options for Extended IP ACLs Depending on Interface
To create a rule for an extended IP ACL, complete these steps:
1. On the Security > ACLs > Configuration screen, in the ACL section, select an
extended IP ACL.
2. Click the Add button under Associated Rules. The Add Rule screen is
displayed.
Option VLAN Interface Uplink Port Downlink Port
deny operation X X X
permit operation X X X
mark operation X X
source IP address
and mask
XXX
destination IP
address and mask
XXX
protocol X X X
protocol options X X X
WLAN index X